#modules

1 messages · Page 109 of 1

vital adder
cedar void
open ember
#

I only see the student ID, it's not 60 characters long

acoustic owl
maiden spindle
#

hashcat doesn't work on my virtual machine so i ran it on my pc. The mut_pssword.list file it created doesn't have sam's password. I ran hydra. I don't know if the size of the file hashcat gave is too small. If i try the pwnbox I don't know how to download the resources, it bugs out if you go to HTB pages that load the pwnbox

vapid isle
cedar void
#

I have been working on the second question of the section of module(https://academy.hackthebox.com/module/22/section/290) for about an hour or so and I am stuck. I typed out this command( python3 /opt/windapsearch/windapsearch.py --dc-ip 10.129.42.188 -u inlanefreight\james.cross -U --full --output "final_output.txt"
), it listed all 12 users on that domain and saved the output of the result of the command to a file. When I typed C+F and typed "SMARTCARD_REQUIRED" I could not find that term in the file I created anywhere.

The question:

What user account requires a smart card for interactive logon (SMARTCARD_REQUIRED)?

tidal mango
cedar void
tidal mango
tidal mango
cyan ginkgo
#

can someone help me on the bash introduction

cedar void
cyan ginkgo
#

i created a script but it doesnt work i think the key is wrong but i dont know how to fix it

tidal mango
cedar void
#

What is the OID?

#

Object IDentifier

tidal mango
#

Object Identifiers (OIDs), like I said it is in the prior section

lunar lily
#

I just got into Academy and I have a question. It says I pay 10 cubes for free modules and I get 10 cubes from them. Do I get extra cubes for solving the individual questions inside them? Like can I make cubes just by solving free modules?

cedar void
tidal mango
astral swift
#

Hello, anyone can help me on the AD assessment - Part 1 ? I have all flags except the cleartext password of one user and I think it might be broken

astral swift
#

Submit this user's cleartext password.

cedar void
tidal mango
tidal mango
spiral leaf
#

I need help with Password Attacks/Credential Hunting in Linux: I tried using Hydra to bruteforce ssh into the target with the username Kira and a mutation list of the password given in the hint. Unfortunately this didn't work. Can anyone give me a hint?

deep owl
#

it never worked for me cracking the TGS

velvet sparrow
#

Can someone help me with Active Directory BloodHound:Skills Assessment last question Find the percentage of users with a path to GLOBAL ADMINISTRATOR I used my query and when I put my answer it say wrong I'm sure that my query is ok

deep owl
#

did you use "upload data" to uplod your docs in the bloodhound

winter blaze
#

can someone please help me in "Attacking Common Services - Easy" i just gained access but idk how to enumerate the Windows env, i tried dir and go back with cd .. and i tried to enumerate using dir and i tried a reverse shell as well but i couldn't

trail leaf
#

Try using an encoded poweshell reverse shell

#

Or the IEX one with a powershell script hosted on your own webserver

pine dagger
#

Question on Linux Privilege Escalation -> Python Library Hijacking. The examples show the commands using sudo multiple times, but the htb-student doesnt have the ability to sudo there... what am I missing from completing the examples?

trail leaf
#

You should have sudo

candid gale
#

Hey guys, how are you doing? I'm having little troubles with the mutation part of password attacks. I know it get a lot of time to crack a password, but its gonna take line 14 hours.
It's been like an hour so far and nothing came up. It's like this?

keen axle
#

If it's for the hashcat module none of them should take that long

#

I think the longest one took for me was about 5-10 mins

digital pewter
candid gale
pine dagger
raw venture
#

Module: Attacking Common Applications

Section: Attacking Common Applications - Skills Assessment I

Hello, I've completed this section but via msfconsole. Any hints to solve it in right way?
I can only run &dir command. Already tried to use type and more command with encoded path but no luck to view the flag.

wheat garden
trail leaf
carmine quail
#

I'm working on the "Attacking Common Applications" Module and Exploiting Thick-Client Applications. I made the new fatty-client.jar file with changed port and MANIFEST, removed both hashfiles, and rebuilt it successfully. It runs and I can login, BUT... I can't open any of the files the course content says I should be able to. There's not an "Open" button in the lower part of the window. Any advice/tips?

trail leaf
#

The back half of the attacking common applications module is so weird

#

Mass Assignment and LDAP injection just come out of nowhere

thorn urchin
#

that module is the random grab bag of the course

trail leaf
#

I don't hate the Thick Client section but also why is there another rev related thing like 5 sections later, feels like it makes more sense to keep all of that together

carmine quail
#

Any tips for why I’m not seeing the “Open” button that will allow me to read even the basic files?

shut owl
#

Could I get some help with the Broken Authentication Predicatable Reset Token question? Thanks in advance.

heavy marsh
#

Having some issues with the vhosts lab in information gathering. I was able to get one of the flags last night, flag #3 by choosing one of the subdomains I got with ffuf. Today when I went to get the rest I had to rewrite my /etc/hosts file from scratch using what I was able to find online for a default. I'm running a live boot persistent kali usb drive, but there was nothing I could find that had a default /etc/hosts file nor a way to automatically generate a default so I am stuck. The flag for flag #3 still works, and by the same method none of the other subdomains are giving me a flag when I curl the subdomain. I am using the same method of inputting the subdomain and ip into the /etc/hosts file as I did with the flag #3 last night.

#

Doesn't make any sense

thorn urchin
#

default etc hosts is just 127.0.0.1 and localhost

some distros may add some random stuff but theyre rarely truly mandatory

#

I don't know why your etc/hosts would be so borked you had to rewrite from scratch though

heavy marsh
#

I must have deleted it somehow

thorn urchin
#

odd, wouldnt think itd break anything though

#

hosts is checked first but its not checked last

heavy marsh
#

This is what it looks like, I just put a window over the subdomains to hide them as spoilers

#

It's what I found with ffuf

#

the only one that works with the curl command is the one that I used last night

echo glen
#

Hi guys, I'm in the getting setup module. It wants us to set up a windows 10 VM in which it points us to a link for windows 10 VM, but it is bringing me to windows 11 VM. Will this be an issue going forward with the different scripts and chocolatey manager we are to setup?

#

"Setting up" module

thorn urchin
vital adder
rugged veldt
#

For Windows Priv Esc Part 2, how should I find the iamtheadministrator creds? I've been searching for xml, config and txt files but nothing so far

candid gale
heavy marsh
#

still not sure why the rest of the domains arent working

#

I'm doing the exact same thing I was doing yesterday with the 3rd flag

vital adder
quaint hemlock
#

hi, I have a problem with the academy vm instance, I already turn it on but there's just blank screen and later disconnected, already switch from using vpn or non vpn but nothing work, anyone know what's wrong?

vital adder
rugged veldt
vital adder
#

give me a sec my note suck ass on that one part for some reason but basically yes that's what you have to find

quaint hemlock
vital adder
#

if both your vpn and the pwnbox are on at the same time then both will try to kick each other of the network and that's your issue

rugged veldt
#

It's like finding a needle in a haystack

vital adder
quaint hemlock
#

so I should only use one?

vital adder
#

yep and one only

quaint hemlock
#

ok thx

rugged veldt
#

I'm gunna try pipe select string and get childitem

#

Oh

#

There we go xd

quaint hemlock
heavy marsh
#

I said vhosts, I meant /etc/hosts, modified the above comment

shut owl
knotty gust
#

In the footprinting module, DNS section, I am currently having trouble finding the FQDN whose octet ends in x.x.x.203. If anyone is able to help, I can share what I have tried so far in DMs.

knotty gust
# iron plaza did you find the zones?

I was able to use dig axfr internal.inlanefreight.htb @[target-IP] and dig axfr inlanefreight.htb @[target-IP], but I don't know where to go from there. I tried using dnsenum, but I could only get it to work on inlanefreight.htb, not on any of the subdomains. I'm not sure if I'm just using dnsenum wrong or if my methodology is wrong.

iron plaza
knotty gust
#

Okay, I will try to use dig some more to see if I can find the answer. Thanks for your help!

quasi wave
#

hi I completed most of the getting started module and completed all privesc except for last thing from Nibbles box. I got help a couple of weeks ago and I think I understand the material I'm just having loads of frustrating typos at this point. I did MOST of the privesc in the module. Will it hurt to look at walkthrough of module? I mean the part of the module I'm stuck on is just a walkthrough of Nibbles box.

