#modules

1 messages ยท Page 111 of 1

inner sand
#

is there anyway ?

#

or hackthebox and tcm will be enough ?

quiet ember
supple patio
#

Did you read the hint?

deep owl
#

got it but am not able to transfer the zip file generated from the windows host to the linux host as the linux host oes not have interneet to download the packages to do it the way i always do it

opaque shadow
#

how do i hack a steam account? it not for evil purposes

deep owl
supple patio
fathom pendant
deep owl
supple patio
#

You can do it without the bloodhound

opaque shadow
#

i created two account with the same name and email and i cant log on my second account and there 50$ on my second acc

supple patio
#

Hint and powerview would be enough

supple patio
#

But actually you can make the zipfile with bloodhound-python on linux

opaque shadow
deep owl
#

yeah it can be done via powerview buuuttt either the commands return nothing or tons of users

supple patio
#

There was a hint

rustic sage
#

why loop do need work with me?

vital adder
#
for i in {1..4};do echo hi $i ;done
fresh pine
#

I run into this issue in in PASSWORD ATTACKS
Pass the Ticket (PtT) from Linux with impacket (i upgraded he package but no success there):

[proxychains] Strict chain ... 127.0.0.1:1080 ... ms01:445 ... OK
[-] ('unpack requires a buffer of 4 bytes', "When unpacking field 'length | !L=0 | b''[:4]'")

I changed to the exact version of the example and still get trouble ๐Ÿ˜ข
Impacket v0.9.22 - Copyright 2020 SecureAuth Corporation

[proxychains] Strict chain ... 127.0.0.1:1080 ... dc01:445 ... OK
[-] invalid principal syntax

rustic sage
#

Hello I need help on bug bounty write report. I do not understand the question

karmic knoll
#

Can anyone help with AD attacks - Bleeding Edge? I have set up the share to work with the exploits but I get a File Not Found. Anyone able to lend a hand and look at my syntax?

rustic sage
#

guys i do not get solution for this upnormal questin

#

and when searching for the solution i found this

fresh pine
#

I tried this method in the "Automating payloads & Delivery with Metasploit" in "Shells & Payloads" and its not working. ๐Ÿ˜ข I search all across forums and old messages and this was the prefered method. What am I doing wrong? ๐Ÿ™

rustic sage
# rustic sage

ุŸุŸุŸุŸุŸุŸุŸุŸุŸุŸุŸุŸุŸุŸุŸ

acoustic owl
# rustic sage

you should read the chapter with the if conditions again.

rustic sage
rustic sage
acoustic owl
thorn urchin
#

very off tooic

#

also @sterile hawk whats the rules on someone having a nazi flag in their pfp

proud pine
#

They already left. Just came here to advertise their garbage game.

sterile hawk
thorn urchin
fathom spade
#

Hello, i'm new to tech and all this stuff. just wondering, but how does a RCe attack work? what application would you have to need for it to process

thorn urchin
upbeat dragon
#

Hi, need help for module "Web Attacks - Skills Assessment".. Is it normal that the button "Submit" doesnt work?

fathom spade
thorn urchin
#

maybe, that depends on if csgo has a vulnerability that enables RCE

#

RCE is just a possible goal of a vulnerability

fathom spade
fathom spade
thorn urchin
#

You dont protect against RCE directly, its an end goal for some types of attacks. To defend yourself youd defend against various other stuff.

#

RCE is remote code execution, it just means that the attacker has managed to load code on your system. This can be as complicated as exploiting some vulnerability to it, to having your credentials from somewhere and just logging in as you, to tricking you to run their malware that gives them RCE

fathom spade
#

Is this similar to a rat?

thorn urchin
#

a rat would be a type of tool employed to achieve RCE

proud pine
thorn urchin
#

rat may be loaded by a different RCE vuln, or possibly by tricking you into running it, etc

fathom spade
thorn urchin
#

I tend to recommend it to my avg customers. But its def not the best or anything.

thorn urchin
#

but any AV is better than no AV

fathom spade
thorn urchin
#

yes

fathom spade
thorn urchin
#

Could be

fathom spade
#

simply by opening it you can get hacked appareantly

thorn urchin
#

most software do

#

getting off topic here

fathom spade
# thorn urchin most software do

"Hackers can EASILY severely infect your PC with malware, including Remote Administration Tools, which allow complete control over your system by a foreign party. This means the hacker can install malicious programs, execute malicious programs, have access to banking/financial info, have access to any other passwords, open browser windows, or even format your hard drive, wiping all data from the computer in the process."

#

thats what i saw in the steam reviews of the game

#

I cant believe this can also happen with call of duty

thorn urchin
#

this channel is mainly for htb academy module discussion

#

not for discussing maybe cod vulns

fathom spade
fathom spade
thorn urchin
#

yes

fathom spade
#

What does it do?, i never really understanded it. Does it just crack passwords?

thorn urchin
#

Its for cracking hashes yes

fathom spade
thorn urchin
#

ofc

fathom spade
#

What's it mainly used for?

thorn urchin
#

cracking hashes

#

both the good guys and the bad guys regularly need to crack hashes

fathom spade
#

Have you ever used it before?

thorn urchin
#

Yes

fathom spade
#

Did you use it legally?

thorn urchin
#

Ive used it for both. I do not recommend committing crime though. Against server rules. I did it as a dumbass teenager ages ago

thorn urchin
#

but again, this chat is for module discussion. If you want to access the generic discussion channel you need to verify your account following the instructions in #welcome

fathom spade
thorn urchin
#

cause this channel is for htb academy. which is HTB training materials and course stuff

#

I don't use VPNs except for lab stuff

fathom spade
#

oh alright

zinc marsh
#

someone who completed cme module?

#

is it worth it?

thorn urchin
#

id worry about it after completing CPTS

acoustic owl
fathom spade
fathom spade
#

ok maybe i was a little bit TOO SPECIFIC

fathom spade
#

guys

zinc marsh
#

out of topic

fathom spade
#

i was abit to specific

zinc marsh
#

and wrong server

fathom spade
#

why wrong server?

