#modules

1 messages · Page 103 of 1

mortal shadow
#

it should work idk

gusty zinc
#

which section

mortal shadow
#

Advanced Command Obfuscation

#

click the link

#

without the pipe everything is working

gusty zinc
#

sending you a dm

#

Module: session security
Section: Skills Assessment
Question: Read the flag residing in the admin's public profile. Answer format: [string]

Anyone available for nudge?

mortal shadow
#

it can't be login

#

maybe the advanced document search on the top right

umbral wigeon
#

What are u stuck on?

umbral wigeon
mortal shadow
#

tinyfilemanager

umbral wigeon
#

yeah so it has got to do with file managing

mortal shadow
#

not sure if i understasnd what you mean

umbral wigeon
#

explore the webpage more and discover new functionalities that you would normally see when u think about file mangement

mortal shadow
#

but don't we need to do the inclusion on POST request?

red current
#

Got an issue. I've never used BloodHound on this VM before and it won't take the default password neo4j:BloodHound. Is there a way around this?

umbral wigeon
#

play around with the functions u discovered and take a look at the url GET parameters and try to do your command injections there

rustic sage
#

what is mean mounted file system?

fathom pendant
#

When you "mount" the filesystem you are telling your system that you wish to access the information on that shared folder(s)

fathom pendant
#

Technically speaking, when you plug in a USB storage device it mounts it to the system while plugged in

#

I'm referring more to remote file shares

rustic sage
fathom pendant
#

Basically, this is something you can also just google

zinc marsh
#

If I made a tunnel with ligolo, with what ip should I set the shell file?

#

I opened wireshark and I have this ip for the 172.16.x.y network

molten sequoia
#

Can anyone recommend VIP machines on HTB with real life scenarios and not CTF Style?

molten sequoia
#

That’s great thanks for the recommendation , I will try this

zinc marsh
quaint hemlock
#

hello? can someone help me with this?

latent sigil
#

im having trouble with the Attacking Common Services - Hard module

#

im at the final question but i cannot impersoante john

tight trout
#

Did you get anywhere on this? I've been banging my head against it for a bit now.

quaint hemlock
#

nvm, just solved it lol

burnt sluice
quaint hemlock
#

he probably asking for help

burnt sluice
#

you going down the pentester path?

#

ik it's off but i just noticed ur XSS question so i thought to ask u

fathom pendant
rustic sage
#

how the hell I get rid of this quote> thing? I know that its correct answer but everytime I get this quote thing

burnt sluice
#

so close it on the other end and u should be good to go

quaint hemlock
burnt sluice
quaint hemlock
#

not yet

burnt sluice
#

oke oke, ty

fringe tiger
#

hello guys, May I ask you about the Penetration Tester does it have any prerequires to go straight?

#

as I newbie to the cybersecurity world, which path should I take it?

maiden bear
#

Hi are there anyone has issue while working evil winrm and powerview

#

?

#

especially using Get-DomainObjectAcl ?

#

\

brittle herald
#

How do you guys manage your time with these modules? Curious to see how others are working through them.

quaint hemlock
heavy marsh
#

Going through the MySQL footprinting lesson, I had to use -T5 on the nmap script given in the lesson for the script to work.

#

That didn't give me the version, only the script information, so I had to run a scan without the script and just on the port to get that info

#

Any rhyme or reason, or is this just slow response time for HTB servers

#

?

#

sudo nmap <IP> -sV -sC -p3306 --script mysql* -T5

#

sudo nmap <IP> -sV -sC -p3306

#

this is the --script scan above

#

this is the normal port scan above

#

When I was doing the script scan without the -T5 it kept creeping up exponentially slower and slower towards 100% and stayed at an average of about 17 seconds remaining

#

forgot to add, I also used -vvv

#

Is this normal?

latent sigil
#

hello, how do i apply modifications to a sql server

#

i mean like execute them so they 'save'

#

or is it continuous

#

i think i found it in sql server configuration manager

#

im having trouble with one of the last steps in attacking common services hard

fathom pendant
heavy marsh
#

Is there a different port I should be using

fathom pendant
#

I don't recall using Nmap scripts for sql

latent sigil
heavy marsh
fathom pendant
#

Like I said I don't recall using Nmap to complete it

#

It's been a bit

heavy marsh
#

No rhyme or reason as to why my scans showed up the way they did. just had to do it in two scans

#

Nmap is used for the scanning section

#

then mysql for the interacting section

tight trout
digital viper
digital viper
quaint hemlock
digital viper
#

the goal is to download the file right?

quaint hemlock
#

you didn't have to download the file to get flag

#

just curl (target) do the job

digital viper
#

I mean the hint even suggests that I download the file

quaint hemlock
#

idk, I solved it without download any file

#

don't forget to add /download.php after the target

digital viper
#

yeah weirdly enough when I tried that it actually just didn't work at all

#

it went from giving responses to breaking entirely

#

idk, to be fair my copy and paste wasn't working properly and since it's late it's likely I just overlooked a typing error

#

I figure I'll try this tomorrow and have better luck, thank you for the help though.

quaint hemlock
#

try curl TARGET_IP:PORT/download.php

digital viper
#

yeah that's what I did

#

I terminated the process like 5 minutes ago because I had something come up but I just wanted to know if maybe I did something wrong

quaint hemlock
#

can you ss in dm what the result you got by using curl?

digital viper
#

again terminated but thank you for the help

quaint hemlock
#

okay

tawny axle
#

hi everyone. I have a problem with Wordpress hacking - Skills assessments.

#

Scan Aborted: The remote website is up, but does not seem to be running WordPress.

#

what should I do?

#

who can help me?

acoustic owl
tawny axle
#

I can't start a skill assessment because WPScan says the remote site is running, but wordpress isn't

autumn pilot
#

Enumerate

rustic sage
#

Can someone hint me in module attacking common applications, section osTicket. I login with kevin******** email and there's no open or closed tickets, i found other email and try to brute force it but doesn't work

pulsar needle
#

The exercise tells me this, but they only give me the nameserver, but I need a domain to be able to enumerate the server, how do i find this domain?

fathom pendant
#

Probably inlanefreight.htb

#

Or inlanefreight

tall saffron
#

There is a big problem with "AD enumeration & attacks", printnightmare and petitpotam doesnt work... Time to fix it, i Lost too much on it and not the only one.

pulsar needle
fathom pendant
#

It probably says it. But it's also not out of reason to assume

#

I'm glad they changed this to have the credentials instead of needing to hunt or use the hint

pulsar needle
#

Did you have to find the credentials before

#

?

