#modules

1 messages · Page 105 of 1

fathom pendant
#

The error they are getting isn't even mounting the remote system

autumn pilot
#

additionally, you turned it into general chat (#858470491676737536) where the purpose of that channel is completely different

heavy marsh
#

yeah, posted to erratum after I verified I had tried everything

autumn pilot
#

I've just tested the exercise and with the command, and it is working as intended

fathom pendant
#

They are getting the "not in host:dir format"

#

I'm currently trying to get wifi hooked back up but that's gonna be a few weeks

#

Which I think that error is a user error not a remote host error

umbral wigeon
#

<ip>:/

heavy marsh
#

it worked as root for some reason

fiery berry
fathom pendant
heavy marsh
fathom pendant
heavy marsh
#

I'm all for learning, but this was an unnecessary rabbit hole

fathom pendant
#

It's an easy thing and literally has been discussed

#

In this channel, multiple times

heavy marsh
#

It's okay, I addressed it in erratum, hopefully it will be addressed in the future with changes

fathom pendant
#

Discord does have a search feature yakno

heavy marsh
#

I appreciate the help!

#

Yeah, I use the search feature extensively

#

It helps most of the time

modern hill
#

Guys, for the MacOS fundamentals there's no actual Mac VM to do the exercises?

fathom pendant
heavy marsh
#

Anyway, now that I'm through that issue, all I have now is a bunch of text files.

#

.... so just cat xxxxx.txt

#

ad nauseum?

#

Is there anything worthwhile in these or is this just another waste of time?

fathom pendant
#

@modern hill

modern hill
#

Yeah, just me rushing it and not seeing that.

#

Thanks.

fathom pendant
#

At least it's fundamental and only 10 cubes

fathom pendant
#

As it states though you can at least take notes on the content

modern hill
#

Yeah, for sure.

fathom pendant
#

Just may not be able to complete the exercises

prisma spruce
#

It's probably the best of the windows/linux/mac trio

fathom pendant
prisma spruce
#

Only to use the package manager i(brew)

fathom pendant
#

That's why you're smarter than me

hushed furnace
#

Anyone playing Authority?

#

Windows machine.

acoustic owl
#

If you have no access, read and follow #welcome

fathom pendant
#

Hi payload I see you are picking up the graveyard helpdesk shift OK bye leaves 1000 tickets on desk

acoustic owl
#

yes I take the shift here 😉
Good Night Marcie

hushed furnace
#

I've logged in. Still

acoustic owl
#

Have you verified your account?

fathom pendant
analog dock
fathom pendant
#

In the screenshot

analog dock
#

That’s just a screenshot of the welcome page

#

You have something different?

fathom pendant
#

Brother I'm talking about the font from the screenshot

analog dock
#

As in what language? Or what lol

#

I guess I’m too stupid to comprehend your question

#

If language, it’s German

fathom pendant
#

Nevermind

analog dock
fathom pendant
#

Font: the style that the text is in

analog dock
#

Yeah, and I asked if yours is different, this is just the font discord mobile is in for me so I don’t know any better lol

fathom pendant
#

Like I said never-mind

analog dock
#

👍🏼

rustic sage
#

Can someone help with this problem ./logrotten -p ./payload /home/×/× /lib/x86_64-linux-gnu/libc.so.6: version GLIBC_2.34 not found (required by ./logrotten)

fiery berry
rustic sage
fiery berry
fiery berry
modern falcon
#

Hi I need help on AD Enumeration & Attacks - Skill Assessment Part II question 10. I have got admin access to MS01, how do I get the password hash for user C****?

vital adder
#

read the hint on question 9, go back try the stuff showed in the sections for getting a foothold

barren apex
#

Im on windows priv esc Prilaging module, anyone know what part of the hash the answer wants, ive tried the whole thing, NT and LM but cant get it to work

acoustic owl
#

Read the question. It should be defined there what exactly is being asked

barren apex
#

Just says the Administrator hash

#

and none of them work

acoustic owl
#

Then i guess its the NTLM Hash

barren apex
#

just got it, there was 2 different backups to restore, i was doing the old one

rustic sage
coral wraith
#

Hello, I'm in the Web Attacks module in Bypassing Encoded References:

I found:
MQ%3D%3D >> 1
c4ca4238a0b923820dcc509a6f75849b.

Any hint please.

graceful mortar
#

Hi guys...
I'm currently grappling with the challenges posed by the Broken Authentication module, specifically in relation to Bruteforcing Cookies. This topic seems completely baffling to me... Is there anyone willing to reach out through direct message and provide instruction? I'm in desperate need of assistance and support.

acoustic owl
acoustic owl
graceful mortar
#

Yes

acoustic owl
#

This question is really posed in such a way that it often leads to misunderstandings.
||You must assign the role "super" to the user||

graceful mortar
#

Yes, i saw this here on channel, but how do i tamper this role? And i dont know what i need to do after that

#

If you could teach me on dm how to do this steps i will really appreciate

acoustic owl
#

The module shows you how to decrypt cookies. If you know the content, change it in your favor, encrypt it again and swap it with your existing cookie

acoustic owl
slate palm
#

soooo linux privesc assessment flag1.txt isnt where its supposed to be any hints?

graceful mortar
vital adder
slate palm
#

ooooooof thank you very much I got it

torpid haven
#

Hello

#

Question 4 of the using ffuf module

#

Of the skill assessment

#

Also I would appreciate it if someone explained when I should fuzz for parameters in practice

fiery berry
torpid haven
#

Well it's saying that every request sends back an error

fiery berry
torpid haven
#

Ig I should've done that before askign for help

#

Thanks anyway though <3

fiery berry
iron plaza
#

Did anyone finish the INTRO TO ASSEMBLY LANGUAGE? I have a question relating shellcoding tool assessment ... i try to push the shellcode through netcat but end up getting "Failed to run shellcode!" even though they work on my system ... so wanted to figure out what I am doing wrong

rustic sage
#

Can someone hint me in sudo section linux priv esc when i open the program that i can run with sudo what should i do

#

I typed some options and nothing happens

acoustic owl
rustic sage
#

I'm so pissed off

#

This thing took me 2 hours

#

I open the root directory and then can't open the flag file

acoustic owl
#

I really can't tell you any more without telling you the solution than to tell you to look at the features of this program

rich perch
#

Hello! I need help on the Windows Privilege Escalation module.
The question is " Which account has WRITE_DAC privileges over the \pipe\SQLLocal\SQLEXPRESS01 named pipe?"

The module says I need to use Accesschk to get data of the named pipe, but when I try to run it both cmd and Powershell say the command isn't found.

acoustic owl
#

have a look in c:\Tools
I think the program is there

rich perch
trail leaf
#

Honestly, I recommend just playing with the syntax a little bit to understand how to use the tool. It took me a minute to understand it at first but figuring out the syntax yourself will help internalize it.

tranquil axle
tranquil axle
#

yea sounds good

rich wraith
#

I am struggling with this, can somebody help me?

misty mural
rich wraith
#

Linux Privilege Escalation, 2.section

misty mural
mossy nest
#

Hi guys ! Got a quick question about the footprinting module (DNS part). I saw that we always use the Base_IP + Name_Server in order to dig things. But how do we dig into a subdomain ? Should we keep the Base_IP or use the new IP (from "A "record of our subdomain) ?

I do the following
for sub in $(cat /opt/SecLists/Discovery/DNS/subdomains-top1million-110000.txt);do dig $sub.inlanefreight.htb @10.129.179.179 | grep -v ';|SOA' | sed -r '/^\s*$/d' | grep $sub | tee -a subdomains.txt;done
ns.inlanefreight.htb. 604800 IN A 127.0.0.1
mail1.inlanefreight.htb. 604800 IN A 10.129.18.201
app.inlanefreight.htb. 604800 IN A 10.129.18.15

But to domain bruteforce mail1.inlanefreight.htb will I use 10.129.179.179 or 10.129.18.201 ?

misty mural
misty mural
rich wraith
#

yeah I know, but I couldnt find the file

misty mural
#

There’s a way of searching the entire file system for files that contain a particular string. Do some Google-Fu. Anything further and I’d be handing you the answer.