#

this server for hacking, yes?

acoustic owl
zinc marsh
#

white hat

thorn urchin
#

server for legal stuff

fathom spade
#

yes but i am doing legal stuff to

#

miner bitcoin in legal use

zinc marsh
#

deploying a malware in remote computers to mine cryptocurrencies

thorn urchin
acoustic owl
thorn urchin
#

and even if you werent, theres no security benefit in regards to crypto mining

zinc marsh
fathom spade
#

when i say bitcoin mining, i'm not planning on stealing information or doing any of that kind of stuff

thorn urchin
#

Either way, read #welcome abd verify your account

thorn urchin
#

youre off topic

fathom spade
#

ok

fathom spade
zinc marsh
#

literally u said deploying a malware in someone elses computer

thorn urchin
#

Even answering some of your basic questions was pushing the limits of offtopic discussion

thorn urchin
fathom spade
#

simply just injecting malware into someone elses computer but not stealing theyr information

thorn urchin
thorn urchin
fathom spade
#

what do you guys even do?

#

you guys make money?

#

or what

zinc marsh
proud pine
#

can we not humor this anymore? lol

thorn urchin
#

People here are either security professionals or aiming to be security professionals

#

pentesting/red team type stuff

fathom spade
#

ok fair enough

thorn urchin
#

@fathom spade but this is the last one. verify your account

thorn urchin
#

or were just gunna start pinging for offtopic

zinc marsh
#

I had thought doing cme, kerberos attacks and bh for AD before the exam

thorn urchin
#

I wouldn't

proud pine
thorn urchin
#

good info, but likely to teach a bunch of stuff you wont see in the exam

acoustic owl
zinc marsh
#

:/ I am still not confident to try the exam

#

I just want go when I am sure I will pass it

thorn urchin
#

yeah but excess stuff outside if the course wont necessarily improve your odds

#

itll make you overall better sure

#

but in pure terms of passing the exam, it wouldnt be efficient

proud pine
#

It's easier to jump into the water, than to go inch by inch.

zinc marsh
#

I have been practicing with medium boxes after finishing dante and zephyr

#

for the fooothold

thorn urchin
#

just remember: red teamers have failed this exam because theyve overthinked things

zinc marsh
#

I have a mate doing the exam and he got the foothold in the day 4

thorn urchin
#

there is some advantages to being dummy mode haha

sly kelp
tidal mango
#

For anyone using Kali VMs. I feel like I used to be able to upgrade my reverse shells the standard way. Once a reverse shell is kicked back to me, assuming the box has python, I would do ```
python3 -c 'import pty;pty.spawn("/bin/bash")'

