#modules

1 messages ยท Page 113 of 1

simple falcon
#

here

thorny valve
#

i do believe you can get away with just manual enumertion tbh the auto scripts sometimes output too much info

#

whats everyone using as their default brute force password list 'rockyou' ?

eternal mason
#

I am in the Working with Rules excercise i got the SHA1 password, test it and the excerceise do not accpet as valid

thorny valve
#

fair fair loool

simple falcon
#

i cant send a picture

#

how

#

thanks

tall saffron
#

im sure it is on linenum output but i didnt use it, the first things to try is sudo -l

#

it is on getting started, the last root?

#

from what you find with sudo -l you can have a rev shell as root

simple falcon
#

ok

tall saffron
quasi wave
#

ok

tall saffron
#

easy root shell, think about it ๐Ÿ˜‰

#

cant you have a rev shell with php binary?

simple falcon
#

so what am i supposed to do? thers no password prompt or anything?

tall saffron
#

just apply sudo to the equation and you are root

tall saffron
simple falcon
#

i know

#

im asking my own question

#

lol

tall saffron
#

what is the module

#

sorry i didnt followed xD

simple falcon
#

Linux fundamentals

tall saffron
#

didnt made this module but are you sure it is on port 22 you are supposed to connect?

simple falcon
#

when i type the ssh command it just makes my terminal blank

pale oriole
#

Working on the Password Attack Lab - Medium, and not sure if I am on the right track but I cracked the password on a word doc, but I don't know how to open the word doc itself from the parrot box. All of the things I have googled have proved to not work...

tall saffron
#

i must takes notes of the solutions i used xD

simple falcon
#

idk what im doing wrong

#

could it be becasue im using a vm?

tall saffron
#

do a ping to verify and sometimes ping isnt allowed so use nmap with -Pn option on port 22 and see if it is open, just to eliminate network connectivity problem

simple falcon
#

i pinged it seems up

quasi wave
simple falcon
#

im sorry, im really new to this

quasi wave
#

thanks ok

tall saffron
#

in the shell you already have ๐Ÿ˜‰

quasi wave
uncut flint
#

*in terminal

tall saffron
zinc marsh
#

is there any way to grep the time response

#

in burpsuite?

simple falcon
#

mind joining vc so i can screenshare?

tall saffron
simple falcon
#

fk

fiery berry
undone narwhal
simple falcon
#

im in here

#

idk my pushtotalk buttoon one sec

zinc marsh
tall saffron
simple falcon
#

yes

zinc marsh
#

am practicing sql blind injections manually

simple falcon
#

why no permissions? to stream

zinc marsh
#

and with the time delay injection I cannot find a way to fuzz the password

#

yes

simple falcon
#

but why cant i? too new?

zinc marsh
#

this is my payload but I cannot find a way to add the response time to the intruder

simple falcon
#

does that when i press up arrow

uncut flint
zinc marsh
#

what happen

#

yea

simple falcon
#

ctrl C just kicks me out of it

#

doesnt solve my problem lol

pale oriole
uncut flint
#

Now restart ssh

simple falcon
#

how

tall saffron
pale oriole
uncut flint
#

Same cmd from your pic

pale oriole
thorny valve
#

wait is there another way to do it?

simple falcon
#

i feel like such an idiot

thorny valve
#

I know i was saying is there any other way to do a blind sql injection WITHOUT covering your eyes ๐Ÿคฃ

#

I know i enjoyed it and was feeding into it lolol

tall saffron
#

he understood it the first time...

tall saffron
simple falcon
#

its not

pale oriole
simple falcon
#

i have 90 min

tall saffron
#

reset it ๐Ÿ˜‰

simple falcon
#

i have

#

multiple times

#

im so confused

thorny valve
tall saffron
#

make a nmap -Pn theIP -p 22

#

and send result

simple falcon
#

host is up

tall saffron
#

are you sure you are supposed to connect via ssh?

thorny valve
#

netcat 4 lyfe ?

pale oriole
uncut flint
tall saffron
#

because that's weird xD

tall saffron
simple falcon
#

Linux Fundamentals>The Shell>System Information

tall saffron
#

i dont have access to this module

simple falcon
#

its 10 cubes

#

you get 10 cubes for doing it to

tall saffron
#

ok good night lol

simple falcon
thorny valve
simple falcon
#

huh?

tall saffron
#

he cant connect via ssh

simple falcon
#

yeah

tall saffron
#

i really dont know what to say more, if you are connected to the VPN, or trying with your pwnbox instance and cant connect to ssh WTF

#

sorry i tried ๐Ÿ˜ข

simple falcon
#

am i doing it wrong?

tall saffron
#

nope

simple falcon
#

is it cuz im using a vm?

tall saffron
#

nope

simple falcon
#

ugh

tall saffron
#

you are connected to the VPN, your VM can ping the target, all is good, idk what's the problem

#

or im too tired it is very late here but that must work normally xD

simple falcon
#

ok then

#

thanks anyways

uncut flint
simple falcon
#

no

#

.....

#

what cmd is that?

uncut flint
#

Sudo apt upgrade && update

simple falcon
#

still nothing

tall saffron
# simple falcon thanks anyways

lmk if it works in the last few days, im really crurious to know what was the problem, but i think it is a a problem on their side

simple falcon
#

ok

#

maybe im downloading the vpn wrong?

tall saffron
#

can you do the nmap -p 22?

simple falcon
#

it looks like this is my downloads

tall saffron
simple falcon
#

says 0 ips found

tall saffron
#

nmap -p 22 IpofTARGET

#

nmap -p 22 10.129.183.39

simple falcon
#

1 ip found

tall saffron
tall saffron
#

at least the problem isnt on the VPN side

simple falcon
rustic sage
#

Hi, has anyone finished the Attacking Enterprise Networks module? I am stuck with cracking a hash - I am clearly missing somithing obvious. Cloud someone assist me?

tall saffron
simple falcon
#

oh

tall saffron
#

try same command but with -Pn

#

nmap -p 22 10.129.183.39 -Pn

simple falcon
#

ssh still doesnt work

ashen umbra
#

alright. I am stumped. I have ran the psexec version of eternalblue several times. RHOSTS is 172.16.1.13 LHOST is 10.129.204.126.

I remember I have had this issue before, but I am not sure from what. will send the show options

tall saffron
#

yep the port isnt open for whatever reason

#

you forgot the -p before 22 xD

#

nmap -p 22 10.129.183.39 -Pn --reason

#

but host is running but port 22 is closed wtf

ashen umbra
#

and here are my options on the eternal blue

simple falcon
#

brb gotta p

tall saffron
#

the port must be open for this exercise

#

try using their pwnbox

simple falcon
#

i only get 1 per day

#

i cant use it

#

and im not paying for shit when i have a perfectly fine VM with the same OS lol

#

whelp imma get on MW2 ill catch ya later thanks for trying ๐Ÿ™‚

uncut flint
#

You update your vm

tall saffron
#

yeah try when you can have one or tomorrow ๐Ÿ˜‰

#

hf on mw2 ๐Ÿ™‚

ashen umbra
uncut flint
simple falcon
#

did that too lmao

tall saffron
#

you already used your VM to make some exercises? because it seems there is no connections between you and the target

#

nmap say Host is up because we asked no ping

#

and with the ping it doesnt seems up

#

that's why you must try, when you will have access, with pwnbox

thorny valve
thorny valve
#

Hey yall quick question for the assessments on the Vuln Asses section it says the following
'Alternatively, use the pre-populated scan data to answer the questions below without having to wait for the scan to finish but feel free to practice configuring and running it.'

But where idk where the scan data is
any help ?

high reef
#

hey everyone, so i took a break and wen to the gym. and i'm still stuck on this section.

#

password attacks/password mutation

#

i used crackmapexe default PW zip file and got john:123456 smb

#

but he has no access to anything i get access denied

#

any hints on how to move forward ?