You’ve got this!

narrow solar
#

where can i get rubeus.exe?

urban sage
narrow solar
#

actually i am not sure how to convert it to exe 😅

vital adder
urban sage
#

Or that yep.

narrow solar
#

thank you both 🥰

rich wraith
#

but I hate it when the content of the section is useless for the assessment

fathom pendant
tough kettle
#

I am doing the footprint module's medium lab and I can't connect to the || SQL Management Studio || .
I need help to understand why it's failing?

fathom pendant
#

Did you find the important document

tough kettle
#

Yeah I am using the creds from it .

fathom pendant
#

You can also use the password for a more powerful user

#

To remote with

tiny grove
#

Hi guys, I’m doing the AD Enumeration & Attacks - Skills Assessment Part II and I’m stuck at the question “Submit the contents of the flag.txt file on the Administrator Desktop on the SQL01 host”.
I got a reverse shell from the sql01 but I’m not able to escalate privileges, I tried with the printnightmare but every time it return an error with the driver path and I tried to transfer files from the attack box to it in many ways but nothing worked, someone has any hint?
Thank you!

umbral wigeon
tiny grove
#

Yes and I know what you mean, but how can I use it?

fathom pendant
#

@cinder cobalt refer to your notes about what the information could mean

umbral wigeon
fathom pendant
acoustic owl
#

HTTP basic authentication

hushed rivet
#

i am stuck at the lfi with languages/en.php prepended, can someone dm me ?

#

running out of ideas

acoustic owl
hushed rivet
#

yea but i dont wanna post spoilers

#

can i dm you ?

acoustic owl
#

sure

trail leaf
#

File transfers is another thing though, it shouldn't be that difficult for you to do it considering both machines are on the same network. My advice is the same, if one method doesn't work, try something else.

warm kernel
#

anyone here able to give me a hand with file upload module?

fiery berry
warm kernel
#

I've found the available extensions that are accepted along with the content types, although as soon as I make any changes to the content, I get rejected immediately. Screenshots incoming

warm kernel
fiery berry
warm kernel
#

no

fiery berry
#

well, could you be more precise?

warm kernel
#

Type Filters module

#

what do you addtionally need to see?

fiery berry
#

Nothing else, did you manage by the way to upload an image without getting any error? I would go from there by fuzzing the extension with a PHP list you can find on PaylaodAllTheThings

warm kernel
#

the image yes, I've got my list of extensions and content-types that were allowed

#

anything else I got errors

fiery berry
#

Nice, so I think you're close

warm kernel
#

I am, but any change to the file content, poof

#

i've been on it for a while, and ive brute forced my options to no avail

fiery berry
#

I've used "GIF89;"

warm kernel
#

the course doesn't go over changes to the content being an issue, which is suprising, this is out of scope of its contents

#

even with a clean picture, doesnt chew it up

fiery berry
tough kettle
fathom pendant
tough kettle
fathom pendant
slate palm
#

or to save a dollar or two

deep owl
#

hello all

graceful mortar
#

Could someone help me with broken authentication cookies. I'm stuck for a long days in this module... if anyone could dm to give me a guide/help it will be appreciated.

zinc marsh
#

what is wrong here?

slate palm
#

python2 get out reeeeeeeeeeeeeee

fathom pendant
zinc marsh
slate palm
#

you could use python2 to run it

zinc marsh
#

I changed them for input()

thorn urchin
#

you can also try 2to3

#

more and more systems these days dont have python2 native installed

slate palm
#

or the best way: dont use python2 anything. if something is not in python3 its outdated and end of life. unmaintainable

#

even python thinks its a bad idea to still run python2

thorn urchin
#

yup thats how tech works

zinc marsh
#

ýea

#

ty

zinc marsh
slate palm
barren salmon
#

hi. im new to the academy and pen test in general. Was hacking a box again. This time web enumeration. In the text for the question the just asked me to run some enumeration, that we just learned in the text previously. So i did some enumeration, without any flag. Then i did a whatweb on sub net. You know 0/24 at the end of an ip. And oh lord i got a lot of information, about website and email from people im pretty sure doesn't have anything to do with hack the box. Im a bit freaked out, because i really don't wanna violet anything of anyones private data without permission. Is whatweb a aggresive scan?

fathom pendant
#

You never need to go into subnets

barren salmon
fathom pendant
#

You're overreacting

#

Chill

#

Just do the thing and move on.

barren salmon
barren salmon
fathom pendant
#

Again you're overthinking it

#

What web only scrapes info

acoustic owl
barren salmon
fathom pendant
#

If you did a scan on 10.10.x.x/24 or 10.129.x.x/24 you're fine

thorn urchin
#

yeah I dont even see how whateweb woulda even found anyones LinkedIn stuff

#

even using it wrong

fathom pendant
#

^

thorn urchin
#

but yeah never acan against the lab subnet. If they want you to do a subnet scan of any sort. theyll have you connect to a jump box first for an internal network to scan

barren salmon
fathom pendant
#

Or whatever that address schema is

barren salmon
acoustic owl
barren salmon
acoustic owl
#

There are still Docker containers. You can recognize them by the fact that they always specify a port as well.

For example: 83.136.251.168:50637

barren salmon
acoustic owl
#

This IP is also from HTB.

barren salmon
acoustic owl
#

Which IP exactly have you scanned?

barren salmon
#

well as long as its HTB i good

#

2 sek. ill have to start linx up

thorn urchin
#

yeah cause its starting to sound like you got a public docker IP which means you did scan a bunch of rando servers that might not have anything to do with HTB

#

which isnt toooo bad. whatweb is just enumeration, public services wre getting such scans 24/7

fathom pendant
#

^

barren salmon
#

here is the line: whatweb --no-errors 94.237.56.0/24

thorn urchin
#

yeah that's public

acoustic owl
#

okay, docker

thorn urchin
#

you scanned some random peoples stuff

barren salmon
#

noooooooo

thorn urchin
#

its fine. I wouldnt lose sleep over it in this instance, just be more careful in the future

acoustic owl
#

If you get an IP with port, then be sure to stick to this IP incl. port.

thorn urchin
#

maybe go learn some networking fundementals so you can recognize stuff like that

#

at least you werent running anything destructive

fathom pendant
#

^ Just a silly little scraper

#

Which is most of the active tools

#

For web enum

barren salmon
thorn urchin
#

You woulda been, except what you scanned wasnt htb servers lol

fathom pendant
#

Yep

#

This is why I said specifically 10.10.x.x and 10.129.x.x

#

As those would be your internal networks

#

Through the tunnel

thorn urchin
#

@barren salmon your homework today is to go learn networking address ranges and memorize the difference between public address ranges and private address ranges, noting specifically which ranges are private.

fathom pendant
#

There's 4 classes of private and like a handful of ways to differentiate

barren salmon
#

that fucking sucks. but the server i was provied was 94.237.56.76:54499

fathom pendant
barren salmon
thorn urchin
# barren salmon yah i guess it is. damn

dont worry, you were going to have to learn it sooner or later. Youre actually lucky in that now you have a first hand experience on why you need to learn it sooner rather than later.

thorn urchin
barren salmon
#

but i assume the information i got from whatweb is just what there is already public

barren salmon
thorn urchin
#

its also why scoping is such an important thing in pentests and bug bounties

barren salmon
#

theres is so much to learn

#

no i would do that again

rustic arrow
#

Module: Attacking Common Services
Section: Attacking SMB
https://academy.hackthebox.com/module/116/section/1167

Third challenge: I got RCE using smbclient, but does anyone have any idea why impacket-(at/smb/ps)exec, crackmapexec, and Metasploit psexec won't work?

