#modules

1 messages · Page 133 of 1

sly dome
#

black box web for me is a pain

#

when you do not see the response and all that stuff

rustic sage
#

said no one ever

hallow kiln
#

said me just now 😂

#

I love AD

sly dome
hallow kiln
#

how did you know

sly dome
dim hound
#

but doesn't seem to get the information what I need 😁

brittle tendon
#

Hello every one, i need some help : ffuf -w /opt/useful/SecLists/Discovery/Web-Content/burp-parameter-names.txt:FUZZ -u http://94.237.53.115:40888/admin/admin.php -X POST -d 'FUZZ=key' -H 'Content-Type: application/x-www-form-urlencoded'
when i run this command i get no answer, here's what i found : :: Progress: [2588/2588] :: Job [1/1] :: 1708 req/sec :: Duration: [0:00:05] :: Errors: 0 ::
[20:51]
would someone please help ?

orchid pine
#

yo huys i reviewd my memory watached some youtube video and i read the module about networking in the academy and this till not making sens for me

#

they are on the same network even tho chat gpt say so

#

im feeling dumb like for real

#

wht its /24 when the subnet mask in 255.255.0.0

harsh patrol
#

@orchid pine where do you have /24? which module?

#

pivoting moule?

orchid pine
#

yes

harsh patrol
#

maybe if this helps: both 172.16.6.0/24 and 172.16.5.0/24 is in 172.16.0.0/16, and sometimes it makes sense to add only a part of the subnet to route through a pivot host.

lusty thicket
orchid pine
#

i can only acces 172.16.0.0/16 i can only acces 172.16.5.0

#

i cannot acces 172.16.6.0

harsh patrol
#

I don't remember that module very well, and my notes only consist of some proxychains stuff

#

maybe try to add multiple pivot routes

#

whats your ip a of your starting host?

sly dome
harsh patrol
#

@orchid pine maybe try with multiple, smaller leaps / pivots, that's how I solved this module. I used proxychains, but maybe you can do it with the pivot module in meterpreter

orchid pine
#

i solved it

#

it just it didnt make sens somehow

#

that i have a route too 172.16.0.0

#

but i cannot reach 172.16.6.25/16

rapid kiln
#

hi @here , require help for Attacking Common Services - DNS
I am stuck on "Find all available DNS records for the "inlanefreight.htb" domain on the target name server and submit the flag found as a DNS record as the answer. "
Can I DM someone I have try using subbrute with the nameserver got from nslookup

harsh patrol
#

@rapid kiln sure, glad to help if I can

rapid kiln
#

Thanks @harsh patrol , Can I DM you will send you details what I have try

harsh patrol
#

yeah

rapid kiln
#

Hi @harsh patrol DM you

mossy hatch
#

Module Name : Password Attacks
section name : Pass the hash
question : Connect via RDP and use Mimikatz located in c:\tools to extract the hashes presented in the current session. What is the NTLM/RC4 hash of David's account?
can someone help me the section dont talk about dumping hashes so i dont know the one for david and dont know how i can find it

sly dome
#

Connect via RDP and use Mimikatz located in c:\tools to extract the hashes presented in the current session

thorn urchin
mossy hatch
sly dome
#

it is telling you how to do it

orchid pine
#

Introduction to Active Directory Enumeration & Attacks on this module they will talk again about pass the hsah and pass the ticket ?

sly dome
#

do not forget about the "exit"

mossy hatch
mossy hatch
# sly dome it is telling you how to do it

mimikatz.exe privilege::debug "sekurlsa::pth /user:Administrator /rc4:30B3783CE2ABF1AF70F77D0660CF3453 /domain:inlanefreight.htb /run:cmd.exe" exit i did this but dont know what to do next

orchid pine
#

cuz i kinda forget XDD

sly dome
#

mimikatz.exe "privilege::debug" "sekurlsa::logonpasswords" "exit" >> c:\tmp\mimikatz_output.txt

#

its asking you for the current session

orchid pine
#

and im about to start AD

sly dome
#

PTH and PTT techniques are widely used in AD enviroments

#

so i guess yes

orchid pine
#

and i want to know if they talk about it on this module or i need to go and review opassword attacks

mossy hatch
#

i dont understand.....just want to give up on this f question

orchid pine
#

dont give up

#

broo i dint write notes about this and im on my place

#

i wish i can help

mossy hatch
#

yeah i'll try later it's been a day on this question i'm so mad ahah

orchid pine
#

u can type the question on google

mossy hatch
orchid pine
#

and u can visit the forume

#

website

#

u will find a lot of people helping there

#

chech it out

mossy hatch
sly dome
#

if it is asking you to do it in RDP probably you have to dump the memory

sly dome
#

but idk u can do it from PS also

fathom pendant
#

You can literally look at what the course sections are when you click on it

sly dome
#

idk man it is that easy that maybe ur doing it complicated

rain briar
#

can anyone help on the attack common services dns section

sly dome
#

sure just ask

rain briar
#

i found 4 servers but cant axfr with any of them

sly dome
# sly dome

@mossy hatch dm me to double check ur process

rain briar
#

ive read the instructions but am struggling here

#

subbrute keeps erroring too

orchid pine
#

tell us

#

what you did till now

#

from the first and the error you got

rain briar
#

wasnt fionding anything with subbrute so i went with dnsenum and found ns helpdesk and control.inlanefreight.htb

