#modules

1 messages · Page 112 of 1

vital adder
#

you need a wordlist

coarse escarp
#

ok, now I'm completely confused... Why would they show terminal and Websites if I just need the websites?

vital adder
#

@coarse escarp to be honest if you don't know how basic tool like curl or gobuster work then i would recommended thm it's way more beginner friendly, htb even the academy need the try harder mental

coarse escarp
#

I will brute force it untill I get it done

vital adder
coarse escarp
#

willing to do it again

#

my lack of understanding is only macheted by my unyielding iron to move foreword.

distant ibex
#

i can use smbclient to get final flag ?

vital adder
#

i guess you are in the path for gessing that tool but hint no need for that

#

hint enum of the third or the win10 machine

#

so in this section there is a flag some in some directory on the target web side you need to use gobuster which is can brute force directory using a wordlist that have a lot of directory name which is the -w tag is for and in the example they use the wordlist at /usr/share/dirb/wordlists/common.txt so maybe give that a try

azure torrent
#

Okay question, why do some of the module tests ask you concepts that were never explained in the actual modules

#

WIndows Fundamentals is asking me to create a group, none of the modules in windows fundamentals explain how to create a group

proud pine
fiery berry
#

make sure to slow down, fingers are going faster than the brain

vital adder
distant ibex
#

ok

coarse escarp
#

ok well the correct way says that I can't log in

#

which is even more confusing

vital adder
coarse escarp
vital adder
vital adder
coarse escarp
vital adder
coarse escarp
#

so basically it acts like traffic controlls

#

and can also hide stuff to

#

hide things like flags

vital adder
#

it's can but hint it's not really the case for this

coarse escarp
#

so I don't need it then

vital adder
#

here is a bigger hint you may want to check something that's "disallowed"

#

of way they explain this quite well under the Robots.txt part in the section 🤣

coarse escarp
#

If someone doesn't want me there then it's a good idea of where important information is

#

problem is how

vital adder
coarse escarp
#

have some pie (even though I don't have pie)

vital adder
#

or a redbull 🤣

coarse escarp
#

I got that Hawiian Punch

lethal swallow
#

bruh...i tried to do the Meow very easy module hours ago and i couldnt even ping the machine. i do the same thing now and it works perfectly

gleaming halo
#

hi

quick magnet
#

hi im working on Nmap Firewall and IDS/IPS Evasion - Medium Lab, already made port 53 open and got version, but when i answer it incorrect

vital adder
slate palm
noble moat
#

Hello, I'm stuck on question 2 for Active directory

Kerberoast an account with the SPN MSSQLSvc/SQL01.inlanefreight.local:1433 and submit the account name as your answer

I can't seem to import powerview whenever I do Import-Module .\PowerView.ps1 it doesn't seem to work any ideas?

pulsar needle
#

Check if its loaded

#

Like the module

mossy nest
#

Hi guys, I'm currently doing the payload and shell module and there is a question asking us for Powershell Version.

#

I don't know what i'm doing wrong i tried $host.version in Pwnbox but the reply doesn't work with x.x.x or Powershell x.x.x

#

So I thought that maybe it could only be the one wrote in the lecture

#

But 7.1.3 and Powershell 7.1.3 are not valid answer

#

Also not working with PowerShell instead of Powershell

#

I tried by writing it by myself without any CTRL+V but still not work

proud pine
mossy nest
#

Thank you @proud pine

#

It was just in front of me

proud pine
full echo
#

If one field is not working then how about other fields?

naive wadi
#

Looking for help with attacking common services DNS "submit the flag found as a dns record" I have enumerated the subdomains. However whenever I attempted zone transfers etc it just fails and times out. What am I doing wrong? I do dig axfr <subdomain> @<ip>

acoustic owl
naive wadi
naive wadi
acoustic owl
naive wadi
#

Been using this ||dnsenum --dnsserver 10.129.8.236 --enum -p 0 -s 0 -f /usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt inlanefreight.htb|| to enumerate.

acoustic owl
#

root comes from SOA Entry, right?
But then it is a mail address and not a subdomain 😉

naive wadi
#

Can you give me a nudge where my enumeration is going wrong?

acoustic owl
#

Try a smaller list.
Not every list contains every entry

naive wadi
#

thanks

coarse escarp
#

So, I'm trying to find a way to gain access to robots.txt to be able to get to the flag

#

My suspisson is that it has to do with the fact that wordpress was moved. Moved where?

#

I have the idea of transferring robots.txt to wordpress but I can't log in so smb commands wont work

#

the puzzle has to do with wordpress though..

#

can someone play if I'm hot or cold on this one?

proud pine
coarse escarp
#

?

proud pine
#

Yeah, but as I said before, this isn't about just getting a flag. You can't use that as a judge of progress. It's about understanding.

#

MRtom gave you a bunch of help on this, but you're missing some core concepts.

coarse escarp
#

Getting started with a pentest distro is about setting up an OS for your workflow

#

If I'm missing some core oncepts then what are they?

gleaming halo
#

hello guys i need some advice i want to start learning to

coarse escarp
#

It's not very helpful to say I'm missing something then give vague solutions on what I should do. Because then I don't know wha to look for in my gaps of knowledge.

proud pine
coarse escarp
#

otherwise I won't know what to go for

#

because the door will be to open

plain coral
#

Are you trolling?

coarse escarp
#

I'm not

proud pine
#

Once you have a better grasp, it would make progressing through these modules easier.

proud pine
plain coral
coarse escarp
proud pine
#

HTB generally expects a little more experience, at the beginning.

coarse escarp
#

actually nvrmnd

#

I could skip the step

#

wellll

coarse escarp
#

How often are these sites updated?

#

I actuall do need to dm you now

vital adder
coarse escarp
vital adder
coarse escarp
vital adder
coarse escarp
#

that's really off putting for someone trying to learn if they are brand new

#

at least with HTB I was able to connect and complete modules

vital adder
# coarse escarp I have ADD and Dyslexia didn't wanna bring out that card but no

i have no idea if this will affect anything but you shouldn't follow 100% what example showed, like if an example run gobuster on a domain that is clearly fake or only for demonstrate purpose like example.com or like fakebank.com you still shouldn't follow the example and run the tools on these domain because in most case you are running pentesting on a site that didn't allow you to

coarse escarp
#

I'm the dumb dumb

#

I thought you meant my url used at the top not what I wront

#

wrote

vital adder
coarse escarp
#

look I am genuinely trying to learn and I do want to learn

vital adder
#

@zinc marsh figure it out that quick? 🤣

zinc marsh
#

I need to read better lol

coarse escarp
vital adder
coarse escarp
#

God I hate dyslexia

zinc marsh
#

well I didn't try it but I guess I got what I have to do lol

#

am gonna try it now. Yea it worked

vital adder
#

@coarse escarp look i've been on all 3 platform THM, HTB and HTB academy so if you are new to this and need some help feel free to shoot me a dm if you questions on those platform

zinc marsh
#

what's his problem

vital adder
#

mostly he's just new to this, the actual problem is just simple stuff but the hard part is learning how things work

zinc marsh
#

oh

coarse escarp
zinc marsh
#

well he can ask the doubts and someone will answer him

coarse escarp
vital adder
coarse escarp
zinc marsh
#

I ask sometimes general doubts or about something I am doing

coarse escarp
#

one of my main reasons for getting on the force

vital adder
zinc marsh
#

not from the academy content

vital adder
#

yea that's mostly because me and 3 other great guy are here 24/7 😂

quick cloud
coarse escarp
quick cloud
high zinc
#

The Firewall and IDS/IPS Evasion - Hard Lab test in the Network Enumeration with Nmap module seems rather unreliable... is that so?
Anyone got experiences with this / tips?
I've read "the relevant section" but even so I'm not getting any additional findings

green socket
#

I run logrotten on ~/backups/access.log

civic zenith
#

I am on SOCKS5 Tunneling with Chisel and i am setup like so:

#

But when I try rdp I get:

green socket
#

I see the copy with payload in /etc/bash_completion.d and get deleted, but the payload doesn't execute.

fiery berry
civic zenith
#

oh ok

frozen mesa
#

DNS enumeration with Python - Determine the IPv4 address of "ns1.inlanefreight.htb" from your target and submit it as the answer.
nsloopup gave me 178.128.39.165 but that is not ok. Other enumeration gave me the same results. Did i miss anything?

fiery berry
frozen mesa
#

.htb

fiery berry
frozen mesa
#

teach me how to use those spoiler tags please 🙂

fiery berry
frozen mesa
#

Ah thanks

fathom pendant
#

You used .com

zinc marsh
#

meh

frozen mesa
#

aaah

zinc marsh
#

better with ||test|| as well

fathom pendant
#

Do nslookup {domain} {ip}

high zinc
zinc marsh
fathom pendant
#

Or just nslookup {ip}

inland mesa
#

Hello world!

zinc marsh
fathom pendant
fathom pendant
#

.5 seconds error find

slate palm
#

inlanefreight*.com*

fathom pendant
#

Speed run leaderboards

fathom pendant
proud pine
#

modules any%

fathom pendant
inland mesa
#

🫵

zinc marsh
fathom pendant
fiery berry
rotund urchin
#

I am looking for some help on the Web Proxies Skill assessment, I do not understand the question about fuzzing the md5 cookie. Can I DM someone about it?

fathom pendant
#

BTW you need to verify your main htb account following #welcome

#

Automod stuff removes certain things

frozen mesa
#

DNS enumeration with Python - I get only these results: ** server can't find 236.226.129.10.in-addr.arpa: NXDOMAIN / ** server can't find ns1.inlanefreight.htb: NXDOMAIN / ** server can't find inlanefreight.htb: NXDOMAIN

What did i do wrong with the enumeration?

fathom pendant
naive wadi
fathom pendant
#

.htb isn't a registered tld and the target is spawned in an internal container. External dns won't find it

knotty hemlock
#

Hello, I'm stuck at the same point: Use the LINUX01$ Kerberos ticket to read the flag found in \DC01\linux01. Submit the contents as your response (the flag starts with Us1nG_)
Found several cache ticket files, but not sure which one is connected to linux01...

frozen mesa
vital adder
#

@zinc marsh just notice your github cheat sheet and i think you can't share that not 100% sure if the sharing the cheat sheet is also against TOS but for the academy you can't be sharing anything but the tier 0

noble moat
#

Hello I'm stuck on question

Find cleartext credentials for another domain user. Submit the username as your answer`

I can't seem to upload anything to ms02 so how can I check for clear-text credentials? Any tips on how to do this? Thanks 😄

dawn parrot
#

@vital adder where can you read the TOS

vital adder
#

the short version is here

#

and that will link the TOS

narrow solar
#

hey friends, i am at Login Brute Forcing Skills Assessment at 2nd question and keep getting this response, whats wrong with this?

#

the site is up

cinder mortar
#

maybe vpn issue?

narrow solar
#

it works fine at the other questions

analog dock
#

Are you sure the post form is correct?

narrow solar
#

i will double check it but i think yes

vital adder
#

90% sure

zinc marsh
analog dock
#

I don’t think you are allowed to share academy cheatsheets no, but tbh all those things are known online so if you’d make an own cheatsheet the contents would be similar

zinc marsh
#

I am not giving a solution to anything

vital adder
narrow solar
vital adder
zinc marsh
#

I will change it to private repo

#

it should be private now

vital adder
#

backing up or making your note on github is good and recommended by the holy god John Hammond but just don't share private stuff like imagine John shere is Offsec notes 🤣

gloomy bramble
# naive wadi Can you give me a nudge where my enumeration is going wrong?

been stuck on this module for way too long. just want it to end already. I enumerated root, and got a bunch of subs, but none of those were it. As mentioned, guess they are not. I ran dnsenum with a certain wordlist and found 2 subdomains(1 ns). At this point, no matter what I try, nothing works. dig TXT on all subdomains I found, sublist3r, even gobuster, though go was the one that found all the roots.

radiant abyss
#

in the windows privilege escalation module, Windows server section, the spawned machine is refusing RDP connections, even when the task says to connect to the machine via RDP. what to do?

radiant abyss
zinc marsh
#

literally my notes about this question are

naive wadi
trail leaf
#

Can't test it myself right now, but I think I did that one a little over a week ago and I didn't have any problems with it, so genuinely not sure

zinc marsh
#

yea I am checking the section I think I could rdp with no problem

trail leaf
#

Probably just need to wait a few minutes for the server when spawning then

#

That solves a lot of issues

radiant abyss
trail leaf
#

Just installed xfreerdp on my Ubuntu 22.04 VM and can confirm that the issue exists

#

The solution in the erratum message I linked works though

#
xfreerdp /u:htb-student /p:'HTB_@cademy_stdnt!' /v:10.129.26.28 /sec:rdp
harsh tulip
#

#modules hello guys i stuck at knowledge check at getting started module , how can i esclate to get root privilege

harsh tulip
zinc marsh
harsh tulip
trail leaf
#

why ask when you can try

gloomy bramble
harsh tulip
#

i know i will change cmd to listner with ip and port i guess and get reverse shell not sure

autumn pilot
#

What is the version of xfreerdp you guys are using @trail leaf and @radiant abyss

trail leaf
#

checking right now

zinc marsh
#

this is what I used when I did that module

radiant abyss
zinc marsh
autumn pilot
#

Seems like an older version from the one in the workstation, and the one in kali

#

Are you both using Ubuntu?

trail leaf
radiant abyss
trail leaf
zinc marsh
trail leaf
#

Didn't realize how behind the Ubuntu repo was

radiant abyss
autumn pilot
#

if you have multiple tun interfaces, that could cause the mentioned crashing behavior

harsh tulip
zinc marsh
harsh tulip
zinc marsh
#

@autumn pilot sorry could I ask u about 1 question? I am not sure if it is out of date

autumn pilot
#

sure, go ahead

zinc marsh
#

the first question Perform MIC cracking using the attached .cap file.

autumn pilot
#

feel free to dm

zinc marsh
tall saffron
tall saffron
#

the problem is the windows 2008 server iirc

radiant abyss
tall saffron
#

cool it helps 🙂 i had this problem and was like you 🙂

tall saffron
radiant abyss
harsh tulip
zinc marsh
analog pewter
#

how can i priv esc in linux

#

sudo -l

#

(ALL : ALL) NOPASSWD: /usr/bin/php

zinc marsh
#

@trail leaf ah shit, here we go again

tepid hemlock
zinc marsh
tepid hemlock
#

Aka, is it enough that I just follow the CPTS path or do I need to take these first?

trail leaf
#

the entire internet is at your fingertips!

tepid hemlock
#

For example

trail leaf
#

this isn't the first time someone has tried to privesc with PHP, surely someone has written about it before!

