#modules

1 messages · Page 119 of 1

fathom pendant
#

It's not looking for a version #

#

That's not even close to the longest iirc someone said theirs was like 150

lapis pelican
#

Either the question was not clear or I didn't understood it well. 😅

frozen mesa
#

Thanks for the help with DNS, will be back later because i still dont get the results where i can work with.

fathom pendant
#

Unclear question tbh

shut wraith
vital adder
#

welcome to the cartel

shut wraith
#

Time to see how this course compares with Offsec and THM

fathom pendant
#

They're leagues better than offsec (according to those that have done offsec)

lapis pelican
#

I heard offsec course videos are very short and not much clear. Not sure if that's true.

shut wraith
#

For everyone I've spoken to, they said that the modules are sufficient and do a good job. But for me, I found them overwhelming and insufficient. That's why I'm using HTB

vocal tusk
#

Hi Guys im trying to work on my report writing is there any module that goes in detail on how to figure out CVSS scores and how to place the vulnerabilities you find

#

im doing this one and it just skims over how to format it whats good or bad but not if you have x vulnerability you could take theese steps to identify its severity etc

shut wraith
#
When we have completed (at least) two modules and are satisfied with our notes and documentation, we can select three different retired machines.

Is it saying to get a VIP so that I can practice after the modules?

vocal tusk
#

i think it says that you can select 3 retired machines to practice on where dose it metntion vip ?

shut wraith
#

Oh so I get to select machines for free? That's cool

#

Time for some enumeration review

#

Nvm. Still another intro module left "Getting Started"

red valve
#

nice

shut wraith
#

And help each other

red valve
#

as soon as i reach hacker rank i think i'll buy it

tranquil axle
pulsar needle
#

You get to do 1 for free

#

Following a guide, and using the IP, its just a seperate instance of a retired box i am pretty sure

shut wraith
#

But no endgame stuff for free ?

misty mural
#

I’m working on the Protected Files page of the Password Cracking module.

The question asks to use the cracked password of the user Kira to log into the host and crack the password for the SSH key.

It assumes I have a cracked password for Kira (I don’t). || Should I be using hydra to brute-force ftp mutating the provided pass list in resources or did I miss something? ||

fathom pendant
fathom pendant
#

Yes it's the same password...

fathom pendant
#

It is in the mutated list from resources

misty mural
fathom pendant
#

Well guess you gotta recheck the module

#

The linux and windows labs in this module get reused

#

So keep this in mind for future: save username/password combos

misty mural
#

Good practice for reporting. 💯

fathom pendant
#

It's early on iirc one of the first handful of sections

vital adder
radiant verge
#

does anyone here know what a RCe attack is?

fathom pendant
wispy aspen
#

also known as based encryption

ornate compass
#

Unable to install mysql server in kali. Have tried several youtube videos. Anyone run into this?

ornate compass
shut wraith
#

I'm so relieved

#

I just connected via the VPN for the first exercise and the connection is flawless

#

This means I will be able to go through this whole course and do boxes without technical issues

tulip parrot
#

Hello all, i get big difficulties in the module Active Directory Enumeration & Attacks, Bleeding Edge Vulnerabilities. I tried all the 3 exploits, and I get bug on 2 of them, and the third (noPac) I can't get the file (my previous message was delete i dont understand why)

fathom pendant
tulip parrot
#

Can u help me through ?

burnt sluice
haughty lark
#

Hello, I want to report a vulnerability to hackthebox. Can an authorized person contact me via LinkedIn?

warm drift
burnt sluice
warm drift
#

ye

barren apex
#

have you tried subtree as well?

#

if i remeber right only one worked for me

warm drift
burnt sluice
barren apex
# warm drift no

give it a try, I remeber having trouble with getting responder to get the hash

tulip parrot
burnt sluice
# warm drift no

Try to remove the GO from the endEXEC master..xp_dirtree '\\10.10.*.*\share\'

burnt sluice
tulip parrot
#

thx u ❤️

warm drift
warm drift
#

netdiscover? idk

#

same

#

I don't even know anything

#

OSINT?

burnt sluice
#

idk why it doesn't work with the GO tbh

warm drift
burnt sluice
weak copper
#

Im working on password attacks module, at the Password Mutations section, I mutated the passwords.list with the custom.rule as told, then im trying to bruteforce smb and ssh "sam" user with it but it's taking long. Should I wait?

burnt sluice
burnt sluice
warm drift
weak copper
#

alright, the only one that I didnt try is ftp I think so I will try with it too

#

Thanks!

burnt sluice
burnt sluice
plain coral
weak copper
warm drift
tulip parrot
plain coral
weak copper
vocal tusk
#

2

burnt sluice
mild ingot
#

What’s this

#

💀 I’m new

burnt sluice
#

Welcome on board :)))))

mild ingot
barren apex
#

mate have a look at the funderental modules on the academy, they will walk you through all the questions your asking, IP settings are different based on shell/OS

barren apex
burnt sluice
burnt sluice
barren apex
plain coral
weak copper
#

Thanks to everyone for your answers, will do some test to get maximum performance!

burnt sluice
#

i tried cranking it up to 64, anything more than 48 and u start getting drops.
Idk why exactly tbh.

plain coral
#

How come I got the flag with 64 threads then?

barren apex
barren apex
#

its very hit or miss

burnt sluice
burnt sluice
tulip parrot
burnt sluice
plain coral
barren apex
#

The terminal

plain coral
burnt sluice
fathom pendant
#

Default terminal in linux

vast geyser
#

Hello, I am learning BOF. I am stuck in "bad characters" concepts.
I think the "bad characters" will stop the function of the application.
So I need to find out which characters will stop.
Is my idea correct?
Could anyone can explain it?
Thanks.

burnt sluice
tulip parrot
#

thanks u i ll try again

weak copper
naive wadi
#

Doing the RDP and SOCKS Tunneling with SocksOverRDP in pivot, tunneling & port forwarding module and keep getting this error

burnt sluice
fathom pendant
#

I know your screenshot didn't show but I can 99.9999% guarantee that would be the issue

naive wadi
#

I have turned it off.

fathom pendant
#

It's separate from defender

naive wadi
#

I have turned it off

#

It's a seperate error from one you have responded to. I searched here first and have seen you respond

fathom pendant
#

Then follow the section from top to bottom

naive wadi
#

I also can't upload a screenshot for whatever reason...fun

fathom pendant
#

Because you haven't linked/verified your main htb account here

#

It's to prevent mass image spam

#

This section goes a -> b -> c

#

C being the question login

naive wadi
#

no, this is an issue with the very first part importing the dll

#

let me verify to send a screenshot

#

i've restarted the machine too

fathom pendant
#

Can you md5sum the zip file you transferred on both your system and the target?

naive wadi
#

yeah lemme check

#

yeah, good shout the transfer is messing it up.