#

tried to axfr all of those with the machien IP

orchid pine
#

give me like 5 min and ill be with ya

rain briar
#

ok

#

cool

sly dome
#

maybe axfr is disabled

fathom pendant
#

There is another

rain briar
#

how would you enable it

fathom pendant
fathom pendant
rain briar
#

Lol Rafa

#

Let me@confirm

#

it does

fathom pendant
rain briar
#

It does have the spawned ip

#

Keeps going to no nameserves found trying fallback list

sly dome
#

yea axfr is enabled

#

im just completing random questions just to test xDDDDDD

rain briar
#

Ya idk

orchid pine
#

you have the server name or not btw

sly dome
#

subbrute works > then axfr

#

cant say more actually

rain briar
#

I have ns.inlanefreight.htb

#

And control and Helpdesk

#

And support

sly dome
#

i did not find any of those

orchid pine
#

yeah then you u use the name server in the resolver.txt

sly dome
#

you just bruteforce the subdomains

orchid pine
sly dome
#

the only resolver you have is the actual ip

#

you cannot find more resolvers with the information provided

#

python3 subbrute.py inlanefreight.htb -s ./names.txt -r ./resolvers.txt

#

the command is on the module

rain briar
#

thats what i have

sly dome
#

you will find one human subdomain

rain briar
sly dome
#

why use names small

#

tho

rain briar
#

i tried regular as well

fathom pendant
#

What does your revolvers.txt file look like

#

Because that's where the issue is with subbrute

rain briar
fathom pendant
#

You don't need the ns line

#

Also if you added the site to your /etc/hosts sometimes it acts dumb

sly dome
#

but should it makes a difference?

#

having an extra resolver

fathom pendant
#

It doesn't know how to resolve ns.inlanefreight.htb

orchid pine
fathom pendant
#

As htb isn't a valid tld

sly dome
#

ahh yea

#

i only have "<IP> inlanefreight.htb"

#

in the hosts

orchid pine
#

i added bouth and it worked

sly dome
#

both?

#

the exercise only provides 1 ip and 1 domain

fathom pendant
#

I think they mean to /etc/hosts and to revolvers.txt

sly dome
#

ahh

#

makes sense

#

but in resolvers is weird if u add random top level domain as marcie said

#

im looking at the python code

fathom pendant
#

¯_(ツ)_/¯

orchid pine
#

it worked for me

#

and this ismy resolver

rain briar
#

i literally have all that

#

weird

acoustic owl
# orchid pine

This works, but requires additional, unnecessary DNS requests.
Better specify the IP directly

fathom pendant
# orchid pine

I just did it (used usb tethering to get a connection going) and only put the ip in resolvers.txt, after a minute I got the right answer

rain briar
#

I found Helpdesk

fathom pendant
#

Nope

rain briar
#

But stuck from there

fathom pendant
#

You should be able to do it with the default names.txt file

rain briar
#

Hmmm

orchid pine
#

just sepcify the adresse id right

#

i will try that

acoustic owl
fathom pendant
#

^

#

Like I said its completely possible with the default names list and ip in resolvers.txt

#

As stated I JUST did it and it's working just fine.

#

Was able to axfr to the proper subdomain

fading oracle
#

Hi! i have a question regarding,SOCKS5 Tunneling with Chisel module

#

i copied chisel over to the target machine

thorn urchin
#

I swear if you say GLIBC

fading oracle
#

:DDDD

thorn urchin
#

learn to statically compile

orchid pine
#

😂

fading oracle
#

....

#

very funny

#

guess since its a go binary

#

its not gcc

#

i mean other than gcc i never used anything else before

orchid pine
#

im not gonna liebut i used

#

chat gpt to staticly compile

#

ligol-ng

orchid pine
#

learn it

#

└─$ CGO_ENABLED=0 go build -o agentcompile -ldflags '-extldflags "-static"' ./cmd/agent/main.go and i used this to compile it staticly

hallow kiln
#

huh, the windows attack host for LLMNR/NBT-NS Poisoning has no desire to spawn properly today

#

took a few resets

fading oracle
#

i did this

#

sudo go build -o chisel1-ldflags '-w -s -extldflags "-static"' main.go

#

had no errors

#

copied over

#

still the same error

hallow kiln
#

the module says that if you're getting an error, try an older version

#

well, different version which would mean older in this case

thorn urchin
#

Thats not the correct way to build statically

orchid pine
fading oracle
#

how i can do it properly? or where i can read about it since fuckin chatgpt fucked me over with this syntax

#

why they didnt put compiling into the modules?

#

i love trial and error learning no doubt

#

but...

thorn urchin
thorn urchin
sly dome
#

ur missing

#

CGO_ENABLED=0

#

why don’t academy include a section about using google

thorn urchin
#

why google when you can use chatgpt and get 5 year old outdated answers

hallow kiln
sly dome
#

i will never support chatgpt, like im smarter than chatgpt

sly dome
thorn urchin
#

Ive liked chatgpt when Im exploring a concept out a bit. But it I need something specific its always better to just hunt down an actually accurate resource

hallow kiln
#

it can be helpful for some things, but yeah, google is the first stop the majority of the time

sly dome
#

i have found some weird answers on chapgpt but probably was my fault

#

my google-fu is stronger 🤣

#

ive seen courses about learning chatgpt btw

hallow kiln
#

oh yeah, there's one from ec council 💀

fading oracle
#

allright i get the point no need to kick me when i am laying on the floor

#

i managed to do it, another question

#

everytime i do this i always should manually edit the proxychains.conf or is there a better way to change between socks4 and 5?

thorn urchin
#

technically we were roasting shadowexe too, you were only getting half of the kicks

#

manually edit or write a little bash script to do it for you

#

I like having little bash scripts for pivoting. I have one for autostarting my ligolo setup

orchid pine
#

dont go to hrash XD

thorn urchin
thorn urchin
# sly dome yoo sweet

just like three lines, and dumbly takes an argument in for the subnet for creating the route

sly dome
#

i thought so

swift valley
#

hello

#

i need help plz

lusty thicket
swift valley
#

why

thorn urchin
#

because its such a low effort ask

formal root
#

Hi everyone, Im stuck on 'Service Authentication Brute Forcing' from the module 'Login Brute forcing'. When I try to SSH to use b.gates with the password I get the following question: Are you sure you want to continue connecting (yes/no/[fingerprint]

#

When I press, yes

#

I get this: Warning: Permanently added '94.237.53.115' (ECDSA) to the list of known hosts.
b.gates@94.237.53.115: Permission denied (publickey).