ctrl-z

stty raw -echo; fg
enter
enter
export TERM=xterm
```Lately that seems to results in something like this where I cannot get back to my session after typing the fg; enter enter Any help as to what I am doing wrong?

zinc marsh
#
CTRL + Z
stty raw -echo; fg
reset xterm
export SHELL=bash
export TERM=xterm-256color
stty rows 38 columns 116
source /etc/skel/.bashrc```
tidal mango
#

so after typing echo; fg, I should type reset xterm? is that before or after the enter enter following fg? and Thanks for the help!

digital pewter
tidal mango
rotund urchin
#

Anyone ever get this with Zap? I cannot figrue out what is causing it. I dont have any additional add-ins installed etiher.

sly tapir
#

is there a way to reset a module so it erases the answers?

faint rampart
sly tapir
mild cypress
#

Can anyone enlighten me a little as to the differences between gobuster fuzz -w ./vhosts -H "HOST: FUZZ.domain.com" -u "http://10.129.179.60" and ffuf -w ./vhosts -H "HOST: FUZZ.domain.com" -u "http://10.129.179.60"? I'm not sure why I get different results ๐Ÿค” I imagine it has to do with how the url is handled?

fathom pendant
#

It's just a difference in the tools

mild cypress
#

Fair enough I guess, I'm just surprised how drastically different the results are.

#

Specifically, gobuster gives me effectively nothing whereas ffuf is putting out exactly what I'd expect.

proud pine
rustic sage
mild cypress
#

Actually, I can definitely see it has to do with how I'm passing the -u into gobuster - I guess it doesn't handle it the same way - though I'm not sure the correct way for managing that.

proud pine
#

This is the vhost method.

fathom pendant
mild cypress
#

Which brings me to my second question, why am I not getting the expected results from gobuster vhost -w ./vhosts -u "http://domain.com" as I am with ffuf.

fathom pendant
#

ffuf is just better

rustic sage
proud pine
#

Yeah, need to see the actual command and output you're running.

rustic sage
#

I assume he's just not using gobuster correctly

fathom pendant
#

I dont use either enough to comment on what the differences are

mild cypress
mild cypress
rustic sage
#

Yeah, well for this use case there should be no difference in results.

proud pine
#

yeah, that's fine

fathom pendant
#

ยฏ_(ใƒ„)_/ยฏ

rustic sage
#

Like you can absolutely use gobuster to run through a wordlist for vhosts

#

a "difference in tools" is that ffuf is probably faster, but the results should be the same because it's the same wordlist and both tools work

proud pine
#

I would expect gobuster to be faster.

rustic sage
#

In vhosts mode it might be

rustic sage
#

should work

mild cypress
#

Same results ๐Ÿค” (as in, the same as before - not the same as ffuf )

rustic sage
#

Something weird is happening, do you have proxy setting pointing to burp suite or something?

mild cypress
#

Nope, just straight up running the cli tools against the given IP. No proxies or anything like that.

covert mason
#

@wary plover can you friend me? i have to say something in dms

rustic sage
#

O_o

covert mason
#

I REALLY HAVE TO

rustic sage
#

it works for me, albeit on a different target

covert mason
#

i dont really know if I can sau those in here

#

you here?

rustic sage
#

Sure, but the results should be the same because they are being instructed to do the same thing

mild cypress
rustic sage
#

im on phone atm so cant, sorry

#

i dont use discord on my laptop cause its for work :p

mild cypress
#

Yeah, fair enough, rat is looking through it with me so ๐Ÿคž there's a solid explanation (probably that I'm dumb), haha.

rustic sage
#

ok but that's not helpful here because we're trying to figure out why gobuster isnt working..?

mild cypress
#

Mystery solved. I needed --append-domain ๐ŸŽ‰

(Without seeing my wordlist, it makes sense that this wasn't obvious)

Thanks to everyone who chatted through this with me ๐Ÿ™

tldr: rtfm

covert mason
#

@zinc thunder dm

fathom pendant
#

Most people aren't gonna blindly dm

#

And i swear if it's "I need help hacking an account/website"

covert mason
mild cypress
#

In b4 MarcieLee gets rickrolled.

fathom pendant
mild cypress
covert mason
#

Please

proud pine
fathom pendant
rustic sage
#

Be kind please

fathom pendant
#

You have (allegedly) all the info to do it yourself

covert mason
rustic sage
#

Tell him to fuck off in dm PepeProtecc

fathom pendant
covert mason
#

FUCK YOU

rustic sage
#

lol

fathom pendant
#

Considering you're coming in here and blindly asking people

covert mason
#

FUCK YOU

rustic sage
#

well that escalated more than xss -> rce

fathom pendant
#

Is it possible sure.

fathom pendant
# covert mason FUCK YOU

cant you say it without swearing? are you thinking that swearing makes you cool?? I havent done anything bad to you

rustic sage
#

I've seen some xss -> rce in electron apps ๐Ÿ˜Ž

fathom pendant
#

Still funny

rustic sage
#

he's got more issues than a HTB box

mild cypress
#

So curious what that dude was after.

rustic sage
#

he wanted someone to photoshop his girlfriends face on mia khalifa's body

fathom pendant
#

TLDR reason I said it here was bc he was probably gonna keep trying

fathom pendant
proud pine
#

Really need all channels behind a verification filter.

fathom pendant
#

For a full academy id rather than it being just behind the pay wall

quaint gate
#

I just installed the latest Parrot OS to do some Wfuzz work. Anyone getting this error about Pycurl

fathom pendant
fathom pendant
quaint gate
#

The image is fine. The Wfuzz tool is not working right off the hop on the latest

fathom pendant
quaint gate
#

Copy that

#

Thanks

#

This little gem, is my issue. Just started Broken Authentication now going to fix the tool, I guess. Quick google and this an old issue I thought.

#

Tried to start my pwnbox instance. It basically told me no dice, no available instances. So much for checking that out option out.

fathom pendant
#

Ah

fathom pendant
fathom pendant
heavy marsh
#

I'm getting an "unable to connect" error on the Nessus Skills Assessment when inputting the IP into my browser.

#

Anyone else have similar issues?

#

Already did a reset and tried another IP, still no luck

heavy marsh
#

I tried a new vpn file too

#

just now

fathom pendant
heavy marsh
#

Not sure what that means

fathom pendant
#

That's how you connect to nessus

#

On this assessment iirc

#

You have to use the ip:port

#

Just ip defaults to 443 for https

#

Which isn't open

#

I forget what port nessus runs on

heavy marsh
#

Oh I see, I had to go back to the earlier modules to figure it out. So basically the IP they're providing is the IP to Nessus, not the IP of the "target"

fathom pendant
#

Yes

heavy marsh
#

To be fair it was explained earlier in the module, but the "target" part threw me off.

fathom pendant
#

The targets are the ones from the section. Which they have prepopulated scans for you to use

heavy marsh
#

Thanks for the help.

fathom pendant
#

But easy to miss

keen seal
#

Yo

#

I need help hacking

#

Like real bad

winter blaze
#

hello can someone please help me with this question

#

i tried nslookup -type=any -query=AXFR inlanefreight.htb