#

It seems and feels like its been three or four weeks and I want to progress and I have done most of module.

#

is looking at a walkthrough and taking notes for getting started module a bad idea?

trail leaf
#

Isn't the privesc only like 1 step? And the module also walks you through it?

quasi wave
#

yes

#

but I keep having typos

#

lot to type in

#

and its getting frustrating

#

so at this point I think I understand it

#

and I know there will be privesc in future modules right?

proud pine
#

Using the walkthrough at that point is perfectly fine.

trail leaf
#

If you have typos, just take this as an opportunity to practice not making those errors

quasi wave
quasi wave
proud pine
#

Unless you mean the assessment portion

quasi wave
#

as does @trail leaf

#

no assessment portion I will be fine with

proud pine
#

If you mean the actual walkthrough part, and you were trying to do it without using what they were showing you

#

They absolutely expected you to follow along at that part

quasi wave
#

Ok ya but I am doing that and its taking forever and I understand it but I keep running into typos and I think I understand the privesc and what reverse and bind shells are

#

I was doing what they showed me

#

but I think if I watched a video walkthrough of module and took notes that would be ideal at this point

#

do you agree?

proud pine
#

Getting Started was more of a brief introduction, and getting you to a feel of what the process is like.

proud pine
#

If you're planning to use external stuff, that's probably iffy. There's no way to know how much of it is good information, or bad.

#

I can vouch for the quality of the material in the course itself, but if you're looking at some random youtube video, it could be some guy who knows nothing.

proud pine
quasi wave
#

yes

proud pine
#

Yes, anything ippsec is good.

#

Though, that video is ancient, and his processes have changed a lot since then lol

quasi wave
#

ok cool

#

I think there's other walk throughs that are official tho no?

#

alright thanks

rugged veldt
#

Anyone ever had a WebDriver error when running eyewitness?

#

Had wrong selenium version

knotty gust
rugged veldt
#

For burp suite I'm receiving receiving a No route to host for dev.inlanefreight.local, have added to /etc/hosts

#

Fixed it, had one too many IPs pointing to same host in hosts

quaint hemlock
#

I'm on cracking with hashcat module, I tried to activeated the pwnbox but it says connected to undefined, it's active but no screen are showed
anyone know what's wrong?

quaint hemlock
#

now it says disconnected

final maple
#

Can someone help me on the second question for File Inclusion - File Inclusion Prevention? The question is: "Edit the php.ini file to block system(), then try to execute PHP Code that uses system. Read the /var/log/apache2/error.log file and fill in the blank: system() has been disabled for ________ reasons." The hint says to put a PHP vile in the /var/www/html directory, but I have to be root to do that. I also cannot edit the php.ini file without being root. Any hints? Thanks!

final maple
final maple
# fiery berry list your `sudo` permission

Actually, I can...here it is: Matching Defaults entries for htb-student on lfi-harden:
env_reset, mail_badpass,
secure_path=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin

User htb-student may run the following commands on lfi-harden:
(ALL : ALL) ALL

fiery berry
final maple
knotty panther
#

Hello, I have question on Pivot and Tunneling Skill ASSESSMENT
Submit the credentials found in the user's home directory. (Format: user:password)

#

Plain Human work! ohh i get it... weird for normalpassword to have space

haughty current
#

I am stuck on Ooopsie Task 2 What is the path to the directory on the webserver that returns a login page? I put /cdn-cgi/login and I get network error.

#

I tried asking on pwnbox but I do not have access to writing in the chat fields.

haughty current
#

yes

#

My main problem is that I can not enter the correct answear to task 2

#

Burp give me the link /cdn-cgi/login on the target tab

fiery berry
#

I'll dm you to see why you can't access the "pwnbox" channel, here is for the "academy" modules

haughty current
#

My name on hackthebox is noobie79

vital adder
silver mesa
#

Hi guys
Im currenlty working on password attacks - hard lab.
I have runas to david cmd - found backup.vhd file. unable to download becoz of file size.
Im stuck on mount the baclup.vhd file from windows to linux.
can any help me with this.

lyric oar
compact apex
#

Hello, does someone know why the following command does not retrieve the allowed HTTP verbs ? ```shell
curl -i -X OPTIONS http://SERVER_IP:PORT/


as it is supposed to be as explained in the web attack module
fiery berry
silver mesa
acoustic owl
# silver mesa Hi guys Im currenlty working on `password attacks` - hard lab. I have `runas` to...
It's FOSS

Here’s the scenario. My system came with Windows 10 Pro and that came with BitLocker encryption. I installed Ubuntu in the dual boot mode even with the BitLocker encryption enabled for Windows.

You can easily access the Windows files from within Linux. No hi-fi stuff here. Just go to

silver mesa
#

Thanks

compact apex
# fiery berry can you post a screenshot of the output? I did a random `curl` and I can see an...
┌──(honeypot㉿kali)-[~]
└─$ curl -i -L -X OPTIONS http://94.237.59.206:48113/   
HTTP/1.1 200 OK
Date: Wed, 26 Jul 2023 09:20:20 GMT
Server: Apache/2.4.41 (Ubuntu)
Vary: Accept-Encoding
Content-Length: 1108
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html>
<html lang="en">

<head>
    <meta charset="UTF-8">
    <title>File Manager</title>
    <link rel="stylesheet" href="//netdna.bootstrapcdn.com/bootstrap/3.0.3/css/bootstrap-theme.min.css">
    <link rel="stylesheet" href="//netdna.bootstrapcdn.com/bootstrap/3.0.3/css/bootstrap.min.css">
    <script src="//netdna.bootstrapcdn.com/bootstrap/3.0.3/js/bootstrap.min.js"></script>
    <script src='https://cdnjs.cloudflare.com/ajax/libs/jquery/2.1.3/jquery.min.js'></script>
    <link rel="stylesheet" href="./style.css">
</head>

<body>
    <div class="form-group">
        <h1>File Manager</h1>
        <form role="form" action="index.php" method="GET">
            <input type="text" class="form-control" placeholder="New File Name" name="filename">
        </form>
        <form action="admin/reset.php" method="GET">
            <input type="submit" value="Reset" class="btn btn-danger" />
        </form>
    </div>
</body>
</body>

</html>

<div></div><ul class="list-unstyled" id="file"><div><h3>Available Files:<h3></div><ul><li><h4><a href='notes.txt'>notes.txt</a></h4></li></ul></ul>   
#

And with --head instead of -i:

┌──(honeypot㉿kali)-[~]
└─$ curl --head -L -X OPTIONS http://94.237.59.206:48113/
HTTP/1.1 200 OK
Date: Wed, 26 Jul 2023 09:21:26 GMT
Server: Apache/2.4.41 (Ubuntu)
Vary: Accept-Encoding
Content-Length: 1108
Content-Type: text/html; charset=UTF-8
compact apex
#

Web attacks section 3 but the command is explained in section 2

fiery berry
alpine glade
#

exit

compact apex
willow saffron
#

Can anyone help me? I got stuck for the following question on the module
https://academy.hackthebox.com/module/18/section/75
I try to use the "ls -al /etc" command to list out all files in the /etc folder. Use vim to find the line number that contain the file "sudoers". It's the line 177. I try to submit 177 or 176 but both are failed. Let someone help me.

willow saffron
#

Thx, I understand now.

quaint hemlock
sage granite
#

Use cURL from your Pwnbox (not the target machine) to obtain the source code of the "https://www.inlanefreight.com" website and filter all unique paths of that domain. Submit the number of these paths as the answer.

curl -s https://www.inlanefreight.com | grep  -oiE "www.inlanefreight.com/*[^'\"\ \?\\t\%]+/" | sort -u
 
www.inlanefreight.com/index.php/
www.inlanefreight.com/index.php/career/
www.inlanefreight.com/index.php/feed/
www.inlanefreight.com/index.php/news/
www.inlanefreight.com/index.php/offices/
www.inlanefreight.com/index.php/wp-json/
www.inlanefreight.com/index.php/wp-json/oembed/1.0/
www.inlanefreight.com/index.php/wp-json/wp/v2/pages/
www.inlanefreight.com/wp-includes/
www.inlanefreight.com/wp-includes/css/
www.inlanefreight.com/wp-includes/js/
www.inlanefreight.com/wp-includes/js/jquery/
                                             

Tried 12, and 11 as answers and it says it is wrong, idk what else can I do.

proud pine
sage granite
#

It says 13 is also wrong, this thing gives me a headache.

acoustic owl
#

Try to list all URLs and then sort away the ones that appear twice

final cairn
#

Can a kind soul please explain or speak to how the script, user.sh, reads the html header and executes code. I understand that the payload works because of a vulnerable version of bash. What I don’t understand is how would you be able to tell that the script will take the html headers and execute it. This is for the Shocker box.

acoustic owl
final cairn
#

Could you possibly direct me on how to get access to that channel?

final cairn
#

I went through the verification process, still no luck

acoustic owl
final cairn
#

K I’ll try it again, thanks for the help payloadbunny

lyric oar
vivid igloo
#

any tip on :Web Enumeration

#

mod : GETTING STARTED

#

q :Try running some of the web enumeration techniques you learned in this section on the server above, and use the info you get to get the flag.

steady condor
#

Do I need to learn Splunk if I am only interested in Cissp GRC roles

vivid igloo
#

ik it's some curl flags e.g **curl -IL ** but anyways it would be a great help if u help w this

rapid sparrow
#

New certs!!!