#

will try a different transfer method.

#

thanks

fathom pendant
#

Note I said the zip folders

#

Just in case that got confused

glad bough
#

hello, I made a gobuster for the hidden folders but I don't understand why it doesn't want to show me a download folder. this one more precisely "http://provisions.snoopy.htb/download" I had to go on the internet to see that this file exists on the internet.

fathom pendant
naive wadi
#

Good ol simple python http server has failed me

fathom pendant
#

Ever since file transfer module had me set up a simple nginx server been using that since

burnt sluice
fathom pendant
#

it can but I'm also not worried about it too much as I'm only ever on htb vpn and don't open files I didn't download ¯_(ツ)_/¯

#

If I really wanted to be spook about it I'd change to nat network in vbox instead of bridged

#

But having it accessible on my local network allows me to verify if it's still running :)

summer lava
#

if i have a user in the domain admin group What are the possible ways to get to administrator ??

naive wadi
#

same problem

fathom pendant
naive wadi
barren apex
#

domain admin = pwned

fathom pendant
#

Slowly

naive wadi
#

This is literally the second step "We can then connect to the target using xfreerdp and copy the SocksOverRDPx64.zip file to the target."

#

which is done, then loading it

fathom pendant
#

Yes and you need to disable both defender and real-time protection OR add it to exclusions

naive wadi
#

which I have done

fathom pendant
#

Are you sure?

#

Try adding it to exceptions

summer lava
fathom pendant
#

Use Google

naive wadi
summer lava
#

@barren apex

vital adder
#

that's domain user not domain admin

fathom pendant
summer lava
summer lava
vital adder
#

that one was for someone else

summer lava
#

As a Print Operator

vital adder
#

*not admin

barren apex
#

What module are you doing

barren apex
summer lava
#

Yeah i did that .. wait

neat tide
#

Hello everyone I have a little problem and I need direction

soft reef
#

Where does my help request go if I request help in a module?

fathom pendant
neat tide
#

Web proxies in repeating requests i have changed the request from ip=1 to ip=;ls; , in the previous challenge it was in flag.txt. Now it’s giving me the hint that it is in another directory. What i get is

flag.txt
index.html
node_modules
package-lock.json
public
server.is

But where ever i try to go like for example ;cd public; it gives me a bad request i think I’m not approaching this correctly so If anyone can help please

umbral fulcrum
#

Hi guys, I'm in the "Pivoting, Tunneling, and Port Forwarding" : "Meterpreter Tunneling & Port Forwarding" & according 2 the explanation it doesn't work
some 1 had it 2?

fathom pendant
umbral fulcrum
fathom pendant
#

I had 0 issues following along when I did it

neat tide
umbral fulcrum
fathom pendant
#

No idea

#

Haven't done that one

neat tide
#

The academy is so vague like use commands bro what commands 😭

fathom pendant
#

Don't know what the question is asking you for

fathom pendant
#

Or at the very least you can try ls public

#

Probably due to the nature of the command syntax, you can't cd

shut wraith
#

Are u done the course @fathom pendant if so what was the hardest module(s)

fathom pendant
#

Nope

shut wraith
#

How many have u completed so far

neat tide
#

It is in using web proxies module and the section is repeating requests. Previously it was really easy i just had to intercept a request and then cat the flag.txt file. Now it says Try using request repeating to be able to quickly test commands. With that, try looking for the other flags and the hint is its not in the same directory. They didn’t even teach anything like how to shift between directories or anything they just showed how to repeat requests from history

fathom pendant
#

Half was forces to take a break

fathom pendant
shut wraith
#

That sucks. At least you're not time constrained to finish it. Unless u have a yearly plan or something

fathom pendant
#

You know how to cat a file that isn't in the current directory yeah?

thorn urchin
#

Personally I think windows priv esc was the hardest module in the course

neat tide
warm drift
thorn urchin
#

most people say AD though

fathom pendant
#

Do ls -la

warm drift
trail leaf
#

AD is probably hardest if you're completely new because of how much information there was, but it's arguably the best module on Academy I've done so far.

shut wraith
neat tide
fathom pendant
#

Interesting

#

¯_(ツ)_/¯

#

Might need url encoding

trail leaf
#

Password attacks might also fall in the category of hard because of how grueling those exercises were, even though it wasn't conceptually very difficult

thorn urchin
#

Id say no, but it was interwoven with other parts that I did find hard

shut wraith
neat tide
#

None in the bug bounty program here?

thorn urchin
#

I completed the course and then immediately started exam the next weekend

#

0 extra boxes 0 prolabs

vernal vale
#

Guys

shut wraith
vernal vale
#

I also want to learn hacking

thorn urchin
#

I wouldnt consider so. In my current planned roadmap of skills Im still in the beginner phase.

Took me about 9 months total. I had a couple months spread out where I took s break for life stuff

vernal vale
#

From where should I start?

thorn urchin
#

But my standards are high. My beginner scale is apparently some others intermediate scale

shut wraith
warm drift
vernal vale
#

@shut wraith thanks

warm drift
shut wraith
shut wraith
thorn urchin
thorn urchin
barren apex
shut wraith
barren apex
barren apex
#

just need python installed

shut wraith
#

But that wont work

#

Because the target machines are not connected to the ineternet

barren apex
#

Have you done the file transfer method?

#

module*

shut wraith
#

sI just started today

#

But I'm looking forward to it

barren apex
#

theres loads of ways to get files to targets

shut wraith
#

Okay so I download the tools onto my attacker VM

#

and then I transfer based on operating system

#

Are there any restrictions against automation in the exam?

barren apex
shut wraith
#

But I dont want to get used to automation because its not allowed for OSCP

barren apex
burnt sluice
#

Nop there isn't, the CPTS path shows u the manual method of doing everything first, then introduces u to the automated part, so I don't think you'll get used to automation

regal zealot
#

so i just spent like an hour on a question in the nmap module. turns out, the first command i tried in my kali VM (hyper-v) works perfectly in the pwnbox. Any reason for that?