#

F 💀

fathom pendant
#

The hint gave the credentials. But the previous way was connecting to a service and seeing the banner was a username. And using a weak wordlist to bruteforce it

#

People complained enough (rightfully) about it

tall saffron
#

And what about the AD modules @fathom pendant ? Can you make the issue raise UP the module owner or anyone who can fix the issue

fathom pendant
tall saffron
#

Ok will try

pulsar needle
#

Where can I find the SSH key, ive looked at all the txt records on the subdomains and there is none

#

I just have a shit ton of subdomains and subsubdomains now xd

fathom pendant
#

Well you're not gonna find ssh on dns

pulsar needle
#

But they told me to enumerate it

fathom pendant
#

Think. Why would they give you credentials

pulsar needle
#

i thought itwas going to be in a txt record

pulsar needle
#

Lol

fathom pendant
thorn urchin
#

why would anyone store a ssh key inside a txt record

#

even by ctf standards

pulsar needle
#

I have no clue, lol

fathom pendant
pulsar needle
#

I did, and I found some hostkeys

fathom pendant
#

If they're giving you credentials, they're intending you to use it for a running service

fathom pendant
#

Are you running a full Nmap scan, not against a specific port?

pulsar needle
#

Wait

fathom pendant
#

You narrowed your thought process way too early

pulsar needle
#

Whoops

fathom pendant
#

"Find as much information as possible "

pulsar needle
#

I thought they meant on the SSH/DNS things

#

Not including FTP

fathom pendant
#

Even when given some specific info: always verify that there isn't more. They only tell you the primary purpose of the server. Doesn't mean it can't be used for more

pulsar needle
#

Aaa I am not used to this, my teachers always told me to look, there is no other way or whatever

fathom pendant
#

You are given credentials, think of all services that can use credentials, verify if those services exist

#

All in your methodology

tall saffron
#

When it is in the assesment you must treat it like a normal CTF box

thorn urchin
#

you always look for more ways

pulsar needle
#

Huh, but I always think there is no way, but there is lmao

thorn urchin
#

there is never no way, only ways that arent realistically feasible with your resources or constraints

fathom pendant
#

That's the difference in making progress and getting stuck. Always check if you've tried everything

thorn urchin
#

and ways you havnt discovered yet. but never no way.

fathom pendant
#

Go step by step in your process

#

Dead branches happen, or paths not immediately available to you

pulsar needle
#

Thanks for letting me know hehe

fathom pendant
#

This is also why note taking is important. Even on skill assessments. Note what you've done, results, etc.

pulsar needle
#

ayayay

fathom pendant
#

It also helps you ask for assistance if you can properly provide info of what you have and haven't done. And sanity check specific processes

pulsar needle
#

Then I might need one now, I am on the FTP server trying to list directories and i get this

#

Nothing happens, but when I do "pwd" I get a response

fathom pendant
#

Maybe files are hidden

#

;)

pulsar needle
#

True

#

Nvm, I found .. and .

#

lol

fathom pendant
pulsar needle
#

Indeed

#

I found 4 ports

#

wait

#

there is a ftp server

#

lmao

#

no, port

fathom pendant
#

:)

#

Not on the default port*

pulsar needle
#

Yes, aaaa its nice, combining things and then its like quirky things trying to make you take the wrong decision

fathom pendant
#

Like I said. Get used to hitting a wall, then taking a step back and reevaluating

#

It's how you improve your methodology. Learning to think outside the box makes finding the right steps easier.
My general process is; what do I have, what can I access, how can I leverage it. As I find more things, the leverage gets easier to do

pulsar needle
#

aaa oke

fathom pendant
#

Also, because the skills assessments are wordy, learning how to boil down large blocks of text into important info

pulsar needle
#

Question, I did something and now I have this file I have no clue how to remove named "-R"

fathom pendant
#

For example with this lab:
The fact that it's a dns server is just a red herring.
You are told you cannot leverage any exploits (so no exploitdb or msf exploits).
You are given credentials, and told there is mention of ssh.
Finally you're told you're looking for a flag.txt

pulsar needle
#

It didnt, but i deleted the folder

#

And created it again

#

lol

fathom pendant
#

Or mv "-R" randomfilenamelol

fathom pendant
#

What you do with base info is purely up to your methodology. But if your methodology constantly runs into brick walls, maybe rethink how you approach the problem

pulsar needle
#

AAA

#

ITs a folder

#

Nvm

#

lol

fathom pendant
#

Yep

#

Your -la results show its a directory

#

Super simple once you start from a wide base to narrow it down

pulsar needle
#

Yes, it said something about that in the course aswell, like "The learning process" module, but its been like 4 months since i did that one heh

fathom pendant
#

That's why practice it every time is important

#

Even if you're told what you're looking for. Always doing the basics is important

pulsar needle
#

But thanks for the help

fathom pendant
#

Try changing to the directory first

#

Also a lot of your screenshots can be considered spoilers

pulsar needle
#

Sorry

thorn urchin
#

its all good, just common practice to delete them a short time after getting help about it

acoustic owl
#

This user has no rights to access the database

pulsar needle
#

Oh, ok

inner zephyr
#

yall tryna clikc this weird link i send yall?

acoustic owl
# pulsar needle Oh, ok

Because the user you are logged into Windows with has no rights to access the database.
Consider what role the user you found has and what the role is called in Windows.

burnt trail
#

Hi, I need some help with the "Public Exploits" module

#

Task: "Try to identify the services running on the server above, and then try to search to find public exploits to exploit them. Once you do, try to get the content of the '/flag.txt' file. (note: the web server may take a few seconds to start) "

#

i found out that the webserver is running a vulnerable version of the simple backup plugin

#

used metasploit and the "auxiliary(scanner/http/wp_simple_backup_file_read)" exploit however i only got shit back

#
cat /home/user/.msf4/loot/20230713110330_default_94.237.54.69_simplebackup.tra_540693.txt
root:x:0:0:root:/root:/bin/bash
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
bin:x:2:2:bin:/bin:/usr/sbin/nologin
sys:x:3:3:sys:/dev:/usr/sbin/nologin
sync:x:4:65534:sync:/bin:/bin/sync
games:x:5:60:games:/usr/games:/usr/sbin/nologin
man:x:6:12:man:/var/cache/man:/usr/sbin/nologin
lp:x:7:7:lp:/var/spool/lpd:/usr/sbin/nologin
mail:x:8:8:mail:/var/mail:/usr/sbin/nologin
news:x:9:9:news:/var/spool/news:/usr/sbin/nologin
uucp:x:10:10:uucp:/var/spool/uucp:/usr/sbin/nologin
proxy:x:13:13:proxy:/bin:/usr/sbin/nologin
www-data:x:33:33:www-data:/var/www:/usr/sbin/nologin
backup:x:34:34:backup:/var/backups:/usr/sbin/nologin
list:x:38:38:Mailing List Manager:/var/list:/usr/sbin/nologin
irc:x:39:39:ircd:/var/run/ircd:/usr/sbin/nologin
gnats:x:41:41:Gnats Bug-Reporting System (admin):/var/lib/gnats:/usr/sbin/nologin
nobody:x:65534:65534:nobody:/nonexistent:/usr/sbin/nologin
_apt:x:100:65534::/nonexistent:/usr/sbin/nologin
mysql:x:101:102:MySQL Server,,,:/nonexistent:/bin/false
systemd-timesync:x:102:103:systemd Time Synchronization,,,:/run/systemd:/usr/sbin/nologin
systemd-network:x:103:105:systemd Network Management,,,:/run/systemd:/usr/sbin/nologin
systemd-resolve:x:104:106:systemd Resolver,,,:/run/systemd:/usr/sbin/nologin
messagebus:x:105:107::/nonexistent:/usr/sbin/nologin
sshd:x:106:65534::/run/sshd:/usr/sbin/nologin
autumn pilot
#

In the exploit you need to specify what you want to get

burnt trail
#

makes sense

raw venture
#

Hello, I'm working on ATTACKING COMMON APPLICATIONS Splunk - Discovery & Enumeration but seems the splunk application is unstable. Already tried to restart 3 times and wait at least 15mins still can't connect to port 8000. Should I wait more?

autumn pilot
#

Are you using http or https

raw venture
#

http

autumn pilot
raw venture
#

I see

#

Thank you!

jagged herald
#

Hey guys! Am stuck with one of the HTB Academy's boxes. Basically, i obtained an RCE on a low level user. I realised that Nmap's SUID bits are set. However, I'm having difficulty performing privesc, as:

  1. nmap version does not allow for --interactive
  2. my user is not inside sudoers list, i cant use sudo

I have tried to manipulate by chmod u+s /bin/bash, but changing permissions was denied. Been stuck here for days, any help will be appreciated!