#

HTB CDSA

zinc marsh
#

or maybe a blue team cert

tranquil axle
#

SOC Analyst is blue for sure, sounds interesting, I wonder what a lab for that would look like

zinc marsh
#

I just read CDSA and I had thought advanced or analyst lol

broken warren
#

Im having trouble on the linux privesc logrotate module, I can't get the exploit from github to resolve from the target box. Im in the /home/htb-student directory where ssh drops me when i try cloning the repo. I tried cloning it on my machine and it worked just fine, so i compiled it on my machine and used wget to send it over. But when i try running it, i says permission denied. Is that because i compiled on my machine? or because of the directory im executing it in? UPDATE: I moved just the logrotten.c to the target machine and compiled which seemed to work.

rustic sage
#

Attack Enterprise Networks // Post-exploitation. I'm having trouble getting dc_shell.exe to work. I can't get connection with msfconsole.
Someone can help me?

fresh jay
#

it is a module, could i get some help please 🙂

#

its the payload module for metasploit

fathom pendant
#

Its already set

#

The / is the root working directory of the webapp

warm drift
#

please help In Password cracking module try to copy the shadow of NTDS but I get error I can't send screenshot for some reason but here's my terminal output:

Evil-WinRM PS C:\Users\jmarston\Documents> vssadmin CREATE SHADOW /For=C:
vssadmin 1.1 - Volume Shadow Copy Service administrative command-line tool
(C) Copyright 2001-2013 Microsoft Corp.

Successfully created shadow copy for 'C:'
Shadow Copy ID: {12194c91-d2e0-42c7-a68b-723626288aaf}
Shadow Copy Volume Name: \?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1
Evil-WinRM PS C:\Users\jmarston\Documents> cmd.exe /c copy \?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\Windows\NTDS\NTDS.dit c:\NTDS\NTDS.dit
cmd.exe : The system cannot find the path specified.
+ CategoryInfo : NotSpecified: (The system cann...path specified.:String) [], RemoteException
+ FullyQualifiedErrorId : NativeCommandError
0 file(s) copied.

keen compass
#

on **ACTIVE DIRECTORY ENUMERATION & ATTACKS ** > Bleeding Edge Vulnerabilities, when trying Petit Potam, I am always getting this message (under Windows using rubeus : [X] KRB-ERROR (62) : KDC_ERR_CLIENT_NOT_TRUSTED) or (Error Name: KDC_ERR_PADATA_TYPE_NOSUPP Detail: "KDC has no support for PADATA type (pre-authentication data)" under linux) .

I have tried respawning the lab multiple times (I already needed this at the beginning to retrieve the b64 cert).
Does some of you have an idea of what may be wrong ?

urban sage
#

🥱 and slapped by automod.

tender acorn
#

I have problems with module Broken Authentication Predictable Reset Token

i try a lot finally i am at this point
i use a php script to check the time stemp the given token was generated and generated a token with the user htbadmin.

#

` <?php

function generate_reset_token($username, $timestep)
{
$token = md5($username . $timestep);
return $token;
}
function timerange($username, $timestep)
{
for ($i = $timestep + 0; $i <= $timestep + 2200; $i++) {

  if (generate_reset_token($username, $i) == "2f14f4ab65d13240fa0992494ccb7756") //give token with htbuser

{
echo "timestep: " . $i . " " . "hash: " . generate_reset_token($username, $i) . "<br/>";
echo generate_reset_token("htbadmin", $i) . "<br/>";
}
}
}
timerange("htbuser", 1690384826000) //timestemp
?>`

tender acorn
keen compass
#

your screenshot doesn't provide specific details (at least for me eyes...) please, ask what you need, explain where you are stucked and what you have done...

keen compass
rustic sage
#

does anyone know roughly how long the brute force attack last for on the login brute force skills assessment - website Q2 please? I'm using the rockyou.txt wl. thank you

tender acorn
tender acorn
#

i recomand a smaler version like rockyou-10.txt it is later use in the module

#

this need work

#

but its exact same answer then Q1

keen compass
rustic sage
#

i get no results from rockyou-10.txt

tender acorn
#

it is first in rockyou-60.txt

#

grep -n "admin" rockyou.txt

tender acorn
#

i get a token. this token is the md5 hash from "htbuser" + timestemp millisecond
i get the right timestemp to generate the same md5 hash

#

the question says it generate at the same time a token for the htbadmin user at the same way

#

i test every md5 hash with the timestemp around that whan how is the right but it dont work

digital pewter
#

Did anyone else encounter the below error when performing the Petit Potam exploit in the Bleeding Edge Vulnerabilities section of the Active Directory Enumeration and Attacks module? I ended up getting past it by performing a RBCD attack, but the provided instructions didn't seem to work the way the author described and I'm wondering if it was intentional. If not, I may broach the issue in erratum to make them aware. Thanks!

┌─[htb-student@ea-attack01]─[~]
└──╼ $ python3 /opt/PKINITtools/gettgtpkinit.py 'INLANEFREIGHT.LOCAL/ACADEMY-EA-DC01$' -pfx-base64 "$(cat dc01.pfx.b64 | tr -d '\n')" dc01.ccache

    minikerberos INFO     Loading certificate and key from file
    minikerberos INFO     Requesting TGT

    ...KerberosError:  Error Name: KDC_ERR_PADATA_TYPE_NOSUPP Detail: "KDC has no support for PADATA type (pre-authentication data)"
trail leaf
#

I think Alh4zr3d had a tweet about these errors on HTB a few days ago related to AD CS

#

I think it’s applicable here considering I was able to do it a week or two ago while helping someone else with a different error

keen compass
# trail leaf

wow thanks, ... I could have taken many times continuing to try to find a fix for this !

trail leaf
#

I have a few ways to attempt get around it when doing some of the abuses outlined in Certified Pre-Owned, but I haven’t played with PetitPotam enough to see if there’s a potential workaround here

keen compass
#

you could change DCs date time I guess ?

trail leaf
#

Didn’t think about that as an option but its worth a try

keen compass
#

but that mean you must already be able to have admin right on the domain

trail leaf
#

Oh true

keen compass
#

there might also be needed to disable some service that may be used to timesync the VM Lab with "real world" host server (ESX server or whatever else)

trail leaf
#

Do you have to be an admin to do that? It would make sense but I’ve never had to do it not as an admin.

keen compass
#

you need to be admin to change date time, and in an AD domain, you need to change the DC's time because all others devices are syncing their time with it (it's defined within GPOs)

civic zenith
#

I am on Attacking DNS. Trying fierce I get: fierce --domain inlanefreight.htb
NS: failure
SOA: failure
Failed to lookup NS/SOA, Domain does not exist

#

And Ive added the domain and IP to my /etc/hosts

#

Also subfinder finds nothing while subbrute has a bunch of errors

#

The challenge is: "Find all available DNS records for the "inlanefreight.htb" domain on the target name server and submit the flag found as a DNS record as the answer. "

acoustic owl
alpine ridge
#

yo guys havig a bit of trouble footpring oracle tns question where you have to get the password hash for the stated user, im logged into the db as sysdba but can not seem to find the has when running SELECT username FROM dba_users WHERE username = 'DBSNMP';

digital pewter
thick juniper
#

Hi guys, I’m having trouble finding a way forward in the Password Attacks Hard Lab. I’ve got J and D’s creds and I have the B file but know that I need admin rights on the win box to read it. I’m struggling to find a way to get admin. I want to try and get the SAM but I don’t think I can get that without being Admin first and I’ve run out of ideas. Would anyone be able to give me a nudge please?