zinc marsh
#

php zeroday POGGERS

trail leaf
trail leaf
#

if you got hacker rank without cheating, you should be fine tbh

trail halo
#

Hello friends
I am very tough situation in survive at the time because I am jobless need to help you regarding the job.
So please help me.

trail leaf
#

might be worth skimming the modules though

analog pewter
#

priv esc with php

tepid hemlock
trail leaf
#

oh, then every module you have to pay for is in the penetration tester job path

gaunt surge
zinc marsh
#

for the cpts

tepid hemlock
#

Currently I was told that 1x Platinium and 1x gold sub is enough to get CPTS (course content) since you also earn some cubes from completing.

trail leaf
#

the information security fundamentals stuff isn't explicitly required to do the CPTS

zinc marsh
#

if u think u know it just skip it

harsh tulip
rustic sage
tepid hemlock
#

yea, I might and if I see myself getting stuck I can revist said modules it suggests. I just assumed some of it would be covered by the CPTS path itself.

analog pewter
trail leaf
#

I like using Wireshark or proxying through BurpSuite to troubleshoot what requests my tool is making

narrow solar
#

thats really weird because i am sure of them, i will try proxying

fringe charm
#

Hello, can someone help me with the Authority box? I am stuck

rustic sage
tepid hemlock
#

use command /verify

#

it will tell you how to

analog pewter
#

service running on the target will give you flag

tepid hemlock
#

ok, so one of these then

#

Ah, this is an active box. I would suggest asking in #boxes and maybe don't mention where you got the users from as it appears to be a spoiler.

fringe charm
tepid hemlock
rare spire
#

Hi,
I can someone help me for the C# module please ?

analog pewter
analog pewter
rare spire
#

Introduction to C#

analog pewter
rare spire
maiden spindle
#

Hey I'm on Attacking SQL Databases, the second question Enumerate the "flagDB" database and submit a flag as your answer. I'm supposed to login as mssqlsvc. sqsh, does work for me to login I tried .\mssqlsvc. I was only able to get on with htbdbusre when i used impacket-mssqlclient.

#

sqsh connects me to my own machine

#

sqsh does not work

#

windows auth

alpine ridge
#

yo can anyone help me with the footprintg medium lab, ive gotten to the point where ive found the creds for sa. ive tried then logging to sql server with the creds but with no luck and also tried re RDP into sa but again no joy

tender acorn
#

In whitch module i learn more about
HTTP Headers and Content Security Exploit.
?

tepid hemlock
tender acorn
analog pewter
#

can anybody explain what is rainbow table attacks

#

this is the right flag

#

check spaces before and after the flag

compact carbon
#

For Privilege Escalation do I need to run a shell on the host to run the enumeration tools? I'm kinda confused I feel like given the last lesson that's what I'm supposed to do but also the cheatsheet makes it seem like I should be able to run the enumeration script while logged into the host.

analog pewter
#

ok

thorn urchin
#

youre trading time for disk space basically

#

also only valuable if you intend to reuse the table on more than one campaign

#

so usually people dont make salted rainbow tables at all outside special circumstances

#

Yes, NTLM rainbow tables are pretty popular

analog pewter
#

what are salts now

#

🤔

thorn urchin
#

you can get ntlm tables for every possible combination under certain amount if digits

thorn urchin
analog pewter
#

like this

thorn urchin
#

so p@ssw0rd would be the password generated by the user thats entered into applications or login portals and 123456 would be the salt that the application adds to the users password on the backend

thorn urchin
#

its also worth noting that for many algos, the salt is given in cleartext as part of the resulting hash

#

its NOT secret information

#

its just a clever trick to defeat people precomputing things to give em the middle finger

paper gust
#

when it's a secret, we've taken to calling it a "pepper" or in the case of an HMAC construction the "key"

pine dagger
#

pepper is a per application salt that's added to the hash, in addition to the salt.

thorn urchin
#

the rabbit hole is always deeper

alpine ridge
#

Hi any help with the footprinting medium lab got creds for sa but when i use them login into the mysql server it doesnt work when i run as admin i need to specify admin password but dont have one and the sa creds wont work with

#

also tried remmina but that doesnt work either just keeps flashing up specify RPD authentication

paper gust
#

its just a way to differentiate salts, which are public by nature, from values that are kept private/secret

#

the terminology isn't extractly strict, with pepper only making a handful of "official" docs of any type

pine dagger
#

Per application, as in used inside that DB only.

paper gust
#

yeah that makes sense

#

"per instance" or such

pine dagger
#

Its to help prevent salt reuse between different applications/instances.

#

i.e. if a DB happened to have the same salt + pass in a different DB

paper gust
#

I'm not sure that really makes sense, salts should be random

pine dagger
#

Yeah, but if your salt is only 4-5 characters that only gives you a certain number of combinations.

#

You could increase the salt length, but eh

paper gust
#

sure, but no modern algorithm or construction should have that limited of a salt

#

almost all modern algorithms have a fixed or at least default generation scheme that provides a nice long salt per invocation of the algorithm

pine dagger
#

But adding a pepper makes it even less likely 🙂

paper gust
noble moat
#

Active Directory : Take over the domain and submit the contents of the flag.txt file on the Administrator Desktop on DC01

Can someone help me with the last question please, I can't get either methods to work 😦

acoustic owl
pine dagger
#

How do I hit 100% in Academy? I've already done all the modules 🙂

acoustic owl
pine dagger
#

Nope. All modules done, including all updates.

#

You cant complete the modules if you dont answer them 100%

pine dagger
#

That is simply not true.

acoustic owl
#

At least two DACL modules are in the pipeline.
More Defense Modules are likely to be released for the upcoming exam

thorn urchin
#

if you complete a module and an update comes out youll still have the badge and show as completed but the percentage will drop down.

But PayloadBunny is most likely correct

#

that completion gap is too big to just be random module updates

acoustic owl
#

Today HTB announced another path on Twitter, later deleted the tweet.
Also here are certainly more modules planned

compact carbon
#

So running into an issue and I don't know if I'm just thinking weird but for Priveledge Escalation I'm trying to run a shell on user2 since user1 has bash priveledges over them but when I try to connect to the listener on both lan0 and tun0 neither result in the listener grabbing the connection. Is there something I'm doing wrong?

acoustic owl
pine dagger
#

Awww maaaaaan

pine dagger
acoustic owl
#

So several new modules are to be expected

thorn urchin
pine dagger
#

Why does the Packet carver badge look like Jigsaw? lol

compact carbon
#

This is the reverse shell I'm trying to use obviously replacing the IP with the one from either the tun0 or lan0 same port.

pine dagger
compact carbon
#

That's the listener command I'm using.

pine dagger
#

exams after I feel a bit more confident in box cracking

pine dagger
thorn urchin
#

broski youve solod the entire academy

#

if you aint ready for the exams you never will

pine dagger
#

but... but... boxes....

compact carbon
pine dagger
#

Yeah I meant are you sending them as a single line or not

#

And need to change the IP address to your tun0 address

compact carbon
#

I am. I have it wrapped in sudo -u user2 <insert command here>

acoustic owl
compact carbon
thorn urchin
#

it does if you have a firewall blocking it for whatever reason

#

if youre using base kali it shouldn't

thorn urchin
# pine dagger but... but... boxes....

youve spent more on modules with content nothing to so with the exams than the actual exams cost.