#

all oterh service ssh, ldap, ftp, winrm i get no hits

thorny valve
#

what module and section? I did this one a little while ago and I cant recall tbh

high reef
thorny valve
#

was this the one with a custom.rule you had to apply to make the mutated list ?

thorny valve
#

this one sucks loool

high reef
#

lol thanks for the heads up

thorny valve
#

yea I just applied the mutated password split it into a bunch and started hammering away

#

id try different services

#

maybe youll get lucky with one

high reef
#

i'm trying smb right now i got a hit with the mut list just waiting for a password

high reef
#

lol can i atleast get a small hint

#

i used msfconsole

#

and none of these passwords wok

fathom pendant
#

And for some protocols and tools you'll need to add --local-auth

#

I didn't use msfconsole

thorny valve
#

it should be attack brute force a service with username 'sam' and the mutated list created from the resources

fathom pendant
#

^

#

cme and hydra are your friends

thorny valve
#

Also i agree with marcielee try staying away from msf as a whole it sucks

#

cme ?

fathom pendant
#

Crackmapexec

thorny valve
#

Ahhh so much easier lol

fathom pendant
#

cme is just an alias

thorny valve
#

ima add that to my rc

fathom pendant
#

I just remember using crackmap and hydra

#

Because cme has some more useful tooling with it

high reef
fathom pendant
high reef
#

oh i'm usinf cme

fathom pendant
#

It's either single -local-auth or double dash local-auth

#

Sometimes *

high reef
#

i'm getting somewhere

#

lol nope not all actually

fathom pendant
#

I dont recall if I attacked smb

#

But also

#

Why are you doing a whole list

#

you're given the username

high reef
#

saw some stuff on the forum saying don't attack ssh you'll find that later after i enumerate another service. i was thinking same went with ssh and i didn't need that name yet

fathom pendant
#

pika_sip you've tried ftp yes?

#

I'm not at home to check my notes

high reef
#

yea i keep getting an error when i try ftp

fathom pendant
#

Is your syntax correct? Iirc hydra uses capital/lowercase for single user and list

#

I don't recall if cme supports ftp

high reef
#

i dont believe cme does

#

and when i use hydra it says sam user not found

trail leaf
#

The -L flag is for a file, you want to use -l for a single username

#

The error tells you exactly what's wrong

high reef
#

ooooooooooooooooooooooooo, thanks

livid swan
#

@trail leaf ur a cybersecurity or criminal ?

thorny valve
livid swan
#

yea

thorny valve
#

๐Ÿคฃ

livid swan
#

bro ur just a noob shut up

thorny valve
#

weeeeeeeee

#

my entire life is noob role

trail leaf
#

I am the cybersecurity, thank you for asking

livid swan
echo glen
#

Hi guys, during settup we install a linux GUI on windows 10 app store, did anyone get it working having your VM installed on Vmware?

thorn urchin
cursive oriole
#

Hello everyone, I'm currently studying Linux system hardening. Could you kindly provide me with up-to-date resources on this topic? I've encountered sysctl hardening and similar subjects, but the resources I've found are mostly outdated (kernel v2). Any material related to Linux system hardening would be greatly appreciated. Thank you in advance for any guidance.

thorn urchin
cursive oriole
simple falcon
#

hello, im struggling on the path to the home directory. could someone help?

red current
#

I'm back at it again now. I'll take a look at the permissions and see if I can figure it out. I'll let you know if I have any questions. Thank you!

#

Okay, I'll take a look at that if I run into any issues.

cunning prairie
steady hawk
fathom pendant
simple falcon
#

pwd isnt the answer

#

ooooooooooh

#

thanks

tight mesa
#

anyone willing to give me a hand with Password Attack Module | PtT in Linux..!!!

echo glen
#

Does anyone know why Set-VMProcessor is not being recognized as the name of a cmdlet in Windows Powershell?

tight mesa
#

I'd like to understand if I'm on track with what I'm doing to grab the flag of LINUX01$ at //dc01/linux01

hardy anchor
#

I can't too

raw venture
#

Hello, if you don't mind. May I know how did you do this? Already got the flag but via msfconsole. I tried the printspoofer and it didn't work.

red current
#

Unable to find image 'main_app:latest' locally is the error I get when I try to use the main_app docker image. I have progressed further than before, but I'm not sure why I'm getting this error.

#

This is the modified command that I'm running because there is no 'app' directory. Docker.sock is in the run directory.

#

/tmp/docker -H unix:///run/docker.sock run --rm -d --privileged -v /:/hostsystem main_app

hardy anchor
#

I'm having the same problem. Did you solve it? I'm really stuck in the DCSync module. secretsdump.exe is not working

Edit: Ok secretsdump.exe is working now (the problem was that the output is empty when I use the flag -just-dc) but I didn't get the password for the user ||syncron||.

thorn urchin
#

<@&861185840277487616>

fathom pendant
burnt stone
rustic sage
#

@everyone NAZI

surreal rain
#

@rustic sage We have logs btw

rustic sage
thorn urchin
#

he banned me from his server for external drama lmao

high reef
#

sadly giving up on this password attack module for now, need to rest my eyes

fathom pendant
#

Look at realm info

tight mesa
#

LoL

tight mesa
tight mesa
#

@fathom pendant with linikatz.sh could find what I guess is the LINUX01$ kerberos ticket but, I don't know how to use it....

fathom pendant
tight mesa
simple falcon
#

having trouble with these 2 questions

#

its the linux fundamentals module

tender viper
#

I'm stuck on the Footprinting Lab - Medium and need some help. I was able to find the creds of the user after mounting the NFS but I'm not sure on where to go next

fathom pendant
tight mesa
#

sorry man, I'm not following to you.....

fathom pendant
tight mesa
#

unfortunately I don't understand what you mean

tight mesa
tender viper
#

@fathom pendant any advice on what to next for the Footprinting Lab - Medium after getting mounting the NFS and finding the creds in the txt file?

fathom pendant
fathom pendant
#

@pseudo hill Re: bad IMAP commands
are you including the prefix?

tight mesa
#

hey @fathom pendant I'm back

#

do you prefer a DM?

fathom pendant
tight mesa
#

to not spoiler

fathom pendant
#

I've said similar things in the past and most people have been able to get it from that

tight mesa
#

realm list ?

fathom pendant
#

Whatever the command is they tell you about

tight mesa
#

ok., 1 more thing, in which user david?

#

svc_workstations?

#

||david@inlanefreight.htb@linux01:~$ realm list inlanefreight.htb type: kerberos realm-name: INLANEFREIGHT.HTB domain-name: inlanefreight.htb configured: kerberos-member server-software: active-directory client-software: sssd required-package: sssd-tools required-package: sssd required-package: libnss-sss required-package: libpam-sss required-package: adcli required-package: samba-common-bin login-formats: %U@inlanefreight.htb login-policy: allow-permitted-logins permitted-logins: david@inlanefreight.htb, julio@inlanefreight.htb permitted-groups: Linux Admins||

fathom pendant
#

Try just realm

#

Or realms

tight mesa
#

ok.

fathom pendant
#

Ohhh

#

Sorry

#

My brain lapsed

#

It's not c*d it's s*d

#

Also no new line spacing is gross

#

It took way too long to parse that

tight mesa
#

realm there isn't exist

#

realms need a param as list

fathom pendant
#

Like I said

#

I had to reparse the info

#

Because 1) you didn't code block it
2) info dump block

#

client-software

tight mesa
#

man, no worries I really don't understand your hints I will be making a research

fathom pendant
#

I'm telling you

tight mesa
#

because more than solve the question is understand what I'm doing and I'm not understanding what I'm doing

fathom pendant
#

Look for a directory regarding the name of the client software, just drop the d from the end

tight mesa
#

what directory?

fathom pendant
#

Iejejdhfirnd

#

IM GIVING YOU THE HINT

tight mesa
#

sssd

fathom pendant
#

Now go

#

Root around and find things

tight mesa
#

ok., I guess I found the user you told me earlier

#

and guess he has domain privileges

#

but still haven't the linux01 kerberos ticket..!!!