#

What can I do?

swift valley
sly dome
#

check the hint

#

i mean

#

the hint or the question itself?

#

iirc you have to write PORT instead of the number

sly dome
# formal root I get this: Warning: Permanently added '94.237.53.115' (ECDSA) to the list of kn...

As a data scientist or software engineer you may have encountered the Permission denied publickey error when trying to access an Amazon Elastic Compute Cloud EC2 instance via Secure Shell SSH This error occurs when the SSH client fails to authenticate the users public key with the servers authorizedkeys file This blog post will explain the commo...

swift valley
sly dome
#

check you dont have trailing spaces

#

or leading one

#

ones*

formal root
sly dome
#

i send an article because that error can be caused by several factors

#

double check everything

#

what we know is that from the server side everything is ok (academy provides a well configured environment in the ~99% of the cases) 🤷🏻‍♂️

rustic sage
sly dome
#

nope

mossy hatch
#

am i the only one that can't access the academy?

sly dome
#

gateway error as usual from cloudflare

#

🤣 🤣

bold pebble
#

just for me the web doesnt works ?

high reef
sly dome
#

it seems academy is down probably affecting modules

high reef
#

probably i can't even move back and forth

sly dome
#

yap

high reef
#

the new box visual is crashing the system

formal root
#

Yeah servers down

sly dome
#

all down

swift valley
# sly dome check you dont have trailing spaces

I am confident that there are no spaces or incorrect characters in the answers provided, as I have meticulously reviewed them. I have successfully completed seven modules thus far, encountering issues exclusively with this particular task

formal root
#

they are up now

#

the servers

sly dome
#

how can i help you?

#

that is the correct answer

swift valley
#

this correct or no

#

if no give me name of subdomin or new list name to re scan

high reef
#

any help with my section ?

thorn urchin
#

as stated before. the answer wants PORT not the literal generated port number

swift valley
#

i min

swift valley
#

Bad gateway Error code 502
Visit cloudflare.com for more information.
2023-09-30 23:35:51 UTC

thorn urchin
#

gotta wait, htb infrastructure is a little wonky right now

swift valley
#

I realize now that there was a misunderstanding on my part; I appreciate your assistance in clarifying it for me. The answer has been accepted. Thank you.

sly dome
#

lets go mannn

polar skiff
#

F academy ?

polar skiff
plain shell
#

rip academy

final maple
#

I was having the same issue. I had to use wget to download the latest version of chisel and run chisel from that folder.

#

Anyone here complete the first question on the Crackmapexec Skills Assessment who can help me out?

fading oracle
#

in the last module SOCKSRDP

#

i copy over the binarys but when i try to execute regsvr32.exe SocksOverRDP-Plugin.dll

#

it gives this error

#

this is the very first step setting up so idk what id "did" wrong?

hallow kiln
#

are you in the correct directory?

fading oracle
#

yes and iam running it as administrator as said

#

in the module they just copy it to the desktop

sly dome
#

did u disable real time protection

#

i think the dll is getting removed 🤣

fading oracle
#

i didnt disable anything

#

but now i will:D

sly dome
#

check defender also

fading oracle
#

it is turned off

sly dome
#

then it has to be real time protection

wooden fossil
#

has anyone done Windows Fundamentals?

#

I'm mainly stuck on the skills assessment, I have been able to get the SID of the user i created but it keeps saying that it is the wrong answer

#

same thing with the group SID, I have gotten it but still prompts it as a wrong answer

pulsar nebula
#

Hey stop being fake shaow

wooden fossil
#

?

#

also weird update, it seems to accept the user SID as the answer for the group SID but still doesnt accept either for the question about the user SID

#

so in short, have zero clue what im doing wrong

tame ermine
#

i am now subscribed to academy silver but can in use hackthebox bwnbox

#

?

quick crane
glad edge
fathom pendant
atomic briar
#

Man 25 sections through AD enum/attack, 11 more to go.... so good but so big! Brain's starting to melt...

tidal mango
#

I have a question on Pivoting, Tunneling, and Port Forwarding -- Web Server Pivoting with Rpivot Section. I setup the rpivot on my Kali box and the ubuntu pivot host. I can curl the webpage in question (last question) and see the flag, using proxychains, but when I try to run proxychains firefox, it will never connect to the page with firefox. Has anyone expiernced this? or have ideas ? Thank you!

fathom pendant
#

Might need to comment out one of the proxy lines if there's multiple sometimes its a weird issue

earnest junco
#

Hi...
When a module says it takes 2 days. Is it an actual 2 days or 16hrs(cause i have noticed the time length is either equal or less than 8hrs) ?

fathom pendant
#

It's mostly there for companies to have an idea for employees to get through content. (Enterprise stuff)

#

But the actual time varies from person to person

fathom pendant
#

And sometimes you'll struggle on a module and take 3x the time

short hare
#

Can anyone help me in
ACTIVE DIRECTORY ENUMERATION & ATTACKS: Living off the land

Question:
Utilizing techniques learned in this section, find the flag hidden in the description field of a disabled account with administrative privileges. Submit the flag as the answer.

I used this:
net group "Domain Admins" /domain

And got this users
administrator backupagent bross
clusteragent dclick freightlogisticsuser
jhermann lab_adm ldap.agent
mmorgan mrb3n nagiosagent
proxyagent solarwindsmonitor sp-admin
sqldev svc_qualys svc_sccm

To find disable accounts used this: Get-ADUser -Filter {Enabled -eq "False"} | select name
name

Guest
krbtgt
Betty Ross
Jessica Ramsey

But none of the users have the flag

final maple
radiant verge
#

hey can someone help me, im trying to donwload a program called "process hacker" and i want to make sure its safe before i downlaod it./ can someone lp[ease help me and let me know?

#

has anyone heard of the program?

radiant verge
#

what did i do did i break any rules?

final maple
autumn pilot
#

nothing wrong with the question

radiant verge
#

im very confused, which rule did i break?