At this point the absolute best practice and preparation you could do for the exam is to just take the exam.

compact carbon
thorn urchin
#

tried some surface level idors to leak new cert info but no dice

acoustic owl
zinc marsh
#

use common ports like 53,80,443...

thorn urchin
#

it shouldn't be blocked

#

unless hes doing something weird

#

like NAT vm, but the vpn is running in host

#

thatd cause problems lul

zinc marsh
acoustic owl
zinc marsh
#

they are adding game hacking as well

acoustic owl
#

Yes, but I cannot currently assign this module to any of the leaked paths

zinc marsh
#

u can search boxes here. You can filter them by certificates, skills needed, difficulty...

zinc marsh
thorn urchin
zinc marsh
thorn urchin
#

👍

zinc marsh
#

I am starting the labs from port swigger rn about sql injection, xss, csrf and all that things covered in the path

compact carbon
# thorn urchin unless hes doing something weird

I mean I could be but I don't know, the VM is configured with pretty much base settings aside from an encrypted LVM and the hardware settings are set to use higher than what VMWare reccomended because it was recommending like 4gb of ram and 1 cpu.

#

Could it be the .ovpn file?

thorn urchin
compact carbon
#

Does it need to be ran from in the host? I haven't had issues with it the past few lessons...

thorn urchin
#

good

#

try using wget or curl to see if you can make a connection at all.

#

ping too

compact carbon
#

-_-

thorn urchin
#

theres ofc also the easy way

compact carbon
#

I just realised why it may not be working.

thorn urchin
#

but the easy way wouldnt troubleshoot why no connection

compact carbon
#

On these hosts the only port that's open is the port you connect from.

#

Nmap shows that.

thorn urchin
#

thats not how ports work

compact carbon
#

??

thorn urchin
#

either way, do you want to continue troubleshooting the rev shell, or do you want to just finish it the correct way?

#

both are valid endeavors

compact carbon
#

I'll do the correct way. I was trying to do a shell because I was under the impression we were supposed to use a shell since the last lesson on shells didn't have a pracapp portion. Either way I'm probably still going to try and establish a shell after the fact just to get some practice in.

thorn urchin
#

yeah in this instance you already have a shell, so unless there was some exploitation constraints you wouldnt really want to spawn another shell, itd just be extra noise.

compact carbon
#

I feel like I missed something somwhere along the way that makes this much simpler than my brain is trying to brain it out to be.

#

My line of thinking is that from our SSH connection we have access to user1 who has sudo rights to utilize user2's bash directory therefore running a reverse shell to user2 seems like the most straightforward path to the goal and from that shell we can further move through and enumerate the target system.

thorn urchin
#

youre overgeneralizing

#

you're thinking that 'new access' = 'new shell'

#

but you can completely reuse your current shell

#

by just launching a new process under the new user

#

this is what happens if you use 'sudo su' on your machine to switch to a root terminal

compact carbon
#

-_-

#

It was that simple...

#

It's always simple.

thorn urchin
#

Overgeneralization is a normal concept when learning a new subject or skill

#

It means youre actually progressing

#

its the same phenomenon of why kids learning how to talk for the first time will use words in wrong grammar cases or make up new ones by mishmashing language rules they havnt fully learned yet

compact carbon
#

I don't know, I did this on the last lesson too and every time it hasn't been like an "Ah-hah!" moment. Moreover my forehead is sore from how many times my palm has hit it at this point.\

mild cypress
#

Does anyone know if Remmina can be used without the GUI? I did some brief looking around and found some (janky) workarounds that people have used to do it, but not much else. I'm aware there other options, this is more about understanding the tool (and satisfying my own curiousity) than anything 🤷

thorn urchin
wheat garden
pine dagger
#

….no? 🙂

thorn urchin
#

100% academy

pine dagger
thorn urchin
#

also if its a skill assessment the answer is probably going to be, "Its a skill assessment, figure it out"

wheat garden
steel dawn
#

Hi everyone, I was at 50% of CPTS,
kinda bored of doing the trial alone, with noone to talk about it

if there's any Hispanic going for CPTS or CBBH DM me, I'm bored and drunk asf
Muchas grasias

gloomy hawk
#

I forget somethings?

#

Sorry my english

#

Password attacks module

steel dawn
#

Just passing by,
Did you make the mutate_password. List?

#

Anyway, be patient with hydra, good luck

fathom pendant
#

"kira"?

gloomy hawk
#

Ftp, smb AND ssh

fathom pendant
gloomy hawk
#

Thx, i followed to test

fathom pendant
#

After that it's not too many steps to reach will

fathom pendant
tender viper
#

I'm still stuck on the Footprinting Lab - Easy......... Can someone help assist me in this module? Once I log into the ftp sever with the creds provided, I can't seem to progress form there.

fathom pendant
#

Are you sure you're on the right ftp server :)

gloomy hawk
#

I did with 2 mutate.list AND none, but i followed to test :/

thorn urchin
#

why do you have two mutated lists

fathom pendant
#

^

thorn urchin
#

you should be using the ONE mutated list they instructed you to build

#

sounds like you did your own thing which means no gurantee your list has the correct password generated

tender viper
gloomy hawk
#

The original mutate list with 90k+ word AND other new_mutate with grep -E ‘^.{11,}$’

thorn urchin
#

what are you talking about

gloomy hawk
#

cat mutated.list | grep -E ‘^.{11,}$’ > new_mutated.list

tender viper
fathom pendant
maiden spindle
#

You are targeting the inlanefreight.htb domain. Assess the target server and obtain the contents of the flag.txt file. Submit it as the answer. Attacking Common services - Easy. I'm trying to put the reverse shell through mySQL but no joy.

#

can I dm someone my code to see what I'm doing wrong?

fathom pendant
maiden spindle
#

okay i'll try /

fathom pendant
#

SmileW it was pain

maiden spindle
#

it really is, I'm just throwing shit and hoping something sticks 😛

#

SELECT "<'myreverse shell']);?>" INTO OUTFILE 'c:\xampp\shell10.php';

fathom pendant
maiden spindle
#

I then load /shell10.php in browser no joy and do load in mySQL and it says Null

fathom pendant
#

Also

#

That's not the web root of xampp

maiden spindle
#

i've trioed /xampp/htdocs/

fathom pendant
maiden spindle
#

I thought so but I'll give it another go ty

tender viper
fathom pendant
#

Learning how to read and understand what an error is helps

tender viper
digital pewter
#

Has anyone else had trouble running Eyewitness on their local Kali (2023.2) instance? Its clearly a problem with Selenium, but I did install Eyewitness using apt so you'd think the dependencies would be taken care of. 🙂

$ eyewitness -f scope_list --web -d inlanefreight_eyewitness
Starting Web Requests (7 Hosts)
WebDriver.__init__() got an unexpected keyword argument 'capabilities'
...
Finished in 0.29549288749694824 seconds
[*] No report files found to open, perhaps no hosts were successful

UPDATE:
Seems to be a known issue that is being worked on.
https://github.com/RedSiege/EyeWitness/issues/615

Not too jazzed about the current fix (Selenium downgrade):
https://github.com/RedSiege/EyeWitness/commit/539d074b8edb433f9d6160201d097a7e961f4393

fathom pendant
trail leaf
tender viper
trail leaf
#

Are you trying to SSH with the authorized_keys file?

fathom pendant
fathom pendant
#

I'm tired so didn't catch it at first

fathom pendant
trail leaf
#

The authorized_keys file is a store of the public SSH keys associated with a user