civic zenith
#

@thick juniper theres also bitlocker2john

#

the B file is bitlocker

civic zenith
tranquil axle
acoustic owl
raw wren
#

Hey guys, I'm trying to figure out how to get the root flag but I'm having no luck.

thick juniper
thorn urchin
#

open it on your own system

thick juniper
thick juniper
thick juniper
thorn urchin
#

whatever works for you

#

time for some googling then

dire birch
#

yo, anyone here willing to help with the automated scanning section in file inclusion module? kinda lost here

thick juniper
tranquil axle
deep owl
#

hello all

#

AD Enumeration & Attacks - Skills Assessment Part II

#
  • 1 Submit the contents of the flag.txt file on the Administrator Desktop on the MS01 host.
#

when doing the command setspn.exe -Q /

#

i enumerate service account

#

let's say i managed to get the password

#

how do i know which service account to login with the password i obtained

zinc marsh
#

someone could help me adding users to other computers

#

as domain admin?

acoustic owl
deep owl
#

appreciate any help or hint

zinc marsh
acoustic owl
surreal yacht
#

@everyone

thorn urchin
tough fjord
#

Like we are stupid enough to allow everyone to use the everyone ping 😂

thorn urchin
#

to sell a different course content that could be pirated for free no less

zinc marsh
#

it is a guy called everyone I think

rustic sage
#

Has anyone also had problems with the OSINT module, in the coordinates part ?

silk aspen
#

In the Attacking Common Applications module, the Attacking Applications Connecting to Services chapter, I'm getting different mem addresses compared to the ones in the screens from the course. What could be the cause? I used all the exact same commands

quasi wave
#

hi I completed Nibbles on Getting Started Module

#

now I just gotta do the last section which I will do later

#

but I'm glad I actually am getting through this

trail leaf
#

The example likely already ran the binary in the debugger and then printed out the disassembly, which means the base address has already been decided.

pine dagger
#

I must say... anyone who's considering Whitebox Attacks... be prepared for pain. A fantastic module, but it definitely is challenging. lol

pulsar needle
#

Why do I get this error?

thorn urchin
#

that binary isnt compatible with your setup

zinc marsh
pulsar needle
#

So i need to use another shell then?

pulsar needle
zinc marsh
#

It should show like this when the wordlist is in that directory for kali

#

what happen if u do it with ./wordlist

thorn urchin
#

its nothing to do with the wordlists

#

illegal hardware instruction means the actual CPU received a bad asm op code

#

that comes from not having a compatible binary for your environment, not wrong argument usage

zinc marsh
thorn urchin
#

yes you can use chatgpt

pulsar needle
thorn urchin
#

grab the correct binary for your system or build it from scratch

pulsar needle
#

Build hydra from scratch?

thorn urchin
#

was hydra the one that gave you the error?

#

your screen shot is showing hashcat

pulsar needle
#

Aaa

#

I meant

#

Hashcat

#

Lol

#

I am tired

#

Maybe i should sleep

zinc marsh
#

try running it as root

#

Update Drivers: Ensure that you have the latest drivers installed for your GPU. Outdated or incompatible drivers can cause issues with GPU-based applications like Hashcat. Visit the GPU manufacturer's website (NVIDIA or AMD) to download and install the latest drivers for your GPU.

Check OpenCL Support: Verify that your GPU supports OpenCL and that it is enabled in the GPU settings. Hashcat requires OpenCL to access the GPU's processing capabilities.

Check System Requirements: Make sure your system meets the minimum requirements for running Hashcat. Check the Hashcat documentation or website for the system requirements and recommendations.

Check Dependencies: Ensure that all the required dependencies for Hashcat are installed on your system. For example, Hashcat might require certain runtime libraries or additional packages to function correctly.

Run as Administrator or with Sudo: If you are using Hashcat on a Linux system, make sure you are running it with appropriate privileges. Use sudo to run Hashcat with root/administrator privileges.

Use the Correct Hashcat Binary: If you have multiple versions of Hashcat installed, ensure that you are using the correct binary for your system.

Check Your Hashcat Command: Review your Hashcat command and options for any errors or typos.

Seek Community Support: If the problem persists, seek help from the Hashcat community or forums. Other users may have encountered similar issues and could offer insights or solutions.```
pulsar needle
#

Ok

thorn urchin
#

root isnt going to change an illegal instruction error

#

christ

zinc marsh
thorn urchin
#

I noticed

#

Sometimes its better to apply brain than use chat gpt

zinc marsh
pulsar needle
#

Lol

zinc marsh
#

then remove hashcat and try reinstalling it maybe

thorn urchin
#

its an illegal instruction error

zinc marsh
#

or check if u have different versions installed

thorn urchin
#

As I said, that means the binary youre using isnt built for the cpu youre using

pulsar needle
#

Soooo

#

I should build another vm

#

Lmao

thorn urchin
#

eg x64 bit on 32 bit system, intel on arm, arm on intel, ect

#

No, you should just install the version correct for your system

zinc marsh
pulsar needle
#

Can i do that using CLI?

zinc marsh
#

uninstall hashcat I guess

#

and do apt install hashcat

pulsar needle
#

Ok, ill do it tomorrow

#

Thanksfingerguns

zinc marsh
#
  • apt remove hashcat
  • apt install hashcat
trail leaf
#

I don't recommend using the --force flag, pretty sure that's not part of the issue here, but it's mostly there as an option for devs when they're working on it iirc

zinc marsh
#

to use --force

trail leaf
#

I don't think using that flag changes anything 🤷‍♂️

#

I could totally be wrong on why the flag shouldn't be used, but all I know is that I've seen core hashcat devs (mainly chick3nman) actively tell people not to use it, and they know better than I do.

zinc marsh
#

I don't know either

#

I didn't try it

thorn urchin
#

idr if its necessary to force hashcat to generate the resulting wordlist or not

#

cause youre not actually cracking a hash

#

I think thats why its used but I could be wrong.

trail leaf
thorn urchin
#

neat, thanks for checking

trail leaf
pulsar needle
#

Died

trail leaf
#

on it

thorn urchin
#

word from the dev that it shouldnt be used, and you have proof its not necessary for the intended results

#

👍

mortal shadow
#

what can i do if the remote user of the backup server has pw enabled

#

i always get Permission denied (even with sudo)

#
Permission denied, please try again.
htb-sho@1: Permission denied (publickey,password).
rsync: connection unexpectedly closed (0 bytes received so far) [sender]
rsync error: error in rsync protocol data stream (code 12) at io.c(231) [sender=3.2.7]
#

test.sh:


rsync -avz -e ssh /path/to/mydirectory user@backup_server:/path/to/backup/directory
#

crontab:

mortal shadow
#

nvm just use keypairs and it's working gucci

#

talking about keypairs, do you usually set seedphrases?

maiden spindle
#

what am I missing?

trail leaf
#

Might need to look a little bit harder. You're probably doing it right, but just reading the output too fast and missing what the actual credentials are

fathom pendant
trail leaf
#

Speaking from experience

maiden spindle
#

@trail leaf can I dm you a screenshot of the answer I've got?

trail leaf
#

go ahead

lyric bolt
#

I am stuck on the AD Enumeration and Attacks skills assessment part 2 question 7 I know what i need to do but i am having trouble figuring out how to get the exploit onto the server with the shell i currently have.

#

I was originally using a nc shell but switched to a msfconsole session shell because i was hoping i could make it a meterpreter shell. However, I get the error "Target is running Windows on an unsupported architecture such as Windows ARM!" which im pretty sure isnt the case but okay.