keen seal
#

Who knows how to hack a account

#

I need hel

#

Help

#

Real bad

winter blaze
#

and nslookup -type=any -query=AXFR nc.inlanefreight.htb

winter blaze
keen seal
#

What channel

keen seal
winter blaze
#

we are not able to provide that kind of help

keen seal
#

Oh

winter blaze
winter blaze
#

I tried to do virtualHosting

#

and i tried dig AXFR ns.inlanefreight.htb @10.129.146.134

#

and dig AXFR inlanefreight.htb @10.129.146.134

#

without virtualHosting

#

but it did not work

thorn urchin
#

my general advice is to watch ippsec's video on Fatty

#

the section is almost 1 to 1 rip from part of that box

#

yup

#

yes, those are completely different application types

#

but when I say its a rip I mean its literally the same jar file

#

oh youre still on the hardcoded creds part

#

nvm

#

that one just follow exactly step by step

coarse escarp
#

not sure what the password is

#

or am I using the right command?

rose turtle
#

Hi, can't find a general academy channel, but I wanted to ask, I know there is a HTB SOC Analyst cert coming soon. Is it very soon? Or still a while away.

coarse escarp
#

can someone give me a hint as to what the password maybe?

#

I know it's weak

torn steppe
#

I have issues to rdp to the target machine, what is the problem?

#

RDP to .... with user "Administrator" and password "AnotherC0mpl3xP4$$"

#

I tried with xfreerdp and rdesktop

trail leaf
#

make sure to put single quotes around the password, the $'s will get interpreted differently by the shell if you don't escape them

torn steppe
#

you win a beer today ๐Ÿ˜„ thx

trail leaf
#

I don't drink but o7

torn steppe
#

=S

trail leaf
# coarse escarp

highly recommend following along with the section on this, they show you exactly what you need to do

fathom pendant
heavy marsh
#

Nessus Skills Assessment: What is the name of one of the accessible SMB shares from the authenticated Windows scan? (One word)

#

can't find anything in the scan

#

did the example scan because I didn't want to wait an hour

fathom pendant
#

Look for smb in the scan search

#

It's there

heavy marsh
#

It's all very general, checked multiple areas

fathom pendant
#

You're probably overlooking something

#

I'm not able to double check for you though

heavy marsh
#

Do I need to use anything besides Nessus?

fathom pendant
#

Not that I remember

#

I kinda have a vague memory of this section because it was so boring

zinc marsh
#

Oh that eternal exploit

#

Juicy

heavy marsh
#

lol

fathom pendant
heavy marsh
#

Yeah, I agree

#

Nessus is low effort anyway

fathom pendant
#

Like there's not much they can do to improve it anyways

heavy marsh
#

Try that on OSCP, lol

fathom pendant
#

Can't iirc its a banned tool

heavy marsh
#

Yeah, haha, that's why I was jokin about it

#

I used to hate CLI tools when I started using Linux, now I hate anything with a GUI.

fathom pendant
#

^ navigating imap with CLI ChefsKiss

heavy marsh
#

You were helping me with it a while back and things were not going well IIRC

fathom pendant
#

Lol yeah

#

The fetch command they give you in the example suuuuucks

heavy marsh
fathom pendant
#

And literally the links I found were what I used

fathom pendant
heavy marsh
#

Access!

left parcel
#

Slightly off topic for modules but a friend told me to ask on the HTB Starting Point channel my question about Vaccine box but I donโ€™t seem to have access to that channel. Am I missing a role or something?

heavy marsh
#

Nessus Skills Assessment: What is the plugin ID of the highest criticality vulnerability for the Windows authenticated scan?

#

Tried the one that was rated 10

#

Did not work

left parcel
heavy marsh
#

Tried the other one that is 9.1

#

Still no luck

fathom pendant
#

Sir its the target

#

Like if you look at previous Nmap scans you've done

#

And compare it to the example output

#

It's easy to figure out

heavy marsh
#

yeah I know I tried the ID # and it didnt work

fathom pendant
novel matrix
#

Itโ€™s the server IP that you out there.

fathom pendant
heavy marsh
#

This does not work!

#

Tried 34460, #34460, and Plugin #34450

#

and I tried the mentoring service that HTB says they implemented

#

NO ANSWER!

fathom pendant
#

Try a different service I think you're looking at the wrong one

#

I think they're frustrated that no answer they've tried is working

fathom pendant
heavy marsh
fathom pendant
#

There's multiple scans

#

:)

#

2 unauthenticated and 2 authenticated for windows/Linux

#

Iirc

trail leaf
#

I haven't actually done the exercises for that section yet because I didn't feel like it, but I feel like people have had issues with and/or complained about it because of a lack of rev experience. Could be wrong though

#

I like it though ๐Ÿ™ƒ

fathom pendant
trail leaf
#

that is also very true

#

the opposite of a common application, quite frankly

heavy marsh
#

Filter by Plugin ID worked

coarse escarp
#

why is it giving me a different result and what dos it mean?

fathom pendant
#

cd flag

#

Then do the get command

fathom pendant
#

Ls

#

Is it flag.txt

coarse escarp
#

yes I'm a dumb dumb

#

get flag.txt

#

got it

spice tusk
#

Module: Tcpdump Fundamentals; Question: What TCPDump switch will increase the verbosity of our output? ( Include the - with the proper switch )
I have tried -v -vv -vvv and nothing seems to be working

#

Any ideas

fathom pendant
#

Are you doing tcpdump -v or just -v

#

In the answer field

spice tusk
#

I tried both tcpdump -v and jsut plain -v

fathom pendant
#

Try refreshing the page and trying again?

spice tusk
#

@fathom pendant from some reason just the -v is now working. HA!

fathom pendant
#

Yeah sometimes it's dumb

spice tusk
#

thank you!

quaint gate
pseudo gazelle
#

What software is it?

thorn urchin
#

spoilers, delete

quaint gate
#

wfuzz via both the web base box and the latest issue both have this error. I am trying to fix my local copy. Any ideas?

thorn urchin
#

likely just copy paste formatting issues

thorn urchin
quaint gate
#

Yes

winter blaze
thorn urchin
thorn urchin
#

eh

#

its annoying that its in the course and just a rip. but thats it

winter blaze
#

i tried to many times, and i tried typing it @thorn urchin

#

too-

thorn urchin
winter blaze
#

thank you mad :C

#

the question is Find and submit the contents of the TXT record as the answer.

thorn urchin
#

idk what it is you founf

#

ยฏ_(ใƒ„)_/ยฏ

#

unless they changed it but didnt remove my answer

winter blaze
#

i found by doing the command that is mentioned in the module can i send you my command ?

#

in dm

#

?

thorn urchin
#

im settled into bed so I wont be able to load up the lab to verify

winter blaze
#

ok ok so in a nutshell is another command

#

thanks

acoustic owl
#

Read the question again.

you have to assign this value to the variable salt

rustic sage
acoustic owl
#

i am only here for a short time, but you can always write me a dm

acoustic owl
rustic sage
#

Hi

acoustic owl
rustic sage
acoustic owl
rustic sage
acoustic owl
rustic sage
acoustic owl
#

The code writes you the flag if you have done everything correctly