#

which rule did i break???

autumn pilot
#

If I recall correctly, Process Hacker was part of the sysinternalssuite

radiant verge
#

im using this so i can remove viruses from my computer

final maple
radiant verge
radiant verge
lusty thicket
low girder
radiant verge
low girder
#

He got a bit confused.

radiant verge
#

ahh yeah i see how this is, the assumtions

final maple
#

My bad, you didn't break a rule...but it still sounds like you are asking people on here to help fix your computer rather than help you through HTB material

radiant verge
lusty thicket
radiant verge
fathom pendant
lusty thicket
final maple
fathom pendant
#

¯_(ツ)_/¯

lusty thicket
#

¯_(ツ)_/¯

low girder
#

It is used in Malware Analysis module

radiant verge
fathom pendant
#

And tbh I'd trust htb not to provide a malicious link to a tool

fathom pendant
#

Just download the tool from the official website source and you should be good

radiant verge
#

And also, With you not being to knowleagble enough You PINGED THE STAFF!

final maple
#

Well, like he said...he wasn't asking because it was in a module, he was asking to help remove viruses from his personal computer. It is like asking about tcpdump to help with your personal home router issues in this chat room.

low girder
#

Let us have a relevant discussion on the channel. A mistake can happen.

fathom pendant
#

Either way

low girder
#

@radiant verge Is your question answered?

radiant verge
fathom pendant
#

In future read #welcome and see how you can access more of the server

radiant verge
#

Firstly, Have you heard of "Process hacker"?

low girder
#

I have

lusty thicket
fathom pendant
#

To maybe ask your question in a more relevant place

radiant verge
# low girder I have

Should i be good with installing it?, I scanned the EXE with virustotal but its coming up as Riskware and unsafe, I've seeen others install this application so i dont know if its safe or not

fathom pendant
low girder
fathom pendant
#

Short answer: anything that gets process info and accesses info like that is gonna be classified as riskware

#

Even if not malicious

radiant verge
low girder
#

Yep

final maple
radiant verge
pulsar needle
#

I cant find the Credentials (Attacking Common Applications - osTicket)

radiant verge
low girder
final maple
pulsar needle
radiant verge
#

Is source forge not trusted?

low girder
#

And I believe it is safe

fathom pendant
#

Yeah source forge has a bunch of adlinks

low girder
radiant verge
fathom pendant
#

This is the part that has the actual downloads

#

The rest are all adlinks

radiant verge
fathom pendant
#

I'm on mobile so it might be slightly different

radiant verge
#

oh

#

Yeah well for me when i go try to install process hacker on the official site, it redirects me to Source Forge and than the download just loads

fathom pendant
#

Ah

#

That link is for 2.39

#

I think mine is the older version on the site

#

Ah the Google link I had was an archive link

pulsar needle
fathom pendant
#

Just ask your question

dreamy solar
pulsar needle
fathom pendant
#

That is indeed the module getting-started

dreamy solar
pulsar needle
# pulsar needle

Now I cant try any other passwords, i read online and it just told me to use the default password, but it didnt work, so i tried to brute force it, didnt work, so now I am just stuck

fathom pendant
pulsar needle
#

I did

fathom pendant
#

Rip

pulsar needle
#

But the password didnt work

#

It is () right?

fathom pendant
pulsar needle
#

Welp

#

F

dreamy solar
fathom pendant
#

@dreamy solar hint 1: identify if this is public or private ip

#

Because it sounds like you tried to do an Nmap scan on the ip which is not what you want to do

fathom pendant
#

Hint 2: firefox

dreamy solar
fathom pendant
#

Why are you looking at memory aid?

dreamy solar
#

because there is a "hint"

fathom pendant
#

Yrs

#

Yes*

#

But what is actually pushing you in the direction of "memory aid"

dreamy solar
#

I can't resolve the question even after several hours of plug-in research.

fathom pendant
#

Think about what my second hint could mean

#

Perhaps there's a reason you're given the port alongside the ip

#

Ugh cloudflare being dumb rn

lusty thicket
#

then you might get the hint

fathom pendant
#

The hint is referring to if you've already looked at the ip:port

#

Not as a "before you even do anything"

dreamy solar
#

Okay okay ^^" this port does not exist NotLikeThis

fathom pendant
#

Wdym

dreamy solar
#

So either I'm completely stupid or there's something I'm missing

fathom pendant
#

Try resetting the target

#

The yellow arrows next to the ip

#

But also STOP USING NMAP

quick crane
#

who can help me,in this module "WINDOWS PRIVILEGE ESCALATION-Pillaging" last question "Restore the directory containing the files needed to obtain the password hashes for local users. Submit the Administrator hash as the answer." how can I do

fathom pendant
#

Nmap will get you nowhere fast with this exercise

dreamy solar
#

so I use what tools?

fathom pendant
#

I'm not repeating myself

dreamy solar
#

(I don't know in another way

fathom pendant
#

firefox

#

This section is intentionally done this way to get you away from Nmap as your only enumeration tool

quick crane
#

@fathom pendantcan you help me

fathom pendant
#

Things you're given:
Public ip
Port

dreamy solar
#

yes but I don't use this for enumerates all ports with Firefox sorry

fathom pendant
fathom pendant
#

You're give a specific port

dreamy solar
#

yes... indeed

#

sorry

#

after resetting the machine it works

#

I finally have a glimpse

fathom pendant
#

Technically speaking all websites have you access them via 80 (http) or 443 (https) but sometimes there exists alternate ports, which you would need to specify it in your request

dreamy solar
#

yes okay thanks

fathom pendant
#

The alternatives are usually for websites hosted on public servers but not registered

#

In which case navigation is done via http(s)://ip:port

#

If you really want to use Nmap to verify the type you can also do -p {port} to specify the given port