Command: sudo nmap -sCU -p 53 target

On pwnbox i get the nsid of the DNS, which is the flag that i needed. On my kali vm i get nothing except the UDP port - open and TCP -filtered

barren apex
umbral fulcrum
#

can some 1 help me in "Pivoting, Tunneling, and Port Forwarding" : "Meterpreter Tunneling & Port Forwarding" .....

regal zealot
shut wraith
barren apex
barren apex
umbral fulcrum
thorn urchin
umbral fulcrum
#

I'm trying 2 make a Meterpreter Session Establishment

barren apex
echo roost
umbral fulcrum
#

not even go there it just doen't work

barren apex
echo roost
#

I know how. Thought it was in there aleady

#

thanks

barren apex
umbral fulcrum
barren apex
#

did you set the LHOST correct, to you VPN ip, not theres and not your WAN?

umbral fulcrum
barren apex
#

Change the LHOST to the same

umbral fulcrum
barren apex
umbral fulcrum
barren apex
#

DM me

narrow solar
#

.

echo roost
sly kelp
#

There are several things that you have to do on order

File validation bypass is first
Then checking file
Correct extension bypass
Upload directory location

#

Give more details at what step are you right now

sly kelp
narrow solar
sly kelp
#

xss is not the right path here

sly kelp
high dove
#

In the crackmapexec module, section Asrep. crackmapexec ldap 10.129.204.177 -u userslist.txt -p '' --asreproast asreproast.out, i got this error (SMB 10.129.204.177 445 DC01 [*] Windows 10.0 Build 17763 x64 (name:DC01) (domain:inlanefreight.htb) (signing:True) (SMBv1:False)
Traceback (most recent call last):
File "/usr/lib/python3/dist-packages/impacket/krb5/kerberosv5.py", line 61, in sendReceive
af, socktype, proto, canonname, sa = socket.getaddrinfo(targetHost, 88, 0, socket.SOCK_STREAM)[0]
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/usr/lib/python3.11/socket.py", line 962, in getaddrinfo
for res in _socket.getaddrinfo(host, port, family, type, proto, flags):
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
socket.gaierror: [Errno -2] Name or service not known
). Then i found a solution of just adding --kdcHost in the beginning. But it's not working as shown in the module's section.

narrow solar
#

yes i did, i can bypass it

#

but the same issue, i cant find page

#

let me check something

sly kelp
#

okay

sleek urchin
#

can I dm someone about CrackMapExec: Skills Assessment ?

high dove
sleek urchin
sleek urchin
high dove
narrow solar
high dove
#

let me try it

sleek urchin
#

or like that crackmapexec ldap dc01.inlanefreight.htb -u userslist.txt -p '' --asreproast asreproast.out

sleek urchin
sly kelp
sleek urchin
high dove
# sleek urchin upper or lower case letters won;t matter too much

crackmapexec ldap DC01.INLANEFREIGHT.LOCAL -u userslist.txt -p '' --asreproast asreproast.out
SMB DC01.INLANEFREIGHT.LOCAL 445 DC01 [*] Windows 10.0 Build 17763 x64 (name:DC01) (domain:inlanefreight.htb) (signing:True) (SMBv1:False)
Traceback (most recent call last):
File "/usr/lib/python3/dist-packages/impacket/krb5/kerberosv5.py", line 61, in sendReceive
af, socktype, proto, canonname, sa = socket.getaddrinfo(targetHost, 88, 0, socket.SOCK_STREAM)[0]
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/usr/lib/python3.11/socket.py", line 962, in getaddrinfo
for res in _socket.getaddrinfo(host, port, family, type, proto, flags):

#

same

#

/etc/hosts : # The following lines are desirable for IPv6 capable hosts
::1 localhost ip6-localhost ip6-loopback
ff02::1 ip6-allnodes
ff02::2 ip6-allrouters

10.129.204.177 DC01.INLANEFREIGHT.LOCAL

sleek urchin
barren apex
#

msfvenom has an android module doesnt it?

rapid sparrow
#

Submit the contents of the flag.txt file on the Administrator desktop on the DC01 host.

#

Need some help for this question, I already got the domain admin for the one of the current user, and how could I remote it to DC01

high dove
barren apex
high dove
#

Thanks @sleek urchin

high dove
sleek urchin
sacred orchid
#

Hey I know i'm not supposed to ask questions here but do I have to download the ovpn file everytime I want to start a new machine?

sleek urchin
high dove
rapid sparrow
barren apex
sleek urchin
sacred orchid
# barren apex no, unless you change server

Ah alright, whenever I connect to the vpn on kali in virtualbox it doesn't show as connected. It only does this whenever I browse to the htb website in the vm and download the new ovpn file which is like the first step of the box.

But its not really a problem only a minor inconvenience

vital adder
#

read the #rules keep asking for thing like that and you will get the 👢

sleek urchin
rapid sparrow
sleek urchin
#

after you change the admin password, you are able to login in DC01 and get the flag

sleek urchin
sleek urchin
pulsar needle
#

https://academy.hackthebox.com/achievement/285625/158 this module was fun, wish there was one building upon this one

jaunty vigil
#

anyone can help me out this?

pulsar needle
#

Are you the one from yesterday? Lol

tulip vigil
#

Yeaaaa

pulsar needle
#

Then you should know the answer

analog dock
#

Lmfao

rapid sparrow
vital adder
urban sage
#

Thanks for the heads up! @vital adder

naive wadi
#

With RDP and SOCKS Tunneling with SocksOverRDP is it supposed to go

#

Attack Host --> Pivot Host - 172.16.5.150 --> RDP to 2nd Pivot Host 172.16.5.19 --> RDP to Target 172.16.6.155

remote fulcrum
#

Can someone give me a hint for Q Module: Footprinting, DNS, Last question?

barren apex
#

@urban sage can you check your DMs pls

rapid sparrow
#

but I cannot do Kerberoasting

#

I have no idea how to get the DC01's administrator username

vital adder
barren apex
vital adder
remote fulcrum
naive wadi
barren apex
naive wadi
#

is it a setting I'm missing?

barren apex
naive wadi
#

yeah I did

barren apex
naive wadi
#

that's the one from the page

#

same right?

#

just to be clear are you saying that it needs to run on pivothost 1?

barren apex
#

i cant remeber the IPs, But the socks over RDP server exe goes on the pivot host, then GUI one is on the host you want to connect from

naive wadi
#

Yeah that's what I have

#

Pivot host1 = sockoverrdp, Pivohost 2 = RDP server.exe + proxifier?

barren apex
#

I think I had to close the Portable proxifer a few times and re configure and eventually it dropped in

naive wadi
#

ahhh

#

okay will try

#

thanks

barren apex
#

it was proper glitchy for me

#

i think it connected for me twice and then disconnected, so i just RDP via the pivot host to get the flag once I knew I had achieved the aim

#

RDP in a RDP in a RDP lol

naive wadi
#

RDP inception

naive wadi
barren apex
#

I think that means windows is blocking the connection in realtime 👀

naive wadi
#

so the target is blocking me....fun times

#

will do this tomorrow I think

#

thanks for your help

barren apex
#

If i remeber right....

rigid lion
#

I'm stuck here too - any hints?

tight mesa
#

hey guys, I'm stuck with Lab Hard from Password Attack module, I enumerated the target machine and found a RDP port , base on that and the user hint mentioned in the task, i tried to brute forced thru CrackmapExec the passwd but, the mut_password.list doesn't success....

tight mesa
#

after that -sC & -sV

barren apex
#

perhaps try UDP

tight mesa
#

why?, if the target is Windows.....