#

-rwsr-xr-x 1 root root 3026928 Mar 23 2020 /usr/bin/nmap

rare topaz
#

Preferably tell us which module and section ur working on

jagged herald
#

It’s a private box called liberty machine, not sure if you guys can access it though 😭

deft escarp
#

I'm on password attacks module, network services section. || I can't seem to find the right username and password list to brute force any of the services.||

vital adder
vital adder
deft escarp
#

Facepalm

#

Can't believe I missed that lmao

tranquil hornet
#

Hi!
I’m doing the “getting started” module, and I am stuck at the Privilege Escalation section last question.
Once you gain access to user2, try to find a way to escalate your privileges to root, to get the flag in /root/flag.txt. I manage to get access to the user2 and read the private key in the id_rsa file.
I then went back to my profile and copied the key to a file pkey.txt and add access limitation with the chmod 600 I then tried an ssh connection with the flag -i pkey.txt but it doesn’t work.
Any tips to move forward? Thanks in advance

split ruin
#

i'm having hard time with hard module on attacking common services

#

impersonated user, but cannot proceed further

whole grotto
#

Hi everyone, i'm in the kerberoasting from linux section in AD module, and when i want to enumerate the SPN the tool ask me for a password, but idk why it don't accept the password of htb-student

vital adder
vital adder
split ruin
vital adder
whole grotto
vital adder
whole grotto
split ruin
vital adder
#

that's the Skill Assessment 🤣

vital adder
split ruin
whole grotto
#

in the course they use the forend creds

#

but they don't give the creds

#

they don't give the password

sonic ferry
#

I'm stuck in "AD Enumeration & Attacks - Skills Assessment Part II" in question "Obtain credentials for a user who has GenericAll rights...". I have a|| Evil-WinRM ||connection and I have imported PowerView.ps1, but none of the PowerView commands work. Also when trying to run apps such as Mimikatz or Responder, I get an error "The specified executable is not a valid application for this OS platform". Even the hint says I should get the knowledge the same way as I did with the initial foothold, but that isn't even possible? Also tried RDPing with proxychains and chisel but it doesn't connect.

vital adder
vital adder
tranquil hornet
split ruin
vital adder
sonic ferry
timber ore
#

thanks @west canopy

sonic ferry
# vital adder wdym rdp with proxychains and chisel? you can use ssh dynamic port forwarding (`...

I'm still facing the problem that PowerView doesn't work at all. I can't passthehash with xfreerdp as any user, so I am stuck as a low privileged user (username & password) since none of the hashes could be cracked that I found. I'm missing something very badly here. Never been this badly stuck. Like am I supposed to try to figure out a way to become admin on the system or am supposed to tackle this problem without that account

novel matrix
graceful mortar
#

Someone could help me with Brute Forcing Cookies - Broken Authentication module? I'm stuck.

vital adder
vital adder
rustic sage
#

i do not understand what he mean by "Why is the printer network talking to the servers over HTTP?"

rustic arrow
coral wraith
#

Please can someone help me in this module: Attacking Common Services - Easy

coral wraith
#

I can upload the shell, but I don't know where it's stored

rare topaz
#

which module and which section

#

send screenshots, the commands used etc

#

istfg we need a verbosity flag for human interaction

graceful mortar
vital adder
#

oh that part should be straight forward, just use CyberChef

graceful mortar
whole grotto
#

I have a question ? can i find the objectAceType a user has over a group with bloodhound ??

rustic arrow
whole grotto
#

i can't get the ObjectAceType of the first right that the forend user has over the GPO Management group in the ACL section in the AD module can someone help me pls ?

maiden bear
#

Hi anyone has an issue while tunelling to internal target and accessing using xfreerdp?

#

i am able to access the target, with ping evilwinrm and others. but can not access the rdp

#

googling already didnt found the solution

zinc marsh
#

If I am member of administrators but there is no AD how can I open a cmd as administrator?

vital adder
flint steppe
#

Anyone know if there’s a channel where you can submit requests for future content?

vital adder
vital adder
vital adder
quick cairn
#

Anyone Please Help : Attacking Common Applications - Skills Assessment II What is the URL of the WordPress instance?

vital adder
quick cairn
quick cairn
rustic sage
sonic ferry
#

I managed to get to the end of AD skills assessment 2, but my NTLM hash isn't taken as a correct answer. Anyone care to elaborate?

vital adder
#

last question?

sonic ferry
#

Yes

vital adder
#

if you are using secretsdump for this try using -just-dc-user krbtgt just to make sure you got the right hash

sonic ferry
#

Yep I'm doing that, which is why I'm a bit confused

vital adder
#

so did you found answer?

sonic ferry
#

Well yes, but the form on the website says it's incorrect

vital adder
#

shoot me a dm with the hash that you got i'll confirm it for you

maiden bear
rustic sage
#

guys i do not understand this

prisma spruce
#

Oh, I see what they mean.

#

They basically scanned their own subnet but didn't scan any other subnets. I bet they didn't use -Pn too.

trail leaf
zinc marsh
#

am not sure if I am modifying it right

trail leaf
#

sure

mortal shadow
rustic sage
trail leaf
#

oh lol, I thought it was the pivoting one 😅

#

in that case, don't worry if you don't get it the first time, subnetting is always a slightly confusing topic at first

zinc marsh
west spindle
#

hey,
Any 1 can access Windows RDP labs?
I'm on DACLs attacks module and I can't RDP to any of the IPs, I tried multiple times + restart + from another server the same issue. Is this a known issue?

mortal shadow
#

anyone got that issue with basfucator as well?

running install
/usr/lib/python3/dist-packages/setuptools/command/install.py:34: SetuptoolsDeprecationWarning: setup.py install is deprecated. Use build and pip and other standards-based tools.
  warnings.warn(
/usr/lib/python3/dist-packages/setuptools/command/easy_install.py:146: EasyInstallDeprecationWarning: easy_install command is deprecated. Use build and pip and other standards-based tools.
  warnings.warn(
Traceback (most recent call last):
  File "/home/htb-ac-886032/Desktop/Bashfuscator/setup.py", line 32, in <module>
    setup(
  File "/usr/lib/python3/dist-packages/setuptools/__init__.py", line 108, in setup
    return distutils.core.setup(**attrs)
  File "/usr/lib/python3.9/distutils/core.py", line 148, in setup
    dist.run_commands()
  File "/usr/lib/python3.9/distutils/dist.py", line 966, in run_commands
    self.run_command(cmd)
  File "/usr/lib/python3/dist-packages/setuptools/dist.py", line 1213, in run_command
    super().run_command(command)
  File "/usr/lib/python3.9/distutils/dist.py", line 985, in run_command
    cmd_obj.run()
  File "/usr/lib/python3/dist-packages/setuptools/command/install.py", line 74, in run
    self.do_egg_install()
  File "/usr/lib/python3/dist-packages/setuptools/command/install.py", line 117, in do_egg_install
    cmd.ensure_finalized()  # finalize before bdist_egg munges install cmd
  File "/usr/lib/python3.9/distutils/cmd.py", line 107, in ensure_finalized
    self.finalize_options()
  File "/usr/lib/python3/dist-packages/setuptools/command/easy_install.py", line 335, in finalize_options
    self.local_index = Environment(self.shadow_path + sys.path)
  File "/usr/lib/python3/dist-packages/pkg_resources/__init__.py", line 1044, in __init__
    self.scan(search_path)
  File "/usr/lib/python3/dist-packages/pkg_resources/__init__.py", line 1077, in scan
    self.add(dist)
  File "/usr/lib/python3/dist-packages/pkg_resources/__init__.py", line 1096, in add
    dists.sort(key=operator.attrgetter('hashcmp'), reverse=True)
  File "/usr/lib/python3/dist-packages/pkg_resources/__init__.py", line 2631, in hashcmp
    self.parsed_version,
  File "/usr/lib/python3/dist-packages/pkg_resources/__init__.py", line 2685, in parsed_version
    raise packaging.version.InvalidVersion(f"{str(ex)} {info}") from None
pkg_resources.extern.packaging.version.InvalidVersion: Invalid version: '1.14.0-unknown' (package: gpg)
prisma spruce
#

So if they fat-thumbed a /25 instead of a /24, they would have missed out on half the addreses.