#

You need the private key

fathom pendant
#

Well I was trying to lead up to that point

#

But yeah, basically when have you ever used the authorized_keys to authenticate

misty current
#

either, he stored the private key in a file named authorized_keys or he's actually using real authorized_keys file. (I doubt anyone would name their private key that lol) and as marcie said, you're missing the username to authenticate.

tender viper
neon basalt
#

hi guys

zinc sentinel
#

Hello i am a few hours into the AD Enumeration & Attacks - Skills Assessment Part I , answered half the questions and was running smoothly but now constantly running into this errors when trying commands/uploads in the ps webshell, have reset the box waiting 5-10mins between resets.. sometimes i get a few commands in and this error again? anyone experience it?

proud pine
digital pewter
warm drift
#

Help in the Windows credentials section of the Password Attacks module question 3 says: What credentials does Bob use with WinSCP to connect to the file server? (Format: username:password, Case-Sensitive) ...... but each time I send the tool over to target with powershell and run it it just crashes...https://academy.hackthebox.com/module/147/section/1318

warm oak
#

Looking for advice / resources for help with the buffer overflow courses. I have been struggling with them for some time. Buffer Over flow is one of those things I am having a hard time grasping.

analog pewter
vital adder
#

use nvim

vital quiver
#

60 days in and i am have 4 modules to complete in Hackthebox Academy towards CPTS and then the prolabs... \o/

warm drift
proud pine
iron plaza
warm drift
warm drift
woven otter
#

hey, what's up? did someone completed the password attacks labs? I'm stuck on the middle one

cedar void
woven otter
median dawn
#

I am stuck with the SocksOverRDP question, and it seems to be a technical issue. The .dll has been loaded successfully, but after starting mstsc.exe, I do not get a prompt the the plugin is enabled and info about the listener. I have tried rebooting the machine etc with no effect. (Hence, if I go further and attempt to start the server, it does not find a listener and it all stops)... Any tips on what I can do?

warm drift
# woven otter check the hint

ran hydra with user Kira against the provided pass list and tried Kira user with love password and didn't work either I'm still stuck

woven otter
#

also, once you find that pw SAVE IT SOMEWHERE, you will use it in the future and it would be a pain to re-do all of that again (as I did)

warm drift
zinc sentinel
#

Hello anyone on to nudge me in the right path for AD Enumeration & Attacks - Skills Assessment Part II the very last question " "Submit the NTLM hash for the KRBTGT account for the target domain after achieving domain compromise. " i have the access to DC01 via ps session/ user C*** and have transfered most tools
i try with the mimikatz but it just spams the screen

trail leaf
#

PSRemoting is not an interactive shell, so you can't use interactive prompts

#

There's a way to specify all of your arguments on one line in mimikatz, that will work

zinc sentinel
#

sorry im burnt out here, ill be sure im understanding i have Enter-PSSession -ComputerName DC01.INLANEFREIGHT.LOCAL from the rdp session im in

trail leaf
#

Yep, that's not an interactive shell

#

You can run commands, but nothing that is interactive, like when something will prompt you to enter a password

sonic ferry
#

Been trying to get through "Windows Server" of "Windows Privilege Escalation" module. Sometimes my RDP connection doesn't work and the other times the Rundll (smb_delivery) exploit doesn't work. I managed to get the reverse shell once, but then the RDP connection broken down once again. This section is simple as it can be but the problem with the target box is making this the most difficult part of this module. I can't be the only one not managing to get through this?

zinc sentinel
trail leaf
#

There is a way to run Mimikatz commands without the interactive prompt (google search, shouldn't be that hard to find 😉 ). Alternatively, you can use that PSRemote session to spawn yourself a meterpreter shell or some other interactive reverse shell that will let you use Mimikatz the way you like.

digital pewter
fathom pendant
zinc sentinel
#

The secrets have revealed themselves to me XD

grand scarab
#

Hello! Right now I am in the Introduction to Network Traffic Analysis module, I am in the Start of packets area, dissecting network traffic with Wireshark, I have already activated the VPN and entered the host that is requested, but they tell me that I must I need to connect to the ENS224 interface from Wireshark, but no success. Can someone give me a hand?

gentle root
#

Following lesson - Exploiting Web Vulnerabilities in Thick-Client Applications
Clicking on the newly created file doesn't do anything. Anyone able to work throug this recently?

thick juniper
#

Hi guys, I’m wondering if there’s an issue with the SocksOverRDP module. I’m trying to log in as Jason as the module shows, with some fixes from the forums too I might add, and I’ve got no way to get in still sadly. I can’t even get in with Jason and says it’s being used so shuts me out of the RDP as it’s booting it. Anyone know of a work around or if somethings wrong?

zinc marsh
#

just follow step by step all

gentle root
#

FML lol

zinc marsh
#

u did something wrong

gentle root
#

It's step 1 I did nothing wrong

#

But atleast you must be right

#

I'll respond back in 2 weeks

zinc marsh
#

then why it doesn't work

#

the section would be easier if we hadn't to change the java code with the notepad lol

echo roost
#

I am used to using wfuzz and I want to use ffuf instead just because. I can't figure out how to get the results of the same code to show up on one line. I get this instead

zinc marsh
#

the size is 280 for all so just filter the size

#

-fs 280

echo roost
#

yeah but it does it with 200 as well

zinc marsh
#

I don't know just play with the filters

#

filter the ms, words, status whatever u need

echo roost
#

each 301 or 200 response is on a new line instead of showing 200 response then the results below and 301 response with result below

#

Like this -

#

how do I get the output to show up like the above screenshot? It looks so much cleaner

zinc marsh
#

I don't know I never cared about that

#

u can grep them to a file

#

and sort them as u want

echo roost
#

yeah true wfuzz or feroxbuster is winning over ffuf

zinc marsh
#

I use dirsearch

#

I just use ffuf for subdomains

echo roost
#

that one too is better

#

I figured I would try ffuf to see if I like it better than my current "go-to" tools .

#

thank you

#

wfuzz - way cleaner

wanton estuary
#

Anyone got a hint on password attack medium going from d***** user to root?

warped cloak
#

On Password Attacks -Medium lab: I ssh'd into j**** and got into the mysql using his password. Once in the mysql, nothing shows up or works. Am I doing this right?

wanton estuary
#

What do you mean nothing shows up?

#

Can you show databases;

warped cloak
#

nah

#

empty

wanton estuary
#

Show me the mysql command you are using g

warped cloak
#

mysql --password=jasonspass

#

show databases

wanton estuary
#

Try removing --password and just use -p

#

And then enter the password in the prompt

zinc marsh
warped cloak
#

still getting -> empty line after show databases

wanton estuary
#

Are you using correct syntax?

#

With a ; to end the line

warped cloak
#

...