fathom pendant
#

pika_sip remember you can use ccache files

#

Also the daemon isn't a user

tight mesa
#

what do you mean with daemon?

fathom pendant
#

It's what the d stands for

#

A daemon is a user-agent much like how www-data is usually a web user agent

#

simplified

#

It's what helps things run in the background

tight mesa
#

||I ran ls -la /usr/libexec/sssd/ but can't understand the content of the directory||

fathom pendant
#

Just... look around

tight mesa
#

where can I read info regarding the content of this directory

fathom pendant
#

I'm telling you. How I figured it out, was simply by looking around

#

you should be able to cd to that directory

tight mesa
#

hahaha is not easy to look around when you don't know what exactly you have to look

fathom pendant
#

pika_sip like I said I found out the fafo method

#

I just kinda dug around until I found it

#

Like at any point after this it'd be hand holding

tight mesa
#

ok., can you share any documentation before continue?

fathom pendant
#

What module is this again

tight mesa
#

I said before I don't wanna find the flag, I need to understand what I'm doing

tight mesa
#

and the information in this section is not very clear or explanatory about your hints

fathom pendant
#

Also

#

It's not in a sssd location

#

I said explicitly drop the d from the end

#

The linikatz example output also shows something

tight mesa
#

ok., with that I could find if the machine is not part of a domain

#

ok., now we're talking something different

fathom pendant
#

It's honestly something that was right there, you just didn't know what it was

tight mesa
#

with linikatz I could find the path of linux01 ticket

fathom pendant
#

like I said you can just use the ccache ยฏ_(ใƒ„)_/ยฏ

#

Also it should have stored the extracted cache stuff in a folder for you

#

You just didn't know what it was

#

ยฏ_(ใƒ„)_/ยฏ

tight mesa
#

wait a minute

#

||is Ticket cache: FILE:/tmp/krb5cc_647401106_HRJDux the tgt for LINUX01$@INLANEFREIGHT.HTB||

fathom pendant
#

Maybe maybe not

#

I'm specifically ignoring tgt

#

And stuff

#

I'm telling you

#

The answer is in the example

tight mesa
#

to this question : Use the LINUX01$ Kerberos ticket to read the flag found in \DC01\linux01. Submit the contents as your response (the flag starts with Us1nG_).

fathom pendant
#

Yes. That's the question

#

I'm telling you

#

Look at the example output of linikatz, your output

#

And apply critical thinking

tight mesa
#

ok. but, you know when I impersonate linux01 with ccache ticket and try to connect to //dc01/linux01 I got an error....

#

BUT

#

can connect to //dc01/C$ but cannot ran any command more than dir

fathom pendant
#

Are you using the right one. Ccache files can expire ๐Ÿ˜‰

tight mesa
#

yep

root@linux01:/opt/linikatz.5394# klist
Ticket cache: FILE:_tmp_krb5cc_647401106_PDEOyy.13549
Default principal: j xyz@INLANEFREIGHT.HTB

Valid starting Expires Service principal
08/04/23 04:55:02 08/04/23 14:55:02 krbtgt/INLANEFREIGHT.HTB@INLANEFREIGHT.HTB
renew until 08/05/23 04:55:02

#

this is the error that I talked

root@linux01:/opt/linikatz.5394# smbclient //dc01/linux01 -k -c ls -no-pass
NT_STATUS_ACCESS_DENIED listing *

fathom pendant
#

That looks like a krbt not Ccache

tight mesa
#

hmm I'm doing the same what explained in this part of the section

Importing the ccache File into our Current Session

#

root@linux01:~# klist

klist: No credentials cache found (filename: /tmp/krb5cc_0)
root@linux01:~# cp /tmp/krb5cc_647401106_I8I133 .
root@linux01:~# export KRB5CCNAME=/root/krb5cc_647401106_I8I133
root@linux01:~# klist

fathom pendant
#

Hint: it's not in tmp

#

Just take a step back

#

Evaluate the information you're being given

#

Here's where I'm telling you to apply critical thinking. Maybe change the file you're copying and using as your krb5ccname

tight mesa
#

I'm using it as krb5ccname

#

do you know the terminal command in wirndows to find file?

#

not sure if what am going to say is an atrocity, I guess linux01 as user there isn't exist

root@linux01:/opt/linikatz.5394# smbclient //dc01/C$ -k -no-pass
Try "help" to get a list of possible commands.
smb: > dir
$Recycle.Bin DHS 0 Wed Oct 6 17:31:14 2021
Config.Msi DHS 0 Wed Oct 6 14:26:27 2021
Documents and Settings DHSrn 0 Wed Oct 6 20:38:04 2021
john D 0 Mon Jul 18 13:19:50 2022
julio D 0 Mon Jul 18 13:54:02 2022
pagefile.sys AHS 738197504 Fri Aug 4 04:13:43 2023
PerfLogs D 0 Fri Feb 25 16:20:48 2022
Program Files DR 0 Wed Oct 6 20:50:50 2021
Program Files (x86) D 0 Mon Jul 18 16:00:35 2022
ProgramData DHn 0 Fri Aug 19 12:18:42 2022
SharedFolder D 0 Thu Oct 6 14:46:20 2022
System Volume Information DHS 0 Wed Jul 13 19:01:52 2022
tools D 0 Thu Sep 22 18:19:04 2022
Users DR 0 Thu Oct 6 11:46:05 2022
Windows D 0 Mon Oct 10 10:48:55 2022

    7706623 blocks of size 4096. 4459270 blocks available
#

smb: > cd users
smb: \users> dir
. DR 0 Thu Oct 6 11:46:05 2022
.. DR 0 Thu Oct 6 11:46:05 2022
Administrator D 0 Wed Jul 13 18:53:11 2022
All Users DHSrn 0 Sat Sep 15 07:28:48 2018
david D 0 Thu Oct 6 11:46:05 2022
Default DHR 0 Wed Oct 6 20:38:04 2021
Default User DHSrn 0 Sat Sep 15 07:28:48 2018
desktop.ini AHS 174 Sat Sep 15 07:16:48 2018
john D 0 Thu Jul 14 16:12:03 2022
julio D 0 Thu Sep 29 18:37:29 2022
Public DR 0 Wed Oct 6 20:46:09 2021
svc_workstations D 0 Thu Jul 14 12:26:47 2022

    7706623 blocks of size 4096. 4459270 blocks available
fathom pendant
tight mesa
#

I'm trying to find the flag file with this command
smb: > dir "flag*" /s
NT_STATUS_NO_SUCH_FILE listing \flag*

fathom pendant
#

That's useless

tight mesa
#

ok., tomorrow is another day....

fathom pendant
#

Just slow it down

#

Sleep it off

tight mesa
#

I'm completely stuck with this question

#

I'm gonna read the whole section tomorrow to see if I'm jumping some

#

thank you for your help btw

last moss
#

https://academy.hackthebox.com/module/189/section/2011
Use WCVS to identify an HTTP header vulnerable to web cache poisoning in the provided web application.

should i here provide the header name as Answer or use the header to poison the cache and get the content of the admin page!?? Could you please make such questions more clearer!! @tough fjord

rustic sage
#

Hello everyone im in the module ATTACKING COMMON APPLICATIONS in section Attacking Thick Client Applications i have to get the falg but is so hard, please can anybody help me?

digital pewter
#

Anyone else having trouble accessing Splunk in the Attacking Common Applications module? PRTG comes up just fine, but Splunk doesn't.

rustic sage
#

if you up a machine you will wait 2-3 mins to everything go up

digital pewter
rustic sage
#

i do this module on monday and no problems

#

share a screenshot

digital pewter
fiery berry
rustic sage
#

https

slate gate
#

https

rustic sage
#

x3 jajajajaja

slate gate
#

kkkkkkkk

fresh compass
#

Hi! Any help in the password attacks module, pass the ticket from linux module?