#

Reporting that the domain controller is down in an actual report is pretty funny tbh.

agile rapids
#

anybody able to give me some leads on shared object hijacking from linux priv esc mod?

#

nvm it just requries a glib version no.

tawny axle
#

hi there! who can help me with sqli in Web-Service & api attacks. I'm stack in here
Identify the username of the user that has a position of 736373 through SQLi.
My payload: Select+username+from+users+where+position=736373. It's doesn't work

tawny axle
#

nope, it's doesn't work too(

prisma spruce
uneven dune
#

guys i am confused with this question

fathom pendant
#

Ask your question

uneven dune
#

i am not sure if i need to put there the result of the name account or i need to get an access using that

#

or my machine is broken

#

i am confused

#

i got the results and try all the things but dont works

fathom pendant
#

The username

uneven dune
#

can be broken ?

#

let me show

fathom pendant
#

"User account"

uneven dune
#

with double cuotes ?

fathom pendant
#

No

#

I'm telling you what it's asking for

uneven dune
#

dont works

fathom pendant
#

I remember looking up my question

#

Are you sure you have the right account

uneven dune
#

yes

#

let me show you

fathom pendant
#

Look at all of the info given

rare topaz
#

what the hell XD

uneven dune
#

for example there is the output

#

i am not sure how to explain it XD

fathom pendant
#

...

uneven dune
#

because i think i can reveal some information to solve the module

fathom pendant
#

Because that's not how you're meant to get the answer

#

Lol

rare topaz
#

you're probably meant to be looking at logs.

uneven dune
#

but you know what exactly i do ?

prisma spruce
#

Use event logs via powershell

fathom pendant
#

There's a reason it tells you "event logon failures"

uneven dune
#

i am looking the logs

rare topaz
#

with what command

uneven dune
#

using get-winevent

#

adn put the result of bad loggon per grather than

rare topaz
#

wait shouldn't they literally tell you how to go about this from the module

fathom pendant
#

There's a way to filter it iirc I ended up using Google and stack overflow

rare topaz
rare topaz
#

bro is asking us as if he didnt read the module 😭

uneven dune
#

hm

fathom pendant
#

It's the windows command line module

uneven dune
#

my english is bad may be i miss something

tawny axle
rare topaz
tawny axle
#

omg why so hard

rare topaz
#

Anyways, i googled it and it was the first google result.

So.....

uneven dune
#

but in therory what i understand is this

#

i am understanding wrong ?

prisma spruce
rare topaz
rare topaz
fathom pendant
#

Yes

uneven dune
#

i back later i am stucked i need to think in another way

bright arrow
#

Yes

#

Keep on thinking sir

#

It is da way

uneven dune
#

xd

#

i dont be sacre to feel like stupid

rare topaz
#

i cant tell if this is a language issue or a skill issue

bright arrow
#

Both
But I like him

bright arrow
fathom pendant
#

Recheck the log section

prisma spruce
fathom pendant
#

It gives you some info that you may need to work around

prisma spruce
#

Maybe they're counting the number of users in $username

uneven dune
#

i count the logs

rare topaz
uneven dune
#

per user

rare topaz
#

do not count logs, just filter logs by event id

uneven dune
#

i filtered by the id an then i use a format table -wrap

fathom pendant
brittle wagon
#

Hey guys, thought id ask a question about the power of XSS, especially stored xss. If finding stored XSS exists on a web application. Could you not insert a php shell into the html so whenever the page is loaded the shell runs and connects to your local machine ?

fathom pendant
#

Literally first Google result

uneven dune
#

i litteraly do the same

#

and i thing the response starts with "A"

#

but dont works, i am doing something wrong but i am not sure what

fathom pendant
uneven dune
#

i go fo a coffe and i check again what i can miss

uneven dune
#

i back in 5 min

fathom pendant
#

Copy and paste from that website I linked

uneven dune
#

❤️

fathom pendant
#

It also explains each element

rare topaz
#

at least give us the command ur using

uneven dune
#

but that can be a spoiler for another people

#

i can do it ?

prisma spruce
#

Well, you aren't spoiling anything if it isn't working lol.

fathom pendant
#

You can delete it after we confirm or deny

uneven dune
uneven dune
#

wait me a sec

rare topaz
uneven dune
#

one of what i test is this one
||

Import-Module -Name Microsoft.PowerShell.Diagnostics
$eventLogName = 'Security'
$loginEvents = Get-WinEvent -FilterHashtable @{
    LogName = $eventLogName
    ID = 4625
}
$loginAttempts = @{}
foreach ($event in $loginEvents) {
    # Obtener el nombre de usuario del evento
    $username = $event.Properties[5].Value

    # Verificar si el usuario ya existe en el hash table, y si no, inicializar su contador en 0
    if (-not $loginAttempts.ContainsKey($username)) {
        $loginAttempts[$username] = 0
    }