fresh compass
#

Hi! Iโ€™m on password attacks, credential hunting in linux module and I cannot find any valid credentials. Any help?

rustic sage
#

this my code after edit

fresh compass
rustic sage
#

and give me bad decrypto error

fresh compass
#

I have found a valid credentials for Will user but I can only list smb shares with them

#

So not very useful

rustic sage
#

how?

autumn pilot
#

please refrain from posting related spoilers from modules that are above tier 0

acoustic owl
#

My image was a printscreen from the module. It does not contain any hints. ๐Ÿคท๐Ÿปโ€โ™‚๏ธ

autumn pilot
#

well, to be precise you are posting a content of tier 1 module, where people have invested their time and efforts into developing it

#

not to be published for free

rustic sage
#

I'm really grateful to you

#

but why my code removed?

acoustic owl
thorn urchin
rustic sage
thorn urchin
#

its unreasonable to enforce it to the extent you currently are

autumn pilot
thorn urchin
#

this channel cannot function like this.

where did this moderation guidelines come from?

autumn pilot
#

ToS

thorn urchin
#

no, where did this moderation guideline come from?

#

Who do I need to ask about this?

autumn pilot
#

Please, do not continue to argue

thorn urchin
#

No, Im intending to report a complaint about this, and I would like to know where I need to direct it.

autumn pilot
#

Feel free to whomever you want ๐Ÿ™‚

thorn urchin
#

Really?

thorn urchin
autumn pilot
#

Up to you

rustic sage
autumn pilot
#

Just to note, noone stops you from discussing modules/section, where you can re-phrase or point to specific question

rustic sage
#

how i can discuss with out send snippet

thorn urchin
autumn pilot
#

Guys, if you are going to using that ridiculous route that eathebuffet is going, there is not point into discussing more

autumn pilot
rustic sage
#

How can I made a complaint?

thorn urchin
analog dock
rustic sage
#

@autumn pilot so i can not made write ups about module?

rustic sage
#

+i see in forums alot of people share snipsset

fresh pine
#

I run into this issue in in PASSWORD ATTACKS
Pass the Ticket (PtT) from Linux
with IMPACKET (i upgraded he package but no success there):

[proxychains] Strict chain ... 127.0.0.1:1080 ... ms01:445 ... OK
[-] ('unpack requires a buffer of 4 bytes', "When unpacking field 'length | !L=0 | b''[:4]'")

I changed to the exact version of the example and still get trouble ๐Ÿ˜ข
Impacket v0.9.22 - Copyright 2020 SecureAuth Corporation

[proxychains] Strict chain ... 127.0.0.1:1080 ... dc01:445 ... OK
[-] invalid principal syntax

Can anybody help please? ๐Ÿซถ

autumn pilot
rustic sage
thorn urchin
rustic sage
thorn urchin
#

and he could very well just be doing his job. Thats why I asked who to complain about it to. Its being handled one way or the other, so theres no use in arguing or prodding. Just makes it more likely you get the boot regardless.

umbral wigeon
slate palm
proud pine
visual forge
#

In the Shells & payloads module, there is an example bind shell that specifies target IP. Why is that even needed? I never used it in previous modules and all my notes only include a port, which would be expected with a bind shell. https://academy.hackthebox.com/module/115/section/1105#:~:text=the TCP session-,No. 1%3A Server - Binding a Bash shell to the TCP session,-Target%40server%3A

thorn urchin
slate palm
#

big brain time

umbral wigeon
#

๐Ÿค“

slate palm
#

make sure to gib credit when you write your blogpost that becomes the next big thing on the internet

narrow solar
#

can you help please, i am still stuck ๐Ÿ˜…

fiery berry
burnt sluice
narrow solar
#

yes i did, and its empty

#

only default databases

fiery berry
burnt sluice
narrow solar
#

yes i did, and i cant det to the desktop because no permissions

fiery berry
narrow solar
#

and i tried having a revshell but same

fiery berry
burnt sluice
#

did u try priv esc?

narrow solar
#

do i have to take the priv esc module?

burnt sluice
#

enumerate the user u landed in, there should be a trait that will enable u to priv esc.

#

no, no need for priv esc module, there is a priv esc technique within the AD module.

#

check the user u landed in, enumerate the traits, and check the stacking the deck section :)

narrow solar
#

ok friends, thanks a lot, i will try that ๐Ÿฅฐ

burnt sluice
#

no probs

wind pumice
#

Hii

burnt sluice
#

guys quick question, did HTB remove the feature where u could extend the life of the exercises machine?

pine dagger
#

No

#

It just is only on certain execises I think

narrow solar
#

guys whats wrong here, i dont see the problem

sonic valve
#

Hello I have a question regarding the subscription. I have student subscription with access to all modules until Tier2. When I upgrade to Platinum, will i have my student access to all Tier2 Modules + each month 1000 Cubes? Thank you in advance

zinc marsh
#

just 1000 cubes a month

#

complete all the tier 2 before

sonic valve
fiery berry
narrow solar
#

i managed to do it through smb, but i will try this

narrow solar
fiery berry
lusty egret
#

I have a question that how I can become a HTB ambassador ?

noble moat
#

Hello, in Miscilanious for Active Directory module, the question

Find another user with the "Do not require Kerberos pre-authentication setting" enabled. Perform an ASREPRoasting attack against this user, crack the hash, and submit their cleartext password as your answer.

I found the cleartext password but it's not accepting my answer, can anyone confirm with me if i'm doing the right thing its for asreproasting the ||mmorgan|| user

fiery berry
noble moat
#

@fiery berry Thanks, I found it, needed to use ||best64|| rule

torpid haven
#

This question in the command injection module is driving me insane:
Use what you learned in this section to execute the command 'ls -la'. What is the size of the 'index.php' file?
I've tried every possible combination of bypasses already and nothing seems to work.

pine dagger
torpid haven
quick cloud
#

What does this output mean and how can I fix this? ubuntu@WEB01:~/ptunnel-ng/src$ sudo ./ptunnel-ng -r1-.129.190.178 -R22
[sudo] password for ubuntu:
./ptunnel-ng: /lib/x86_64-linux-gnu/libc.so.6: version GLIBC_2.36' not found (required by ./ptunnel-ng) ./ptunnel-ng: /lib/x86_64-linux-gnu/libc.so.6: version GLIBC_2.34' not found (required by ./ptunnel-ng)

pine dagger
torpid haven
#

Same result

torpid haven
pine dagger
#

Would change the time to resolve.

torpid haven
#

Yeah that's what I'm saying

pine dagger
#

are you sendingit in ip=

torpid haven
#

yes

pine dagger
#

oh, lol

#

Wood for the trees ๐Ÿ˜„

torpid haven
#

Thanks a lot

fiery berry
#

cause of this

torpid haven
#

I was sure that I have already tried that

#

Cause of what?

fiery berry
#

cause that's not how you use ${ls,-l}

torpid haven
#

Yeah that's what I also thought, I was trying it cause wolfiej told me to give it a go.

fiery berry
#

He probably didn't mean to do it in that way, just a small mistake I guess

torpid haven
#

Yeah, thanks again

pine dagger
#

Yeah, I'm on a team meeting, so slightly distracted ๐Ÿ˜„