Edit: yes, I have changed the --exec-method flag on CrackMapExec to every options available to test

autumn pilot
#

the 3rd question asks you to use SSH

rustic sage
#

what are the best modules for building up to doing easy boxes/ challenges? I only have access to tier 0s and 1 or 2 tier 1s btw

fathom pendant
#

All the fundamentals

#

And you'll be mostly fine

#

And doing the starting point boxes with help from uncle Google and the official writeups

thorn urchin
rustic sage
rustic arrow
fathom pendant
#

Yes

#

Tier 0

rustic sage
#

So if I just do the ones tagged fundamental I should know enough to be able to move on to doing stuff like the hacker bootcamp?

fathom pendant
#

haven't looked at it ¯_(ツ)_/¯

#

But the fundamentals get you at least started

rustic sage
#

Ok cool thanks

fathom pendant
#

And Google can take you a long way

rustic sage
fathom pendant
rustic sage
#

oops i just rememberd i dont have my hackthebox account connected to this lol

thorn urchin
#

idk how good the new guided stuff is yet, but its interesting enough to give a shot.

rustic sage
thorn urchin
#

That way everytime you overcome becoming stuck, it becomes part of your repertoire for every future machine you encounter.

fathom pendant
#

Mhm

#

Always expect to hit a wall

thorn urchin
#

Im actually slacking right now cause theres a bunch of boxes n stuff I havnt transferred over inti general notes yet

rustic sage
thorn urchin
# rustic sage oops i havent taken notes on this hacking stuff like at all... maybe thats why i...

Yeah my notes from the beginning of academy and the end of academy are drastically different in quality.

Had I kept proper notes I would t have had to relearn so much stuff from my hiatus.

Good note taking is the difference between bad hackers and good hackers. Or even good hackers and great hackers 😉

very few people can get away with little to no notes and theyll often regret it eventually.

rustic sage
rustic sage
thorn urchin
#

notion is cloud only and not encrypted. Which is okay for personal notes, but if you ever get serious in offensive related roles and start doing stuff for clients like pentesting thats not gunna be allowed at all. Like lose your job. So if youre not going to be allowed to use notion for client notes youre gunna have to learn a new tool anyways. Might as well learn a tool you can use for personal notes now and for client work down the line.

rustic sage
thorn urchin
#

The hot one everyone is using at the moment is obsidian. Not encrypted by default but its offline so thats fine. You can pay for Sync which is end to end encrypted or use some plugins and git shenanigans to rig your own sync setup with encryption.

thorn urchin
#

so yeah obsidian is what I recommend but if you stumble across something better by all means use that instead.

Just specifically a cloud only one like notion is bad if youre going to be in offensive stuff.

noble fiber
#

Hello boys, i have no clue how to find the flag on the Authentication Module --> Reset Token --> Question 1. I'm might missing something, tried to modify the reset_token_time.py script (https://academy.hackthebox.com/storage/modules/80/scripts/reset_token_time_py.txt) adding the milliseconds converting the time and adding the username but nothing seems to work. Here's what i added --> added a line 12 --> user="htbadmin" | line 16 --> x=str(x*1000) | modified line 17 --> md5_token = md5(str(x + user).encode()).hexdigest() | also, modified the url variable

trail leaf
#

I found that results were a lot more consistent if I could parse the time stamp that they give you into a base time to work off of, but I don't know if that's how other people did it too

strange pawn
#

I am on the footprinting module in the DNS section. It asks "What is the IPv4 address of the hostname DC1?". tbh, I don't really know what this question is asking... what is DC1 ?

trail leaf
#

What have you done so far?

strange pawn
#

nvm didn't realize it was located when searching the internal subdomain

#

we good

#

thanks though

winter blaze
#

hello if you got stuck in Footprinting Lab Hard, please ping me aside ill help you out, because the time is so valuable to waste it 🙂

burnt sluice
#

hello guys, I have a question regarding the SQLMap Fundamentals module, in the Attack Tuning Section's questions, there is this question What's the contents of table flag6? (Case #6) , My question is how am i supposed to figure out the prefix without refferring to the hint given?

trail leaf
#

You can potentially use that to figure out the correct time instead of brute forcing from your own time

#

Can't really respond to DMs right now but hopefully that's enough of a tip

noble fiber
trail leaf
#

This is a section a lot of people get stuck on, so there's also a lot of stuff from people on the forums

calm heath
#

Hey guys im stuck on active subdomain enumeration. I cant figure out how to find the txt file! Any hints?

burnt sluice
#

what module?

calm heath
#

Information gathering-web edition

burnt sluice
#

I've done it a while ago so i don't remember the method a 100%

#

but from what i recall, you try to do a zone transfer with the domain given, you will see a list of subdomains

#

then you try a zone-transfer on one of them to get the flag

burnt sluice
maiden spindle
#

Hey, I'm on Footprinting Lab hard, I've managed to ssh in as one of the users but I don't know how to escalate my privileges/what I'm supposed to do now

#

my bad I'm in as root

burnt sluice
#

i was just gonna say u gotta search for a different service in order to move on, no need to escalate anything xD

fringe shell
#

Hey, i'm on the File Inclusion assessment. I've made it a few steps through, but i'm not sure if the method i'm trying is wrong or I'm just doing it wrong lol

rustic sage
#

I have completed this one

#

Where are you having doubts?

fringe shell
rustic sage
fringe shell
#

hmmm mind if i dm so I don't post spoilers?

rustic sage
#

Sure

rustic sage
#

Hello all, I'm currently working through the AD Enumeration & Attacks - Skills Assessment Part I and have completed the assessment with the exception of retrieving the cleartext password for t*****. I've tried using mimikatz to dump LSA secrets on the MS01 machine but I still can't seem to find the password. Can someone lend a hand?

umbral wigeon
rustic sage
burnt sluice
#

hello guys, i need some help on the skill assessment of the SQLMap Fundamentals module, i can't seem to find the parameters to test on the website, i have gone through every menu/catalog option, and every form while inspecting each request in the network monitor, any tips would be appreciated.

graceful mortar
#

Tamper the session cookie for the application at subdirectory /question1/ to give yourself access as a super user. What is the flag? - Brute Forcing Cookies - Broken Authentication

Any tip please?

sick frost
#

Hi guys, I'm currently doing Attacking Common Services module. I got stuck in the easy lab. I found out the username to use but not able to crack the password for it. If I'm using rockyou with hydra it is showing an estimated time of 2600 hrs. I also tried mutating the password list given in the module but it didn't work. I will be great if anyone can give me a nudge

fringe shell
fathom pendant
heavy marsh
#

Stuck on the Medium Footprinting lab

#

so far I have rdp access

#

and have found the important.txt file

#

txt password isn't working for the SQL server application

#

am I wasting time or is this a valid approach

#

?

fringe shell
wispy iris
#

Hello Team, I'm trying SQL injection Fundamentals module but in the SQL statements content, I can't see the development table. Can you help me?

fringe shell
heavy marsh
#

management studio 18

fringe shell
knotty panther
#

hello can anyone guide me with "attacking common service Lab Medium" i been bruteforcing simon at port 2121 for so long now

heavy marsh
#

the sa password from the "important.txt" file doesn't work

fringe shell
#

spoilers my dude, you can dm me

heavy marsh
#

not spoilers if they don't work, lol

#

just showing what I've tried, hoping it will save some time for someone else

fringe shell
heavy marsh
#

as the login and pw?

fringe shell
#

i will dm

heavy marsh
#

k

jolly canopy
#

has anyone done the mac os fundementals

maiden bear
#

did anyone getting trouble with ldapsearch with -h flag ? why the -h flag is asking for help not represented as host/target

maiden bear
#

-H for ldap uri (ldap://ipaddress/

steady hawk
#

Yes, wasn't that your question?