    # Incrementar el contador de intentos de inicio de sesión para el usuario actual
    $loginAttempts[$username]++
}
foreach ($user in $loginAttempts.Keys) {
    $attempts = $loginAttempts[$user]
    Write-Output "Usuario: $user - Intentos de inicio de sesión fallidos: $attempts"
}

```||
pulsar needle
#

I tried to do a Nmap scan and I got this, I tried to connect to the ssh as htb and it didnt work, so I tried to login to pop3s and imaps without a username and password, neither worked

fathom pendant
uneven dune
#

if i put this one from the website

fathom pendant
#

You get a lot of info. But read through it. Just scroll through what it gives you

prisma spruce
uneven dune
#

if i use this one the result of the counts is the same for the name accounts
||```
Get-WinEvent -FilterHashTable @{LogName="Security"; ID=4625} | format-table -wrap

prisma spruce
#

The question doesn't ask who has the most failed login attempts.

#

It asks who had a rapid sequence of failed login attempts.

pulsar needle
uneven dune
#

yes but what i understand if that is the case the response if still in the "name account" right ?

#

i try all the possible name accounts and dont works

fathom pendant
uneven dune
fathom pendant
#

It will become glaringly obvious what user

#

They throw in a handful of extra fails for users to force you to look at the whole thing

gusty ermine
#

Hi Guys - Navigate to http://[Target IP]:8000, open the "Search & Reporting" application, and find through an SPL search against all 4624 events the account name that made the most login attempts within a span of 10 minutes? Any ideas?

#

sourcetype="WinEventLog:Security" Account_Name=*
| bucket _time span=10m
| stats count(eval(action="success")) as successes count(eval(action="failure")) as failures by Account_Name dest _time
| where successes>0 AND failures>5

uneven dune
# prisma spruce Yes.

so the answer still there in the name account, if that is the case i try with all posibilites, but i gonna keep there some hours more, i know i miss something, and i thing is something obiously that i cant see

fathom pendant
uneven dune
#

so you think i solve the another 9 cases using brutte force ?

#

i am just stucked, i back in some hours

fathom pendant
#

No. I'm saying you're trying to brute force this one

uneven dune
#

i gonna keep see the output

fathom pendant
#

Which is not needed

prisma spruce
#

@uneven dune Just look at the output and don't filter it.

fathom pendant
uneven dune
#

ok

#

thanks guys

fathom pendant
#

Cause it's possible the username being bruteforced isn't actually a username on the system

gusty ermine
#

Navigate to http://[Target IP]:8000, open the "Search & Reporting" application, and find through an SPL search against all 4624 events the account name that made the most login attempts within a span of 10 minutes? Any ideas?

#

ref to UNDERSTANDING LOG SOURCES & INVESTIGATING WITH SPLUNK Mini-Module

mortal shadow
#

sqlmap module is much fun

#

some courses are reaally good to learn

#

others need some better cleanup and especially not jumping from one tool to another outta nowhere

mortal shadow
#

how can i delete the local storage form sqlmap

#

--flush-session

midnight plinth
#

Hey hows it going. Did you get the answer to this one? I found the answer but dont quite understand how I got there and was wondering if anyone could help out (dont want to say anything and spoil it here)

tawdry vapor
#

can anyone help me with footprint module? The final question to DNS What is the FQDN of the host where the last octet ends with "x.x.x.203"?

supple radish
#

I am stuck on the password mutations oin the password attacks module. I have used the mutation file and used hashcat to mutate the password list provided and when I go to brute force ftp for the sam account user I can't find a valid password. I have split the wordlist into wordlists containing 10000 words that way I have better efficiency and am running -t 64 for hydra but even after doing all the wordlists I can't seem to get sam's password.

tawdry vapor
supple radish
#

i believe for that one you have to do a zone transfer to find the FQDN

pulsar needle
#

Am I on the right path on the skill assignment named "Footprinting labs hard"?

#

Idk If I have gone down a rabbithole

#

lmao

supple radish
#

Im looking at my notes from the footprinting lab and that definitely is a rabbit hole

subtle flicker
#

Definitely a rabbit hole ahah

#

I had the same thought

#

But u're not too far from it

acoustic owl
supple radish
pulsar needle
#

Ayayay, ive tried enumerating the account and i found 3 users, the passwords dont work on these users on imap, pop3 or shell. I tried using the password I found for ||tom|| on these accounts but it dosent work. I also tried to ||SSH into all the accounts with the id_rsa file I found, but this key only works for tom||

supple radish
#

All you need is to ssh into tom then your very very close

pulsar needle
#

Ive tried enumerating it so hard, but i guess ill keep going lmao

quiet ember
supple radish
rotund urchin
#

Has anyone done this module and kerberoasting across a forest? Neither John or Hashcat will recognize the hash that I get

pulsar needle
#

lmao

open monolith
#

Any moderator can help me with my acc issue

quiet ember
supple radish
#

thanks bro i really appreciate it

thorn urchin
#

contact support

open monolith
#

I was a member of HTB since 2020
This shows me as a new user!!

thorn urchin
open monolith
thorn urchin
#

Bruh just go verify your account

open monolith
#

the bot can't verify it

quiet ember
tawdry vapor
open monolith
thorn urchin
acoustic owl
open monolith
thorn urchin
#

Not on this account

pulsar needle
#

I found out he is a part of the ||MySQL|| group, but how am I supposed to access the folder if I do not have permissions?

open monolith
#

The error was "Identification error: please contact an online Moderator or Administrator for help."

tawdry vapor
tawdry vapor
#

ok

pulsar needle
open monolith
#

Clubby or Roadrunner may remember me and help me with that

acoustic owl
open monolith
#

:))

thorn urchin
#

DNS is notoriously fickle and is amongst the first real hard interactions with a protocol that people on the CPTS course face

acoustic owl
#

Once you understand the principle of zones, DNS is actually not particularly difficult

open monolith
#

I remember there was an off-topic general server
Admins delete it?

#

I also can't find any place for help or etc.

acoustic owl
open monolith
supple radish
#

you access it off toms account

#

use toms username and no password and you should be able to get into it

#

im not sure about the no password part though

pulsar needle
#

xd

supple radish
#

there is no outfacing mysql server

pulsar needle
#

wait

supple radish
#

but there is an internal sql server

fathom pendant
pulsar needle
#

Thanks

fathom pendant
open monolith
supple radish
fathom pendant
#

That also helps

pulsar needle
#

And that took away all my attention

fathom pendant
uneven dune
fathom pendant
#

Iirc unless I'm misremembering

uneven dune
#

starts with j

#

now i need answer may be i today i not gonna sleep

fathom pendant
uneven dune
#

i need to know why i cant get the result looking the logs xD

pulsar needle
fathom pendant
pulsar needle
#

Ah, lol what a coincidence

uneven dune
fathom pendant
uneven dune
#

so reading some things in internet that say can be an user with privileges

supple radish
fathom pendant
#

If you copy the whole command from earlier and scroll its super duper obvious

fathom pendant
#

That's what a lot of our own trial and error boiled down to

acoustic owl
#

Right.
I mean, asking here if a command works is really pointless. Until an answer comes, you have tried it yourself for sure 🤷‍♂️

uneven dune
#

bro i wanna die, 5 hours solving something that i needed to trace

#

i understand now, know i can sleep
||```
Administrator usernames may not appear in login events in some cases. This is because administrators may have special settings or privileges that allow them to perform actions without logging events in certain circumstances.

#

but, happy

fathom pendant
#

Idk what does it tell you

mortal shadow
fathom pendant
#

So do that

#

When you hit a wall, check your notes. More often than not, the answer is there

acoustic owl
mortal shadow
#

yes i know the ID is vulnerable

trail leaf
#

Look at the two IP addresses in that first screenshot

mortal shadow
#

but not how to read the position

trail leaf
mortal shadow
#

NVM

timber beacon
#

I'm stuck on it myself

trail leaf
#

Explain what your xp_dirtree command is doing here

#

Yes

#

Always helps to step back and ask yourself what you’re doing 😉

#

That too

#

Usually taking a break has a similar effect for me, as much as I refuse to do it in the moment

#

Lmao

#

o7

mortal shadow
timber beacon
#

sorry for the ping but could I get some help on the splunk module first section:

Navigate to http://[Target IP]:8000, open the "Search & Reporting" application, and find through an SPL search against all 4624 events the account name that made the most login attempts within a span of 10 minutes. Enter it as your answer. 

My current query looks like this:

sourcetype="WinEventLog:Security" "eventcode=4624"
| bucket _time span=10m
| stats count by Account_Name, _time
| sort - count

I'm unsure of how to continue, and the documentation for the range() function is somewhat hard to understand. Thanks for reading

thorn urchin
#

<@&861185840277487616>

arctic basalt
#

is this general

trail leaf
#

No

analog dock
arctic basalt
#

ooh ok

manic talon
#

Hey gusy can someone help me in the module Getting started: Public Exploits

#

I used searchsploit to find three exploits, but I'm struggling making use of them

#

the searchsploit codes are 34553, 44943, 48918

supple radish
mortal shadow
#

https://academy.hackthebox.com/module/160/section/1475
already checked the servers /etc/passwd via SOAPAction spoofing but didn't find anything

just this, but i don't know where i should use SQLi