tender thicket
#

Hello everyone, looking for new Pentester friends to make here I am a Cyber Major on my pentest path, I would like to learn and share some of my experiences with some of ya

viscid stratus
civic zenith
#

Hey guys. I'm on Meterpreter Tunneling & Port Forwarding: Which of the routes that AutoRoute adds allows 172.16.5.19 to be reachable from the attack host? (Format: x.x.x.x/x.x.x.x) So far when I run the executable that I made with msfvenom it connects back to my multi/handler only for a split second and closes out immediately. msf6 exploit(multi/handler) > run

[] Started reverse TCP handler on 0.0.0.0:8080
[
] 10.129.222.140 - Command shell session 1 closed.
[] 10.129.222.140 - Command shell session 2 closed.
[
] 10.129.222.140 - Command shell session 3 closed.
[*] 10.129.222.140 - Command shell session 4 closed.
and on the ubuntu pivot host I get: ubuntu@WEB01:~$ ./backupjob2
Segmentation fault (core dumped)

fathom pendant
#

I suggest following this section to a T

#

Like exactly to a T

civic zenith
barren apex
#

can someone help me on the shells and payloads as I cant work this out for the of me. Its asking for the location of the aspx on the pwn box. and I have entered every possible combination it wants, with file name, different folders that have the same folder and none work

fathom pendant
#

You're connected to the pwnbox yes? Use the locate command or find command

barren apex
civic zenith
#

just got it

#

lol i feel dumb

fathom pendant
civic zenith
#

thx again

barren apex
fathom pendant
barren apex
#

yep, im literally sat in the folder where they are located and copying pwd and its not accepting it

fathom pendant
#

If all else fails, refresh page and put it in again

barren apex
#

right theres 2 locations for the file and the hint points you to the wrong one...

fathom pendant
#

Dm me

barren apex
#

tells you to look in the /webshells folder where this is the file again

barren apex
#

I have it now

#

i was in the correct one but didnt add the shell.aspx extension so looked at the hint and it takes you to the wrong folder

#

thanks

fathom pendant
#

The hint isn't incorrect

#

It's to start you in the right direction unless it's saying there's a /webshells off of root

#

And not /path/to/webshells

barren apex
#

still confusing how its installed in 2 locations on the machines

#

oh well, cheers tho

fathom pendant
#

You don't need to Crack the key, the intended way is a cache file

#

Hint: the daemon of the realm shows you the way

#

It has to connect to Kerberos as the device yeah? Why would it not store those in its own files

dusk cloak
#

Hi guys! If anyone has done Working with IDS/IPS module, can you please DM me?

autumn pilot
#

with which section do you need help

dusk cloak
autumn pilot
woven otter
#

hey, what's up? I'm taking the Password Attacks module and struggling with the question on Credential Hunting in Linux, did anyone here completed it?

pine dagger
pine dagger
#

Mistag?

zinc marsh
#

I wanted ask u a thing

#

is it worth it doing the powerview module?

#

the one which costs 1000 cubes

pine dagger
#

Cost wise, probably not. I think it would be better priced at 500. But as a module I thought it was a decent module building on AD Enumeration.

summer flame
#

Hi, for "Documentation & Reporting Practice Lab" do I have to do further enumeration and exploitation to gain access to DC01? and I cant login to WhiteHat app, tried the given credentials. I also need to do further enumeration for this? Thanks...

zinc marsh
#

here what is the @@ .... @@ for?

pine dagger
pine dagger
#

I know nothing. Just found the link ๐Ÿ˜„

zinc marsh
#

oh okay ty

pine dagger
#

Sorry!

misty elk
#

Attacking Common Services - Easy... I'm so close. Is RDP utilized at all?

fathom pendant
#

Is rdp open?

misty elk
#

Indeed it is

fathom pendant
#

Then it's probably utilized

#

My notes don't reflect utilizing it tho

#

The first step was smtp

misty elk
#

Haha hmm okay thanks. I'm still looking for how to trigger the php shell

fathom pendant
#

Ahh check you
1: used the correct slash direction
2: are in the right web directory:)

misty elk
#

๐Ÿ˜… Thanks ๐Ÿ™‚ I'm thinking I missed a directory

fathom pendant
#

Web roots are fun

misty elk
#

So why'd you set it to 'PORT'

gentle root
#

Lost here too son

fathom pendant
#

It is, in the example

gentle root
#

Still working on it, I'll lyk if I can't rig it up

fathom pendant
#

'PORT' can be any one of the 65535 ports

#

It's based on the attack

#

There are some default values

rustic sage
#

Hi

fathom pendant
#

Port is just whatever port the service happens to be running on

rustic sage
#

Infact it was to say that I need the most powerful cheat of codm I am ready to pay to have it who are interested tell me I pay first

#

If who is interested let me know

rustic sage
#

sorry

gentle root
#

Am I doing something wrong with Attacking Thick Clients, can't run monta.ps1 and it throws an error running with -ep bypass in cml, therefore can't create "service.exe" to inspect

fathom pendant
#

You can just fuck all the way off <@&861185840277487616>

ripe blaze
sharp cove
ripe blaze
#

i ddint mention hack or anything

fathom pendant
#

Please explain how we would help without hacking

#

If it's banned then chat with Snapchat support

ripe blaze
#

explaining to me what can i do

fathom pendant
#

Like it's that simple

#

If they banned it for a legit reason, you're not getting it back

ripe blaze
gentle root
#

I am someone else btw

fathom pendant
#

Nope support is the way.

ripe blaze
#

shit sucks

fathom pendant
#

Then chat with their support dude

ripe blaze
#

i did they also dont have a actual human support

#

just ais who arealdy fucked me

sharp cove
fathom pendant
#

^

#

Sorry I'm dragging this out more

ripe blaze
#

party poopers

fathom pendant
#

ยฏ_(ใƒ„)_/ยฏ

fathom pendant
maiden spindle
rustic sage
#

Hello i am stucked in Pass the Ticket (PtT) from Linux , i don't know what is going wrong
at this question Use the LINUX01$ Kerberos ticket to read the flag found in \DC01\linux01. Submit the contents as your response (the flag starts with Us1nG_).
Can you help me

maiden spindle
#

... No, I figured it would be in the file they gave us. thanks I'll try that

rustic sage
#

thank you for you quick response
i found the path of the cache of linux1 with linikatz and i export it in KRB5CCNAME
after that i try to get acces with smbclient

fathom pendant
#

Are you sure it's the right one

#

There is a directory that the daemon uses

rustic sage
#

i found only one ticket cache for LINUX1$ with Linikatz

tranquil axle
#

I have a general question regarding tunneling with chisel and co. Iโ€™m on a box that has a website hosted locally and I expose it via chisel and use proxy chains with Firefox to access the website. Now the website itself includes some bootstrap JavaScript libraries from the open internet. The box doesnโ€™t have internet access and when I use proxychains on Firefox neither does Firefox. Now the website is stuck trying to access those js files and I canโ€™t really browse it. Is there a solution to this?