#

but, I will try it...

barren apex
#

I cant remember exactly, but i think there was a unusal port open somewhere

tight mesa
#

hmm well, this is the UDP scan with no success

sudo nmap -sU -n -p- --max-retries 1 -vv 100.129.35.82

wraith spoke
#

hi there I am working on PIVOTING, TUNNELING, AND PORT FORWARDING section socks 5 tunneling with chisel. The problem I encounter that I cannot run the freshly compiled chisel because the target system had not the right libc6 version.
my question can i compile chisel with the different version need for the libc6 ?

pulsar needle
wraith spoke
pulsar needle
#

No, I used another pivoting technique cuz i couldnt get it to work, then i saw that someone said that it was a problem with the box so idk

barren apex
barren apex
jagged fossil
#

Hey guys I wish to pursue the cloud security track at HacktheBox which modules should I complete first to begin with simple machines such as streamcloud?

tight mesa
# barren apex What ports have you got open?

PORT STATE SERVICE REASON VERSION
111/tcp open rpcbind syn-ack 2-4 (RPC #100000)
135/tcp open msrpc syn-ack Microsoft Windows RPC
139/tcp open netbios-ssn syn-ack Microsoft Windows netbios-ssn
445/tcp open microsoft-ds? syn-ack
2049/tcp open mountd syn-ack 1-3 (RPC #100005)
3389/tcp open ms-wbt-server syn-ack Microsoft Terminal Services
5985/tcp open http syn-ack Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
47001/tcp open http syn-ack Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
49664/tcp open msrpc syn-ack Microsoft Windows RPC
49665/tcp open msrpc syn-ack Microsoft Windows RPC
49666/tcp open msrpc syn-ack Microsoft Windows RPC
49667/tcp open msrpc syn-ack Microsoft Windows RPC
49679/tcp open msrpc syn-ack Microsoft Windows RPC
49680/tcp open msrpc syn-ack Microsoft Windows RPC
49681/tcp open msrpc syn-ack Microsoft Windows RPC

barren apex
tight mesa
#

I tried smb with no success as well

wraith spoke
barren apex
tight mesa
barren apex
neat tide
#

Hello

#

Is anyone up

#

I need help

tight mesa
tight mesa
barren apex
tight mesa
acoustic owl
tight mesa
#

let me see if the machines is not resposive

#

the machines is responding to ping si, it's up

#

but 5985 not found message

#

I'm going to reset it

tight mesa
#

I'm completely lost

barren apex
tight mesa
#

ok.

shut wraith
#

Whats the tool for scanning wordpress sites?

#

nvm it's just called wpscan lol

barren apex
wraith spoke
fleet kite
#

I have something to show the world, You must see this file. & Start reading from line 30 if you are lazy. on telegram search telegram akberxy. i can't uplaod it here that's why

hoary mauve
#

for attacking common services > SMTP >Attacking Email Services, how are we supposed to leverage the credentials (the username and password) into logging into the email server? the module doesn't explicitly mention any tool or resource for doing this. i tried using thunderbird and populating the correct fields (mail server/ports/credentials), but i still couldn't access the email server with the correct credentials

wispy aspen
rustic sage
trail leaf
#

Rank doesn't mean that much. The platform has been out that long that people who played in 2018-2019 had a much easier time than people today (people also frequently cheat).

#

Not dissing SySinclair or anyone else here though, my point is that simply being here, engaging with people, and actually trying is all you need to learn.

wispy aspen
obsidian crag
#

Friends i want to make a complain to the anonymous group..can anyone suggest me the process. And sorry to asking a personal question..it is most important for my life

#

And for my state too

burnt sluice
#

guys, are the attacking passwords modules' skill assessments supposed to take long to solve?

#

i've solved the first one quickly but this second one looks like it might be a while before its solved.

#

Any tips on how to make it faster are appreciated.

burnt sluice
alpine nexus
#

parrot 5.3 is based on which debian version? and where can i see the docs? thank you

tight mesa
#

hey guys anybody knows why this SMB command doesn't work, when I type the passwd (brute forced previously ) for the user:
smbclient --user ||j***|| //<ipAddr>
This is from Lab Hard/Password Attack module

latent sigil
#

smbclient -L //server -U user

#

then write the prompted password

tight mesa
rugged veldt
#

For the SIEM Visualization Example 4: Users Added Or Removed From A Local Group (Within A Specific Timeframe) module. I am submitting the date that is being returned, but its invalid?? I am following all the instructions to a T

latent sigil
#

i havent done the module but have you tried diffrent time formats?

#

for example 01012023 instead of 112023

rugged veldt
#

yup

latent sigil
#

ah then i cant really help you more as you have probably way more experience as i do, i joined like 2 months ago haha

rugged veldt
#

well once u do it let me know

latent sigil
#

alright

rugged veldt
# latent sigil alright

also, sure i may have been in here longer than u but that doesnt mean i know more :) we are all here to help eachother !

latent sigil
#

It's tough but I love it, this platform is really fun, I'm trying to do it in less than 4 months just as a challenge.

iron plaza
naive wadi
#

Doing Pivot Tunnelling Module & The Socks Over RDP challenge keeps stumping me. I keep getting this erro and proxifier keeps failing. Does anyone have any idea?

#

I've reset this lab 3 times & waited 10 mins before connecting etc

#

Ignore me, my idiocy knows no bounds

pulsar needle
#

You probably have this error because you wrote the wrong IP

buoyant grove
#

where do we find the passwords.txt file for Kerberoasting module in the Attackbox?

pine dagger
#

Try rockyou

#

find / -name "rockyou.txt" 2> /dev/null

vital adder
buoyant grove
#

ok thanks

obsidian crag
#

I want to learn how
TCP or UDP payload will be generated

hidden trellis
#

is it possible again to give where im at and what im thinking for whitebox attacks skills assessment to see if im in the ball park?

shut wraith
#

Module: "Getting Started
Chapter: Public Exploits
Question:

Try to identify the services running on the server above, and then try to search to find public exploits to exploit them. Once you do, try to get the content of the '/flag.txt' file. (note: the web server may take a few seconds to start)

Hint:

Search for plugin exploits

The web app on the host is wordpress. And the hint confirms that the exploit has to do with a wordpress plugin. So I searched on google "wordpress plugin exploit". I also searched on searchsploit and metasploit.

But there are countless results even when I specify the version which is 5.6.1. How do I know which exploit to use? Can you please help.