```also tested with sqlmap 
```http://10.129.64.112:3002/wsdl?wsdl``` ![pepecry](https://cdn.discordapp.com/emojis/949266103799001118.webp?size=128 "pepecry") ![pepecry](https://cdn.discordapp.com/emojis/949266103799001118.webp?size=128 "pepecry")![pepecry](https://cdn.discordapp.com/emojis/949266103799001118.webp?size=128 "pepecry")
quartz coral
#

hi, I’m facing same issue.
i also checked file as binary, but there is no interesting readable character rather than just get and cat file.
should i reverese aes256 hash of a kt file?

paper gyro
#

uh.... I am hacin solving Unified starting point machine

#

chould anyone help me?

thorn urchin
#

it doesnt say to put those in as script.js those are a variety of potential xss payloads to try launching a hosted script

#

if your xss payload is good

#

xss imo is very finicky and you have to play with payloads sometimes tweaking single characters at a time.

Without backend source code xss is a lot of fiddling intuition and persistent guessing to get something working rather than outright knowledge.

#

as far as initial payloads go

#

usually you have to at least close out the html tag wrapping your input, so I suggest looking at the html and seeing if you cant guess it, assuming its not a blind xss

#

hence a lot of payloads starting with "> and variants.

#

Then suffer 😂

mortal shadow
#

did you solve it?

thorn urchin
#

iirc that whole module I had to tweak and deviate things constantly to make it work

mortal shadow
#

im skipping module over module just because i'm missing some small details lol

thorn urchin
#

thats ill advised

#

You can, Id just not recommend

mortal shadow
#

me?

thorn urchin
#

yeah

mortal shadow
#

on the contrary what should i do

thorn urchin
#

complete one by one, focus on honing the lessons of the module and understanding the material

#

if you skip around when things get tough then youre just not challenging yourself or dwelling on a topic long enough to understand it. Itll slow overall progression

mortal shadow
#

i'm not missing many sections

#

yes but sometimes it's just too random

thorn urchin
#

But everyone learns different so if you insist, that's your prerogative, I just dont recommend

mortal shadow
#

if modules do something similar to the tasks before like fuzzing, sqlmap whatever i get it

#

but with some it feels like there is no path

thorn urchin
#

I dont normally like to parade status, but this advice is coming from someone that has actually passed the CPTS exam, so Im not advising this lightly.

proud pine
#

Many modules expect you to be using techniques from previous modules. The more you keep that up, the more you're going to end up with things that don't make sense.

thorn urchin
#

Yeah, many modules presume expected prior knowledge. you very well can be running into obstacles purely because you skipped the prior knowledge, causing you to skip again and then miss prior knowledge for the next one too

mortal shadow
#

no for sure, but some tasks require you to have a feeling for things

latent sigil
#

There's a fake flag

proud pine
latent sigil
#

Or the wrong one

thorn urchin
mortal shadow
#

im just saying

#

some courses are better to follow than others

#

wer you learn one tool but really good

#

instead of 5 attacks, of which only one will be used in the assignment task

proud pine
quartz coral
proud pine
#

Jumping ahead on modules makes your progress bar go up, but it doesn't prepare you for an exam.

mortal shadow
#

just modules don't make sense to me, especially their binding to the sections before

thorn urchin
#

like seriously probably the #1 reason

#

right up there with time management

#

The exam had me scouring sections for things I deemed unimportant enough to put into my notes and didnt absorb fully. I was wrong and humbled for it.

mortal shadow
#

doesn't look like im skipping much (red cross not counting, had no time to continue)

but just saying at some point it would make more sense to get hints instead of randomly pasting commands

thorn urchin
#

username typo

#

its same creds as sqsh

mortal shadow
#

lol

#

2 modules i've had problems with

thorn urchin
mortal shadow
#

damn stop being toxic

thorn urchin
#

But feel free to do so, this is the sort of thing where Id feel happier being proven wrong than proven right

proud pine
#

sure

thorn urchin
#

dante is easier than the exam, finishing dante doesnt necessarily mean youll pass

#

its just nice extra practice

zinc marsh
#

am doing dante and is easy

trail leaf
zinc marsh
#

the exam is between zephyr and offshore

mortal shadow
#

had to register on another mail cus of cheaper tier2 subs

trail leaf
#

aight

mortal shadow
#

but fair point

zinc marsh
#

but dante is very good to master the fundamentals

thorn urchin
#

If were have a brutal honesty session here moo, I think youre going to struggle greatly with the exam too.

You clearly have overall persistence and drive, but you consistently give up far too quickly judging from the type and frequency of questions you ask.

You should try pushing a but harder before you ask for help.

#

A lot of the mistakes you make or struggle with you definitely had all the tools to figure out yourself

#

Like youre not dumb, you just dont seem to make that extra willpower push where real growth happens

#

if you did Id bet your learning rate would skyrocket

#

These are just my observations, what you do with them or not is up to you.

zinc marsh
#

The life doesn't care about the problems of the people

#

It just checks the results

#

yea

mortal shadow
#

everyone has strenghts, weaknesses

thorn urchin
#

Yeah, Im just pointing out problems I see, ones I may not be correct about. The causes or solutions behind the problems are outside what I could comfortably comment on

zinc marsh
#

I see u everydays here a lot of hours studying and asking doubts

mortal shadow
#

some people help you, some don't and rather laught at you but as lond as you keep going you'll be fine

zinc marsh
#

just keep consistency and hard-work and u will arrive far

thorn urchin
#

Ill help and people get mad cause they dont like what I have to say and then I laugh

candid juniper
#

As a noob I'm trying to get through the fundamentals but tend to get stuck on the Linux one, I've used the search function and read a few comments about people highlighting that it might expect some prior knowledge. Yet research doesn't always help me.
ATM I'm trying to do the SELinux exercises of network configuration, but just can't get SELinux to launch in the first place. Whatever I do SELinux stays disabled post reboot, any tips?

mortal shadow
#

try better

thorn urchin
#

Ive never actually touched SELinux lul

#

heres how to get linux fundementals down: erase windows, single boot linux as your daily driver and struggle solving problems with it till you get comfortable

mortal shadow
#

fr

zinc marsh
mortal shadow
#

at some point you'll get the base commands

thorn urchin
#

I have a windows desktop I still use for games and some stuff, Im not one of those linux only puritans. but practice is practice

zinc marsh
#

I think at the beginning I learnt linux with a lab

#

which was like finding flags using just linux commands

#

but I don't remember the page

supple radish
zinc marsh
#

anyway from my point of view tryhackme is still better to learn the basics from zero

#

then move to hackthebox

supple radish
#

i agree

thorn urchin
#

🤮

candid juniper
#

I mean I have some background, I can get some things to work as I had like a crash course into pen testing before. It's just consistently disabled. I'll take @valid hamlet's advice since that one seems solid.

zinc marsh
#

I am not sure if in the starting point they teach u basic commands for linux

thorn urchin
#

I learned the insane way by daily driving backtrack 3 like a lunatic

zinc marsh
#

unless the linux fundamentals module should

thorn urchin
#

and later installing LFS

brittle herald
#

Having an issue with nmap hanging at around 88-95%. Has anyone ran into this issue before? I'm using the pwnbox and running -A on 7 ports, it shouldn't take longer than 5 minutes no?

polar widget
rare topaz
#

Personally, I booted up a kali vm and started grinding and getting used to Linux.

#

I started a couple projects like creating a docker container for pentest tools and it forced me to get even more used with Linux commands.

manic talon
supple radish
manic talon