#

I have also attempted to make the MS01 a httpserver so that i could pull the file from there

#

any help would be appreciated

proud pine
lyric bolt
#

ahh i shall try that thank you

proud pine
#

If you need any help messing with it, you can DM me.

lyric bolt
#

will do

thorn urchin
#

when in doubt if your shell sucks upload a better shell 😉

flint linden
#

Looking for someone who has completed the javascript deobfuscation skill assessment. I have answered all questions and stepped through the entire process including finding the final flag. however, the 2 questions prior can only have one answer along that progression and the module will not accept either as an answer. I know the answers but potentially HTB wants them in a string or given format that is unspecified? anyone that can help it would be appreciated.

thorn urchin
#

feel free to DM what answers you attempted

echo glen
#

Hi guys, i'm doing the Setup module -- it is sending us to link to download windows 10 VM, but the link now actually leads to windows 11. Will this matter later on when actually using the window system?

obsidian sandal
#

a

rugged veldt
#

For Windows Privilege Escalation Skills Assessment Part 2, When running a program named Sharp*.exe I am getting a message to install .NET framework 3.5. Am I using the wrong tool? I also can't run CVE-2020-.

runic inlet
#

lazagne

thorn urchin
#

lazagne can find some application specific loot that mimikatz doesnt look for

trail leaf
trail leaf
#

Regardless, there’s a reason the module shows you more than one tool for a lot of the different sections. I don’t want to say anything else about that skill assessment before I spoil something.

thorn urchin
#

its always worth rechecking things with different tools even if you think they cover the exact same info

#

it sounds dumb, but experience will teach you it isnt

trail leaf
#

Tools can and will lie to you

knotty gust
dark rampart
#

Guys am i dumb or it is normal that i get off topic tasks in Linux module? Eg. I am studying how to filter files and it asks me to work with servers and IP addresses. How am i supposed to know that.

fathom pendant
#

Like what section specifically

static condor
#

I think I know (I'm doing Linux fundamentals right now)

#

Filter Contents is my guess as to which section they mean

#

I'm pretty sure the tasks are asking you to use commands seen earlier on in linux fundamentals, though, combined with some filters.

fathom pendant
#

^

static condor
#

I did struggle with the last one, granted, but the first two are definitely doable

fathom pendant
#

It's a bit if you don't know the basic filtering commands for sure

static condor
#

I've been having trouble all day trying to download packages to a Pwnbox while following along in the section Package Management (Linux Fundamentals). I've tried resetting the Pwnbox to no avail. It seems to be a connection issue, but I'm certainly not having any internet problems right now (and I'm not sure that'd matter on a Pwnbox?). Does anyone know what I might be missing here?

fathom pendant
#

I don't think pwnbox has internet access

#

You're getting net unreachable errors so yeah

proud pine
#

I think it does if you're subscribed

fathom pendant
#

wouldn't know ¯_(ツ)_/¯

proud pine
#

but yeah, free doesn't for sure

fathom pendant
#

Always read your errors people lol

static condor
#

I mean, I read them

#

I just didn't realize the free Pwnbox didn't have internet access

#

I was under the assumption it would if it needed it. The section implies I should be able to follow along regardless.

fathom pendant
#

I believe it's installed by default

#

But also I think the tool itself can be reached I believe it's a very tight whitelist for what can and can't be downloaded

static condor
#

It's less about having the tool and more about installing it (the focus of the entire section is becoming familiar with installing packages), but thanks regardless.

fathom pendant
#

I use my own vm

river trail
#

Is there anyone here interested in unlocking my phone?

#

will probably take credit for it

languid dawn
#

no that sounds illegal

river trail
#

illegal?

languid dawn
#

illegal means against the law

#

sure if you can prove the phone is yours and don't mind getting scammed

#

or your info stolen

river trail
#

today i heard more rockets

#

reason for?

#

hanabi

#

i mean hanabi

languid dawn
#

ok please the channel on topic, this is for help on academy modules

river trail
#

my phone is android

#

I don't know unfortunately

haughty grotto
#

Who did pwn sau i kindda stuck on PE

final maple
#

Can someone help me on File Inclusion - Skill Assessment? Right now I am trying to find the php.ini file using base 64 (from this section of the training: https://academy.hackthebox.com/module/23/section/253) - specifically, the ||php://filter/read=convert.base64-encode/resource=../../../../etc/php/7.4/apache2/php.ini"|| command. I have found the website uses ||nginx|| and is running ||PHP 7.3|| I've tried the following command: ||curl "http://83.136.252.24:52595/index.php?page=php://filter/read=convert.base64-encode/resource=../../../../etc/php/7.3/fpm/php.ini"|| Is this what I am supposed to do? I've been reading through the chat and others have said to ||get the index.php file|| but I haven't been able to do that either.

steady hawk
final maple
steady hawk
#

Only one way to find out 🙂

final maple
final maple
turbid kraken
#

Hey guys, in the module "Shells & Payloads" > "Laudanum, One Webshell to Rule Them All" > Question 2: "Where is the Laudanum aspx web shell located on Pwnbox? Submit the full path. (Format: /path/to/laudanum/aspx)"

Can someone confirm the question is either out of date or broken? I did a find on the entire box and no answer seems to fit the question 🤷‍♂️

tranquil axle
turbid kraken
#

same issue witht he antak question on the next module :/

tender lake
#

The awnser is there bud

turbid kraken
#

disregard.... you have to include the damn file name 🤦‍♂️

tender lake
#

hehe

turbid kraken
#

I hate these low-level confusing questions...

#

I don't mind getting stuck on something for a few hours, but that...

tender lake
#

yeah, I got stuck on the first part of the Password Attacks Hard assessment for a few days trying to brute force the username and password. Only to see that an username is given in the little blurb at the top 🤦. Felt like such an idiot.

#

Thats the first thing I usually do, but in this case I just didn't read the scenario and went straight to the question. Learned a lesson there.

uneven dune
#

hello guys i have a question

#

i am curious about this module

#

becaus i solve it but they mentioned they have 2 ways to do the foothold

turbid kraken
#

yes?

#

one using Metasploit and one via a manual process

uneven dune
#

yes but i am curious about the manual process

#

because i search the paths

turbid kraken
#

what is your question exactly?

uneven dune
#

yes i am sorry

analog pewter
#

hey somebody had done the password attacks module

uneven dune
#

the question is, there exist a way to solve it using a password cracker or something like that ? , because in the course of this module if i am not wrong they mentioned a way to try with some information that you can search in path

#

i solved using metasploit

#

but i am curious about the password cracker i never used one before

#

i assume i can use the information obteined in the path and then use it to try it in the login

#

i just i am curious about that

#

i solved it in this case using metasploit

analog pewter
#

i found the creds not able to log in

uneven dune
pulsar needle
#

How can I make the command just "hashcat"?

#

I cant install it using sudo apt install hashcat cuz i get this error, then when i try to update apt it says its updated

fiery berry
pulsar needle
#

how?

fiery berry
pulsar needle
#

ok

#

brb

#

but its already updated

#

what

fiery berry
pulsar needle
#

I cant install anything

pulsar needle
#

Litterly nothing works on my machine lol

fiery berry
#

then try to install hashcat one more time

pulsar needle
#

Like I cant download anything

#

or

#

it tells me everything is updated

fiery berry
#

maybe its missing the right repository

pulsar needle
#

But

#

How come

#

the tutorial tells me to download update-manager

#

but i cant download it

#

(I need hashcat to do a module, but I cant install it, the binaries work but then it wont update on its own and i dont know how to make the file path i need to specify short)

ivory cargo
#

Before you download it, type apt update firsttipsfedora

fiery berry
#

try to update the archive-keyring as root: wget -q -O - https://archive.kali.org/archive-key.asc | apt-key add

pulsar needle
#

Ah

#

now it works

proud pine
#

you should not be doing updates on kali like this. It will almost certainly break a ton of things.

hushed rivet
#

like what ?

pulsar needle
#

A lot of programs stopped working

#

And hashcat dosent work

#

Lol

#

This sucks

pulsar needle
thick juniper
#

Complete the PW attacks Hard Lab, thanks for the pointers guys 👌 as a side, one of the commands “modprobe ndb” worked for me, but when I reset the machine to try it again to make sure I had it, it failed and came up with a fatal error. Anyone have an idea why it worked once and not the second time?

solar smelt
#

I'n in the linux fundamentals and for the love of god trying to find the What is the path to the htb-student's mail? under the system section

tall saffron
#

im the only one who cant connect to the VPN in EU 1 or 2?

eager merlin
#

@solar smelt Hint, the full path does not exist yet, but you can know what it would be

solar smelt
cedar void
#

Do I have to 'google' the userAccountControl bitmask for NORMAL_ACCOUNT and ENCRYPTED_TEXT_PWD_ALLOWED?