#

bruh

wanton estuary
warped cloak
#

im embarrassed

#

no ;

wanton estuary
#

You won't make that mistake again haha

zinc marsh
#

the mysql should tell u to use ;

warped cloak
#

been on this for too long lol

zinc marsh
#

anyways

zinc marsh
wanton estuary
#

I'm stuck trying to proves to root

#

Privesc

#

I found a passphrase for the ssh key and thought it could be password reuse to get root but that's not right

#

Solved it

wooden dust
#

could some1 help with linux privEsc - logrotate? I found file, running logrotten, writing some data to log file, logrotten returns 'waiting 1 seconds before writing payload', but nothing shows up in /etc/bash_completion.d, and no shell is obtained

fathom pendant
#

Ssh is definitely the right direction

#

But why is it pw protected big_think_onion

drowsy swallow
raw lynx
#

hello anyone is there?

thorn urchin
#

nope

raw lynx
raw lynx
sonic ferry
#

Doing the Skills Assessment 1 of Windows Privilege Escalation and would like some help. I have reverse shell. I know what the system is and how to use ||JuicyPotato|| I also know what CLSID I should be using (||Using Tasklist I found out a task that is running that I can use||). But I'm still getting the same 10038 error when trying to run juicypotato. Just to be sure I tried out all the CLSID's from the list, but none of them worked. I also can't run the test.bat successfully since the output from web page is limited and the reverse shell doesn't give proper output for all commands.

fathom pendant
raw lynx
#

can explain me What information can be withheld from the ICO , What is an ICO Dawn Raid and What are the ICO's Power's in a Dawn Raid

thorn urchin
fathom pendant
#

This is unrelated to academy modules

drowsy swallow
#

I need a hand if possible,
Password Attacks Lab - Hard. Still trying to brute force the||johanna|| user, being 1hs:30min still going zzzZzzz. Trying ||rdp,smb and winrm|| with cme

thorn urchin
thorn urchin
drowsy swallow
thorn urchin
#

idr which list I used. but I usually start with the unmutated list first cause its faster

#

Discovered creds -> original list -> mutated list -> rockyou

that order for me

drowsy swallow
#

ok thanks

sonic ferry
wooden dust
keen summit
#

Hi all.
I believe the final challenge for "Injection Attacks" is bugged. At some point, it becomes pretty obvious what should be done next, but it just doesn't work. Can anyone confirm?
edit: pretty much right b4 i discover what the first vulnerability is. can't exploit it in any way described in the module. perhaps im doing something wrong - can anyone help?

noble moat
#

Module: Active Directory and Enumeration Q. Obtain credentials for a user who has GenericAll rights over the Domain Admins group. What's this user's account name?

I've been stuck on this question I found the username I am suppose to get but I don't know how to obtain their credentials and I'm a bit lost can I get some help please? When I try to use Get-DomainUser on MS01 I get an error "The specified domain either does not exist or could not be contacted"

sleek urchin
noble moat
#

@sleek urchin yes I was able to get those creds

sleek urchin
#

good, login on MS01 either via evil-winrm or rpd, then use Inveigh.exe or Inveigh.ps1, get the hash and crack it

maiden spindle
#

hey, I'm doing Attacking Common Services - Hard. Stuck on the last question I see people talking about a linked server... I don't know how to find it or what I would do.

noble moat
#

@sleek urchin Thanks for the help I got it 😄

sleek urchin
sleek urchin
sleek urchin
# maiden spindle hey, I'm doing Attacking Common Services - Hard. Stuck on the last question I se...
maiden spindle
#

ty

elder ibex
#

once you find the answer and paste the full URL into the answer dialog, then replace the actual port number (ex. 53121) with the word PORT.
http ://...academy.htb:54321/the_rest_of_the_url --> http://...academy.htb:PORT/the_rest_of_the_url

frozen mesa
#

test

#

why cant i post qestions, the bot keeps removing my messages.

thorn urchin
rich wraith
#

I recently saw there is a new C# module, will there be a C programming module someday? I would happy for that

frozen mesa
#

Done that...but ok. Didn't get me my answer since i dont flood the same messages. I'm only using same start since it is the same module (but the rest of the message is totally different).

#

so i cannot post any info about the module...

#

only these kind of reactions, otherwise it is marked as spam

thorn urchin
#

well considering your name is still white, you didnt read em very closely

rich wraith
frozen mesa
urban anvil
#

Has anyone solved Windows Privilege Escalation: Citrix Breakout? I am trying to use the command Import-Module .\PowerUp.ps1

#

But it gives error

acoustic owl
calm quarry
#

im stuck on the getting started module, the section is Public Exploits. The question is Try to identify the services running on the server above, and then try to search to find public exploits to exploit them. Once you do, try to get the content of the '/flag.txt' file. (note: the web server may take a few seconds to start). Ive done a nmap scan (nmap -T5 -pn -p- (ip) ) but im stuck there

acoustic owl
#

It is obviously about a web server.
You have found ports with your scan.
What happens when you call up the website with the browser?

urban anvil
thorny valve
acoustic owl
thorny valve
#

I SEE SAID THE BLIND MAN. Now impacket comes in to save the day again i see

thorn urchin
#

its certainly more handy though if you do imo

thorny valve
#

but it looks like the impacket-mssqclient is having an issue connecting

thorny valve
#

:0000

thorny valve
#

oh snap ok let me touch back up on searching for strings using sql queries

#

so i tried using SQLCMD Mode and the command to list the most recent entries as the hint suggest but no luck. Im on the right path tho ?

ashen umbra
#

I am in the live engagement on the shells and payloads module. I am in the foothold machine provided and there doesn't seem to be a browser on it? anyone else encounter this?

thorny valve
thorny valve
trail leaf
#

Parrot layout can be weird if you don't use it often

thorny valve
#

you can usualy run 'firefox' from terminal

trail leaf
#

that too

ashen umbra
#

oh dang I was using "firefox.exe"

#

that worked

thorny valve
#

Im really enjoying kali piurple over parrot but that might just be cause im used to the kali theme and layout lul

elder gate
#

hey guys im doing the netmon machine right now and port 80 doesnt show on nmap scan nor can i access the page through browser. anyone knows why?

muted jacinth
#

Hey guys, i'm currently doing the "using crackmapexec" module and i'm completely stuck after the second q of the skill assessment, i know it's oddly specific but if anyone have any hints i'll gladly take them

drowsy swallow
#

Hi!
Im still stucked on Password Attacks Lab - Hard
||I cant manage to bruteforce johanna's password. I grabbed the passwd list from resources and mutated with the cust rules. I tried bruteforcing rdp, winrm and smb. With hydra,crowbar and cme. Still nothing. I dont know what to do||

tulip parrot
lyric bolt
#

Hello its me again. I am still stuck on question 8 on Active Directory part 2 I have done everything I can think of and even in my troubleshooting was able to find the answer to question 9. But still unable to find a way to get the answer to question 8. ||I have tried to do the same things that got me the answer to question 1 from my elevated privileges on SQL01 but i only get the same user from question 1 when i use inveigh and no users with responder.exe any help would be appreciated.||

calm quarry
tight mesa
#

anyone who has finished Password attack module | PtT in Linux section?

gloomy bramble
#

Finally found the flag!! this module took me way longer than it should have, especially knowing the steps to it now. WOW!

fathom pendant
tight mesa
#

anyone who can give me a hint with the last question of Linux PtT

#

I guess I found the ccache file for Linux01 but can't find the flag

#

also I'm not sure if I'm using the ticket for the right user

quasi wave
#

hi can someone help me with the last section of Getting Started module? I am logged in as admin to the website but its not letting me upload files

#

is this not a file upload vuleratbility unlike nibbles which is the one I solved previously?

#

I am unsure because when I click on "upload files" it does nothing. Should I look for a way to upload a file or look for another vulnerability?