supple radish
manic talon
fringe shell
#

Does anyone know if there are any academy modules that cover PenTest/VA of Operational Technology networks?

manic talon
#

I don't believe so

fringe shell
#

Yeah, i had a look around and couldn't find anything. Be good to know some industry standard tools and procedures so I don't go inadvertently opening valves or something

brave vale
#

Hi someone knows why in getting started module (Nibbles initial foothold) Im listenig in the right port and everything but I don't have the tty

#

So i can use the reverse shell

#

neither the user flag nor the root flag

fringe shell
brave vale
brave vale
fringe shell
brave vale
#

sounds good?

fringe shell
brave vale
#

Tysm

fathom pendant
rare topaz
#

sup

#

probs one of those AD ones

#

i mean i personally enjoyed AD a lot, on my home lab at least.

Dunno how it's like on HTB's academy platform.

I live very far away from the US/EU so it's very laggy to do AD stuff on htb.

#

I do recommend starting up an AD home lab at some point, it's real fun and let's you configure attacks for yourself. (and obfuscation/bypass techs)

fathom pendant
#

AD itself is just interesting

#

No sanity

trail leaf
#

The ratings are a combination of number of distinct steps plus overall complexity

zinc marsh
#

well hard normally the first blood are in 6h

#

insane I have seen some with +24h

trail leaf
#

Oh if all of those password attacks skill assessments were part of main platform boxes, they'd all be under easy 😆

zinc marsh
trail leaf
#

maybe medium at best

zinc marsh
#

from the last season

#

+2 days for the 1st blood

#

imagine for an average hacker kek

trail leaf
#

An insane box like that is not too common these days though

#

Insane boxes have their own spectrum from your Brainfucks to your Bookworms to your RopeTwos

#

also this discussion is more appropriate for #boxes

zinc marsh
#

This is the last hard machine

trail leaf
#

don't apologize to me lol, I just know if other people want to look at modules discussion it gets a bit cluttered

zinc marsh
#

@rustic sage I recommend u doing dante after finishing the cpts path

umbral wigeon
#

i think u should place them in a one-liner

zinc marsh
#

idk I write the report in all what I do

#

u have impersonate permission

#

u just check what users are there and u impersonate which u think could be interesting

#

that is just an example...

#

like when someone says person x and person y

fathom pendant
#

Take it one part of the command at a time

rare topaz
#

You can look at the submissions guide for boxes as they clearly detail how they differentiate the difficulties.

Also details the rules like which wordlist should a password appear in.

manic talon
#

Hey guys, could somebody help me in the getting started module: public exploits part

fringe shell
manic talon
#

i've used searchsploit, to find exploits, and found three exploits, but don't think they're applicable since I need admin privilages for 2 of them. And I found a couple of exploits on google but couldn't pinpoint the exact exploits

fringe shell
swift nexus
#

@pine galleon can we talk in dms?

pine galleon
#

why?

novel matrix
swift nexus
#

i need help and i prefer talk in private bc people tend to judge alot

strange pawn
#

😆

pine galleon
#

shrugFreg well I don't do help in private unless I already know what it's about and it's not bs

#

and i think i can see where this is going already 🙃

swift nexus
#

where do u think its going?

novel matrix
#

let's keep this channel on topic please

swift nexus
#

ok

#

sorry

proud pine
#

There are no restrictions on tools. You will not be able to ask any humans for help.

thorn urchin
#

yup

#

Honestly I couldnt spot many points where advanced paid tools that normally would be banned would be even useful

rare topaz
#

You don't need scans that's just a waste of time

#

Huh?

fiery berry
#

I guess is referring to the burp scan and not any port scanner which will help you find out the services running on the machine

rare topaz
#

How is he confusing Nmap w burpsuite pro FeelsWeirdMan

#

Also isn't burpsuite pro web scan only

fiery berry
rare topaz
#

Who let bro cook 💀

knotty panther
#

on ATTACKING COMMON SERVICES Attacking DNS

#

is the TXT domain a fake answer flag?

rugged veldt
#

On attacking common services for tomcat I have found host manager but what can I do from here

proud pine
rugged veldt
#

I went derp mode and got ahead of myself

#

I was trying to attack the manager when I was still in the enumeration module

acoustic owl
warm drift
#

please does anyone know how to access/trigger an apache tomcat .war payload that has been uploaded I'm trying the solve the first target in live engagemnt of the shells and payloads module

acoustic owl
# warm drift please does anyone know how to access/trigger an apache tomcat .war payload that...
WonderHowTo

Web applications are a prime target for hackers, but sometimes it's not just the web apps themselves that are vulnerable. Web management interfaces should be scrutinized just as hard as the apps they manage, especially when they contain some sort of upload functionality. By exploiting a vulnerability in Apache Tomcat, a hacker can upload a backd...

thorn urchin
#

read the question closely

sly reef
#

yeah

#

my bad

thorn urchin
#

👍 it happens

warm drift
sly reef
#

and the link there is a GET request. probably just go to /manager

warm drift
#

I've already uploaded a msfvenom .war file

sly reef
#

aight, you should view the path in the deployment page. Then you can navigate to the shell

#

hard to tell with a link to be honest

warm drift
#

can I send a screenshot?@sly reef nevermind , all I had to do was click it lol

short gulch
cold glacier
#

is anyone up rn

#

im a little stupid and new to all this, so i could use some help
i assume its pretty basic though

acoustic owl
#

Just ask your question here. Someone will then give you an answer

quick cloud
#

I think the most non-technical thing CPTS has taught me is how to organize my notes haha

#

Everything is so much easier once your notes are organized and you understand them

#

big emphasis on understanding them

#

That said if anyone needs note taking tips or wants to give any note taking tips for obsidian please pm me

hushed rivet
#

i cant copy paste

#

on those browser based vms

#

cant i just connect to an academy .ovpn file ?

#

its weird because it says here that those clipboard settings are on

acoustic owl
hushed rivet
#

i am in fullscreen

#

ah lower right corner

#

ill try that

#

thanks

#

that works great!

thorn urchin
#

also yes you can just use your own vm with academy vpn

hushed rivet
#

u can ?

thorn urchin
#

the option is right next to launching the pwnbox instance

hushed rivet
#

in academy ?

#

i think thats only on the regular pwnbox

acoustic owl
torn blade
#

random but is fuff acting werid for anyone else

#

went from being able to do like 2500 things in like 5 seconds to its been 3 minutes and its on 498/2588

#

connection is fine, idk why its suddenly going slow

cold glacier
#

Okay so my question is
on the first part of HTTP fundamentals, there's a question where it needs you to download a file returned by /download.php with curl
but every time i try it says it needs a URL
where do i find this url
im confused
again, excuse me, im really new to this stuff

acoustic owl
#

We are all here to learn new things. No need to apologize.

When you start the machine at the end of the lesson, you get an IP address with or without a port, depending on the module.

The URL is then for example
http://10.10.10.10:12345/

cold glacier
#

so i have to write it with the http: on the command prompt?

#

i guess that was what i was missing
i put that first and then curl and the name i suppose

#

i'll try it

supple radish
#

enumerate the mounted tech support drive better

#

cat them all at once using * only one should actually have text

#

let me know if it works

#

lol what went wrong

grizzled wind