maiden bear
#

i mean, the module and a lot of refference i read is using -h to spell a host instead of -H

fringe shell
steady hawk
#

Oh, I haven't done the LDAP module, but there's a short section in Attacking Common Applications where they do use -H

maiden bear
#

ah i got. nowadays -h is deprecated and changed for -H

fringe shell
fluid edge
#

I finished it

knotty panther
fringe shell
winter blaze
#

hello, can someone please help me on Footprinting Lab hard i found the .sh file using braa, a mean i found the path and i found this user called xxx but i did not find any password to enumerate IMAPS service or POP3 service

winter blaze
#

thanks @fringe shell

atomic veldt
#

In what order should I do the modules

thorn urchin
atomic veldt
#

I have started Cracking into Hack the Box

thorn urchin
#

then follow the order of the modules for the skill path

atomic veldt
#

Okay do you have any knowledge where i should go onto after that

#

I'm going into college and studying cyber forensics and security and just wanted to get the fundmentals down and keep learning

knotty panther
fathom pendant
heavy marsh
#

I'm logged in as Admin, thanks, but yeah, stuck on where to go from here

fathom pendant
#

Try logging into the sql database using a different authentication option from the drop down, maybe local

heavy marsh
#

Someone DMed me with some good info and I'm already authenticated as Admin, just trying to work my way back to how I would have found the info myself

fathom pendant
#

Just trying tbh. Also abstracting what sa could mean as well

silver depot
#

hiii

gaunt monolith
#

Hello I'm in SOCKS5 Tunneling with Chisel (PIVOTING, TUNNELING, AND PORT FORWARDING )
to solve question I write
||./chisel client -v 10.129.175.171:1234 socks || in my parrot
||./chisel server -v -p 1234 --socks5|| in ubuntu
when wrote proxychains xfreerdp /v:172.16.5.19 /u:victor /p:pass@123
I get error
why ?

fiery berry
gaunt monolith
# fiery berry can you paste/screenshot the error you get?

||./chisel client -v 10.129.175.171:1234 socks||
2023/07/18 08:21:33 client: tun: Bound proxies
2023/07/18 08:21:33 client: Handshaking...
2023/07/18 08:21:33 client: Sending config
2023/07/18 08:21:33 client: tun: SSH connected
|| ./chisel server -v -p 1234 --socks5||
2023/07/18 07:11:06 server: Fingerprint qDgBBAANJX0YNDQX0YKqRIQOKv8CIVw6GSFZybgRNWA=
2023/07/18 07:11:06 server: Listening on http://0.0.0.0:1234
2023/07/18 07:21:33 server: session#1: Handshaking with 10.10.15.25:52946...
2023/07/18 07:21:33 server: session#1: Verifying configuration
2023/07/18 07:21:33 server: session#1: tun: Created (SOCKS enabled)
2023/07/18 07:21:33 server: session#1: tun: SSH connected

[proxychains] config file found: /etc/proxychains.conf
[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4
[proxychains] DLL init: proxychains-ng 4.14
[proxychains] Strict chain ... 127.0.0.1:9050 ... timeout
[08:27:42:783] [4249:4251] [ERROR][com.freerdp.core] - freerdp_tcp_connect:freerdp_set_last_error_ex ERRCONNECT_CONNECT_FAILED [0x00020006]
[08:27:42:783] [4249:4251] [ERROR][com.freerdp.core] - failed to connect to 172.16.5.19

fiery berry
#

When you run chisel you can see that is attempting to connect using port 1080

torpid haven
gaunt monolith
# fiery berry can I see the last lines of proxychains.conf? You are using port 9050 for proxy,...

now its like :
#socks4 127.0.0.1 9050
socks5 127.0.0.1 1080
but get this error
[proxychains] config file found: /etc/proxychains.conf
[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4
[proxychains] DLL init: proxychains-ng 4.14
No protocol specified
[08:56:58:181] [4733:4733] [ERROR][com.freerdp.client.x11] - failed to open display: :1
[08:56:58:181] [4733:4733] [ERROR][com.freerdp.client.x11] - Please check that the $DISPLAY environment variable is properly set.

torpid haven
# torpid haven

When I run the above command I get this kind of output. It runs forever. When I run the same command on my kali vm it says "zsh: parse error near '&'.

winter blaze
#

Please check that the $DISPLAY environment variable is properly set.

fiery berry
winter blaze
#

aaaaa

#

so do i have to reboot it ?

#

and it will work properly ?

#

@fiery berry

fiery berry
# winter blaze so do i have to reboot it ?

probably there was another work around so I'm not saying that rebooting is the best solution, but since he is in control of his machine troubleshooting it myself wouldn't be that "confy"

winter blaze
#

@fiery berry i was taking about the footPrint module the medium lab xD

brittle berry
#

Can someone help me out with Attacking Common Applications / Exploiting Web Vulnerabilities in Thick-Client Applications I'm following the guidelines but the newly created .jar file doesn't start...

winter blaze
#

i receive that message error when i was trying to login

fiery berry
winter blaze
#

:C

winter blaze
#

can you please help me ?

#

xD

fiery berry
winter blaze
#

some people said that use remmina instead but i dont know how to use it

quick crane
fiery berry
quick crane
vital jetty
winter blaze
vital jetty
vivid igloo
#

kindov stuck with Find the password for the ldapadmin account somewhere on the system.

#

Windows Privilege Escalation Skills Assessment - Part I

#

tried LaZagne juicepotato

#

non worked

vital adder
vital adder
pure osprey
#

I just did this today and the machine is wildly inconsistent. I ran the same scan which effectively points you to the solution of the challenge a few times and only had it work maybe 50% of the time - it seems like people are getting stuck on this due to a HTB issue and not a student issue?

#

I strongly doubt this is a network issue on my side as I've had no issues with any other HTB Labs/Modules or any other networked services at all

slate palm
#

wtf?! why are the answers case sensitive in the first place?? is it so hard to add a call to the lower function?!

#

just wasted another hour on enumerating users

pure osprey
#

Regex 2 hard

slate palm
#

next time it would be more efficient to just brute force the damn answer request (dont do that please)

frozen mesa
#

ATTACKING COMMON APPLICATIONS - PRTG - Attack the PRTG target and gain remote code execution. Submit the contents of the flag.txt file on the administrator Desktop.

I've found the flag.txt but the flag isnt accepted. Any tips?

https://i.postimg.cc/SxVvs5Fp/htb-prtg-flag.png

acoustic owl
#

reload the page and make sure you have no spaces at the beginning or end of the flag

slate palm
#

its the wrong flag

rustic sage
#

Hello everyone, can anyone help me understand for what is the variable value used here, because when I do the if with the comparison I get what I need but I didn't understand why I have to put the * wildcard to get all values, does this mean that when the programm encodes the var, one of the values of the encode will equal the one in the variable value, or is it just random?

#

Sorry for the stupid question guys but I just can't figure out that little part

ebon coral
quick crane
#

can you help me

quick crane
vivid igloo
gaunt monolith
#

In ICMP Tunneling with SOCKS write this command
proxychains nmap -sV -sT 172.16.5.19 -p3389
and 3389 open
now when write proxychains xfreerdp /u:victor /p:pass@123 /v:172.16.5.19:3389
no connection I'm waiting a lot of time its normal or not ?

proud pine
gaunt monolith
#

nothing happen just this command i show in terminal

[proxychains] config file found: /etc/proxychains.conf
[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4
[proxychains] DLL init: proxychains-ng 4.14
[proxychains] Strict chain  ...  127.0.0.1:9050  ...  172.16.5.19:3389  ...  OK```
barren apex
#

anyone done windows priv esc skills assesment 1?

#

mu juicypotato / printspoofer isnt working

frozen mesa
#

I keep getting this error whenever i try to connect to the rhost. The creds I've used are working (can use them on other occassions without error) but not when i try to connect with MSF. What do i do wrong?

[] Started reverse TCP handler on 10.10.14.236:4444
[-] Exploit aborted due to failure: no-access: Failed to authenticate to the web interface
[
] Exploit completed, but no session was created.