SOLVED:
The web app says the plugin.

restive trellis
#

Hey

winter root
#

Hi, can you tell me how you managed to generate dictionaries for user and pass. I'm using cuppa and username_anarchy. I shorten the password dictionary according to the hint and unfortunately I still don't get the right data, besides brute force lasts over an hour.

winter root
restive trellis
#

Hii

#

Wait whete

#

Where are

#

You all from

winter root
#

So for now, I'm dead. I created the dictionaries according to the information and unfortunately nothing goes through. Thanks for the answer

thick juniper
#

Hi all, I’m on the Using Web Proxies Skills Assessment. I’ve done Q2, 3 and 4 fine but Q1, enabling the disabled button is sticking me. I’ve tried popping getflag=true at the bottom of my request but that doesn’t work, also tried putting it at the top after lucky.php/?. Anyone able to nudge please?

thick juniper
#

I’m using Inspector to enable it and forwarding that through the proxy to intruder but it just doesn’t seem to like it

#

Got it, anyone else stuck on this one, you need to click loads in repeater, you aren’t going crazy haha

high reef
#

good morning all

#

i'm doing the hard lab assessment on the password craccking

#

i keep getting this error when i try and run lazagne.exe

#

all tips on how i should run it ?

silver mesa
#

try .\lazagne.exe all

high reef
#

lol no passwords found

hardy egret
high reef
hardy egret
#

Oh my bad sorry, I was needing help with Attacking Common Services - Easy Lab

acoustic owl
#

What have you tried and what exactly is not working?

shut wraith
#

Is this stupid I'm trying to transfer LinPeas in base 64 to my target host but it's massive

#

I tried to start a python server and transfer with wget but I couldn't connect to my attacker vm from the host machine (yes I used tun0 VPN IP )

tranquil axle
#

Are you connected via ssh? You could use scp then

shut wraith
#

Okay I'll try that. But I'm worried I wont have that option on all boxes

wispy aspen
shut wraith
#

Yes

wispy aspen
#

Can you edit that file with vi or nano?

shut wraith
#

You're write, I should just copy the file since it's not a binary

#

LinPEAS is a python script

wispy aspen
#

Yes

shut wraith
#

nvm it is binary

shut wraith
lapis pelican
#

Excited 😄

wispy aspen
# shut wraith

I would recommend opening up the linpeas.sh in your kali VM, copying its contents, going to your established shell, opening nano, and pasting its contents. If that doesn't work, there is a File Transfers module in HTB Academy with a plethora of options

vast geyser
#

Hi there, I am learning Linux BOF through the Linux BOF module.
I have solved the Skills Assessment but I have question.
I must use ||./leave_msg payload|| in the bash to get root.
Why can't I get the root when I run the shellcode in the gdb?

summer lava
#

so guys.. i found this SSRF vul.. it calls back and it actually dumps the file content.. the system is Windows..
Please any idea on how to exploit this more ?

lapis pelican
vital adder
lapis pelican
#

A webpage or subdomain that is only accessible to internal users.

summer lava
#

Yeah i tried that for ex. it rendered the index.php file but i got no ideas of the files in the web server

lapis pelican
summer lava
#

tried brute forcing and found nothing

summer lava
#

Hey bro! that actually worked

#

i tried accessing the port 5000 like 10.10.10.239:5000 but i got access denied and then i used the local ip

vital adder
#

pls take this to #boxes if you are on the love box

wintry jolt
#

hello guys
if anyone need a job support ping me guys

proven silo
#

Hi, can someone explain the difference between -Pn and --disable-arp-ping?

shut wraith
#

Hello can someone help. I am user 1 what is the command using su to switch to user 2. This is the output of sudo -l:

        ng-519917-gettingstartedprivesc-frc5g-f5b6cf4fc-54kn9:
    (user2 : user2) NOPASSWD: /bin/bash
shut wraith
#

Thanks I just got it

elfin cedar
#

hello. I am at the Skills Assessment - File Inclusion https://academy.hackthebox.com/module/23/section/513
I am at the RCE part. I am poisoning the log and it isn't working. I managed to change the user agent to an example word but when I try the PHP shell code nothing works and I think it breaks the target and I have to keep resetting.

vital adder
#

try with single quotes

elfin cedar
vital adder
#

trial and error

urban valley
#

Hi, can someone help me with the Window Priv Esc module for the Server Operators section? I got the last part where you get the hashes and I'm trying to pass the hash using psexec. Not sure if im using the right syntax but it doesnt seem to work:

elfin cedar
#

it keeps going blank and I keep resetting the target

#

I dont get it, it worked for "&cmd=ls+/" before and now when I try again the same exact way after refreshing the target it goes blank

proven silo
vital adder
elfin cedar
#

ITS RIGGED

#

😭

vital adder
vital adder
proven silo
elfin cedar
#

OMG it keeps going blank its so STUPID

vital adder
#

both of you don't need to add that part here 🤣

vital adder
elfin cedar
#

ITS BROKEN

vital adder
#

spamming the issue isn't going to fix it

#

try restart the target machine

elfin cedar
#

i reset it 20 times going straight to Burp

#

the only command I am sending is catting the flag

#

I use single quaotes and it goes blank

#

I tried refreshing it so many times and not touching it except for that one flag

#

its fucking broke man

vital adder
#

just give it a try and got the flag still in the same firefox f12

elfin cedar
#

I WANT MY MONEY BACK ITS RIGGED 😭 😭 😭

vital adder
acoustic owl
sly kelp
#

I read it 2 times but I couldn't understand what the issue is

#

He is getting blank flag ?

#

Or no output at all ?

fathom pendant
#

Probably not forwarding the request fully in burpsuite

thorn urchin
#

theyre looking at the webpage

#

instead of doing it through burp

elfin cedar
#

like a blank admin panel

sly kelp
#

Man 1 think about HTB is you need 60% thinking skills to solve a lab

elfin cedar
#

I tried in repeater too

fathom pendant
#

Check repeater output

vital adder
#

oh yea i didn't think of that why tf are you looking in the admin panel for the output??

elfin cedar
#

The Response area in Repeater right?

vital adder
#

sure

elfin cedar
#

blank as in 500 Internal Server Error

#

in the repeater

vital adder
#

try the network tab in firefox f12 like i did 🤣

elfin cedar
#

all I get is 500 Internal Server Error

#

I am done

#

its always something with these modules

sharp ore
#

[HELP]
I have noticed that the Penetration Testing Process module has been updated. How can I identify the new additions or easily locate where the updates have been applied?

sly kelp
sly kelp
#

Modules >> Change log

sly kelp
sharp ore
#

Thanks for your help

tight mesa
#

hello guys, I need a hint cuz I'm stuck with the Lab Hard from Password Attack module, let me give you some context what I did so far, I found (brute forced) the password from the user name in the question exercise, with this credential I tried to enumerate SMB : smbclient -L //server -U user obtaining a completely different Path as I got when connect with xfreerdp , this on the one hand.