#

Iโ€™m stuck finding the credentials for the user svc_workstations

digital pewter
fresh compass
fiery berry
analog pewter
#

anybody had done cracking passwords with hashcat

fresh compass
#

It didnt work for ssh, but it did work for WinRM but it seems like a dead end

fiery berry
fresh compass
#

Nope

#

I donโ€™t know where to find

fiery berry
#

the question in saying "Check Carlos' crontab" go from there

fresh compass
#

I did

#

I generate the ticket in tmp file using the kinit command

fiery berry
#

have you check the content of "kerberos_script_test.sh"?

fresh compass
#

Yes

fiery berry
#

and...

fresh compass
#

I launch the script and it get stuck

fiery berry
#

did you went to see in that "folder" what there may be

fresh compass
#

I create a ticket (in tmp folder) and use to access with smb and get stuck

#

Yes, I have the ticket

#

But if I simply open it its encoded

fiery berry
#

if you have the keytab use keytabextract.py

fresh compass
#

It works on the ticket?

#

I was using this app just for .keytab files

#

Iโ€™ll try

#

Nothingโ€ฆ can I talk to you by pm?

fiery berry
tall saffron
#

@simple falcon so what was your problem yesterday since it seems to work today?

rustic sage
#

Hello everyone, im in module ATTACKING COMMON APPLICATIONS im trying to get the flag of Exploiting Web Vulnerabilities in Thick-Client Applications but i cant please could somebody help please?

rustic sage
#

What are you stuck at exactly?

#

Is the App not working after taking it apart?

quick magnet
#

hi im stuck in footprinting lab medium, aleady get cred ||alex|| and ||sa||, but still can't login SQL Server Management Studio.
is there any other user ?

high reef
keen dune
#

Hackthebox academy vpn not working

high reef
#

reset vpn download a new vpn connection

real stratus
#

Is there any way to use VPN for Frre in Kali Linux

keen dune
#

Tried everything, and did some editing of my own as well, still not working

quick magnet
acoustic owl
tepid hemlock
#

Hey, I am doing Getting Started module where I need to find a public exploit. Using msfconsole I am able to find & run the exploit to get the flag but how would I go about doing this on my own following the instructions for "2. File Download" from the found exploit?

Example 1 : Download tools.php source file :
http://127.0.0.1/<WP-path>/wp-admin/tools.php?page=backup_manager&download_backup_file=

Example 2 : Download a backup file :
http://127.0.0.1/<WP-path>/wp-admin/tools.php?page=backup_manager&download_backup_file=backup-2016-02-21-111047.tar

But I am not sure how I would go about constructing the URl to be about flag.txt

My attempt was

http://TARGET-IP:TARGET-PORT/flag.txt?page=backup_manager&download_backup_file=

quick magnet
gaunt surge
#

Just finished Attacking Common Services. This was a great one

round gale
#

in the intro to SQL injection fundamentals, module SQL Operators, for the question "In the 'titles' table, what is the number of records WHERE the employee number is greater than 10000 OR their title does NOT contain 'engineer'? " . i am not able to find the titles table, i can usee only employess table when i use the SHOW DATABASES; command in mysql

drowsy swallow
#

Hi! Quick question if anyone knows.
Im in lateral movement module. Section rpivot.
I managed to establish the connection to the victim IP
The section is telling me to do ||proxychains firefox-esr 172.16.5.135:80|| which opens FF but doesnt display the webpage which is wierd cause
if i do ||proxychains nmap 172.16.5.135|| it works fine and says port 80 is opem, also did ||proxychains curl 172.16.5.135|| and works, it returns me the webpage but not with firefox. Any ideas? I just checked in case, buprsuite is close and foxyproxy is disabled

sly grotto
#

hey
can i send DM about Credential Hunting in Linux to someone?!

turbid tartan
#

i have insane problems at the logrogate section in linux privesc

i really dont know what to do. I know that it has somethng to do with the ||backups/access.log.1|| but i cant figure it out. And how its described in the section really doenst help me

simple falcon
#

so im trying to use the $tree command to see the last modified file, how can i tell which was the last to be modified?

vital adder
tepid hemlock
turbid tartan
#

yeah i stuck forever on that

vital adder
#

wrong channels bro

turbid tartan
#

i dont know if thats inteded

vital adder
#

oh wait you mean the logrotate section in the linux privesc module??

turbid tartan
#

im stuck on that forever. thats the last module in the pentest path that i need

vital adder
#

feel free to shoot me a dm if you guys need help with that

round gale
vital adder
round gale
robust anchor
#

Hey guys, I'm stuck in the Footprinting-Hard lab. Here's what I have done so far:

  • Enumerated the running services and found IMAP & IMAPS, POP3 & POP3s, SSH, and SNMP.
  • Enumerating POP3/IMAP requires credentials to a user's inbox. Hence, I figured to start with SNMP.
  • Using snmpwalk gives a Timeout error. (snmpwalk -v2c -c public $IP)
  • Tried to bruteforce comunity strings using onesixtyone, but did not get anything. (onesixtyone -c snmp.txt $IP)
    Am I missing something? I'm unable to enumerate SNMP and am unsure of how to proceed further.
round gale
violet tundra
#

Hello, I would want to understand what i'm doing wrong in the Password Attacks -> Pass the ticket section:

Use john's TGT to perform a Pass the Ticket attack and connect to the DC01 using PowerShell Remoting. Read the flag from C:\john\john.txt
I connected to the DC01 using Powershell remoting, but cannot find the flag in C:\john.

weak stirrup
#

i am working on windows privilege escalation final assessment one and the timer for the target box counts down its 120 minutes in under 5 minutes. Is this a known issue right now?

violet tundra
coarse escarp
#

I finally freaking got the enumerator in "getting started" module done

#

boy was I over thinking

vital adder
vital adder
weak stirrup
#

In windows privilege escalation skills assessment 1 am i missing something basic? I don't see how to get any login credentials with the information given in the course or on the page. I nmaped and see a very boring web server which i tried to find directories in with a more interesting interface but found nothing and i see an rdp port open.

thin knot
#

how can i scan port service version bypass firewall TCPWARRPED

vital adder
vital adder
robust anchor
weak stirrup
vital adder
#

hint try some basic web exploit

weak stirrup
# vital adder hint try some basic web exploit

can you guide me to which module in the section might have a hint to this 'basic web exploit'... google is not being very relevant.. tried to feed it some trash such as <?> etc and i get an error page but that is it

weak stirrup
vital adder
#

hint it's a type of ||injection|| attack but remember there is 0 db

weak stirrup
vital adder
#

hint you should be able to get ||RCE||

pseudo hill
#

During our penetration test, we found weak credentials "robin:robin". We should try these against the MySQL server. What is the email address of the customer "Otto Lang"?

#

I GOT THE MAIL FROM SQL TABLE BUT IT DONT WORK

#

IT IS FROM FOOTPRINTIG MYSQL

weak stirrup
vital adder
eternal mason
#

Hi, there is a reference to Wirless attack module, but I can not find it, does this module exist?

sage granite
#

There is some stupid bug or idk, I need correct answer

zinc marsh
#

u didn't even send the command

sage granite
#

I fetched urls with:

root_paths=$(echo "$curl_output" | grep -oiE "($target)[a-zA-Z0-9/_.?-]+/" | sort -u)

And I also did something similar with python, and with js, and I even did manually count this focking shit and it always says wrong answer.

keen compass
#

On USING WEB PROXIES > Intercepting Web Requests : am I the only one to have trouble make ZAP work properly ?

From my kali VM, i manate to make it work but had sometime to refresh stuff, was not able to intercept request and modify them. Had to do it without the HUD.
From the pwnbox, the hud does nothing when I click on buttons (again I can use Zap but the Hud seems to not be stable at all)

From what I have read the HUD can sometime be not stable, but I would have thought the HTB course (more over using the pwnbox) would work properly no ?

zinc marsh
#

anyways to read the source code of a website it is just curl -s <url>

acoustic owl
zinc marsh
#

I remember I skipped what I couldn't use

maiden spindle
#

Hey guys, I'm struggling with RDP and SOCKS Tunneling with SocksOverRDP. Windows security is disabled. Is the box just loading incorrectly? I tried reloading twice and waiting over 5mins.