#

Perhaps after this module you should go through the Information Security Fundamentals path to get a better grasp of the basics

dreamy solar
#

I don't see the connection with the plugin indicated in "hint'^^" Now that I'm finally unlocked I'm going to watch this

fathom pendant
#

Metasploit will be where to go once you figure it out

fathom pendant
#

Iirc it is pretty blatant with the plug in it wants you to search

dreamy solar
#

ohh plugin is Metasploit ?

fathom pendant
#

No

#

Metasploit is a tool that can be used to exploit vulnerable services

#

The way that's intended for this exercise is via a plug in that you should be able to search using Metasploit

dreamy solar
#

thanks you

quick crane
#

who can help me

analog dock
analog dock
#

Why

quick crane
#

give you picture

analog dock
#

Verify your acc here and you can also send a picture

fathom pendant
#

^ this tells you how

dreamy solar
#

hello excuse me it's me again, do you help me please, I think I found the exploit to perform but I don't understand how to use it, I enter the target and once I launch the tool I have this

dim hound
dreamy solar
#

finally I managed to have access to the files which refer to all the users (GID / UID) (bug of my box agains)

dreamy solar
hidden spade
#

In the setting up module, it's described how to set up a windows VM and a VPS.
I set up a parrot VM so I don't have to use the pwnbox.
Can I skip it or are these steps of value?

oblique spoke
#

Hi! Got a bit stuck with this questnion on active subdomain enumeration in information gathering web edition

#

should i count all the records?

#

yes

#

thank you for your help

#

😄

#

figured out

short hare
#

Yes all A records

inner holly
#

print("Hello World")

high reef
vital adder
#

if you have the hint try ||pop3||

vital adder
#

the service

fathom pendant
hidden spade
fathom pendant
#

Yes

#

Using the email protocol, access the email

#

...with pop3

rustic sage
#

try looking up imap/pop3 cheat sheets online

fathom pendant
#

However it's described to connect

rustic sage
#

the module/section taught you how to connect didn’t it?

fathom pendant
#

:)

#

It even gives you a brief overview of simple commands

vital adder
fathom pendant
#

the annoying one is the one where you have to use imaps ¯_(ツ)_/¯

#

Because the command they give doesn't give you the thing properly

short hare
vital adder
#

-attr description lol

short hare
#

Try connecting with telent at 110 using the password you found from brute forcing
Then used LIST command to list the mails

Yeah..! POP3 kinda wired..!

fading oracle
#

Hi! i am doing the SocksOverRDP module. i am doing and following everrything to the T, i want to login as jason to 172.16.6.155 and i get this error. I did switch to modem connection as explained in the module.

#

Nevermind i solved it! For others in the future: Only switch to Modem connection in Experience with the 172.16.5.19 RDP

merry flame
#

Hey, I am doing the "Using Web Proxies" module and the question is "The string found in the attached file has been encoded several times with various encoders. Try to use the decoding tools we discussed to decode it and get the flag."

The string is ||VTJ4U1VrNUZjRlZXVkVKTFZrWkdOVk5zVW10aFZYQlZWRmh3UzFaR2NITlRiRkphWld0d1ZWUllaRXRXUm10M1UyeFNUbVZGY0ZWWGJYaExWa1V3ZVZOc1VsZGlWWEJWVjIxNFMxWkZNVFJUYkZKaFlrVndWVmR0YUV0V1JUQjNVMnhTYTJGM1BUMD0=||

The hints says try 'base64 and url-decoding", Am i just supposed to n-times base64 decode and then m-times url-decode.
It just seems brute-forcey, and it seems i'm missing on something.

#

Any help?

sly dome
sinful horizon
#

hey can someone help me out with a question .In linux essentials there is something asking me to find xxd binary.What does it reffer to ?

#

like I found 2 paths for xxd but what does binary actually mean

merry flame
sly dome
#

👍🏽

merry flame
sly dome
#

be able to detect which enconding is being used

#

you decode it with base64 once and it is obviously again a base64

#

repeat until it does not look like base64

merry flame
#

Makes sense, so in a nutshell just general familiarity with how each encoding looks like

sly dome
#

yes

merry flame
#

Got it, Thank you so much

sly dome
#

base64 sign is the symbol for padding which is =

#

also only alphanumeric characters

sinful horizon
sly dome
#

no

sinful horizon
sly dome
#

which xxd

#

issue that command in the terminal

rustic sage
#

Hey, what you do in general if you have a user on the "*Print Operators" group which has the SeLoadDrivers privilege, however if you do a "whoani /priv" you cannot see the privilege, and if you do it from an elevated promp you do ?, i was able to do that from an RDP connection but most of the time we dont have that privilege, i've tried to bypass the UAC by hijacking the "srrstr.dll" with SystemPropertiesAdvanced.exe trick but no luck also i've tried the elevate.exe, in this case what any do ?

#

im doing the windows priv module

leaden pond
#

I'm working on the WordPress enumeration section of the Attacking Common Applications module. I'm stuck on the first question (find flag.txt) but was able to answer the final two questions. I have been navigating the site, viewing source code for as many pages as I can. I also fuzzed for subdirectories and found wp-includes, which itself has lots of subdirectories. I've been manually looking through all of those in my browser trying to find flag.txt but can't find it anywhere.

cedar void
#

For the second question in https://academy.hackthebox.com/module/24/section/160 Am I going to be strictly using the pawnbox or my own machine?

"Upload the attached file named upload_win.zip to the target using the method of your choice. Once uploaded, RDP to the box, unzip the archive, and run "hasher upload_win.txt" from the command line. Submit the generated hash as your answer. "

Could I RDP into the windows machine from my Pwnbox? I am kind of confused

hallow kiln
cedar void
hallow kiln
#

yes, you can

jovial rune
#

Hello everyone, I'm just beginning to learn to hack. What do you think is a good path to start with?

mossy hatch
#

Module name Passowrd attacks
Section name : Protected archives
Problem : i cant crack the password for the archive Notes.zip

i did transfer my file to my machine using base64 encode and decode and then this command zip2john Notes.zip > zip.hash and then i did john --wordlist=/usr/share/wordlists/rockyou.txt zip.hash but i cant crack the password

compact patrolBOT
mossy hatch
leaden pond
#

Solved the question I was stuck on but had to upload a webshell

slate creek
#

ls

civic zenith
#

I have a reverse-shell on a "windows server 2016 ." How do I get a meterpreter shell??

fathom pendant
#

Do the same thing you did to upload the rev shell, but instead use a meterpreter payload using msfvenom.