#

See it sucks that you had to be so blunt here, but I honestly think the lab is a bit unfair because it almost goes against what you learnt in the NFS module, which is perhaps why it seems a few people are struggling here. We learn that being in the nobody group means you’re being root squashed, and although your not technically being root squashed when you log it as your default user, thats where the student’s brain is going, so I was never going to try as the root user. Furthermore I wasn’t actually aware I could switch to the root user in pwnbox outside of sudo. I didn’t realise it was the same password as the default user. Doing your own research into nobody group when you’re not root user takes you down a massive rabbit hole of something being wrong on the server. So here I am trying to change the NFS version when the answer was way more simple. I think the lab should be changed to show that the root group owns the folder, rather than the nobody group.

In saying that I did learn a valuable lesson in making sure I truly look properly at the folder permissions. Despite being in the nobody group, we can still ascertain which user we need to mount as via the folder folder permissions output, as ONLY the root user has permissions on the folde

#

I hate when HTB does these kinds of stuff, not the first time. I understand that we need to learn but this is just stupid. I like the content but the tasks are not noobies friendly.

My question to HTB staff, how can I know this if I have never even encountered it before? How can I research into something that I did not know was possible?

torn blade
#

anyone here do the web service api skill assesment?

supple radish
grizzled wind
grizzled wind
supple radish
# grizzled wind

I never finished my notes on this assessment smh but I would try playing around with the server authentication types but I really dont know

acoustic owl
#

What does the SQL Server require?
A Windows password?
With which user are you logged in? Does the user have access to the database?

#

By the way, some users and also admins are lazy and use the same password for multiple logins.

dull thunder
#

does anyone know why when i import Powerview.ps1 i dont get all the functions. like Get-DomainObjectACL

manic bramble
acoustic owl
acoustic owl
manic bramble
manic bramble
#

thanks !! i'l try it

#

i'm enumerating the footpringtin lab - hard. tried all tcp ports and nothing came worth while i think. i'm checking udp snmp but when i run: snmpwalk -v2 -c publick <ip>

#

snmpwalk: No securityName specified
it gives me

sly reef
#

Module: Windows Attack & Defense. I can't connect to PKI host no matter how many time i reboot the lab infraestructure. Anyone got the same problem?

umbral wigeon
hushed rivet
#

in : Skills Assessment - File Inclusion i cant seem to logpoison the access.log with burp

#

i wonder why this is

acoustic owl
hushed rivet
#

in the useragent

#

just an example to see why it doesnt work

#

but its not getting there

#

for some reason

#

im gonna reset see if it still doesnt wanna work

acoustic owl
#

Look at the hint from me

hushed rivet
#

yea the quotationsa re in the useragent

#

i know how log poisoning works

acoustic owl
hushed rivet
#

?

#

im injecting in the user agent

#

like im supposed to

#

what do you mean, that is the problem ?

acoustic owl
hushed rivet
#

ill show u a screenshot

#

sure

rustic sage
#

????????/

acoustic owl
# rustic sage ????????/

What exactly do you not understand?

Chrome and Edge use the system proxy, Firefox uses libcurl
That's what this text snippet says. No idea where you got it from and in what context it stands.

frigid dove
#

.,

supple radish
# rustic sage ok thanks

Whenever I reach a text passage I dont fully understand I copy paste it into chatgpt and ask it to make it simpler and give better explanation and ussually makes me a lot more confident on the subject

quiet ember
#

Like a private network

rustic sage
quiet ember
# rustic sage but why?

Organizations don't have internal network publicly accessible, hence the need for pivoting

quiet ember
#

Link for exercise?

quiet ember
#

You don't need to impersonate for this exercise

#

Try using responder

rustic sage
quiet ember
#

The ||mssqlsvc|| user?

#

What command did you use to try logging in with it?

#

Try it with ||windows auth||

#

Yes, because mssqlsvc is a service account on windows and not just an mssql account

#

No

#

I'm not sure the syntax for using windows auth with sqsh, but it's just -windows-auth with impacket-mssqlclient

tight mesa
#

hi guys, sorry for the silly question bit, someone in this channel told me xfreerdp has a way to share files between PCs, can't find how to do it, can guide me to some kind of documentation, please?

autumn pilot
#

xfreerdp --help

rustic sage
#

can we consider firewall as reverse proxy?

quiet ember
#

It does a few times in there

proud pine
#

It absolutely did.

#

So, this is sorta what madf0x had told you in the past. If you see something you don't understand in the module, you should go research it.

#

But as we've told you, this part of self-research is a skill you need to learn. The exam is going to be more difficult, and you'll be completely cut off from this kind of help.

trail leaf
#

There is no way that an academy module can write down every single possible thing with the utmost detail that you're supposed to know to be successful. The biggest benefit academy is meant to give you is a solid foundation on particular topics, to give you enough ground to reason through what you know and don't know.

#

Same thing applies to real school. When they teach you about solving systems of linear equations in algebra, they don't show you every possible combination of problems because the focus should be learning the process and methodology over individual, specific facts, if that makes any sense

marsh wave
#

can sombody help me in a question in the module introduction to active directory ?

dull thunder
acoustic owl
dull thunder
quiet ember
marsh wave
#

I put this policie Application Control Policies - Settings to control which applications can be run by certain users/groups. This may include blocking certain users from running all executables.

quiet ember
#

I'm sorry, I haven't done that part yet

naive wadi
#

Looking for clarification: I am doing Pass the Ticket From Linux section and in the "Using Linux tools with kerberos" section the part where it is using Impacket with proxychains and kerberos authentication there is the command

  • proxychains impacket-wmiexec ms01 -k however, further down where it shows us another way to do this part of the attack and pass the ticket it is using impacket and says
  • proxychains evil-winrm -i dc01 -r inlanefreight.htb so am I being crazy in thinking that the impacket command should be using dc01 as well as we have already extracted the ticket from ms01?
#

Is it a type-o or am I missing something in the process?

marsh wave
clear hatch
#

Anyone available to help with "Attacking Common Services | Attacking DNS"??

Having a hard time getting the zone transfer to occur... not sure im issuing the right commands, or maybe i dont have the proper /etc/hosts structure i should?

clear hatch
acoustic owl
#

htb cannot be resolved because it is not an official TLD.
If you want to resolve htb, you have to specify a NameServer which can do the resolution

clear hatch
acoustic owl
#

It is necessary

#

Specify an ip as NameServer

clear hatch
#

so do i use .com or figure out how to specify a NS in resolution?

rare topaz
#

bro rlly got explained why it was necessary and still asked.

💀

clear hatch
#

is that...

#

dig axfr @sub.inlanefreight.com XX.XX.XX.XX ???

#

ip being NS ip?

#

this defines gatekeeping fasho

quiet ember
clear hatch
#

yes but after digging here i found that im only seeing 5 of 8 subdomains

quiet ember
#

Can you send exercise link?

clear hatch
quiet ember
#

dig AXFR @<name_server> sub.inanfreight.htb

#

Try that for the sub domains you found

clear hatch
#

the @nameserver would be something like @ns*.inlanefreight.HTB or .COM ????

quiet ember
#

.htb since it's a local lab

#

Show me your /etc/hosts

clear hatch
#

even though host only replies to .com??

clear hatch
rustic sage
#

Edit your /etc/hosts with
Ip here inlanefreight.htb

clear hatch
#

yep

quiet ember
clear hatch
#

as its own entry?

#

and add both ns1 and ns2?

rustic arrow
#

@clear hatch you added the target IP as a resolver, correct? Then you executed subbrute

clear hatch
#

they both respond to the host command but only as

rustic arrow
#

The /etc/hosts will map a name to an IP, but it won't use it to resolve any subdomain.

rustic sage
#

YouI can add subdomain

#

@rustic arrow

rustic arrow
clear hatch
#

SO.. what i misunderstood was that the "target IP" is ALSO a nameserver??

rustic arrow