#

nevermind I think I figured out its not FTP

digital pewter
quasi wave
#

hi I found out its not FTP but can I DM someone to ask about the final section of getting started module? I get that its a PHP vulnerability. I just need a hint in the right direction.

calm quarry
quasi wave
#

I find that the vulnerability has to do with editing PHP in themes. Can someone help me in the right direction? What should I plug into google?

fathom pendant
red current
#

Has anyone else tried the new section Docker in Linux Privilege Escalation? There appears to be an issue with the way they explain to go about escalating your privileges. There doesn't appear to be a way to do it because the requisite permissions necessary to even run the commands aren't granted to the HTB-Student user.

calm quarry
fathom pendant
#

Refresh the target and try again

steady hawk
gloomy bramble
#

sorry, just saw this. At time of my issues, no, but at time of resolve, yes.

cunning prairie
thorn hawk
#

Morning to all. I have found the options 'Enable disabled form fields' . 'Remove input fields length limit' and 'Remove JS from validation' in Burp. But I dont understand why somebody will want to do that. Why disable JS validation for example?

gaunt surge
thorn hawk
#

Buit is it possible to remove input field length without burp? with a html code?

gaunt surge
#

Well if you inspect the page you should be able to.
ex;
<input type="text" name="username" maxlength="20">

can change to
<input type="text" name="username">
or
<input type="text" name="username" maxlength="100">

thorn hawk
#

Is this done through Developer mode in a webbrowser?

thorn hawk
#

OK cool thanks 😄

#

Just wanted to make my head around this. thank youuuuu

keen summit
pulsar needle
#

If ive done all the easy modules in the cpts path, should i be able to do an easy box (Active)?

acoustic owl
#

After all, nothing can happen.
Either you make it, or you don't.

pulsar needle
#

ok

#

lol

#

thanks

rough crescent
#

Hi all. I am currently stuck in the last section of Footprinting Module. I am unable to find the community string to be used along with snmpwalk. Can someone who has solved this, can provide a hint

pine dagger
rough crescent
pine dagger
rough crescent
#

Let me try that

gaunt surge
#

I just got the flag in Attacking Common Services - Easy.
The flag implies that there are multiple ways, anyone who could share the other option?

twilit gull
#

Hello cyber security experts, can anyone guide me through linux privilege escalation docker. I'm not good with dockers, I would love a good explanation.

spark lagoon
#

Just google "Linux pic esc hack tricks"

#

*priv esc

twilit gull
spark lagoon
#

Sorry docker

#

Not linux

slender coral
#

whereas it should just display post request to download.php

hidden grove
#

Hey guys, I am on the module "Command Injections" and section "Bypassing Other Blacklisted Characters" .
The assignment in this section is asking me to find the user in the /home folder. I have already solved this challenge but I am still confused as to why I am getting 2 different outputs by using slightly different payloads.
If I use this payload

  1. ip=127.0.0.1%0a${IFS}{ls,${PATH:0:5}} --- I get the genric folders like bin,usr,lib

but if I use below payload:-

  1. ip=127.0.0.1%0a${IFS}ls%09${PATH:0:1}home -- i get the username(which is the correct answer).

I have attached screenshots for both outputs as well.

tranquil axle
#

In example one you use the first 5 characters of the path variable as argument for ls, this could be /usr/ and then you’d see what’s in that folder. In example two you use the first char of path and add home afterwards. That’d be / followed by home

sonic ferry
#

Anyone I could message about Windows Privilege Escalation Skills Assessment - Part I. I've been banging my head against the wall for way too long. I understand how it's working and I feel like I'm doing the exact right thing but it's not working. -> So I'm doing something wrong

neon basalt
#

I was looking for good materials to learn tcpdump and Wireshark until someone recommended htb 😌. just concluded the intro to network traffic analysis module using tcpdump and Wireshark and it literally gives you everything you need to know about those tools

W module 🔥

hidden grove
weak stirrup
#

I am working on windows privilege escalation: pillaging I cannot not figure out the last question Restore the directory containing the files needed to obtain the password hashes for local users. Submit the Administrator hash as the answer. I have restored the SYSTEM and SAM files from restic and moved all the different copies i could find them to my attack box and then ran them through samdump2 but i have only got empty hashes aad3b435b51404eeaad3b435b51404ee what am I missing?

tranquil axle
obtuse verge
#

Hi!! Im doing the Windows PrivEsc module and i need to use SecretsDump but i have this error. Can someone help me?

last moss
#

ABUSING HTTP MISCONFIGURATIONS:
Use WCVS to identify an HTTP header vulnerable to web cache poisoning in the provided web application. WCVS didn't find any vulnerable header!! any help pls?i used the same wordlist with burp intruder but no luck!

obtuse verge
#

the problem is with secretsdump

undone narwhal
#

command looks good to me

obtuse verge
#

yes

undone narwhal
#

you sure youare using the right creds and ip

obtuse verge
#

yes

undone narwhal
#

maybe try reinstalling the impacket tool kit

high reef
#

hey so i'm doing this module

#

I'm stuck on this question

#

when i run this command i get nothing

#

any tips for this module, i know they have a password.list for this lab however i wanted to use the resources in kali to crack this lab

undone narwhal
#

i have not done this Module but what do you mean by resources in kali

high reef
#

at the buttom of the page, they have this to use

#

it conatins a PW.list

undone narwhal
#

oh, so you want to use your own passwordlist?

proud pine
#

You're free to use your own lists, but there's no guarantee you will get the answer.

high reef
#

yea somthing that comes installed with kali or parrot. Only because it will be more realworld feel you know

undone narwhal
#

like rat said, you can try if you want to, rockyou.txt is one wordlist that people use in ctfs there are also other wordlists in seclists

undone narwhal
digital pewter
obtuse verge
fathom pendant
# high reef yea somthing that comes installed with kali or parrot. Only because it will be m...

The reason they give you a pre-made list is to save time I'm sure the passwords and usernames can be found in SecList lists (there's a username section in SecLists) but the point is to seem like you're on a team, and your teammate already narrowed down a handful of things. But also, with pw attacks, you're meant to create a mutated wordlist fairly early on with the pws.list and custom.rules from that

#

Using resources isn't necessarily a crutch and a company could give you a pregenerated list of passwords they've seen used most commonly

high reef
high reef
weak stirrup
digital pewter
# obtuse verge

Looks like you used pip or pipx to perform a user install of impacket. Probably best to remove it and use the version built into kali. The binaries built into kali are all prefixed with impacket-, so you run them like impacket-secretsdump. This is also likely to save you from other headaches later since many other tools (like crackmapexec for instance) use impacket scripts to achieve their goals.

digital pewter
undone narwhal
keen summit
#

@pine dagger may i dm? its about the question i asked here earlier. i read in history you were doing this module i struggle with too

weak stirrup
undone narwhal
#

strange, It worked for me fine. can you share the screenhost of snapshots available

pine dagger
# keen summit here <@125384868887658497>

Shouldn't be bugged. There's a couple things you need to do. Once you've found the injection point, try some local file inclusion, maybe look for some useful configs, that will identify a secondary injection point.

keen summit
#

i read the php file this vulnerable request goes to and there is some config disclosed that looks useful.. and thats where i got stuck. like.. nothing i try to do with it works and nothing hints me as to what else should i LFI

weak stirrup
pine dagger
keen summit
#

oh thanks. will do

weak stirrup
#

@nar3ndra can you dm me i am having a bot issue with the channel

subtle flicker
#

Hey, i'm trying to enumerate users with kerbrute, and i'd like to save the results in a file with the right flag (-o/--output) but, it doesn't work. The tool creates the file but doesn't write into it. Anyone knows why?

high reef
#

i got the flag for all the other services along with password and etc, however the smb one is giving me trouble issue with connection

#

nvm it worked now weird

#

its timing out again just gotta be persistent i guess

broken warren
#

I might be in the wrong channel but i was jsut wondering for the challenges where they have a download available like Neonify for instance. Where you download like a whole bunch of stuff and a dockerbuild. Is that essentially just the stuff that makes up the challenge or is it actually part of it? Caue i just navigate to the instance itself in my browser and do it that way.

digital pewter
# broken warren I might be in the wrong channel but i was jsut wondering for the challenges wher...