ATTACKING COMMON APPLICATIONS - PRTG

slate palm
vital adder
fresh compass
#

Hi, im with the final exercise of Shells and Payloads module, the live engagement section. In the host number 3 I have uploaded a bind shell and I got the shell but with no administrator privileges. Htb talks about eternalblue but I cant get through in this way, msf or manual way. Any help please?

barren apex
vital adder
#

there is a good few that will work and the rest doesn't

vital adder
#

also why do you have the port in the ip??

vital adder
vital adder
fresh compass
#

Using the exploit of msf it doesn’t work, using autoblue from github doesn’t work either

#

I will check with winpeas

vital adder
#

use the one that let you run a single command

fresh compass
#

Can we talk by pm?

vital adder
#

sure

quick magnet
#

nvm already solve

elfin cedar
#

anybody have trouble getting through the Metasploit module? I wasted so much time and its so simple. It wont connect to the host.

sick frost
pulsar needle
elfin cedar
#

Use the Metasploit-Framework to exploit the target with EternalRomance. Find the flag.txt file on Administrator's desktop and submit the contents as the answer.

fiery berry
elfin cedar
#

msf6 exploit(windows/smb/ms17_010_eternalblue) >

#

then I set rhost to the target ip

#

then enter "run"

fiery berry
elfin cedar
#

I tried eternal romance

#

thats the next module they have you do and it didnt work for me either

fiery berry
elfin cedar
#

it fails at this part [*] 10.129.221.7:445 - Triggering free of corrupted buffer.
[-] 10.129.221.7:445 - =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
[-] 10.129.221.7:445 - =-=-=-=-=-=-=-=-=-=-=-=-=-=FAIL-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
[-] 10.129.221.7:445 - =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=

#

okay

#

nothing

fiery berry
#

which one did you use?

elfin cedar
#

all 3

fiery berry
#

let's move to dm

elfin cedar
#

thanks

elfin cedar
#

last resort I will reboot vm and my computer I guess

livid pier
#

anyone around finish the linux priv esc capabilities section?

vital adder
#

sure what's the issue?

forest zenith
#

Im doing Kerberos Attacks Module and I got a issue with dnstool.py, is there someone that has done that?

livid pier
vital adder
#

which section are you on?

livid pier
#

linux priv esc

#

capabilities

vital adder
zinc marsh
#

someone already checked this?

#

I just saw it when I opened google

vital adder
#

not really the place but that's just google GPT 🤣

fathom pendant
#

Unrelated

livid pier
umbral wigeon
zinc marsh
livid pier
#

or sis

#

thank you

zinc marsh
vital adder
zinc marsh
vital adder
forest zenith
# acoustic owl What exactly is not working?

What could I be doing wrong:

┌──(kali㉿kali)-[~/krbrelayx]
└─$ python3 dnstool.py -u INLANEFREIGHT.LOCAL\\callum.dixon -p C@lluMDIXON -r roguecomputer.INLANEFREIGHT.LOCAL -d 10.129.186.191 --action add <kali_ip>
[-] Connecting to host...
[-] Binding to host
Traceback (most recent call last):
  File "/home/kali/krbrelayx/dnstool.py", line 596, in <module>
    main()
  File "/home/kali/krbrelayx/dnstool.py", line 418, in main
    if not c.bind():
           ^^^^^^^^
  File "/usr/lib/python3/dist-packages/ldap3/core/connection.py", line 589, in bind
    self.open(read_server_info=False)
  File "/usr/lib/python3/dist-packages/ldap3/strategy/sync.py", line 57, in open
    BaseStrategy.open(self, reset_usage, read_server_info)
  File "/usr/lib/python3/dist-packages/ldap3/strategy/base.py", line 146, in open
    raise exception_history[0][0]
ldap3.core.exceptions.LDAPSocketOpenError: socket connection error while opening: [Errno 111] Connection refused
acoustic owl
cold narwhal
#

can I ask the question about htb of retired machine :Active here?

fathom pendant
acoustic owl
forest zenith
zinc marsh
#

best user security ever

acoustic owl
#

Oh wait, you have swapped target and your IP
@forest zenith

thorn hawk
#

Hey guys. I just scanned one of the academy servers with nmap for all 65535 ports and i think HTB is using one computer for all exercises LoooooL

acoustic owl
acoustic owl
forest zenith
#

That was it

#

Thank you @acoustic owl

forest zenith
#

@acoustic owl Now, Im also getting a error while trying to use addsn.py. Is it the right account:

┌──(kali㉿kali)-[~/krbrelayx]
└─$ sudo python3 addspn.py -u inlanefreight.local\\callum.dixon -p C@lluMDIXON --target-type samname -t sqldev -s CIFS/roguecomputer.inlanefreight.local dc01.inlanefreight.local
[-] Connecting to host...
[-] Binding to host
[+] Bind OK
[+] Found modification target
[!] Could not modify object, the server reports insufficient rights: 00002098: SecErr: DSID-0315145A, problem 4003 (INSUFF_ACCESS_RIGHTS), data 0
granite ibex
#

Hi

#

Anyone here

#

I

#

K

quiet ember
#

Yes?

fresh jay
#

hi

#

im currently completing the metasploit module, payloads. I have no idea how to exploit the druid service. Im not sure if im using the right payload since nothing ive tried has worked...

fathom pendant
versed stump
#

Hello everyone, it's probably a dumb question but I haven't find the answer for this one. I'm doing Linux fundamentals, file system management part and there is a question "What is the size in GiB of the "/dev/sda" disk in our Pwnbox?". The problem is that there is only one option to start pwnbox is by activating instances which i can't because I've already powered it on (I have only 1 activation per day). Is it possible to somehow connect to pwnbox with, for example, ssh and answer this question without googling it? Thanks in advance

acoustic owl
versed stump
#

Oh okay, will wait until tomorrow. Thanks

thorn hawk
#

y0 y0 to all. I need some help on SQL injection fundamental module at the last question. I have this webserver with a login being trying to inject some SQL code for 1 day now and i can't seem to do nothing to the database or login page. I have also BURP setup and can send the request from the repeater to see If i get a response in the body with some type of leak but can't seem to see something. I have also nmap the trarget and found the apache serve version.

How can i found out if the database is affected by SQL injection non of the special characters work?

west perch
#

Hello

#

I'm working on Starting Point, I barely know anything at all concerning htb, however I do have experience with Linux, and my current machine has WSL enabled
Is it possible to work on the starting point with WSL? Or do I need to create a linux VM?

maiden spindle
acoustic owl
west perch
#

oh yes thanks man

acoustic owl
rare topaz
west perch
#

oh ok I understand

rare topaz
#

there is a module in HTB Academy that sorta eases you into the whole box stuff as well

#

and setting up a vm is included.

thorn urchin
#

eh I think plenty of content is more advanced then starting-point

#

overall starting-point just kinda sucks imo lol

west perch
#

I know how to setup a vm, I'm just wondering if it's absolutely necessary, given that my laptop is lacking in storage, and that I already have WSL set up

west perch
thorn urchin
#

lots of people have issues getting WSL to work, I do not recommend

maiden spindle
#

@acoustic owl when i do nslookup without adding it I got error messages is there a way to get results without adding it?

rare topaz
#

It's just generally more convenient to get ur own VM setup.

acoustic owl
thorn urchin
#

if you cant setup a vm yet, then make good use of your pwnbox instances

west perch
#

welp, time to make a vm :(
I'll set up Fedora

thorn urchin
#

just grab kali

#

unless you feel like doing hard mode

west perch
#

(I don't drink coffee)

#

Nah, it's just that I'm more familiar with Fedora

thorn urchin
#

Your poison

#

Vast majority of guides and tuts and academy content are going to presume youre using kali or parrot. So be prepared to have to fill in a lot of setup gaps yourself

thorn hawk
#

is fedora pre installed with sqlmap? 😛 hahah i dont know really lol

west perch
sly grotto
#

help for Where is the SAM database located in the Windows registry? in the Password Attacks Attacking SAM ?