fathom pendant
rustic sage
maiden spindle
#

hydra estimates it'll take 700hrs

#

Is this the right way to get it?

fathom pendant
#

^

maiden spindle
#

I'm at 64 threads, I tried the pws.list file that came with it(I didn't mutate it) now doing rockyou.txt

fathom pendant
#

I think the password should be in pws.list

#

I'll have to spin my box up

maiden spindle
#

okay I'll reset, first time I ran nmap there was no FTP and I had to reset

fathom pendant
#

Also running too many ftp threads can have it falsely skip the correct answer

maiden spindle
#

oh didn't know that

#

didn't get it again, I'll try again without specifying thread amount

fathom pendant
#

Wait

#

There's a rabbit hole here

fathom pendant
maiden spindle
#

oh god

#

ty

#

no login failed

fathom pendant
#

There's a special file here that's helpful ๐Ÿ˜‰

#

Really login failed?

maiden spindle
#

user error I got the files ty

fathom pendant
#

Rest is easy

green socket
#

Hey! I'm doing Linux Privilege Escalation, Containers section and the command it gives to run "lxc exec privesc /bin/bash" just gives "Error: Command not found"

quick cloud
#

Is there any section that teaches you how to use docerfiles?

green socket
#

Yeah

#

The user isn't in the docker group though

rustic sage
trail leaf
green socket
#

I checked and it is

trail leaf
#

To clarify, the image they have you import in the section is Alpine Linux, which does not, by default, come with bash

#

The lxc exec privesc /bin/bash is running bash from within the container, not on your host

green socket
#

Oh, duh, yeah sorry

trail leaf
#

no worries, everyone has made this mistake at least once when working with that distro

vapid isle
#

hey anyone has done Attacking DNS at Attacking Common Services?

quick cloud
#

On Module Pivoting, Tunneling, And Port Forwarding. Section ICMP Tunneling with SOCKS when I try to start the ptunnel on the foothold machine I get the following error. I have a good feeling creating a docker image and compiling ptunnel that way for Ubuntu may fix the problem but this is out of scope for this module and I have never did this before. Is there something I'm missing that's in scope to fix this issue. Also if out of scope how did you solve this issue?
ubuntu@WEB01:~/ptunnel-ng/src$ sudo ./ptunnel-ng -r1-.129.190.178 -R22
[sudo] password for ubuntu:
./ptunnel-ng: /lib/x86_64-linux-gnu/libc.so.6: version GLIBC_2.36' not found (required by ./ptunnel-ng)
./ptunnel-ng: /lib/x86_64-linux-gnu/libc.so.6: version GLIBC_2.34' not found (required by ./ptunnel-ng)

vapid isle
#

i

#

I am stuck on this module for about an age

green socket
trail leaf
#

If you were exploiting this in the wild, you would be uploading your own image, so you would probably know already

#

I'm not too familiar with lxc specifically outside of the privesc, so I would have to do some labbing to figure that out

green socket
#

OK, thanks anyway. Just weird they put it in the module and didn't give a hint.

trail leaf
#

The intent was probably to make you not always use /bin/bash and be cognizant of what image you're using

#

alpine will usually have /bin/sh and /bin/ash

green socket
#

ASH!

#

The only one I didn't try LOL

lusty egret
trail leaf
#

I want to say that the nmap script used to print out the contents of the relevant file, but I have no clue why it's not doing it now

green socket
#

Well, the flag fittingly contains "containers uhhh".

#

thanks for the hint @trail leaf

#

1 is the highest, right?

#

/sarcasm

fathom pendant
rich wraith
#

are these modules in order?

tall saffron
#

using xfreerdp we must use /sec:rdp

#

erratum

fathom pendant
wanton estuary
#

Hello, quick question in password attacks - pass the ticket. It tells us to rdp into the box but the creds didn't work for me. I managed to get round it by using the hash from the pass the hash module. Was this the intended route to get rdp access?

fathom pendant
alpine ridge
#

yo having abit of trouble with the footprinting easy lab, wget all the files for ftp on prot 2121 and found the id_rsa.pub, id_rsa and authorized keys and chmod 600 them all but when i ssh -i id_rsa celi@<box ip> and then login with the provided password i get permission denied? any suggestions

wanton estuary
fathom pendant
alpine ridge
#

lol

#

ceil

fathom pendant
wanton estuary
#

Yea

#

Oh thats so annoying haha

alpine ridge
fathom pendant
wanton estuary
#

Thanks for clarifying ๐Ÿ™‚

fathom pendant
#

Single quotes tells bash to interpret it as string

wanton estuary
fathom pendant
#

pika_sip you'd be surprised how many people have asked this question

wanton estuary
#

I tried searching and found someone with the same issue but someone must have pm them the answer

fathom pendant
#

I swear it's either been answered here or #cpts

thorn urchin
#

its also just Linux fundemental knowledge

#

you should know your special characters

fathom pendant
#

!!

deep owl
#

just finished AD enum and attacks

#

few what a module

#

if anyone needs help dm me

pine dagger
#

Its definitely a tough module. Although its not the hardest. heh.

rustic sage
#

Im doing the network analysis traffic module and one of the files is not showing the questions after extracting the zip file

#

it only shows the answer sheet

simple quail
#

Can somebody hack my old acc that was hacked and i cant have access anymore and give it back to me please i will be grateful a lot

rustic sage
#

idk where to ask for help so im doing it here, why dosent my firefox load anything

quiet ember
#

Why is it that cypher query to find users who can PsRemote only returns one user but I can see with PowerView that there are other users with that right?

trail depot
#

I love this lol

wheat garden
fathom pendant
torn steppe
#

even is not a mandatory exercise anyone could help me with my problem with /etc/proxychain using impacket and evilwinrm

#

proxychains evil-winrm -i dc01 -r inlanefreight.htb
[proxychains] config file found: /etc/proxychains.conf
[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4
error: invalid item in proxylist section: cat /etc/proxychains.conf%

#

socks5 127.0.0.1 1080 is writted in proxylist in the file

thorn urchin
#

saying invalid item, so you typod something

zinc marsh
#

@trail leaf

#

I just read this about --force option

trail leaf
#

:)

paper gust
#

๐Ÿ™‚

zinc marsh
#

lol a hashcat core dev

wheat garden
paper gust
#

lol

zinc marsh
#

thanks for the tool fingerguns. My main tool for hash cracking.

paper gust
rustic sage
thorn urchin
#

?

rustic sage
# thorn urchin ?

yesterday i see moderator didnot allow to send questions with snipsetts

#

and remove my messeges

thorn urchin
#

Ah, just dont worry about it.

rustic sage
thorn urchin
#

Its being handled. And very well could be just that is in fact the new enforcement policy.

rustic sage
#

dude?

raw bluff
#

hello there, i have a question (wasnt sure where to send this); someone was logged into my gmail account and it shows me the general state (same one im in). would it be possible to get that persons exact address?

rustic sage
#

and didnot work