tall saffron
#

no VPN on academy work on my side WTF

solar smelt
tall saffron
#

platform? i tried all the EU and US VPN

solar smelt
tall saffron
#

linux, arch

#

i tried all 5 VPN servers, and this message appears after a few minutes and cant connect to labs in academy

eager merlin
echo iron
#

Currently working through the credential hunting in windows section of the password attacks module. The question is wanting me to use lazagne (I'm assuming the .exe version as python is not installed on the target machine) to find credentials for a file server that the user accesses via WinSCP. However, if I try to run the .exe via GUI I receive the "This app can't run on your PC" error. Trying to run from command line gives the same pop up, along with "access denied" output whether I run as admin or not. Parsed around the system manually, couldn't find the creds so I'm really wanting to use lazagne. Thoughts?

solar smelt
#

@eager merlin thank you

eager merlin
echo iron
cedar void
#

I am having trouble with this question from this module: (https://academy.hackthebox.com/module/22/section/290)

Question: What is the userAccountControl bitmask for NORMAL_ACCOUNT and ENCRYPTED_TEXT_PWD_ALLOWED? (decimal value)

Attempted solution:

I typed out 'python3 /opt/ldapsearch-ad /ldapsearch-ad.py -l 10.129.42.188 -u 'james.cross' -p 'Academy_Student!' -t search -s "(userAccountControl:1.2.840.113556.1.4.803:=128 & userAccountControl:1.2.840.113556.1.4.803:=512 )" -d inlanefreight.local’

And here were my results

silk minnow
#

if i have an ipmi account, does it also allow me to maybe ssh with said account?

#

maybe ipmi account = local account or something like that?

mortal basin
#

Another 🔥

modern epoch
# pulsar needle

Well, pentest/ctf machines are supposed to be volatile because of this things. Ippsec has a pretty good tutorial in his channel to automate real machines using ansible, however that can be a bit tricky depending on your experience with Linux. Another way to go is over virtual machines, I recommend virtualbox because you have snapshots for free and so you can create/restore one always you like. For cracking hashes specifically it's best to have it in your local machine (prefer build your local versions from source or to use a standalone binary) but you have the option to use a docker container leveraging of your graphical card (GPU) as well if you want flexibility. At extreme cases you can use cloud solutions using GPU for the hard work. So, always keep an updated version of the kali and you will avoid a lot of these issues.

analog dock
acoustic owl
tranquil axle
#

Rip to that one guy that finished almost all modules a few days ago

acoustic owl
#

He has already completed this module 🤣

tranquil axle
#

Oh okay

#

Unlocking all modules sounds pretty pricey

acoustic owl
#

The modules are definitely worth it.

#

All the modules I have done so far I would definitely do again.

tranquil axle
#

There are a few I was disappointed in but others are really really good

acoustic owl
#

Really? Which one disappointed you?

OSINT was maybe the module I expected a little more from, but even that module was cool.

tranquil axle
#

Mh i have to recheck if you want a real list but I remember in the cbbh path one of the last modules was we serviced and api attacks

acoustic owl
#

Did you contact the author in each case and tell him what bothered you?
I mean, an author can only do better if he knows what was not good.

tranquil axle
#

And it mainly showed very small examples and referred to the other modules for more in depth

#

Oh no I didn’t wanna be the guy to tell someone I didn’t like the course

#

I just remember being confused that as one of the final courses in the path it wouldnt go into more detail but just refer to the other modules again

acoustic owl
#

Honestly, if I were writing a module, I would want people to tell me that was good and that wasn't good.
But then it is important to say why you didn't like it.

An author can't do anything with the statement, that was crap.

But if you say, that was shit, because this and that was missing, then the author knows what it's about and he has the chance to make it better.

#

A good critique has never hurt.

tranquil axle
#

but I can say I generally agree that the material seems very high quality. I'm currently doing the AD Enumeration and Attacks Module and I really enjoy the content and how it is presented

#

and I remember how great it felt to finish the assessment in upload vulnerabilities or so where I had to combine all methods learned in the module to finally upload a php shell disguised as another file

acoustic owl
#

Don't worry, they are still on my ToDo list
At the latest when the exam is online, I think many will jump on it.

pulsar needle
#

lol

#

but

#

thanks

wanton estuary
#

Anyone got any hints on the last question in using metasploit, sessions. Exploiting an old version of sudo. I have found two poc and compiled them using make then moved them onto the target but get the error: libc.so.6: version 'GLIBC_2.34' not found. How am I meant to compile the exploits if I don't have gcc or make installed on the box?

pulsar needle
#

why cant things just work lmao, the VM isnt installing

pulsar needle
tranquil axle
pine dagger
#

Powerview and LDAP modules are also great expansion modules / refreshers

wanton estuary
floral orbit
#

Hey all, not sure I'm posting in the right place but here it goes

Im working on a OSINT challange

This led me to a blog site where I need to download a CV and look in the metaData of the file.
The blog is actually down. https://dylonellwood.blogspot.com/

What should I do in this case?

fleet bough
#

Hello everyone!! So, I've been at the footprinting module for the pentest path, stuck on the dns one. I've read the forums but when I dig it isn't showing me any other domains, zone transfer fails. I tried with a VPN connection and the pwn box. If anyone is available for hints or help my sanity would appreciate it!

floral orbit
pale oriole
#

In the "Password attacks" module I have been running into issues with transferring files from the windows to the pwnbox. The instructions say to create a share using smbserver.py on the pwnbox, and I should be able to just go to the windows cmd line and type move <file> \<IP><Share> and it should move the file but all I get is "Access Denied". How am I supposed to move the file? It does not seem to matter if I made the file or not.

acoustic owl
fathom pendant
#

Good thing it looks like they're releasing a defensive based cert

fleet bough
fathom pendant
#

{@IP} is a simplification of @nameserver

pale oriole
#

I have the same issue. Were you able to figure it out?

fathom pendant
#

That was a few days ago

#

I forget the syntax they suggest

pale oriole
fathom pendant
#

I'm just saying it's just as likely they forgot. You can just ask the question yourself instead of waiting for the specific user to reply back. That's all really

pale oriole
#

I have also asked the question. Then searched for it afterwards, and saw theirs

keen compass
weak kindle
#

Has anyone did the "Intro to assembly"?? I'm stuck in the final assement #1. Will appreciate your hints. If yes kindly @ me or DM me for further discussion 😄

digital pewter
pulsar needle
#

I guess ill be done in 14 hours💀

timber beacon
#

ngl, I would've left at that point

pulsar needle
#

I did

#

There must be another way (The module told me to bruteforce it so idk if there is)

trail leaf
#

Try enumerating the target, there might be a service that’s easier to brute force

pulsar needle
#

Oke

fathom pendant
#

They need to reword that question

civic zenith
#

I feel stupid, I'm on Attacking Common Services - Easy rn, do you absolutely need to upload a shell on this one to get the flag? Or should I just search the MySQL databases until I find it?

#

Yea the XAMPP site

#

Ok

#

thx again @rustic sage

pulsar needle
#

Yes, but i thought i just had to make a bigger list with hashcat lol

pale oriole
pulsar needle
#

💀

#

Ok

tranquil axle
noble fiber
#

Hi! someone good with regex that can help me understanding a grep command? (web attacks --> Massive IDOR Enumeration)

fathom pendant
analog pewter
#

anybody can help me in password attack medium assissment

fathom pendant
#

I mean unless you ask what you're struggling with

analog pewter
fathom pendant
#

Note you can give vague enough user info by doing like j* and a*

analog pewter
#

ssh into it

#

in ssh service found 2 users

fathom pendant
#

The document talks about an internal service if memory serves correct

#

Which can be used to get info for user2

analog pewter
#

d*** user have ssh hidden folder i can't cd into it

fathom pendant
#

Correct because you can't cd into another user's protected folders, permissions won't allow it

analog pewter
#

i am stucking here only

fathom pendant
#

Read the document over again, you'll find out that there is a certain internal service

analog pewter
#

give me hint

thorn urchin
#

its a skill assessment

fathom pendant
#

I dont recall if the history shows anything helpful on it

#

The information you need to move forward is there that's all you need to know tbh

analog pewter
thorn urchin
#

Providing hints sabotages the purpose of the skill assessments.