#

i tried manythings

trail leaf
#

The module tells you this pretty explicitly. When in doubt, try and copy and paste exactly how it's formatted in the module.

flint steppe
#

anyone available for a question on Credential Hunting in Linux/

rustic sage
#

Is there an alternative to PowerView & SharpHound but for Linux?
I am having a hard time finding one

rustic sage
#

Still stuck? You can dm me.

deep owl
#

hello all please help

#

AD Enumeration & Attacks - Skills Assessment Part II

#

question 4

#

AD Enumeration & Attacks - Skills Assessment Part II

#

Use a common method to obtain weak credentials for another user. Submit the username for the user whose credentials you obtain.

#

am stuck here for more than a week

thorn urchin
#

a week??

#

what common methods have you tried

deep owl
#

i mean i work so i don't have much time

#

i have tried password spraying

thorn urchin
#

did you try spraying using their example passwords

deep owl
#

yup invoked the ps1 file

#

imported it first

#

then used the invoke command

#

am not sure what pass i have to try other the one mentioned in the "Internal Password Spraying - from Windows" section

thorn urchin
#

then perhaps your user list is bad

vernal mountain
#

yo guys can i discuss ctfs in the server?

thorn urchin
#

this channel is for module discussion

vernal mountain
thorn urchin
deep owl
#

did not use a user list as it was not discussed in the section monkaS

vernal mountain
thorn urchin
deep owl
#

but i will definitely look it up

#

thanks a lot

thorn urchin
#

what were you spraying if you didnt have a user list? lol

deep owl
#

helpful tip

thorn urchin
#

gl 👍

deep owl
#

i thought if the user is domain joined then we don't have to use a list 😦

thorn urchin
#

ah tbf, I didnt use whatever ps1 script so perhaps it enums users first

tender lake
#

I'm a little bit stuck on the Credentials Hunting in Linux, I have managed to ssh onto the target after reading the hint, and I have found the bash history file for will but I cant open it or read it ||tail: cannot open '/home/will/.bash_history' for reading: Permission denied|| as with the code shown in the module. Can anyone point me in the right direction from here?

deep owl
thorn urchin
#

depends on the tool

deep owl
#

DomainPasswordSpray.ps1

thorn urchin
#

idk I dont use it

deep owl
#

no worries thanks

tender lake
#

like the .bak files?

supple radish
tender lake
supple radish
#

I'm on the protected Files module and I'm stuck I got the id_rsa file but everytime I try to convert it I am faced with this error:(I've also tried on both my personal machine and pawn machine) ERROR: /usr/share/john/ssh2john.py id_rsa > ssh.hash
Traceback (most recent call last):
File "/usr/share/john/ssh2john.py", line 193, in <module>
read_private_key(filename)
File "/usr/share/john/ssh2john.py", line 103, in read_private_key
data = base64.decodestring(data)
AttributeError: module 'base64' has no attribute 'decodestring'

supple radish
tender lake
supple radish
tender lake
#

yeah, that 8 hour estimate on the overview is deceptive

supple radish
supple radish
tender lake
#

Atleast you found the answer.

supple radish
tender lake
supple radish
tender lake
#

tried copying the file from kira's to my local and use it there byt then the profile does not show up

supple radish
#

oh ya dont do that I know exactly the error your running into

remote fulcrum
#

Who can help me out with the NMap module? Stuck on the last lab.

#

Oh and hello of course 🙂

supple radish
#

Basically when you transfer the file it adds your whole transfer to that file so instead find a way to copy firefox_decrpyt.py into a file on your target machine and run it from there but if you already transferred the file then restart your target ip machine and this time dont transfer it and just run firefox_decrypt.py on the target machine right away

tender lake
#

Makes more sense

#

well, this might be stupid, but when I try to upload the .py : ftp> put firefox_decrypt.py
local: firefox_decrypt.py remote: firefox_decrypt.py
421 Timeout.
or > Not Connected in a follow up attempt

#

am I just being stupid?

remote fulcrum
deft bison
#

were you able to solve this?

tender lake
tender lake
remote fulcrum
tender lake
supple radish
tender lake
sly tapir
#

Has anyone completed the Windows Event Logs Skills Assessment? im on the first question, and stuck..figured it would be easy to find, but none of the .exe files are matching up

remote fulcrum
sly tapir
#

scrach that...for some reason i wasnt opening the DLL event log

tender lake
#

I finally got it. Thans creator

supple radish
rustic sage
#

hello guys

remote fulcrum
#

Need to go all. Pretty late. Have fun. And thanks for the hints.

rustic sage
#

when i open kali terminal in virtual box this message pop up suddenly in the terminal

#

what is it?

remote fulcrum
#

Looks like not enough rresoureces assigned to the CPU or somcthing.

fathom pendant
#

^

remote fulcrum
#

Or SWAP fulll

rustic sage
fathom pendant
#

Lmao

remote fulcrum
#

Give your VM a little bit more resources and SWAP space. Seems like you use low-spec computer.

fathom pendant
#

It has nothing to do with the game

remote fulcrum
#

LOL

#

Anyway. Night night all. _o/

rustic sage
fathom pendant
#

The game got its name from this service

#

It is wholly unrelated

rustic sage
fathom pendant
#

Yes

#

It's a system level service that monitors hardware

fathom pendant
#

:p the service has been around way longer than the game

#

It's really not something gone over in cpts or cbbh if I'm looking at the curriculum correctly

#

But here's an article

#

¯_(ツ)_/¯

quiet ember
#

You could try some one liners with PowerShell or generating a reverse whell with msfvenom and downloading it to the machine

#

It ain't that deep

rustic sage
#

capture request with burp, use an encoded one liner

thorn urchin
#

my goto strat with these tends to be to pull down a shell script and then use a second command to execute it.

#

But otherwise this is a pretty standard thing youll want to have some comfortable tricks using

deft bison
#

I'm currently working on HTTP Attack Module's section TE.TE; can I dm someone about this?

brittle herald
#

Is it me or do some of the HTB modules "over-talk" some of the topics? I'm reading about DNS and all of a sudden the module throws in CHAOS records out of nowhere

rare topaz
#

I mean they elaborate alot on certain things and sometimes skip through certain info.

It's at the end of the day rlly up 2 you how you study and learn more.

winter blaze
#

Hello if you need help in Footprint module easy lab, medium lab, hard lab ping me aside that thing is difficult xD ill try to give you the right direction i just finished them a few seconds ago

brittle herald
#

I spent a good hour trying to figure out what they needed me to find

winter blaze
#

because from my pov all of them were hard

#

xD

fringe shell
rare topaz
#

there's always more to learn

rustic sage
#

well hello there

winter blaze
supple radish
#

Im on password attack module and im on the easy assesment. I have got access to M*** account completely through ssh but now ive been going through his bash history and really trying to find a way to get root but im stuck. Can someone point me in the right dirrection

rustic sage
ivory fjord
#

For the 2nd problem in Windows File Transfer Methods section under the FILE TRANSFERS module (https://academy.hackthebox.com/module/24/section/160), it says to upload file to the target machine and then RDP into the machine to unzip it.

I am able to upload the file after RDPing into the windows machine and get the flag.

Is the question phrased incorrectly?
If not I would really appreciate it if someone could nudge in the right direction so that I can actually solve the problem in the "proper" way.

supple radish
ivory fjord
supple radish
ivory fjord
#

gotcha.
Thanks for the clarification!

raw venture
#

~~Hello, I've been stuck here. I am bit confused where should I modify this htb/fatty/shared/resources/User.java. I tried to modified and rebuild the JAR file but it didn't work. Appreciate if someone can give me a hint. Thanks

Module: ATTACKING COMMON APPLICATIONS

Section: Exploiting Web Vulnerabilities in Thick-Client Applications

Part: SQL Injection

public User(int uid, String username, String password, String email, Role role) {
    this.uid = uid;
    this.username = username;
    this.password = password;
    this.email = email;
    this.role = role;
}
public void setPassword(String password) {
    this.password = password;
  }

~~
Edit: Solved. Thanks @vital adder for the help.

vital adder
vital adder
supple radish
vital adder
#

the thing that you said you have read should have what you need

supple radish
fringe shell
#

In File Upload Attacks - Limited File Uploads, I'm trying to send through basically the same payload as the section notes... but the server just hangs and doesn't send a response. I can upload a normal SVG of course. Can anyone see anything glaringly wrong from my request?