rustic sage
#

what the hell

#

who is remove my question

#

really it is alot of people send snipsets and did not remive there is messages

#

@everyone

fathom pendant
#

Brother you can't @ everyone lol

#

Literally

#

If it's removed there's probably a reason

rustic sage
rustic sage
fathom pendant
fathom pendant
#

I'm not a part of Moderation or Staff

rustic sage
rustic sage
fathom pendant
#

I haven't done this module

#

So can't really help there

rustic sage
#

ok thanks

wheat garden
rustic sage
wheat garden
iron plaza
#

I have a question relating to sqlmap ... how do you discover prefixes or suffixes needed to make your injection work ... in the module they kind of give that info but how do you discover it?

azure shell
#

Please my openvpn on hack the box don't connect it's only showing me UDPV4 link local not bound Tlc error
UDPv4 link remote [AF_INET]

fathom pendant
azure shell
#

Alright

#

Did not work

#

Attempting to establish TCP connection with [AF_INET]38.46.224.104:443
2023-08-01 02:53:06 TCP: connect to [AF_INET]38.46.224.104:443 failed: Connection timed out
2023-08-01 02:53:06 SIGUSR1[connection failed(soft),connection-failed] received, process restarting
this is what it keep on telling me

fathom pendant
#

Try a different region

azure shell
#

okay

#

its work thank you so much

#

for over 5 days now i have been suffering for these..

fathom pendant
#

Always try all available options to you first

azure shell
#

alright

heavy marsh
#

OpenVAS Skilss Assessment is so intermittent!

#

Anyone have details on the HTTP server?

thorn urchin
#

I just used the saved scan reports

#

fuck doing it myself

fathom pendant
#

^

heavy marsh
#

To be more detailed I can see the "Results" under scans, but the minute I click on anything I get an error

fathom pendant
#

Ah

heavy marsh
#

Feels like the 92 employee manufacturing company intranet is being run on a Raspberry Pi 1 Model B+.

fathom pendant
#

How long did you wait to connect and check?

#

Sometimes these can take 5-10 minutes just to fully load properly

heavy marsh
#

I just tried again, at least a solid 10 min.

autumn pilot
heavy marsh
#

I filtered by "http server" and I get a lot of results

#

too many to wait 10+ minutes between each

#

Might it have something to do with cleartext?

#

Where would I find that information?

heavy marsh
#

OpenVAS was a trainwreck. I could not for the life of me get anything to load. Not only that, if it did load, there was no evidence of the "7 worded vulnerability associated with the HTTP server"

#

I had to rely on third parties to provide me the information. How discouraging!

rare topaz
#

Man finds out Google exists

fathom pendant
#

Not so much "finding out Google exists"

#

If you scroll up they literally show an error they are getting client-side of the spawned vm

fading fern
#

YI!

#

HI!

#

HI1!

maiden jetty
#

OpenVAS lab working on my machine, must be a skill issue

fading fern
#

hi!

maiden jetty
fading fern
#

im with rev

#

@rustic sage

analog pewter
#

hey how can i connect to retired machine

fathom pendant
analog pewter
fathom pendant
fathom pendant
fathom pendant
fading fern
#

hi'

#

ok

#

:(

heavy marsh
#

Any resolution?

maiden jetty
heavy marsh
#

Anyone else care to expound on these details?

thorn urchin
#

means the lab is working for other people

modern falcon
#

ATTACKING COMMON APPLICATIONS > Attacking Tomcat: Is there any special configuration that I need to take note of when running metasploit's tomcat_mgr_upload exploit? I am able to exploit the vulnerability by creating a .war file via msfvenom, but haven't able to automate it using metasploit

fathom pendant
#

And in pwnbox

#

:)

heavy marsh
#

Besides that, how was I supposed to find the cleartext?!

fathom pendant
#

Scan > reports, click on the date/timestamp

#

Then there's the first tab on the right

#

It took me a minute because i forgot how frustrating openvas gui was

#

I clicked on the older timestamp for the Linux one

#

And it was there :)

#

Pre-filtered

heavy marsh
fathom pendant
#

pwnbox was being weird for me but I chalk it up to me using tethering ยฏ_(ใƒ„)_/ยฏ

heavy marsh
coarse escarp
#

not sure what's going on

thorn urchin
#

why are you running dns enumeration

coarse escarp
#

for practice

#

and to have a better understanding of it

#

also just figured out that I didn't need to add a port number

coarse escarp
#

unless I need to use SSH

thorn urchin
#

it does not say to log in

thorn urchin
coarse escarp
thorn urchin
coarse escarp
#

So then what is the hint telling me?

thorn urchin
#

its a docker instance

#

if you target other stuff on the server youll have a bad time

thorn urchin
coarse escarp
#

if I'm not supposed to use gobusters or enumeration (which is what's being taught on this lesson) then what am I supposed to use to find the flag?

thorn urchin
#

you are supposed to preform enumeration and use gobuster

#

that doesnt mean youre supposed to use DNS enumeration against an empty domain

coarse escarp
#

Well I don't know that

#

I'm new

thorn urchin
#

go through the section and make sure you understand what its teaching

thorn urchin
coarse escarp
thorn urchin
#

you can be lacking fundementals for the fundementals ยฏ_(ใƒ„)_/ยฏ

thorn urchin
#

when I say fundementals I mean like basic networking, linux, windows fundementals stuff

#

not hacking related

coarse escarp
thorn urchin
#

And I could be wrong, Im just saying thats one possibility why the section may be challenging for you

fiery berry
# coarse escarp That's not very helpful

madf0x already gave you a great advise: "go through the section and make sure you understand what its teaching". If that isn't the way try something else explained there

thorn urchin
#

I do not know your full circumstances and capabilities to say anything definitively

thorn urchin
compact carbon
#

I see now that Public Exploits exists to teach the K.I.S.S method along with Metasploit...

coarse escarp
#

I understand that Gobuster is a tool for remote file searhing

#

I get that

thorn urchin
#

The section wants you to preform the enumeration steps and see if you can notice anything that stands out

coarse escarp
thorn urchin
#

wdym lacking resources?

coarse escarp
#

It was in the "how to learn" module

#

explaining the learning process of the human brain

thorn urchin
#

what about it

compact carbon
distant ibex
#

Pivoting, Tunneling, and Port Forwarding Skill Assessment i got the dc's ip 172.16.10.X. this is right?

coarse escarp
#

I'm not sure I understand this

#

its saying that we can add a dns server but I don't understand why

#

or if I need to

#

if so how would I do so?

compact carbon
#

gobuster dns is a sub-domain scan. Remeber enumeration is for building a map of the target before you try and navigate it. The more information the better.

coarse escarp
#

Ok, but when I try to use it it doesn't give much results because I'm using a subdomain

coarse escarp
#

at least that's my understanding

compact carbon
#

The lesson is for webservers. Try looking at it in the browser of the box.

vital adder