#

The section should go over if

civic zenith
fathom pendant
#

Nope

#

Meterpreter is a shell interpreter

hallow kiln
#

There's a shell to meterpreter module

civic zenith
#

i think metasploit comes with an exploit I need

hallow kiln
#

Do you mean you didn't get the shell with Metasploit?

civic zenith
#

right

hallow kiln
#

Then no, it can't be done

civic zenith
#

ah ok, thx for answering me guys

fathom pendant
#

¯_(ツ)_/¯

#

If the module/section didn't talk about Metasploit its probably not the place to look

civic zenith
#

I'm actually at the skill assessment part of the windows priv esc module

#

I need to elevate to SYSTEM level

fathom pendant
#

You can do that without Metasploit

#

Just look around and see what you can use

#

Also usually with academy the windows targets have some stuff in C:/tools

civic zenith
#

ok, ill give it a shot, I heard that you can elevate with juicy potato but wanted to do it another way

fathom pendant
#

Honestly doing it without Metasploit is the better way, as you'll actually learn more

slate creek
#

Currently stuck on the PtT from Linux section I cant seem to find an answer to "Use the LINUX01$ Kerberos ticket to read the flag found in \DC01\linux01. Submit the contents as your response (the flag starts with Us1nG_)." - Anyone have any tips? Found a .keytab file in /tmp, tried to crack the hash but not succeded, tried kinit... not working with the format. really need some help with this, took me too long. thanks in advance

vernal dove
#

Best app for pracitce part Html/Css is a ATOM and POPW C0DE gys

hallow kiln
#

go back to the part on finding keytab files

sly dome
#

is this correct? i think it isn't but maybe you can correct me

viral cloud
#

How often do you guys face problems with VPN? I've had it in the nmap module (some scan didn't give me the right output) and now I'm doing shells and payloads and sth didn't work and when I changed VPN the issue was gone

hallow kiln
#

I've never had an issue, but I know people do occasionally, switching to a different server and regenerating generally takes care of things

rustic sage
#

Yo I have a question

ebon trail
rustic sage
ebon trail
rustic sage
final maple
ebon trail
#

Not really sure that is ethicall that question here

viral cloud
#

That's not a big problem when doing modules. I'm more worried about having the issue during exam and possibly not realizing that this is the problem. For example if i run sth and won't get the output that I should get

rustic sage
final maple
ebon trail
#

Experimenting*

cyan wind
#

I currently working on password attacks module Passwd, Shadow & Opasswd i used unshadow technique downloaded the password list and used hashcat to find the root password. But it isn't working. Does anyone have a suggestion what i'm doing wrong?

ebon trail
#

I have a question for all of you: I just started my journey on cybersecurity.

Is it better begin with htb-academy or with try hack me? Pros and cons? I find HTB very comololete but sometimes I feel that to resolve pwnbox modules I need to look for external help, forums, etc

viral cloud
# ebon trail What kind of issue are u exprrimenting

In the medium assesment in the nmap module I was running one command and it wasn't working. Then I've read somewhere that this might be caused by VPN so I used pwnbox and the thing worked. Now I was trying to navigate to the shell and I had runtime error. I've changed VPN and it worked

hallow kiln
grizzled sequoia
#

HELLO

ebon trail
hallow kiln
slate gate
#

dont feel bad about googling a lot of stuff, you are lowkey supposed to do it

viral cloud
ebon trail
slate gate
#

just use both imho

viral cloud
#

Yeah, I've started with the thm too. Bit I only did the beginner modules. I'm studying cybersec at uni do that helped a bit

ebon trail
# slate gate just use both imho

Don’t know in the states, but in Spain most THM paths requires premium account. If I have to pay I prefer focus on one of them

ebon trail
hallow kiln
viral cloud
#

But I'm connected to the work VPN so maybe that's causing some issues. I'll test it

ebon trail
ebon trail
ebon trail
slate gate
#

htb vpn breaks my computer mtu for other vpn often

hallow kiln
viral cloud
#

The thing that made me more comfortable was learning networking. So I really recommend you getting the basics of that. That's also often coming handy in my job. I'm currently working in SOC. So deff don't skip that

hallow kiln
#

Indeed, networking is essential

ebon trail
viral cloud
#

Linux and networking makes everything 10x easier

ebon trail
#

Stage*

viral cloud
#

xD jumping straight into pentesting would be messy xDd

sly dome
#

how much am i enjoying broken authentication

#

python scripting is awesome dude

tropic ledge
#

hey could you help me for Oracle TNS?
i logged in with the scott/tiger but i can not find the password hash for the DBSNMP user. any help?
select password from all_users where username = 'DBSNMP';
will not return password hash

lusty thicket
ebon trail
tidal mango
# fathom pendant Might need to comment out one of the proxy lines if there's multiple sometimes i...

Yeah I checked that, I can only get curl to work when using the socks4, I also tried socks5 and firefox never connects, I can see that after the 4th line here it just drops trying and goes back to my terminal prompt. I did try on the pwnbox and it works, so most likely something to do with Kali, I am going to move on for now but if anyone else has ideas I would love suggestions. For easy reference this was my question. "I have a question on Pivoting, Tunneling, and Port Forwarding -- Web Server Pivoting with Rpivot Section. I setup the rpivot on my Kali box and the ubuntu pivot host. I can curl the webpage in question (last question) and see the flag, using proxychains, but when I try to run proxychains firefox, it will never connect to the page with firefox. Has anyone expiernced this? or have ideas ? " Thanks!

civic zenith
#

Ok I got juicypotato working, but how do i access the cmd.exe with higher privs that was created?