#

need to url encode the command. try putting + instead of spaces

vital adder
#

the target hangs but did the file get uploaded?

sleek urchin
#

Just done it today, Best of luck to you all!!

fringe shell
fringe shell
vital adder
#

just give it a quick try and everything seem to be working fine for me

#

used the same payload (without burp)

rustic sage
#

URL encode key characters in burp

#

Have a looked here:
GET /tmpbijqh.php?cmd=python3+-c+'print(100)' HTTP/1.1

rustic sage
fringe shell
thorn hawk
# rustic sage Still stuck? You can dm me.

Hey c0nstant. Thank you so much for getting back to me. I was able to by pass the login page. Now trying to see if I can get info from the database. Might come back to you if I can't find something today hehe. thank you so much for your help

livid quest
#

Does anyone else have problems with accessing their badges, get's an Unauthorized - Warning, when accessing them?

tender lake
#

none on my end

thorn hawk
#

looks OK to me too

acoustic owl
torpid haven
livid quest
# acoustic owl Try logout and the login again

I've this problem the weekend, so i logged in and out serval times in the meanwhile, but without any change, on the weekend i also had problems to start the pwnbox instance, but thats fine now

acoustic owl
vital adder
#

add ' to your url

vital adder
#

yep ('URL')

torpid haven
#

Thank you! Makes sense.

tall saffron
#

If there is someone who can talk about AD enumeration and attacks Skill Assesment II, im on the question about the hash of CT059. 2 days im on it and nothing 😦

#

Anyone know a responder like which Can work well on windows through evil-winrm?

thorn hawk
#

Hey @tall saffron not related to your issue but what module is this in the academy?

tall saffron
tall saffron
#

Maybe it was a problem in an other part so

fiery berry
tall saffron
#

I tried too but no result, maybe with new (reset) box

fiery berry
tall saffron
#

I talk about winrm because i searched for hint today and i saw someone in the forum who said it must be done through evil-winrm (weird idk why)

fiery berry
#

sure

granite ibex
#

Hello

#

Koi hai

sleek urchin
# tall saffron If there is someone who can talk about AD enumeration and attacks Skill Assesmen...

I did it via evil-winrm and logged as admin there but you could do it in different ways, I believe that you have admin hash for MS01 & SQL01, logging via evil-winrm to one of the compromised domain and run Inveigh.exe {found here:https://github.com/Kevin-Robertson/Inveigh/releases/tag/v2.0.10 } NOT Inveigh.ps1 , waiting a couple of minutes and you get CT user hash

GitHub

Removed .NET 6 builds.
Added .NET 7 and NativeAOT builds.

pine dagger
frozen mesa
#

in password attacks, they suggest to use the --force with hashcat whilst in the hashcat module they advise NEVER to use this option.

How big is the chance on incorrect results because of the --force flag

sleek urchin
#

when you in evil-winrm, you could use built in functions, one of them is upload

sleek urchin
pine dagger
#

or I could just drag and drop it via the existing RDP that is already open, and save myself a lot of typing

#

😄

sleek urchin
vital adder
thorn hawk
#

Yeeees after 2 diffucult days i was able to find the flag of the sql module. thank you all for your help

sleek urchin
#

proxychains -q evil-winrm -i some.ip -u administrator -H XXXXXXXXXXXXXXXXXXXXXX

vital adder
#

through a proxy or not the upload "feature" in evil-winrm work like 20% of the time for me

sleek urchin
sleek urchin
proud pine
#

evil-winrm upload should work fine, as long as you give full paths.

vital adder
#

i may mistake the upload with the download but both usually don't work for me

proud pine
#

Same goes for download. If you're seeing it 'fake' an upload/download, chances are you just didn't give it a full path.

#

I used to have problems with it, too.

pine dagger
#

But then it took an arrow to the knee?

radiant abyss
#

In the FTP section of the Attacking common services module, the FTP service is extremely slow, taking like 10 seconds to respond to a login attempt. Since the task is to bruteforce the username and password, this makes it kinda impossible. I tried resetting the target like 6 times but most of the times the service won't even start. What to do?

radiant abyss
sleek urchin
#

good, there is no need to brute force, there is section about 'Misconfigurations' try to read it again and understand it

radiant abyss
sleek urchin
#

I believe that Hydra will work, and use -t 4 for threads along with rockyou

radiant abyss
#

anyway im pretty sure the target in that section is broken so someone from HTB staff should take a look at that

forest zenith
#

On Attacking Kerberos Module, on chapter "Unconstrained Delegation - Users" how am I supposed to use powerview?

#

Since I cant RDP into the machine or get psexec or winrm running

forest zenith
acoustic owl
fathom pendant
forest zenith
autumn pilot
#

you don't need powerview to solve the question

acoustic owl
#

The module provides you with the users. You do not need a powerview

autumn pilot
#

powerview is just an example

vivid igloo
#

this is so annoying

#

xfreerdp /v:10.129.101.50 /u:htb-student
[05:34:33:504] [25401:25402] [ERROR][com.freerdp.core.transport] - BIO_should_retry returned a system error 32: Broken pipe
[05:34:33:505] [25401:25402] [ERROR][com.freerdp.core] - transport_write:freerdp_set_last_error_ex ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D]

radiant abyss
fathom pendant
#

My question was rhetorical

fathom pendant
hollow frigate
#

Hi everyone, I am busy with the updated parts from "Linux Privilege Escalation - Containers" and can't elevate my privalage is per the examples. I did find a work around to get the flag but would like to see if i can get root access.

hollow frigate
vivid igloo
#

what is the name of the mod ?

fathom pendant
#

It's from linux priv esc module

hollow frigate
sleek urchin
hollow frigate
sleek urchin
violet tundra
#

Hello, any news about this module ? I still have 80K to go and i'm running on ftp service, but i don't think this is the best method

hollow frigate
# sleek urchin you are welcome

luckily i read the lxc help page and found that i also can run this command with a bit of cahnges to it ("lxc exec <instance> -- sh -c "cd /tmp && pwd""), an managed to read the flag before i got root 😆

fathom pendant
#

There's a chance you're doing something incorrectly

violet tundra
fathom pendant
#

What section?

violet tundra
#

I will surely eat while waiting :/

#
fathom pendant
violet tundra
fathom pendant
#

Try resetting the target

#

Oh

#

Right

#

Show me the command used?

#

Bc I'm fairly certain I know the other common (user) error people run into

hollow frigate
violet tundra
#

hashcat --force password.list -r custom.rule --stdout | sort -u > mut_password.list

violet tundra
violet tundra
rustic sage
#

Hello everybody im in the ACTIVE DIRECTORY ENUMERATION & ATTACKS module in ACL Abuse Tactics im trying to solve the quest Work through the examples in this section to gain a better understanding of ACL abuse and performing these skills hands-on. Set a fake SPN for the adunn account, Kerberoast the user, and crack the hash using Hashcat. Submit the account's cleartext password as your answer but im doing something wrong when im trying to add damundset in group Help desk 1 have this, please could somebody help im here 4 HOUR!! PS C:\tools> $SecPassword = ConvertTo-SecureString 'Pwn3d_by_ACLs!' -AsPlainText -Force PS C:\tools> $Cred2 = New-Object System.Management.Automation.PSCredential('INLANEFREIGHT\damundsen', $SecPassword) PS C:\tools> Add-DomainGroupMember -Identity 'Help Desk Level 1' -Members 'damundsen' -Credential $Cred2 -Verbose VERBOSE: [Get-PrincipalContext] Using alternate credentials WARNING: [Add-DomainGroupMember] Error finding the group identity 'Help Desk Level 1' : Exception calling "FindByIdentity" with "2" argument(s): "The user name or password is incorrect.

fathom pendant
fathom pendant
#

Also don't need to spam it everywhere

rustic sage
#

in the module works

fathom pendant
#

do you have the AD modules loaded in powershell? ¯_(ツ)_/¯

rustic sage
#

yes i have it

fathom pendant
#

And is this something that's being asked of you in the question?