#

I don't know how I would diable defender on the 172.16.6.155 computer if I can't access it

keen compass
# zinc marsh I remember I skipped what I couldn't use

this is what I did too but was wondering if this was "normal" or not : the tool seems far more powerfull that what I thought, and I would have love to learn how to use it if it can be as good as burp (thanks for the feedback tho)

zinc marsh
rustic sage
#

Hi, could I get a quick tip on the Attacking Enterprise Networks module? I am probably using the wrong wordlist for cracking the hash

raven reef
#

Hey guys so Iโ€™m like very new to coding and stuff, and I wanted to do my own discord bot. I tried doing it on scratch already but it didnโ€™t really work. Iโ€™m here to ask for help, if anyone can teach me simple things Iโ€™d be very grateful.

#

And I really donโ€™t know where to start.

rustic sage
#

Not the right channel, try googling for a more tech oriented server

#

this is just a sanity check mostly because its friday and i might just be overthinking

is it fair to confuse a question that says "/ root directory" than just "/root"

amber sandal
#

Heyy

fathom pendant
rustic sage
maiden spindle
fathom pendant
#

Which is separate from defender running

maiden spindle
#

ty

fathom pendant
#

To be fair your question has been asked dozens of times

maiden spindle
#

I've excluded .exe and .dll

#

and the c;\

fathom pendant
#

You're going to need to re-download the dll

#

And re execute it

#

Literally follow the steps for like 90% of it

rustic sage
#

any idea how to solve this question, module DOCUMENTATION & REPORTING ? Steve is learning about the tool that can make logging a session easier. He messages you for help mentioning that he would like to try to split the panes vertically. What do you tell him? (Answer format: [key] + [key] + [key], i.e., fill in the values for "key" and leave the brackets and + signs.). i have inputed [ctrl] + [b] + [%] as anwer but its wrong

maiden spindle
#

I tried redownloading it, I triedswitching to 56kb modem

fathom pendant
#

Close out of rdp

#

And reopen it

#

:)

maiden spindle
#

Same. Must I rdp redownload and then try? Or must I restart the windows machine

fathom pendant
#

Try restarting the lab

#

Either that or you skipped some steps

#

:)

maiden spindle
#

ty

#

i tried pinging 172.16.6.155 from the windows machine and got nothing

fathom pendant
#

I mean likelihood is that you wouldn't

#

Also is it 172.16.6.155 and not 172.16.6.15?

drowsy swallow
#

i just did it

#

You are missing things.

maiden spindle
#

I rdp over I turn off real-time and excluded the file, I exclude dll and exe for processes then open cmd as admin xfer over the files. extract them then run regsvr32.exe SocksOverRDP-Plugin.dll. it tells me it succeeded I then open rdp and type in the IP

fathom pendant
maiden spindle
#

It can't make it not work though right?

fathom pendant
#

Too many double negatives

maiden spindle
#

@drowsy swallow did I miss a step?

fathom pendant
#

Anyway read carefully

drowsy swallow
#

Read again the section

#

Your problem aint there

maiden spindle
#

but that's as far as I get?

fathom pendant
#

You're missing part 2

#

You've successfully got a foothold at 172.16.5.19 correct?

maiden spindle
#

no

fathom pendant
#

So start from the top and work your way down

maiden spindle
#

yeah.. I thought jason replaced victor

#

thank you sorry

fathom pendant
#

It literally walks you through step-by-step

#

Pivoting is by far the most hand-hold one

maiden spindle
#

I didn't read the ips

#

I assumed the question had the ips I needed, didn't think blindly following the module was what to do

sweet goblet
#

Hey!
im at AD Enumeration & Attacks - Skills Assessment Part II - Question: " Submit the contents of the flag.txt file on the Administrator Desktop on the MS01 host. "

  • i have to pivot somehow from the sql01 host to ms01 as admin
  • I've got system priveleges on sql01 host and try to dump the memory like this:
rundll32 C:\windows\system32\comsvcs.dll, MiniDump 664 C:\lsass.dmp full
./mimikatz.exe log "sekurlsa::minidump /lsass.dmp" "sekurlsa::logonpasswords full" exit > dump8.txt

i cant find anything interesting in the dump. Am i missing something?

fathom pendant
maiden spindle
#

2 of the port forwarding did not work as explained.

digital pewter
maiden spindle
#

ICMP required to look at erratum and chisel needs the older version dled

sweet goblet
fading atlas
#

Hi Guys Has anyone solved Skill the Assessment exercise 2 of Using web proxies?

echo glen
#

Has anyone gotten WSL2 and a Linux subsystem installed properly during Settup module?

#

I can't seem to get Linux subsystem working after installing from windows store, WSL2 gives me error about virtualization not being enabled... when I have checked bios and windows features, everything is enabled -_-

thorn urchin
echo glen
#

I am inside the windows 10 VM they suggest we install, in which we install WSL2 and Linux subsystem inside of it

echo glen
#

Yes

#

Yes lol -- i've been following the Settup Module. We create a linux Vm as well as Windows VM

#

it's been wasting so much of my time

#

Did you not go through the Settup module on Academy?

#

Hackthebox confuses me, it gives us all these recommended modules on academy beforehand doing the labs

#

Did you just start labs?

#

Thanks for input, maybe I will just skip their windows/linux subsystem VM, focus soley on my linux VM

#

cause it is very de-motivating when iv'e spent 2 days trying to resolve this. Lmao

fathom pendant
echo glen
#

Good to know, thank you

fathom pendant
#

Like if windows is needed you're given a host to rdp into

echo glen
#

the windows/linux subsystem would've been cool to know but i never planned on pentesting from a windows machine anyways

fathom pendant
#

The suggestion is mostly if you want to do further testing on your own

echo glen
#

Fair enough

#

I honestly just got caught up on it because I didn't want to leave it unsolved. Lol

#

but i've given up, because at this point I need to start a lab and not stay in settup FOREVER lmao

fathom pendant
#

Good luck

high reef
#

hey everyone

#

has anyone completed the Pandora machine?

thorn urchin
#

channel is for module discussion

fathom pendant
#

There is a whole windows fundamentals and intro to windows command line

trail leaf
#

Windows privesc module is 10/10 would recommend

fathom pendant
#

Well yeah but their question was about "fundamentals"

trail leaf
#

They also explicitly asked about the Windows Privesc module ๐Ÿคทโ€โ™‚๏ธ

fathom pendant
#

Oh

#

You're right

#

They said after

#

My brain is like a poached egg today

heavy marsh
#

Can anyone explain the difference between DownloadString and DownloadStringAsync?