On the other hand, (once connected to the Win Machine) I found a file which I tried to download it in my attacker machine thru : sudo smbserver.py folder -smb2support /tmp/smbshare getting an authentication error once try to share the file, then I did the same with username & password and, everything was great BUT, the file wasn't shared/downloaded/pasted in my attacker machine, once again I received an error, in this time, the error more or less described the file name was not found and, I'm spelling the file name as is in the windows folder.

Any hint, clue what could be happening or what I'm doing wrong or misunderstanding?

fathom pendant
#

Smb is not gonna give you the same thing because smb works off shared folders

#

But also

#

If you do /drive: you can mount a directory to your xfreerdp session

#

Footprinting?

#

Almost like I've answered this before

#

Without context of where you're stuck or what you've tried it's hard to help

#

Next time include that in your initial ask

#

It's just how imap is

#

You should probably select something

#

Well it looks like nothing is in inbox, but there's another folder you to try

digital pewter
#

This is great. Killer share mate. @rustic sage If you give those a good read that should fill any gaps not covered explicitly in the module. 👍

fathom pendant
#

Note if you didn't delete your screenshot, mod probably did bc spoiler

#

It's alright go share, just keep in mind you may need to edit out things that may reveal answers

#

Well did you see '1 exists' after selecting it?

#

Then all you need to do is fetch it's body[]

#

You can do the fetch all command too if you wanna see why I don't recommend it

#

The command is <prefix> fetch <id> <type>

#

But nothing is needed in the square brackets

#

That's only if you're trying to be more specific (see the articles I linked)

#

If there's only 1 email why are you trying to select the second non-existent one

fathom pendant
#

More specifically the <id> is the sequential list

#

Eh

#

The easier way is using an email client

#

I mean it helps get you banners to answer a couple questions

#

It's also familiarity

#

You're used to GUI applications

#

So terminal seems tedious

#

But also if you don't know what you're doing: it's rougher bc you can't just click around and find out

fleet belfry
#

root

fathom pendant
#

toor

lavish phoenix
#

toor

iron oyster
#

Hello. I am working through the Footprinting Module and running into an issue on the DNS section with the first question:
"Interact with the Target DNS using its IP address and enumerate the FQDN of it for the inlanefreight.htb domain"
I have added the generated IP and domain to the /etc/hosts file but when I try to run
"dig ns inlanefreight.htb@(Generated IP)"
I always recieve a NXDOMAIN status
I even tried nslookup and it gave me the same error
Would really appreciate some help
Thank you

digital pewter
iron oyster
digital pewter
iron oyster
digital pewter
iron oyster
shut wraith
latent sigil
#

i cant believe i made it here with constant dedication, now is only the hard modules left. I had no idea how long this would take and how much effort is required.

#

yes eventually

#

ive been trying to finish all the modules first then tryhard in the boxes, as a refresher and practice before the exam in like 3 months.

#

im not sure its best option but at least its something, and there are like zero CTFs in my area.

#

i have 0 background in the field and this is my first cert

#

so just learning the maximum to not get confused works best for me

tulip parrot
#

Hello I need help for skill assessment 2
Submit the contents of the flag.txt file on the Administrator desktop on the DC01 host.
I got the credentials but I dont know ||how I change the admin password||

trail leaf
tulip parrot
latent sigil
latent sigil
tawdry vapor
#

can anyone help me with Password Attacks > Pass the ticket from linux module with this question? Check Carlos' crontab, and look for keytabs to which Carlos has access. Try to get the credentials of the user svc_workstations and use them to authenticate via SSH. Submit the flag.txt in svc_workstations' home directory.

#

i found the AES256 hash, but i don't found NTLM

tulip parrot
#

@latent sigil can I DM you ?

latent sigil
trail leaf
tawdry vapor
trail leaf
#

I said what I said

#

good enumeration practice

tawdry vapor
#

the question says to look in the cronjobs, that's where I looked

#

😢

#

can you help me?

trail leaf
#

You have found a spot where carlos is storing tickets. Maybe there are other tickets there?

trail leaf
#

you have sent the same screenshot twice

tawdry vapor
#

wow

#

i found it

#

thks

trail leaf
#

enumeration is important 🙃

wraith spoke
#

maybe a stupid question about windows, but is this done by defender and is the solution killing defender or is there an other way?

acoustic owl
echo roost
digital pewter
echo roost
#

Directions are pretty straigh forward. I ran hashcat to mutate the wordlist - hashcat --force password.list -r custom.rule --stdout | sort -u > mut_password.list
then ran/running:
hydra -l sam -P mut_password.list ssh://$ip

echo roost
digital pewter
wraith spoke
#

question: What is a good tool to make notes about networks and their connections, something to visualize it.

wraith spoke
# acoustic owl Wireshark?

Let me enhance the question. For the tunneling and pivoting i will start the skillassessment. It would be nice to draw out the network i discover with any credentials in a nice program, rather then drawing on my desk. is there such a program or do i fall back on powerpoint ;d

acoustic owl
tawdry vapor
#

Could someone help me with the Pass the Ticket section, please? Particularly the last question, "Use the LINUX01$ Kerberos ticket to read the flag found in \DC01\linux01. Submit the contents as your response (the flag starts with Us1nG_)."

I have used linikatz and it provided me with the below

||Ticket cache: FILE:/var/lib/sss/db/ccache_INLANEFREIGHT.HTB
Default principal: LINUX01$@INLANEFREIGHT.HTB

I then I used this kinit linux01@INLANEFREIGHT.HTB -k -t /var/lib/sss/db/ccache_INLANEFREIGHT.HTB||

#

but doesn't work

high reef
#

i'm doing the password attacks

#

assessment

elfin cedar
high reef
#

i have the password for all users expect admin

#

having issues mouting

high reef
#

i'm getting this error message

sly kelp
high reef
#

i got this file from smb enumeration using D creds

#

i was told snmp is on this machine

elfin cedar
#

or do you think it will be ok?

sly kelp
elfin cedar
#

when I do &cmd=ls /

#

I did it once and it worked

#

but if I do the cat command it doesnt

#

and then nothing works

acoustic owl
#

Because you are resending the webshell payload.
Send the webshell once to the logfile, then use it.

elfin cedar
#

what???