#

Personally I don't mind troubleshooting a particular method and helping that way. But if you dont even know the path forward you must seek it on your own

fathom pendant
#

Tbh: to be honest

analog pewter
noble fiber
fathom pendant
#

It'll pop in like 20-30 tbh @pulsar needle

fathom pendant
pulsar needle
noble fiber
#

i've been struggling all the afternoon to understand it

fathom pendant
analog pewter
fathom pendant
fathom pendant
#

It's the same documentation you get that info

#

So it's all in that same document

#

That tells you where to look next after ssh in

lilac bison
#

I have the same problem

analog pewter
fathom pendant
#

Note: it may not say it directly

#

But you can probably guess that it should be running

zinc marsh
#

yo someone who used reverse connections with ligolo?

#

I have some doubts

analog pewter
thorn urchin
#

hit me with em

#

@zinc marsh

maiden spindle
#

HI I'm in password attacks. my mut_password.list file is showing as an unknown application and is causing crackmapexec to throw up UnicodeDecodeError: 'utf-8' codec can't decode byte 0xff in position 0: invalid start byte. I tried chaning it to a .txt and then it shows as a text file but crack still throws the same error. Anything I can do to fix this?

#

.txt

maiden spindle
#

I know the hint gives a username but I'm trying to get hydra/crack to run with my mut_password file

#

it runs fine with password.list

analog pewter
maiden spindle
#

@analog pewter what do you mean?

pulsar needle
#

Am i supposed to run a hydra brute force through my ssh connection? (Password Reuse - Password attacks)|| The default mysql credentials dont work||

fathom pendant
maiden spindle
#

@pulsar needle make sure you try the list they link to with the defaults

fathom pendant
analog pewter
#

@fathom pendant yeh found D*** creds then id_rsa into hash then decrypt another cred i got log into ssh with id_rsa but not getting root

fathom pendant
trail leaf
fathom pendant
#

Just take a step outside the box for a second and think

#

You're literally almost there

fathom pendant
#

It's in the provided linked resource

pulsar needle
analog pewter
analog pewter
fathom pendant
#

Sometimes it takes critical thinking

#

Like "huh ... why is it this way"

#

Even though, when you think about it, it would certainly make sense to pw protect your rsa keys

fathom pendant
#

Nope

#

Currently without wifi/internet (using mobile data)

#

So my academy progress has been halted

analog pewter
#

what are you doing cbbh or cpts

fathom pendant
#

Cpts path

thorn urchin
#

Marcie is def gunna pass though

analog pewter
#

too

#

where you write you notes

trail leaf
#

Marcie has spent so much time on the front lines of this chat that I would be shocked if they didn't pass on their first go

fathom pendant
#

Me when I find some new shit

silver flower
#

Hello

thorn urchin
#

no

fathom pendant
silver flower
#

Can anyone can help me to ban my acc from instagram

thorn urchin
#

no

thorn urchin
#

get lost

maiden spindle
#

@fathom pendant I didn't gen using provided commands because I had to run hashcat on windows and the -u caused issues. I xfered it over and am having issues with the file type/permissions or something windows gave it

fathom pendant
#

Your mistake is using windows

maiden spindle
#

hahah

fathom pendant
#

Just download it to your vm/pwnbox and create a new one

maiden spindle
#

my virtual box with parrot won't run hashcat

fathom pendant
fathom pendant
maiden spindle
#

That was the original issue

silver flower
#

Can I get. Some sort of information from here

maiden spindle
#

It says Illegal action. I asked on the hashcat discord and they said don't use a VB

silver flower
#

Like can I learn anything here?

fathom pendant
fathom pendant
silver flower
#

For example

fathom pendant
thorn urchin
silver flower
#

Yeah I have read it

thorn urchin
#

Clearly you havnt

#

or you wouldnt still be a white name

fathom pendant
river trail
#

hanabi hanabi

gaunt surge
#

I've seen some badges shared here, where you can see how many people have it, where can I see that?

river trail
#

hanabi hanabi

fathom pendant
#

<@&861185840277487616>

opal jewel
#

Anyone around to tell me what Im doing wrong in Shells and Payloads - Live Engagement - Host3?

#

Redoing some stuff and its not working this time around

river trail
#

hmmm today we dive bros... and... sisters...

mortal narwhal
#

Hello! Could I please get assistance on answering this question on the Linux directory: What is the name of the last modified file in the "/var/backups" directory?"

Ive tried searching it this way: tree /var/backups and I pull up a directory and the last file is shadow.bak but thats not the answer. Am I looking in the wrong place?

fathom pendant
fathom pendant
#

@mortal narwhal continuing help here

#

If you read the syntaxes and everything from examples, you'll see that you can specify directories in commands like ls @mortal narwhal

#

Ls= list stuff

#

-l gives you it in a neater list format
-a gives you all info (and also shows hidden files/directories

#

Combining flags gets you ls -la

livid pier
distant island
#

hello friends hope you are all having a great day i am new in the cybersecurity field all want to ask is can HTB academy make me able to pass the OSCP test or i need more resorces ?

trail leaf
#

everything you need to pass the OSCP is in the materials that offsec gives you, but htb academy also has good stuff

distant island
#

ok got it

#

first when i was creating my account i choose some interests can i modify them or add more in the future or even do my choices affect my learning resources

trail leaf
#

it does not matter

distant island
#

thanks mate ❤️

thorn mural
#

Hey I''m currently on web proxies assessment and I was trying to do it using zap because to get accustomed to both. how do i fuzz with and encdoe / decode

misty mural
thorn mural
cedar void
tight mesa
#

Hello anyone who has made Password Attack Module | PtT From Linux section....

#

I'm having some issues to find tgt for the svc_workstations

#

any hint?

trail leaf
#

The section almost identically walks through what to do

#

Just have to do a little bit of additional searching

pine dagger
#

You dont need to do any tgt exploits. Just use the tool they talk about in the chapter..

rustic sage
#

hello guys

#

can any one send good and simple videos can help me to do this?

tight mesa
tight mesa
#

using the tools described in the module, I can obtain the AES_256 hash not the NTLM

#

I'm overthinking or missreading something

#

unless I have not to connect via ssh to read the svc user flag

trail leaf
#

that's the almost bit. Take a closer look at the supposed location of these credential files.

tight mesa
#

LoL a little direction of what the searching do I have to do, would be awesome....!!!

#

unfortunately I don't get it / follow

trail leaf
#

You followed the section and found a file in a location, but only got the AES 256 hash. I'm saying look closer at that location.

tight mesa
#

||smbclient //dc01/svc_workstations -k -c ls||

#

LoL

#

1k times LoL, ty @trail leaf

fathom pendant
# rustic sage can any one send good and simple videos can help me to do this?

Improve your skills in JavaScript, HTML, and CSS by building a social media dashboard with a dark/light theme. Jess, who runs the popular Coder Coder YouTube channel, will guide you through a beginner Frontend Mentor challenge.

✏️ Course created by @TheCoderCoder

Resources:
🔗 Responsive Design for Beginners! https://coder-coder.com/responsive...

▶ Play video
rustic sage
fathom pendant
lyric bolt
#

was hoping for a nudge in the right direction on the skills assessment part 2 for AD enumeration im on question 8 looking for a way to escalate myself on MS01 im currently system on SQL01 and have tried just about all i can think of to find creds to escalate myself with on MS01

rustic sage
#

Hello, I am looking for programmers who know about twitch, if you know about that, contact me privately

rotund urchin
#

Any help with the Web Proxy module and Zap Scanner question?

trail leaf
#

Won't say more since it's a skill assessment

lyric bolt
#

appreciate the help

regal orchid
rotund urchin
#

I found the vulns but I am not sure how to exploit them using Zap

#

I requested help through HTB but that was yesterday, just trying to see if anyone can provide a nudge

regal orchid
#

have you requested the url the vuln gives you?

rotund urchin
#

Like in a reg browser or in Zap?

regal orchid
#

either should work

rotund urchin
#

Well the browser is just a blank page

regal orchid
#

hmm one sec im gonna try on my machine

rotund urchin
#

I see the vuln that allows me to read files from the srever but nothing I do works to read anything else lol

regal orchid
#

have you been able to read /etc/hosts?

#

the link the vuln shows is already set up to read that file

cunning prairie
#

sometimes you may have to reset the machine.

wild dragon
#

I completed the Hardware module yesterday, but I have not got this badge 😢 for my collection!

uneven sluice
#

I'm working on the following section of the Active Directory Enumeration & Attacks module: Attacking Domain Trusts - Child -> Parent Trusts - from Windows

#

I can't get the initial mimikatz command to run. It keeps throwing errors.