#

Sorry, meant DownloadFile and DownloadFileAsync

#

They don't explain what it means to "block the calling thread"

molten zenith
#

Okay

#

So what do you like to know about the DownloadFile and DownloadFileAsync

heavy marsh
#

From what I have looked at in other resources online it appears DownloadFile will wait until it's downloaded and you can't do anything else in powershell until it's done, and DownloadFileAsync will essentially background the process so you can continue other commands.

trail leaf
#

Assuming this is about the C# module. When you call DownloadFile, the program does not continue execution until that function has completed. With DownloadFileAsync, you let another thread of execution handle the operation, but need to do some additional handling to know exactly when it's finished downloading, which starts the whole discussion of multithreading/multiprocessing.

heavy marsh
molten zenith
#

DownloadString:
This is a synchronous method, which means that when you call DownloadString, your program will pause and wait for the entire download operation to complete before proceeding to the next line of code. This can potentially cause your application to become unresponsive if the download takes a long time, especially on the main UI thread

#

WebClient client = new WebClient();
string content = client.DownloadString("https://example.com");
Console.WriteLine(content);

heavy marsh
molten zenith
#

DownloadStringAsync:
This is an asynchronous method, meaning that it initiates the download operation and returns immediately, allowing your program to continue executing other tasks without waiting for the download to finish. You provide an event handler to this method, which will be called once the download is complete. This approach is preferred when working with user interfaces or applications that need to remain responsive during the download.

trail leaf
#

But both are part of the .NET framework and are pulling from similar things, so the same logic applies

molten zenith
#

You are right

#

Who can teach me how to carete software on PC

trail leaf
#

ah so your response was just chatgpt then lmao

molten zenith
#

yEAH

trail leaf
molten zenith
#

Do you know how to carete it

trail leaf
#

because this is the chat for HTB Academy modules, and talking about that here will clutter up the chat and be annoying to anyone who has a question about Academy modules

molten zenith
#

I know that but you can in box me one on one and then teach me

trail leaf
#

nah

#

nah

#

I told you what to do if you wanted to learn to program from people here, couldn't even listen to that

vital adder
#

@molten zenith pls read #welcome and #rules after that use /verify at #bot-commands if you are on HTB and ask your question in the appropriate channels, this channel is for HTB academy module so pls stay on tops or you may get the ๐Ÿ‘ข

real copper
#

why the vpn connection is not stable i'am trying to rdp to a machine and its disconnect me every min

" attacking password module "

#

ohhhhhh
i rstore the machine many time and tried difrent machine and its same issue

real copper
#

You know what ..
^%#$%$#

tender yarrow
#

Morning all, the current path I am on is Penetration Tester and I am on the Attacking Common Services section. I am right at the end on the Attacking Common Services - Hard Skills Assessment but I am really stuck! I am stuck on question 1, What file can you retrieve that belongs to the user "simon"? (Format: filename.txt). I have tried the basic / normal nmap enumeration, gone straight for SMB / 445 but cannot get anything to work, cannot get anything useful back. I have read bits of things online and poeple are saying this is the starting point, could I please ask for a small hint to get me moving, been at it for a couple of hours this morning so it might be brain fog and time to pack in for the day. Thanks

real yew
#

morning mates am a fullstack web devloper

#

if u r looking for any web d project feel free for help...

fathom pendant
vast geyser
#

Can anyone help me out? ,In the Active Directory LDAP module LDAP Anonymous Bind section -- The last question is "What OU is the user Kevin Gregory part of (one word, case sensitive, i.e. Marketing)? ". I cannot figure out how to get OU information back with an anonymous bind.

obtuse fiber
#

Could someone help me with the Pass the Ticket section, please? Particularly the last question, "Use the LINUX01$ Kerberos ticket to read the flag found in \DC01\linux01. Submit the contents as your response (the flag starts with Us1nG_)."

I have used linikatz and it provided me with the below

||Ticket cache: FILE:/var/lib/sss/db/ccache_INLANEFREIGHT.HTB
Default principal: LINUX01$@INLANEFREIGHT.HTB||

I then I used this ||kinit linux01@INLANEFREIGHT.HTB -k -t /var/lib/sss/db/ccache_INLANEFREIGHT.HTB||
but that just says "kinit: Pre-authentication failed: Unsupported key table format version number while getting initial credentials"

Have I missed something?

fathom pendant
fathom pendant
autumn pilot
obtuse fiber
fathom pendant
#

No

#

Just go over all the methods discussed

obtuse fiber
#

but using the same ticket correct?

fathom pendant
#

Considering the type of file it is

fathom pendant
dim hemlock
#

Hi guys, Im stuck on this question... I think I know what I need to do just that I didnt understand the question enough:

"Using Julio's hash, perform a Pass the Hash attack, launch a PowerShell console and import Invoke-TheHash to create a reverse shell to the machine you are connected via RDP (the target machine, DC01, can only connect to MS01). Use the tool nc.exe located in c:\tools to listen for the reverse shell. Once connected to the DC01, read the flag in C:\julio\flag.txt."

#

Do I need to login as Julios with the hash? and use his account to invoke the hash?

true prism
#

Snoopy

fathom pendant
true prism
fathom pendant
#

I mean, yes

obtuse fiber
fathom pendant
#

But if you're referring to the box, there's a #boxes channel (if you have no access, read #welcome )

obtuse fiber
#

I have figured it out and got the flag, thanks a lot @fathom pendant .

fathom pendant
obtuse fiber
#

I have a question if may DM you about to not spoils anything more in here @fathom pendant

fathom pendant
#

I dont have access to my notes

obtuse fiber
#

oh no it's about logical thinking

fathom pendant
#

Ah sure dm

vast geyser
obtuse fiber
# fathom pendant I dont have access to my notes

when I used the tool Linikatz I found the path but after restarting the box and using Linikatz again I found another results so how could I find it manually next time ? or was my whole approach wrong to begin with ?

fathom pendant
acoustic owl
#

It is a dog ๐Ÿ˜‰

fathom pendant
#

I struggled manually through it ๐Ÿ˜„

obtuse fiber
#

okay I got it now

#

thanks a lot, I need to get me coffee ahahaha

pastel urchin
#

guys how do i enable this? im getting the same thing when installing openssh and apache2

obtuse fiber
true prism
obtuse fiber
#

"sudo systemctl start openvpn" and then enable it by using "sudo systemctl enable openvpn"

obtuse fiber
true prism
#

I have done the ssh-mitm and I got the credentials for cbrown but I am unable to get the flag. Thatโ€™s makes me hate myself. I took alot of time doing it. But no flag๐Ÿฅน

obtuse fiber
high zinc
#

God I hate module questions that have you bruteforce for literally half an hour or more

fathom pendant
fathom pendant
#

I stated this earlier, you must have missed it

obtuse fiber
#

Guys can you remind me which chapter and question have we done Kira brute force so I can go back to it as I need it in the below
Module: Password Attacks
Chapter: Protected Files
Question: Use the cracked password of the user Kira and log in to the host and crack the "id_rsa" SSH key. Then, submit the password for the SSH key as the answer.

fathom pendant
#

pika_sip I think it was one of the early ones

#

This is a lesson in remembering to save all creds you find

obtuse fiber
#

true ๐Ÿ’”

fathom pendant
#

I mean you should still have the mutated wordlist

#

So just need to recrack the password

high zinc
# fathom pendant Skill issue

KEKW, I was looking at the FQDN thinking "oh that's a funny machine in 2023" then continued running other commands, completely oblivious to what I was actually looking for...........................

sage granite
# acoustic owl With the commands shown in the section, you should be able to filter the source ...
ALL the root paths found in source: 19
https://www.inlanefreight.com/index.php/about-us/
https://www.inlanefreight.com/index.php/career/
https://www.inlanefreight.com/index.php/comments/feed/
https://www.inlanefreight.com/index.php/contact/
https://www.inlanefreight.com/index.php/feed/
https://www.inlanefreight.com/index.php/news/
https://www.inlanefreight.com/index.php/offices/
https://www.inlanefreight.com/index.php/wp-json/
https://www.inlanefreight.com/index.php/wp-json/oembed/1.0/
https://www.inlanefreight.com/index.php/wp-json/wp/v2/pages/
https://www.inlanefreight.com/wp-content/themes/ben_theme/
https://www.inlanefreight.com/wp-content/themes/ben_theme/css/
https://www.inlanefreight.com/wp-content/themes/ben_theme/css/colors/
https://www.inlanefreight.com/wp-content/themes/ben_theme/images/
https://www.inlanefreight.com/wp-content/themes/ben_theme/js/
https://www.inlanefreight.com/wp-includes/
https://www.inlanefreight.com/wp-includes/css/dist/block-library/
https://www.inlanefreight.com/wp-includes/js/
https://www.inlanefreight.com/wp-includes/js/jquery/

And 3 external paths.

//api.w.org/
//fonts.googleapis.com/
//gmpg.org/xfn/

This is all I got, tried all answers in range 18-26 and it says wrong answer. Are you sure that the source haven't change?