#

ok I need to look into that thanks

acoustic owl
#

restart the lab 😉

tawdry vapor
acoustic owl
#

With what?

tawdry vapor
#

"Use the LINUX01$ Kerberos ticket to read the flag found in \DC01\linux01. Submit the contents as your response (the flag starts with Us1nG_)." for password attacks modules

#

I have used linikatz and it provided me with the below

||Ticket cache: FILE:/var/lib/sss/db/ccache_INLANEFREIGHT.HTB
Default principal: LINUX01$@INLANEFREIGHT.HTB

I then I used this kinit linux01@INLANEFREIGHT.HTB -k -t /var/lib/sss/db/ccache_INLANEFREIGHT.HTB||
but doesn't work

acoustic owl
#

Let me check my notes

elfin cedar
#

it didnt work

tawdry vapor
#

hmmmmmm

tawdry vapor
elfin cedar
#

Where am I going wrong?
First thing I do is refresh the access.log page to intercept in Burp
Then put in the PHP web shell in the User Agent
Press Forward
Then I refresh the page again to enter RCE in Burp

acoustic owl
acoustic owl
tawdry vapor
elfin cedar
acoustic owl
#

Restart the Lab and start from scratch.
One wrong character in the log and the log is broken -> Error 500

tawdry vapor
elfin cedar
#

ok but I have tried restarting like 20 times lol

acoustic owl
tawdry vapor
#

hmmmm

elfin cedar
#

stil 500 Internal Server Error on the 2nd repeater tab

#

its BROKEN

mortal echo
#

Can someone help me use the matplotib module?

oak sequoia
#

Hi any tip fixing this problem when doing RDP in File Transfer Module?

mortal echo
#

Yes

#

Maybe try verification again

oak sequoia
#

How can I do that?

elfin cedar
#

THIS IS SICK MAN

mortal echo
#

Can anyone help me with the plot?

#

I need to put a pic

tawdry vapor
elfin cedar
#

oh my GOD I forgot ONE apostrophe?????

acoustic owl
tawdry vapor
#

my head is bursting with pain right here lol

#

this module is so confuse

acoustic owl
tawdry vapor
#

ok

elfin cedar
#

I spent hours on that one single apostrophe missing

#

I cant believe this

#

😭

mortal echo
#

I was trying to make an graphical program output but it did not work @elfin cedar can I dm you an example?

frank moon
#

hi someone can help me with this question ? Some PowerShell code has been loaded into memory that scans/targets network shares. Leverage the available PowerShell logs to identify from which popular hacking tool this code derives. Answer format (one word): P____V___

in https://academy.hackthebox.com/module/214/section/2285 Hunting For Stuxbot ?

elfin cedar
#

man that wore me out

#

ty for the help

frank moon
acoustic owl
acoustic owl
frank moon
misty mural
#

I see we’re all having fun with Kerberos tickets today.

#

Gotta love the learning process!

burnt sluice
#

or u can try escaping the excalamation mark

echo roost
tight mesa
#

hey guys, can I think in the Module Password Attack under Lab Hard, the file sharing features is not allowed in the target machine?

#

I cannot share a folder with xfreerdp and remmina even

echo roost
#

can you enabled an smb share on kali?

#

or spin up a python3 -m http.server 80?

tight mesa
#

I'm not using kali

echo roost
#

doesn't matter

#

can you spin up an smb share with impacket-smb?

tight mesa
echo roost
#

try this attack machine python3 -m http.server

fathom pendant
#

So the xfreerdp /drive: option doesn't work?

echo roost
fathom pendant
#

Hmm

tight mesa
echo roost
#

one sec I have a resource

fathom pendant
#

Idk I didn't have issues when I ran it

#

¯_(ツ)_/¯

#

So I'm not gonna be of help troubleshooting

#

Could just need a lab reset to try again

tight mesa
#

that's why I'm thinking maybe the feature is not allowed in the target

fathom pendant
#

Usually wait a few minutes

#

Fileshare is allowed

#

And drive mounting is absolutely available

echo roost
#

from attack sudo impacket-smbserver share . -smb2support -username saul -password goodman

tight mesa
#

hmm ok., so I'm not sure what it's happening

fathom pendant
#

You're probably doing something incorrectly

echo roost
#

then on windows \\AttackmachineIP\share

tight mesa
#

one sec

tight mesa
echo roost
#

see if it works

fathom pendant
#

\\see

echo roost
#

ah thank you I was just messing with that

#

good ole markdown

#

I fixed it partyTroll

urban valley
#

Has anyone completed the Citirix breakout section of Windows PrivEsc module? I'm trying to access the share on 10.13.38.95 via Paint in order to get powerup.ps1 and UAC-Bypass.ps1 but it says the share cannot be found?

elfin cedar
#

I was just wondering, I am not in a module but I wanted to try and do a box related to the one I just completed. I just spawned the machine but when I enter it into the web browser it says connection failed. I dont think the hosts file needs to be edited does it?

thorn urchin
#

it might

#

depends on the box

elfin cedar
#

oh man

#

you mean I need to enumerate for a subdomain maybe?

#

isnt that what you put in the hosts file along with the ip address?

balmy radish
#

If it is a retired machine you can check the ippsec video on YouTube

elfin cedar
#

thank you

thorn urchin
#

Sometimes while hacking stuff you may need to hack things too

elfin cedar
#

when he enters the ip address it just goes straight to the page its supposed to be

#

man I thought I was ready to just test out one box

balmy radish
#

Are you on the academy vpn or the vpn for the box?

elfin cedar
#

I am on the vpn for the box but I dont wanna clutter up the module chat sorry

tidal mango
#

On the Network Enumeration with NMAP modules, the Medium lab, does anyone know if there is a way to find the flag using a VM? I can get it using the pwnbox but can't seem to figure out why it does not work with the VM. Thanks!

wind juniper
#

Hello, I need some help with Information Gathering - Web Edition. Active subdomain Enumeration Question 4: What is the FQDN of the IP 10.10.34.136. This address doesn't show up in any of my dns enumeration. I've tried a reverse lookup with dig, nslookup and host and I'm coming up empty. What am I missing?

tidal mango
wind juniper
#

dig @10.129.250.101 inlanefreight.htb axfr

#

nothing in there for the 10.10.34.136 address

tidal mango
wind juniper
tidal mango
wind juniper
#

This has probably been the course I've struggled most with so far, ourside a bit of the web proxy stuff. But I've learned a lot - this was the first time I had to break down and ask for help

tidal mango
quick magnet
#

Hi i'm stuck in module attacking common service SQL
can't connect to mssql

  • try mssqlclient in my parrot
  • try mssqlclient in pwnbox
  • try sqsh in pwnbox
urban valley
# urban valley Has anyone completed the Citirix breakout section of Windows PrivEsc module? I'm...

Solved it. If anyone can't import UAC Bypass and Powerup.ps1 like me, what I did was I copied the code from both files on my Kali, made two new text files on the citrix machine (PowerUp.ps1, UAC-Bypass.ps1) and then pasted the code into them. The commands they give you on HTB Academy to execute the tools might not work but if you google for different commands to execute the files, you'll get your answer. This method is pretty scuffed but hopefully they fix the machine or something.

mortal echo
#

Hello guys.

trail leaf
#

I did this one a few days ago and it seemed to work fine, although it was slow. You need to enter the share through the bottom text field, not the top.