#

The reason I cannot get to it is because I am in a reverse shell.

woven copper
#

Hi all for Game Hacking Fundamentas, the section of identify and Dissect Data Structure i found two address the seems to be related with score value but when I modify it and continue playing the value change to original or less than original , if anyone could help, i don't saw how the theory its related with the challenge.

rustic sage
#

Anyone for help on Windows Privilege Escalation - Citrix Breakout? || I have access to the Desktop and a powershell sessions, but cannot escalate privileges.. the smbshare says it's up but copy says the path doesn't exist.. net use works but when i try visiting the drive it says it doesn't exists.. ||

fathom pendant
rustic sage
# civic zenith

trying using another parameter when running the command, spoiler if needed: || look into -a ||

rustic sage
tidal mango
novel matrix
#

Let's keep on topic otherwise, messages will just get removed and potentially muted for repeated action.

If you don't have a role, please read #rules and #welcome

digital pewter
#

Boy, the Kerberos Attacks module sure is fire! IMHO it's very well done and I highly recommend it.

sly dome
#

maybe CME one but idk if it is worth it

hallow kiln
#

I personally don't think I'd bother with a CME module, the help menu is enough

sly dome
#

thought so…

#

but im really attracted by the idea that mpgn is the author

hallow kiln
#

I'm thinking Kerberos Attacks, maybe DACL attacks at some point, though it's a mini-module

#

but Kerberos Attacks is at the top, I definitely need to learn more about constrained delegation and RBCD

sly dome
#

for sure ill eventually do a lot of Tier 3 modules, after exam

hallow kiln
#

there's something to be said about overpreparing for the exam, people have gotten stuck because they were trying things outside the scope of the modules

sly dome
hallow kiln
#

yeah, it said preparing for the exam

digital pewter
# sly dome maybe CME one but idk if it is worth it

The CME module is another that is very well done IMHO, but everything is relative I guess. I can say I am now fluent with the tool and after completing the course I walked aware comfortable making PR's to the repo and even crafting my own modules. I might have gotten to that point eventually on my own, but the course definitely fast-tracked my progress. It was worth it to me, personally. I'm interested to see if and how the academy updates the CME module with all the changes going on with the tool.

sly dome
#

and after exam, more

woven copper
#

I don't recommend OSINT and LDAP 😦 , you can pass it

hallow kiln
#

my point does stand, the Kerberos Attacks module goes into attacks that are way out of scope for the exam

sly dome
#

okk

hallow kiln
#

you'd be better off doing a pro lab for hands-on practice, but that's personal opinion

quick crane
#

now who have free time

#

I have a problem in "Windows Privilege Escalation Skills Assessment - Part I"

vale plume
#

the intro academy module wont let me see what the target says in firefox

vital adder
vital adder
vale plume
#

interactrion section with target

vital adder
# vale plume

that one is just an example of what your target will look like

vital adder
# vale plume

this is your target and what happens if you go to this site?

vale plume
#

nothing, says it cant load

vital adder
#

yea i mean screenshot of that lol

vale plume
#

when i watched someone else do it they had text on the website

vital adder
#

did you use http? also with the port

vale plume
#

yep

vital adder
#

try restart your target

vale plume
#

yep did 3 times

slate creek
#

I appreciate if anyone help me with this. Password Attacks > Windows lateral movement > Pass the Ticket From Linux > Q 8 : Use the LINUX01$ Kerberos ticket to read the flag found in \DC01\linux01. Submit the contents as your response (the flag starts with Us1nG_). I have tried anyhting I know, found a kerberos ticket at used find / -name "*keytab*" 2>/dev/null and found the file /etc/krb5.keytab. however I can't go further than this, tried kinit and it does not work with, tried hashcat to crack the NTLM but still does not work 😦

vital adder
vale plume
vital adder
vital adder
vale plume
#

...bruh

#

works

vital adder
#

nice👍

vale plume
#

stupid game

#

jk lol

vital adder
#

also this is because of free pwnbox doesn't have full access to the internet and this target is docker with public ip but still the pwnbox should be able to access those target but HTB been having some issue lately

vale plume
#

hmm

#

ima get vip over the summer or before when i actually have time

quick crane
#

@vital adderso can I dm you

vital adder
#

this time sure but next time ask question in details like this here first instead of who can help me with ...

quick crane
#

ok

final maple
final maple
slate creek
vital adder
vital adder
slate creek
forest basin
#

Hey all, struggling a bit with the first module of Understanding Log Sources & Investigating with Splunk, Introduction to Splunk & SPL. I'm an actual SOC Analyst and use Splunk every day, and I really feel like I am providing the correct answers to questions 2 and 3 as phrased, but for some reason, I'm missing something. Any guidance would be appreciated 🙏

hallow kiln
#

also relevant to @slate creek

vital adder
#

i guess this would make sense but for me if an attack involve a AD machine like DC01 i would most likely used DC01$ not with the domain at the end like with an AD user

hallow kiln
#

I think the system recognises it cause it's both local to the machine and valid for the domain

#

good to know there's two ways to do things though

#

but yeah, a $ can break the whole thing, single quotes all the way

plain coral
slate tapir
#

nc: bind failed: Address already in use
any fixes?

autumn pilot
#

use a different port

tough kettle
#

the module be like : attacking common services and then brute force .

viral cloud
umbral fulcrum
#

hey Guys, I just solved "File Inclusion" : "Automated Scanning", but in a different way then it was intended (I think), I just have 1 thing that I didn't get:
at the end I got 2 the "example" file but when I tried 2 do ls it didn't worked (but when I entered cat flag it revealed the flag), does some 1 know y?