Edit: Got tired and found the answer via simple js bruteforce, it is a few more, but it doesn't add up with the source imo.

high zinc
fathom pendant
high zinc
#

Ah. Yes. That and distractions KEKW

slender jasper
#

Can anyone help with AD Enumeration & Attacks - Skills Assessment Part II - Q8 + 1 Submit the contents of the flag.txt file on the Administrator Desktop on the MS01 host. I have SYSTEM on SQL01, have run mimikatz and tried using the admin hash to connect to MS01 which didn't work. Ran snaffler and no luck. Appreciate any help.

keen summit
#

i could help you bc i did solve this but i am afk for the next 4-5 hours or so

#

i would have to be on my laptop because it was a long time ago and i dont remember this anymore.
i will dm you, just later - ok?

rustic sage
#

guys does it really matter uppercase or lowercase ssh username or a password ?

pine dagger
#

On the 2nd injection point (which you've found), you need to do ||an XML injection||. There's multiple ways of doing it. The first involves ||enumerating the XML to find the correct path at which point, by returning the correct order, you will find the answer|| or there's a quick and dirty way which you can use by ||simply sending an XML test search||. The quick and dirty method isn't covered in the module, so you'd have to do your own research on how to do it.

pine dagger
slender jasper
pine dagger
#

Try looking for an account, like for ||a service||.

slender jasper
#

wasnt able to do much more with it but I will take another look

pine dagger
hollow hinge
acoustic owl
pine dagger
#

MacOS is based off BSD, which is a Unix based OS.

hollow hinge
#

I am stucked at the exercise, I am getting error like this

4007DF79137F0000:error:1C800064:Provider routines:ossl_cipher_unpadblock:bad decrypt:../providers/implementations/ciphers/ciphercommon_block.c:124:```
rustic sage
pine dagger
#

Yes.

rustic sage
pine dagger
#

Few hours. Depends how fast you read, etc.

#

Non-native english speakers would probably take a little longer, etc.

acoustic owl
#

Try not to complete the modules as quickly as possible, but in such a way that you learn as much as possible.

pine dagger
#

Especially fundamental modules

fickle thicket
#

hi, anyone completed the footprinting module - hard? am i supposed to search the mail and maildir dir?

pine dagger
#

Yes.

fickle thicket
#

never mind. i solved it. is not the mail and maildir

#

lmao

#

thanks anyway

warm bolt
#

hi

sage granite
fickle thicket
#

actually guys, do u guys hack the box after completing all the cpts module?

#

or you can complete one module then do one box?

opal fog
#

@slow ruin could you please help me in this point when i use (net use ) i see (There are no entries in the list) , i already dm you if you dont mind

hazy grotto
#

@coral sundial just a random appreciation post the GOAT. Thanks for all you do

marsh delta
#

hello

hazy grotto
#

Serious Rule Break

rustic sage
#

What's the contents of table flag5? (Case #5) SQLMap Essentials->Attack Tuning, got the flag but it says incorrect

#

nope i checked it

#

maybe but it says flag5 ๐Ÿ˜•

#

as per the hint used the correct comand

fathom pendant
#

Refresh page

#

Try pasting again

rustic sage
#

yep did also logged out and logged in again

fathom pendant
#

Make sure no extra weird invisible characters at start/end

pine arrow
#

Hii

fathom pendant
sly kelp
analog pewter
#

anybody can help in cracking password with hashcat module

tepid hemlock
analog pewter
tepid hemlock
analog pewter
tepid hemlock
#

I will DM you

cold blade
#

hi

little wyvern
#

Hi, I also found the user, could you give me a hint how to get the password? thanks

nova pollen
#

I am on the Windows PrivEsc module right now . Anyone else had a problem with compiling UACME akagi ? i tried it on both windows and linux with different compilers . i am getting these errors everytime #error ANSI build is not supported ^~~~~ .\Source\Akagi\global.h:25:27: fatal error: shared\libinc.h: No such file or directory #include "shared\libinc.h"

rustic sage
#

What's the contents of table flag5? (Case #5) also for flag7 (Case #5) SQLMap Essentials->Attack Tuning recommended running it on a pwnbox, turns out indeed the only thing that differentiated me from capturing the flag was me running sqlmap on my VM - classic

digital pewter
#

The Java application exploitation in Attacking Common Apps is boss. Daaang. ๐Ÿ™‚

quaint gate
#

Using rockyou-50.txt as password wordlist and htbuser as the username, find the policy and filter out strings that don't respect it. What is the valid password for the htbuser account? . I have the password policy down to three requirements and grepped the file requested accordingly to get the "respected" passwords. I have five passwords . None of them work. Anyone know if I am on the right track? This is from Broken Authentication module.

rustic sage
#

im trying to exploit 2.7.10 for WordPress

#

where is the problem why I can't read flag.txt ?

undone narwhal
#

Module: WINDOWS PRIVILEGE ESCALATION
Section: Windows Privilege Escalation Skills Assessment - Part I
Question: Find the password for the ldapadmin account somewhere on the system.

isn't this question suppose to be after getting the admin shell? Cuz i ran a certain tool before and after the admin shell and it only worked with admin privileges also pretty sure the foothold account doesnt have privileges to read those specific files that has the password.

is there another way that would actually wrok with out admin privs?

undone narwhal
#

There only two ports open for this machine I don't think I can use windapsearch

prisma spruce
fathom stump
#

Feel stuck on nmap enumeration - avoiding ids/ips medium.

I've tried changing source port, source ip, decoys, connecting with ncat, -O version scan, udp scan, --script banner, -T5, can't get it to return anything but filtered for -p53.

Am I missing some specific combination of things to get a result?

trail leaf
#

The point of avoiding IDS/IPS is not using things like -T5, scripts, etc. You want to make as little noise as possible.

fathom pendant
quaint gate
fathom pendant
#

Mood

#

Were you like one policy off?

quaint gate
#

Actually who am I kidding, this is not the first time. Oh well.

fathom pendant
#

And likely won't be the last

vast geyser
#

Hi, has anyone done "Active Driectory LDAP"? im stuck at this question "What is the password history size of the domain? (How many passwords remembered.)?". Just need to be pointed to the right direction
Do I need find the admin account?

vast geyser
#

@vital adder
Credentialed LDAP Enumeration

final maple
#

I'm 77% of the way through with the course. Where is everyone else at?

distant island
#

Hello everyone hope you all are having a great day

#

I am newbie and still learning from zero experience

#

Use cURL from your Pwnbox (not the target machine) to obtain the source code of the "https://www.inlanefreight.com" website and filter all unique paths of that domain. Submit the number of these paths as the answer.

#

i am literly clueless on this one its in linux fundmentals

vital adder
distant island
vast geyser
tender yarrow
vast lichen
#

Hello, Can anyone explain to me what is mean that in practically way. It is from shell& payload module

tender yarrow
fathom stump
fathom pendant
fathom stump
#

Yes, it is.

fathom pendant
#

No

#

Do a scan without specifying -p53

fathom stump
#

Go try? The flag is literally from port 53

fathom pendant
#

I dont recall it being on that port

#

But it's been a minute

#

I could be thinking of the other lab

fathom stump
#

Maybe it's changed since you finished, too, but that's where it is ๐Ÿ˜›

quaint hemlock
trail leaf
#

They tell you exactly what to do in the section why would you get a random medium post to tell you what to.

quaint hemlock
trail leaf
#

๐Ÿคทโ€โ™‚๏ธ

#

Are you specifying the absolute path to the DLL?

quaint hemlock
#

yea?

trail leaf
#

Maybe try having the DLL execute a command to put you in Adminstrators/Domain Admins? Not sure what else to tell you

#

It can be a little finnicky when restarting the DNS service iirc, but that's all I remember with my own troubleshooting when I was doing that one

quaint hemlock
#

okay thx dude!

heavy marsh
#

What does this mean?!?!