#

Good on you for finding an alternative route though

urban valley
urban valley
quick magnet
trail leaf
urban valley
trail leaf
#

No clue then

uncut flint
#

I need help on MonitorsTwo machine, can someone DM me please

tight mesa
#

guys, any idea why hashcat is giving me this error with this command:

hashcat -a 0 -m 13400 login.hash ~/<dictionaryPath>/mut_password.list
[s]tatus [p]ause [b]ypass [c]heckpoint [f]inish [q]uit =>

#

and I'm not been able to crack the password

#

any hint, idea..???

iron plaza
copper thunder
#

Is this like the general chat

tight mesa
iron plaza
fathom pendant
fathom pendant
elfin cedar
#

Hi

#

damn it

#

sorry

#

please Marcie I need help

fathom pendant
#

pika_sip 🕰️

elfin cedar
#

lol

#

When I put the ip address of this box into the address bar it says Secure Connection Failed. I don't even know what, if anything, I need to put in the hosts file. I am just trying out a box that is recommended after the doing the File Inclusion module (Beep).

fathom pendant
#

<secure> are you doing http://<IP>

elfin cedar
#

first thing I tried

#

same thing for http

fathom pendant
elfin cedar
#

I mean yes I did do https

fathom pendant
#

Are you being told to attack a specific domain?

elfin cedar
#

I am not told anything

#

I just threw the thing in firefox

fathom pendant
#

I haven't done the file inclusion module

elfin cedar
#

oh dang

fathom pendant
#

And you're attacking the spawned target yes?

#

Not the example ip

elfin cedar
#

you were the first to ever help me

#

spawned target yes

#

I peeked at a video walkthrough and they were able to accept the security risk through Firefox but I dont get an option.

#

Its just a general question

#

I am connected to the vpn

fathom pendant
#

advanced optoons

#

Under the unable to establish secure connection

elfin cedar
#

right I dont get that

#

I looked at ippsec's video and when heput the ip address in the browser the page loaded without any issue

fathom pendant
#

Why is the target 10.10.10.7

#

Usually targets are 10.129.x.x

elfin cedar
#

I have no idea 😭

fathom pendant
#

Weird

#

Anyway update/restart your system

#

You can also

#

Just click "learn more"

elfin cedar
#

There is no option to add a security exception to bypass this type of error.

#

it says lol

#

I thought it was something simple I am missing

#

as soon as I spawn the machine I get an error

#

Its always something

fathom pendant
#

I understand this says disable but the principle should be the same

#

This is more of a firefox error than anything

elfin cedar
#

wow

#

ily

#

that link said to change the "tls" minimum value in Firefox to 2, but that didn't work, so I changed even lower to 1 and it popped

#

thank you @fathom pendant

fathom pendant
#

You wanna know how I found it? By googling

elfin cedar
#

omg

#

you broke my heart

fathom pendant
#

It's a useful skill to learn

elfin cedar
#

and you twist the knife!!

rich perch
#

Hello! I'm stuck at the DNS section of the Attacking Common Services module. I found a few other subdomains and I tried doing AXFR zone transfers but I keep getting "transfer failed" with dig.

gilded talon
#

tbh i feel too fucking stupid to understand this. even as someone who has never done this before it looks like to me i am trying to do calculus in arabic upside down

#

should i be completing my security+ before even going through the hack the box academy ?

rapid sparrow
#

It looks like my dad

fathom pendant
rich perch
#

I honestly don't even know what I'm doing lol

fathom pendant
sly kelp
#

You will get the toolset that you need to use accordingly

fathom pendant
#

That's where you fucked up

#

You need to specify the name server with @ using dig

#

Try dig axfr subdomain @ip

#

Should probably delete this message btw as it's a spoiler

rich perch
#

I got it. Thank you so much!!

fathom pendant
#

You fundamentally misunderstood how dig works, it happens

#

But basically it's dig request target @nameserver/ip

rich perch
#

ty! this is going in my notes 🙂

fathom pendant
#

Similarly nslookup request $target $nameserver

gilded talon
#

@sly kelp @fathom pendant oh I see. I was doing whatever it said to start on with the Pen Test Tiers and I was like HUH

fathom pendant
gilded talon
#

ohhh yeah im like starting from ground 0

fathom pendant
#

Then I suggest to get your feet more wet as well places like tryhackme

#

As they are super noob friendly

gilded talon
#

fire!

sly kelp
fathom pendant
gilded talon
#

Oh nice i saw this one in the info sec fundamentals

#

thank you guys i literally had no idea and was getting super frusterated

#

frustrated

fathom pendant
#

Most of the people that are "new" to this have some experience with Linux and windows, especially navigating

gilded talon
#

oh yeah no im actually new

#

like out of the womb

fathom pendant
#

Yeah

#

That's why taking it at your own pace is super important

gilded talon
#

well i appreciate it

fathom pendant
#

If you ever need module assistance just ask in here with an example of what you tried, and what you're struggling with

gilded talon
#

ok thanks

#

wil do

fathom pendant
#

Mhm

#

Most of the people that have completed the modules know what user you're talking about with first letter then * for instance j*, k*

#

In context of the modules we know where you're at

rich perch
#

hello! I was stuck on the DNS section of "attacking common services" a few hours ago, now I'm stuck at the Mail section. The questions is: "Access the email account using the user credentials that you discovered and submit the flag in the email as your answer."

I have the username, have the password, and connected to IMAP using telnet. However, I can find only one email and there doesn't seem to be a flag in there... the email body just says "Password change". am I missing something?

fathom pendant
#

That looks like it's just the title of the email

rich perch
fathom pendant
#

Perhaps fetching body[] is more useful

#

As you can see. You have a bunch of "nil" data that the "all" command isn't parsing

rich perch
fathom pendant
#

The fetch all is useful for getting data info

#

It's not really mentioned in the footprinting module

rich perch
#

it's the second time you've helped me today. Thank you dude ❤️

fathom pendant
#

The non-cli method is using an email client like evolution

rich perch
#

thanks

#

which one? the one coming out?

#

are you doing cpts path too

sudden flax
#

hi can anyone help me with virtualbox and thb how connect vpn to website i trying now but it doesn't work

sudden flax
#

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>404 Not Found</title>
</head><body>
<h1>Not Found</h1>
<p>The requested URL was not found on this server.</p>
<hr>
<address>Apache/2.4.29 (Ubuntu) Server at 10.129.145.53 Port 80</address>
</body></html>
and website show me apache2 ubuntu

eager merlin
#

you have Parrot running on Virtualbox?

sudden flax
#

oracle Virtualbox

#

kali linux i new

eager merlin
#

does the VPN give a error?

#

did you read how to connect?

rapid lion
#

hello guys ,i have a problem need to ask

acoustic owl