#

Anyone else have this issue?

uneven sluice
#

Any reason why I can't upload screenshots here?

acoustic owl
acoustic owl
wild dragon
#

I did it again, but I still have not got it lol troll @acoustic owl

uneven sluice
#

Thanks.

acoustic owl
wild dragon
uneven sluice
#

not sure what I'm missing here or why it seems the user account doesn't have the privileges required to complete the tasks.

uneven sluice
#

The module provides you an admin login to rdp into.

proud pine
#

token::elevate

uneven sluice
#

No change.

acoustic owl
uneven sluice
#

I figured it out and I hate that, that of all things was the issue.

#

Took me literally hours. I'm going to bed. Thanks folks.

analog pewter
#

bruteforce tool faster than cme and hydra

#

can anybosy tell

fathom pendant
#

Nope

#

Hydra and cme are really gonna be the best for now

#

Also ~threading~

#

[-t]

analog pewter
#

for rdp

#

i want

fathom pendant
#

Most of the ports respond decently well to -t 48

analog pewter
fathom pendant
analog pewter
#

whats about crowbar??

fathom pendant
#

Which is just a similar tool to hydra

#

Haven't touched it or seen anyone recommend it

analog pewter
#

let's try cme

fathom pendant
#

Iirc a flag like --local-auth or -local-auth is needed

#

Fwiw

analog pewter
#

ok well i try with both

woven copper
#

Hello there, anyone could help on Intro to Assembly Language, Skill Assessment Task 1 , i have try a lot of different shellcodes but nothings works , I have the code to xor all the data pushed to the stack with a loop and all of that, but when a dump the decoded shellcode it didn't do anything

tranquil axle
analog pewter
#

i am not able to download a file from smbclient

#

parallel_read returned NT_STATUS_IO_TIMEOUT

#

this error

rustic sage
#

i am copied code of bash from the site and also give me this weird problem?

sage jungle
#

The UDPv4 error is where I have loaded the terminal with the VPN. And the other error is in the terminal where I try to connect to the box...

#

And i cant't upload images in this Channel i don't know why

fathom pendant
fathom pendant
analog pewter
#

@fathom pendant if we have only read permission on smb we can not download any file

fathom pendant
analog pewter
#

parallel_read returned NT_STATUS_IO_TIMEOUT

fathom pendant
#

Try copy and paste

analog pewter
#

this error

fathom pendant
#

¯_(ツ)_/¯

#

Are you also connected from a writable location (such as /tmp/

supple patio
analog pewter
supple patio
analog pewter
#

skill assisment hard one

supple patio
#

what are you trying to install?

analog pewter
supple patio
#

it's because of internet connection issues

#

you can try to install it in pwnbox

#

and crack it there

#

gl

fathom pendant
#

Switching from udp to tcp may also work

supple patio
fathom pendant
#

Looking at my notes smb is the correct second step

supple patio
fathom pendant
analog pewter
supple patio
supple patio
fathom pendant
#

¯_(ツ)_/¯

supple patio
#

probably you're in US servers

fathom pendant
#

Sometimes they don't like us servers and eu works better

supple patio
#

yeah

tall saffron
#

is there a script or existing tool which list recursively all smb shares and look for subdir where we we have write access?

fathom pendant
#

And sometimes it's the other way around

fathom pendant
supple patio
#

or smbclient -N -L

tall saffron
#

it list only dir but not write access to subdir

supple patio
#

-_-

supple patio
sage jungle
#

How can I open a new message in htb support?

supple patio
fathom pendant
tall saffron
#

ok so you dont know lmao xD

fathom pendant
#

Don't be an ass

tall saffron
#

since when it is being an ass to said that... stop your judgement

supple patio
#

well well

fathom pendant
#

We gave a reasonable answer and there very well might be a way to do it in smbmap

tall saffron
#

it isnt because we didnt have the same pov the other day that you must start with statement like this

#

OK?

fathom pendant
fathom pendant
#

OK then start with saying "I've already tried smbmap"

#

You're acting like I'm actually big mad at you

tall saffron
#

if you are still upset from the last time go outside and take a walk

supple patio
#

stop it

fathom pendant
#

Lmao

#

I dont remember the "last time " so its whatever

fathom pendant
#

I really don't lmao

tall saffron
#

so when people answer go chapgpt and you answer him "so you dont know lmao" is being an ass? and answering go chapgpt isnt?

#

yeah for sure not remember last time xD

#

have a nice day

proud pine
fathom pendant
fathom pendant
#

Googling only leads me to smbmap with the options -R or -r and --dir-only

tall saffron
#

cool and i used smbmap and google and it didnt list writable subdir on a share

#

it list subdir

fathom pendant
#

So you're looking for it to tell you it's writeable

tall saffron
#

and that's different to answer like you did than go chapgpt lmao

fathom pendant
#
--no-write-check      Skip check to see if drive grants WRITE access.
  -q                    Quiet verbose output. Only shows shares you have READ or WRITE on, and suppresses file listing when  performing a search (-A).
  --depth DEPTH         Traverse a directory tree to a specific depth. Default is 5.
#

¯_(ツ)_/¯

supple patio
#

#!/bin/bash

function enumerate_share() {
smbclient -L "$1" -U "$2%$3" | grep Disk | while read -r line; do
share_name=$(echo "$line" | awk '{print $2}')
smbclient "//${1}/${share_name}" -U "$2%$3" -c "recurse;ls" 2>/dev/null | grep -E '^\s+D|^/|^\|^$' | awk '{print $NF}'
done
}

if [[ $# -ne 3 ]]; then
echo "Usage: $0 <target_ip> <username> <password>"
exit 1
fi

target_ip=$1
username=$2
password=$3

enumerate_share "$target_ip" "$username" "$password"

#

then ./enumerate_smb.sh 192.168.1.100 john pass123

tall saffron
#

cool thank you, i was asking if there was an existing tool if not i will do the job myself 😉

fathom pendant
#

Have fun

tall saffron
#

gl

supple patio
#

gl

tall saffron
#

chatgpt stuff for sure xD

supple patio
#

ahaha

tall saffron
#

i mean more it doesnt work well and doesnt do what i asked xD

#

it is weird there isnt an already exsiting tool that does it

supple patio
#

#!/bin/bash

function enumerate_share() {
smbclient "//${1}/${2}" -U "$3%$4" -c "recurse;ls" 2>/dev/null | grep -v "NT_STATUS_" | grep -v "DenyMode" | awk -F "|" '{print $2}' | sed 's/^[ \t]*//'
}

if [[ $# -ne 3 ]]; then
echo "Usage: $0 <target_ip> <share_name> <username> <password>"
exit 1
fi

target_ip=$1
share_name=$2
username=$3
password=$4

enumerate_share "$target_ip" "$share_name" "$username" "$password"

tall saffron
#

tools just list subdir without checking if there is an other permission on one of the subdir

supple patio
#

./enumerate_smb.sh 192.168.1.100 shared_folder john pass123

tall saffron
#

ty

#

i will make some scripts in bash and powershell too 🙂

supple patio
tall saffron
#

yeah i didnt found that's why i asked here 🙂

#

thank you for your time 😉

proud pine
#

Whew, that is some really awful code.

fathom pendant
#

I mean for the most part it's not really necessary to need to recursively check write access as it's mostly inherited ACLS ¯_(ツ)_/¯

#

And most modules AFAIK only go maybe 1-2 layers deep

tall saffron
supple patio
tall saffron
#

enum from linux for example is very boring if you must check manually

proud pine
#

I don't know what all this fuss has been, when smbmap exists

fathom pendant
#

OK they probably showed you a way to do it. I don't have that module unlocked

tall saffron
#

no they dont

fathom pendant
tall saffron
#

if that was the case i didnt searched for it xD

proud pine
supple patio
fathom pendant
#

x,y problem ¯_(ツ)_/¯

fathom pendant
supple patio
tall saffron
#

or maybe i dont do it the good way

proud pine
tall saffron
#

that's why a walktrhough when completed the module can be useful 😛

fathom pendant
#

Just do what's taught in the module

#

¯_(ツ)_/¯

supple patio
tall saffron
#

i did and they dont talk about enumeration of writable sub dir on smb share