#

what is 192.168.49.128? the target or the host?

#

what are the -v -n -s ??

#

what does "bye" mean?

fathom pendant
#

This is an example

#

Bye exits ftp

#

If you look at the man page for ftp it tells you

heavy marsh
#

Thanks, I finally found a resource that explained it. I was overthinking it.

#

Seems kind of cheesy

#

Why would I echo commands on a target machine to make a command file to then just run that command?

#

I guess they're just giving us options!

fathom pendant
#

Exactly

heavy marsh
#

Thanks, I thought I was going crazy. If it was for obfuscation, I would understand, but this just seems sloppy in terms of cleanup to avoid detection by digital forensics.

slate carbon
#

How would I go about reporting someone for posting a walkthrough of a modules skill assessment?

fathom pendant
#

Probably DM staff

slate carbon
#

in discord?

heavy marsh
fathom pendant
heavy marsh
#

I haven't seen anything saying module information is not fair game

fathom pendant
#

As tier0 is considered free

sudden prairie
#

hey what is the answer to task 3 on appointment

heavy marsh
fathom pendant
#

Basically

fathom pendant
heavy marsh
#

I think that walkthroughs on skill assessments would be beneficial.

#

If you're stuck and have one detail that you're missing, it's beneficial.

slate carbon
#

That's what the forums are for

proud pine
heavy marsh
#

If you're stuck and you have one detail that you're missing due to an issue with the connection that's beneficial.

heavy marsh
proud pine
heavy marsh
#

I've spent several hours trying random stuff thinking it was a ME issue, just to reset the machine to find it was a ME not resetting the machine issue, lol

#

I don't see a problem with walkthroughs if you're only verifying current conditions before moving on.

#

That's what the guided stuff on the main platform is all about as far as I can tell.

hallow kiln
#

I think the problem is there will be plenty of people who won't just verify current conditions and move on

proud pine
fathom stump
#

On nmap enumeration, how is setting the source IP supposed to work? If I set it to anything but my actual IP, I get an error that a route to the destination can't be found

hallow kiln
#

Guided mode is just questions leading you in the right direction

heavy marsh
heavy marsh
pulsar needle
#

What does it mean show isnt a command

heavy marsh
#

Are you in a mysql command line?

pulsar needle
#

no

#

i am in mssql

#

But the syntax should be the same

heavy marsh
#

what question are you on?

#

I would try one of those, forget which one I did.

slate carbon
pulsar needle
#

First question

heavy marsh
#

In general hacktricks has been clutch for me

pulsar needle
#

Aaah oke thanks

heavy marsh
pulsar needle
#

Nope

#

I used to have platinum

#

But just for 2 months

#

And then i could afford the course

#

Lol

heavy marsh
#

Silver Annual includes "Mentoring"

#

If you answer wrong multiple times it will get you help in discord with a HTB company mentor

#

You probably won't get a response same-day, but I've had some good help with it so far.

pulsar needle
#

Nice

stark fractal
#

My VPN is running (and worked well in the previous modules). However all of a sudden I can't nmap nor can I reach it with msfconsole when I execute check (after entering the target IP address)

fathom pendant
stark fractal
#

When I go to my browser and visit the address, i can see the wordpress page just fine

pulsar needle
fathom pendant
#

Mysql requires a ;
Mssql requires go

pulsar needle
#

aaa i thought that was just for sqsh

#

lol

faint rampart
#

sqsh allows batch queries, dunno about mssql-client
Theres ALOT more differences btwn mssql and mysql than just go and a semi colon tho

fathom pendant
#

That's just a basic

#

The actual lessons do go over query syntax

#

Like reset answers?

#

No

#

Is there a particular reason you want/need to?

tiny reef
#

Seems like targets are not available right now, anybody els having issues?

ivory cloud
#

Has anyone taken the CREST CRT preparation course and passed the exam or was additional training required. I'm interested in hearing your journey if you've taken the CRT, what worked well and what didn't.

last moss
#

Hi, is there anybody on 'Abusing HTTP Misconfigurations'?

acoustic owl
last moss
# acoustic owl What exactly do you want to know?

help on this question: Try to use what you learned in this section to exploit a session puzzling vulnerability due to common session variables and take over the admin account to obtain the flag.

last moss
acoustic owl
last moss
acoustic owl
zinc marsh
#

Perform a zone transfer for the "inlanefreight.htb" domain against your target and determine how many nameservers the company has. Submit the total number of nameservers as the answer.

sleek shell
#

Hi guys, when starting a workstation on HTB academy I get an issue

tiny reef
pine dagger
# zinc marsh I cannot get it works

That's not true. It works. There's plenty of people that solved it. What you mean is "I am unable to get it to work." I just tested the command. It works fine.

sleek shell
#

That's a pity

zinc marsh
pine dagger
#

Probably you are writing .com

zinc marsh
#

can I dm u? I am restarting the target

zinc marsh
pine dagger
#

Literally, all you need to do is write:
dig axfr inlanefreight.htb @<ip address>

zinc marsh
pine dagger
#

Its probably your connection

#

try pwnbox

zinc marsh
zinc marsh
#

between the new "medium" machine and this I am gonna die damn

trail leaf
#

You should have done this in one of the CPTS modules ๐Ÿค”

zinc marsh
#

thanks

pine dagger
#

So, your VPN is your issue

zinc marsh
#

it is the dns enumeration with python module

trail leaf
#

You still do a zone transfer in Footprinting or Attacking Common Services (can't remember)

zinc marsh
astral swift
#

Can anyone help me with Command Injection / Other Injection Operators and the question Try using the remaining three injection operators (new-line, &, |), and see how each works and how the output differs. Which of them only shows the output of the injected command?? Its really frustating, I cannot find exactly the answer it waits

pine dagger
#

When asking questions, you really need to identify the module, chapter, and question you're stuck on, otherwise people will be unlikely to have a clue what you're asking about.

#

There's literally hundreds of questions in the academy

astral swift
#

I edited my previous message, its in the Command Injection module

clear mason
#

hello need a help in the BROKEN AUTHENTICATION module the Brute Forcing Cookies room Tamper the session cookie for the application at subdirectory /question1/ to give yourself access as a super user. What is the flag? i could easily decode and encode the cookie but i need the name that will show the flag it says super user but it doesnt work tried admin tried htbadmin as well won't work or there is something i am missing

trail leaf
#

You're supposed to bruteforce that part and just try words ๐Ÿคทโ€โ™‚๏ธ

clear mason
#

oh okay will try that hope i can find a list for roles

pine dagger
astral swift
#

Multiple of them are working

#

Question does not state if they need to be specified encoded

#

Ok I got it, this question is really terrible to be honest, thanks for the help

clear mason
#

the username is "super"

clear mason
half tendon
#

Hlo

autumn pilot
#

Familiarise yourself with the #rules @half tendon

half tendon
#

Oo

#

Sry

#

@autumn pilot

west spindle
#

Hey, I'm stuck on the last question of the Kerberos Attacks skills assessment. Any hints would be appreciated!

autumn pilot
#

Maybe you should keep an eye on something that happens every few minutes

west spindle
#

I wanna ping you if you don't mind

obtuse fiber
#

Hey all, I need a nudge in the below if possible
Module: Password Attacks
Chapter: Password Attacks Lab - Medium
Issue: I have got ||d|| user and I think I know the way to root but I already struggled before with ||1.8.31||, am I on the right track ? which ||1.8.31 ||should I use ?

fathom pendant
#

What have you tried

obtuse fiber
fathom pendant
#

You're focusing on the wrong thing

#

Ssh

#

That's my only hint

obtuse fiber
#

say no more ๐Ÿ˜‰, thanks a lot got it @fathom pendant

restive steppe
#

SOC Analyst Job Role path. New cert inbound?

analog dock
#

Hard ๐Ÿฅต

proud pine
#

Looks like just one module is listed as hard.

#

Oh, two, actually - Introduction to Malware Analysis

acoustic owl
restive steppe