#

Sometimes the examples don't 1:1 mirror the practice

zinc marsh
#

someone could help me disabling the amsi using powershell?

#

All what I am trying doesn't work

civic fiber
#

Can anyone help me install tplmap

#

I got this error message

#

virtualenv -p python2 venv
RuntimeError: failed to find interpreter for Builtin discover of python_spec='python2'

umbral wigeon
rustic sage
rustic sage
warm drift
#

in metasploit module and trying to priv esc a system running Sudo version 1.8.31 I know theres a public exploit on github but the target system doesn't seem to have a command called make and idk what to do please help

cedar void
#

Having trouble 'Finding the SID of the WS01 host' in the 'Active Directory Search Filters' section of the 'Active directory LDAP' module.

vital adder
#

also you can just compile the exploit on your machine not the target

cedar void
#

Commands I typed out: "
$computerName = 'WS01'
$computer = Get-WmiObject -Class Win32_ComputerSystem -ComputerName $computerName
$SID = $computer.SID

Write-Host "SID of $computerName: $SID""

cedar void
vital adder
#

hint you can just use ||Get-ADComputer|| and there is an example for this

vital adder
#

just search the vuln name in msf

warm drift
vital adder
#

yep

slate palm
#

so password attacks module is an exercise in patience even from the pwnbox? is there some cutoff time when I can be sure I did something wrong?

warm drift
# vital adder yep

please how do I compile a .c exploit on my own host before sending to the target?

fathom pendant
slate palm
#

thank you

violet tundra
#

it seems

#

"real-world scenario" 🙂

rustic sage
#

Could you tell me how hard are AD modules?

rustic sage
#

oh god

slate palm
fathom pendant
#

The difficulty of AD module is that you're dealing with AD

slate palm
#

ono I dont even have half of those tries/minute

#

are you sure the ftp has the same credentials as the ssh though?

violet tundra
#

you doing password mutation too ?

slate palm
#

yes and Im 31 minutes in

violet tundra
slate palm
#

interesting

violet tundra
#

@slate palm what you think ?

slate palm
umbral wigeon
slate palm
#

filter for or filter out? instructions unclear got hydra stuck in ssh

violet tundra
#

For those that will be stuck in password mutation module: remove first 17K lines as stated before

fathom pendant
#

Filtering is not needed though

zinc thunder
#

Anyone else having trouble using nslookup in info gathering - web edition (active sub dom enum). Dig works fine, nslookup works on other domains then inlanefreight

fathom pendant
tall saffron
zinc thunder
fathom pendant
#

Because you'll need to do nslookup domain ip usually as anything that isn't a registered site isn't gonna be on any public dns records

zinc thunder
fathom pendant
#

It's always domain before ip for nslookup

#

Technically the "ip" part can be replaced with nameserver

#

But it helps to simplify

subtle flicker
#

Hey! i have a question on password attack, specifically in the lsass section.
When i try to dump the lsass.exe process, i can't see the actual file to transfer, is that normal? i used the same command in the accademy of course changing the PID of the lsass process.

Edit: restarted the box and now working as intended!

modern hill
#

Question on Metasploit Framework module, I'm in the meterpreter section, and have dumped the hashes, but the hash isn't accepted as the answer, despite that's being asked. Any help on the format?

slate palm
#

I wish you could view hints after you have answered the question

clear mason
#

hello .. in the login brute force module is it normal in the skill assessment that it taking a long long time or am i doing it wrong

subtle flicker
civic fiber
#

python2 --version
Python 2.7.18

modern hill
#

I tried full line, all but username, the last part, with and without colons.

#

Hold on, for some weird reason smart_hashdump and hashdump have different outputs. Let me try the other one.

subtle flicker
#

a : b : c : d ::: --> paste only the "d" hash withouth the colons

modern hill
#

I did get it now, because smart_hashdump and hashdump get 2 different outputs. Apparently needed to use the latter.

civic fiber
#

cf**********************************58

analog dock
slate palm
#

oops thank you 😅

trail leaf
#

I’ve been looking at HTML source if I want to look back at the hints lol

cobalt wraith
#

Question, are we allowed to post writeups for htb academy modules? If we blur the flag?

trail leaf
#

Unless it’s tier 0, no

cobalt wraith
#

rip ty

trail leaf
#

There are better things to do write ups on anyway

cobalt wraith
#

obviously

#

was just curious lol

fathom pendant
#

Proper research and notes from the modules tends to get you fairly far

west night
#

Hi @acoustic owl . Regarding the Password Attacks Lab - Medium, I successfully enumerated the smb share and downloaded the zip file. I then cracked the password and it revealed a document called documentation.docx. Unfortunately I have not been able to figure out how to decrypt the docx file. I went to a windows machine and a second prompt appeared asking for the password. The first password I used to open the zip file, did not work for the second prompt. Not sure what to do next...

kind vessel
#

Hello on Kerberos Attacks module I try to get Domain Admins TGT with Rubeus but can't find any can someone help me ?

fathom pendant
west night
#

Thanks @fathom pendant 🙂

rustic sage
mortal shadow
#

do you guys rahter use gobuster or ffuf?

#

i feel like ffuf is hella slow for me

#

even with timeouts of 1

livid pier
#

Anyone here post their notes from academy online? I am reviewing for the CPTS and working on my notes and was curious about what other people have done

livid pier
mortal shadow
#

ffuf -w /opt/useful/SecLists/Discovery/DNS/subdomains-top1million-5000.txt:FUZZ -u http://FUZZ.thetoppers.htb takes around 5 minutes
gobuster vhost -w /opt/useful/SecLists/Discovery/DNS/subdomains-top1million-5000.txt -u http://thetoppers.htb takes 1 minute

livid pier
#

the new rage is feroxbuster tho

slate palm
#

I just tried to compare my learning time with the time stated on the academy modules and there are "days" and "hours" how many hours are one day?

mortal shadow
livid pier
civic zenith
#

Looking at the time status for hydra: [STATUS] 864.00 tries/min, 864 tries in 00:01h, 93180 to do in 01:48h, 48 active
[STATUS] 839.33 tries/min, 2518 tries in 00:03h, 91526 to do in 01:50h, 48 active
[STATUS] 854.29 tries/min, 5980 tries in 00:07h, 88064 to do in 01:44h, 48 active

When it says 01:44h does that mean 1 hour and 44 minutes?

livid pier
#

yes

civic zenith
#

@livid pier thx lol

slate palm
#

ono

fathom pendant
#

A single day is calculated as a working day. So 8 hours

#

:p I know it's silly but it's easier to digest it as 5 days instead of 40 hours

slate palm
#

yes it makes sense

sand cedar
#

yo so im a lil confused. I did the Attacking Common Services - Attacking SQL Databases and I'm printing the flag but it's either not showing me the full flag, or it's not registering thinkw Am I supposed to find the 2nd piece myself, or is it just buggin out?

fathom pendant
#

I'm not able to sanity check you

#

But I'll confirm/deny if you're in the right area

tawdry vapor
#

in the medium lab of the footprint module i can't connect to MS SQL Studio

#

anyone can help me?

livid pier
#

take a step back

tall saffron
fathom pendant
fathom pendant
tawdry vapor
fathom pendant
tall saffron
fathom pendant
fathom pendant
tall saffron
#

So why there is a methodology in the module if you go that route

#

I give up lol

tawdry vapor
fathom pendant
#

And conversely, writeups can be used to skip learning entirely

fathom pendant
#

There's a reason I said important, hint it's accessible as the current user you have

tall saffron
fathom pendant