The #challenges channel would be the proper place for your question. If I remember correctly, Neonify is a web challenge. When there is a Docker download, it is meant to simulate a white-box web application pentest since they are providing you the source code for the site. The idea is for you to analyze the source code and/or spin up the docker container locally to develop and test your exploit. Once you get the exploit working locally, then you can spin up the remote docker instance and perform the exploit for real (and land the real flag).

analog pewter
#

can anybody help me in this

#

i am not able guess the rule set i tried 8-9 set

sonic ferry
#

I'm failing to get the privileged reverse shell in Windows Privilege Escalation Skills Assessment 1. I managed to get the exploit working but my nc listener isn't catching the shell.

rustic sage
#

Try restarting the target machine

#

Make sure your vpn is on

sonic ferry
#

Tried that and also tried with my own VM and the one provided on the web site. I can't seem to think there is something wrong with the way I'm using netcat, but there isn't a lot to do wrong there.

upper seal
#

What hashing protocol is capable of symmetric and asymmetric cryptography?

high reef
#

i'm back and having issues with a question.

Create a mutated wordlist using the files in the ZIP file under "Resources" in the top right corner of this section. Use this wordlist to brute force the password for the user "sam". Once successful, log in with SSH and submit the contents of the flag.txt file as your answer.

the module says to use this syntax...
hashcat --force password.list -r custom.rule --stdout | sort -u > mut_password.list

when i do so and i cat the mut_password.list its empty. LOL i'm so confused

#

i'm in module password attacks section password mutation

thorn urchin
#

a hash is not intended to ve reversible

high reef
#

literaaly all i did was copy and paste and i get nada

thorn urchin
#

theres no such thing a symmetric or asymmetric hashing protocol

upper seal
thorn urchin
#

what module/section

quasi wave
#

hi I'm trying to get a reverse shell on this last section of the getting started module and it isn't working. I found the page where PHP code on a page can be edited and I'm trying to use netcat to get a reverse shell and it just isn't working

upper seal
quasi wave
#

can someone help me with this box please?

digital pewter
thorn urchin
#

havnt done that module so idk

quasi wave
#

hello this is like the fifth time I've asked for help on this and no one wants to help me. why is everyone ignoring me?

#

I feel ignored

rustic sage
#

@quasi wave can you provide more info? Link

thorn urchin
#

and cause were all volunteers

#

aint nobody owes you their time

high reef
#

@quasi wave you gotta be as detailed as possible

#

section/module... screen shots... etc you haven't nothing to work with here

quasi wave
#

I'm trying to get contents of user.txt to find the flag here are some screenshots

#

I managed to log in and crack the password for the website but the point of the challenge is not to log in as admin to website that's just first step

quasi wave
high reef
#

is this nibble ?

quasi wave
#

no

#

the previous challenge was nibble

#

I thought it was gonna be an FTP vulnerability like nibble

#

but that did not turn out to be the case

high reef
#

does your php payload has the correct ip address?

quasi wave
#

yes I made sure of that

rustic sage
#

There might be a problem with that box(?) i just did the same and had to reset the box x3

#

literally 5 mins ago

#

before nc picked it up

steady hawk
quasi wave
#

let me see something

#

it worked

#

thanks @steady hawk

thorn urchin
#

see a lot easier to get help if you provide information on the problem instead of just stating you have a problem 🙂

high reef
#

i'm having an odd issue tho, lol why me umm no idea how to go about fixing this !

thorn urchin
digital pewter
# high reef i'm still getting blank mut file.

Strange. Try running head on the password.list file to see if it has content. Also do what madf0x mentioned.

head password.list
head custom.rule
hashcat --stdout -r custom.rule password.list
thorn urchin
#

and is your custom.rule and password.list files good

keen summit
thorn urchin
#

if there was an error unzipping and one or both of them were empty itd def cause problems

high reef
sonic ferry
#

First Skills Assessment that I just can't finish. I thought that AD would be the one to break me but I've spent over 6 hours on the Windows priv esc one...

thorn urchin
#

imo windows priv esc module was harder than AD

sonic ferry
thorn urchin
#

specifically referring to their assessments yeah

wide river
high reef
barren apex
#

anyone able to help on attacking common services: sql, I have the password for mssql but when using the -windows-auth or .// to login it fails

sonic ferry
high reef
#

when i drop the pipping i get illegal instruction

thorn urchin
#

there ya go

#

youre using the wrong hashcat

#

that bin was built for a different platform

high reef
#

should i try it on my kali machine then ?

thorn urchin
#

force wont work

#

its illegal instruction

#

people need to learn their architecture basics 😦

thorn urchin
high reef
#

ok

high reef
thorn urchin
#

ive seen it before as well

digital pewter
thorn urchin
#

illegal instruction means the actual assembly op code from the binary wasnt compatible with the CPU

#

which means the architecture the binary was compiled for was for a different one than youre running. (or just a corrupted bad compile or other niche reasons that dont apply here)

#

the error means the same thing no matter what tool youre using though. That error is coming from your system, not from hashcat

high reef
#

thanks for the info

#

the command worked on my kali machine

thorn urchin
#

👍

high reef
#

the mut_password.list has 94, 404 possible passwords i'm gonna be here for a while

quasi wave
#

hi I got the user flag on this box and now I need to get the root flag. I got to the point where I can LinEnum.sh on the machine and found potential was in but I'm not sure if that will help. I already got the user.txt file flag.

#

I'm pretty sure the right result is somewhere in LinEnum.sh output but problem is I can't figure out where in output to look.

#

and no this is not nibbles

#

this is a different box

#

and I already submitted user.txt flag

thorny valve
#

any help to initially starting it? Checked out everything in the section covering the 2 services we find but im SoL lol

hushed bough
#

Password Attacks Lab - Medium -> Any int? i cant bruteforce with hydra just taking to much long with the username.list and password.list almost 2 hours and nothing

#

hint*

thorny valve
#

I split it into 7 myself and let it rip like that

hushed bough
#

all right will try it thx mate

thorny valve
#

yeee yeee best of luck

high reef
quasi wave
thorny valve
quasi wave
#

Ok I will try Linnea’s first before resorting to ippsec’s video

#

Or actually what do you recommend I do?

#

Should I look at ippsec’s video or should I try different script?

ashen umbra
#

I used the antak shell to gain access to a webapp in one of the shell modules. Why can i not change directories? am i using the wrong command?

trail leaf
quasi wave
trail leaf
#

Don’t be 100% reliant on automated enumeration scripts, do some basic checks

ashen umbra
#

nevermind, it is the dir command

simple falcon
#

can someone help? whenever i do the ssh command "ssh user@ip" it doesnt work and i have to hit ctrl+z to stop it

trail leaf
thorny valve
#

sooooo can anyone help out starting with the footprint hard lab loool im stuck

quasi wave
simple falcon
#

can someone help? whenever i do the ssh command "ssh user@ip" it doesnt work and i have to hit ctrl+z to stop it

thorny valve
eternal mason
#

Hello

thorny valve
#

maybe just a bad ssh command ?

trail leaf