wooden summit
#

Hi ppl,
Total noob here
I was wondering if someone can spare a minute to help me out if possible

fathom pendant
#

Just ask your question

fathom pendant
wooden summit
#

❤️
I m running the JavaDeonfuscation Module in the academy,
I m done with all the steps except the last one.
I get a key by deobf curl output (HEX) -> De-HEX -> make a post request as required :
curl -s https://server:port/keys.php -X POST "key=De_HEXED_KEY"

(output is the HEX key again)
I ;m sure there 's something stupid I ;m doing but this got me in a loop between the HEX/de-HEX key

umbral fulcrum
fathom pendant
#

idk haven't done it so I can't be certain : but short answer is, if you got the correct answer then it was probably an intended method ¯_(ツ)_/¯

wooden summit
#

sorry ppl, found my way there,
I ;ve missed the "-d" flag, each of the five times I got to try..
everything fine> thnx

fathom pendant
#

Sometimes writing your question out can make you rethink how you're doing it

#

¯_(ツ)_/¯

wooden summit
winter copper
#

hey, help needed; for the Python3, there should be a simple question, right? In "Code block 2" the blank should be filled with what, to output all numbers in a terminal?
I've tried using print(f'{num})

#

and it works in IDLE

#

however, the answer is incorrect

#

and the hint is "Each underscore represents a letter or symbol"

#

why would print(f'{num}) be incorrect
and instead just ask me to use
print(num)
that is my question 🙂

fathom pendant
#

Because sometimes it's dumb

winter copper
#

lol 😄

fathom pendant
#

But also your print(f' command has an open quote

winter copper
#

oh sry, I closed it in the code

fathom pendant
#

You would need to print(f'{num}')

winter copper
#

yes, you are right

fathom pendant
winter copper
#

but "this is not the answer we are looking for" 😄

#

print(num)

fathom pendant
#

Well it's specifically talking about code block 2, python is indent based context

winter copper
#

yeah

#

used tab instead of four spaces

#

but the answer specifically asks print (num)

fathom pendant
#

¯_(ツ)_/¯

winter copper
#

not print(f'{num}') // although it would work 😉

fathom pendant
#

If you want more practical experience with python3 I suggest looking into a (free) ebook: automate the boring stuff

frozen mesa
#

Anyone can explain me what I am doing wrong or forgetting? [DATA] attacking ssh://94.237.53.115:22/
[ERROR] target ssh://94.237.53.115:22/ does not support password authentication (method reply 4).

Brute force - assesment 1

fathom pendant
#

Well since it's a public server I'm assuming that you're meant to use an http brute force method, and you're also most likely supplied a port to use

frozen mesa
#

Ah, i understand. Thanks.

fathom pendant
#

generally for academy content public ip:port = web ¯_(ツ)_/¯

frozen mesa
#

You are right, missed it 🙂

sonic seal
#

Hi! Can anyone give me a hint about Intro to Assembly module? I am stuck on that procedures section.

boreal crest
#

Hello, could I get some help with the "attaching thick clients" portion of the module "Attacking Common Applications"

Honestly cant find the the MAP section which is Read/Write.

Here is what I have already done:

Restarted x64dbg with only the Entry breakpoint
Tried importing Ghidra and analyzing the exe (no strings found apparently)
I have tried searching in x64dbg for the Ascii (4D5A - MZ) and its apparently only in two places as a file header (the restart service block with its .text,.data, .bss sections) and (the dll section which is irrelevent)
Dumping these gives me the error file isnt a .NET PE which is frustrating.
Any help would be appreciated.

pulsar needle
#

I just finished it

#

I can help heh (Ive sent a DM request)

boreal crest
#

Oh thatd be great

#

I'll pm you

sly kelp
pulsar needle
#

I have no clue, reverse engineering or whatever that was is new to me

#

Xd

sly kelp
#

Lol

#

I got the answer but it is not accepting as correct

#

So I am stuck for few hours and need to confirm that

#

I think I am not using the correct answer format

rustic sage
#

Could I get a nudge on Linux Priv Esc - Environment Enumeration

rustic sage
rustic sage
tough kettle
#

attacking common services : medium assessment
anyone has the flag for help?

static mauve
#

Hi, which discussion thread can I go to to ask questions about a Box? Referencing the box Naught

elfin cedar
#

Can anyone help me with smbexec? I get the error: "You can't CD under SMBEXEC. Use full paths." I have tried cd C:\Windows and even \server\share\path\to\file_or_directory.

rustic sage
sly dome
#

and its saying you cannot CD 🤣

elfin cedar
#

hi!

hallow kiln
tough kettle
#

i meant someone solved the assessment not the actual flag, so i can dm my progress

elfin cedar
#

nevermind

fathom pendant
tough kettle
#

||i found an ftp server running on a non-default port and extracted a file with some creds , tried to brute force ssh with it but nothing worked . ||

forest basin
rustic sage
#

"At the Web Attacks - Skills Assessment, can anybody please help me? I am trying to perform a POST request with <!ENTITY name SYSTEM "php://filter/convert.base64-encode/resource=flag.php"> as an admin, but I am unable to retrieve the flag. I have also attempted using GET requests and other entities such as details and date, but I still have not succeeded."

rustic sage
sterile epoch
#

I am facing error with whatweb each time I try it I am getting ERROR Opening: /{machine_url}/ - exectuion expired

#

any help

spark barn
#

send it

lunar cipher
#

Hello 👋
I am on the "Active subdomain enumeration" module on the question section. I dont have ans information about "inlanefreight.htb" domain with nslookup, dnsdumpster or shodan. Any problem ? Someone can have some informations, its just me ?

#

OK, was found. I need to specify domain name and ip of the target that i just started

#

Thank you all

leaden yew
#

Anyone having any issues in the Module: Using Web Proxies for ZAP Replacer? Im not able to get ZAP to replace anything...

hallow kiln
#

@rustic sage you said you have the NTLM hash, how did you get it?

rustic sage
hallow kiln
#

great, then just use the keytab file with kinit

#

that's all

rustic sage
#

i tried that but get this error kinit: Keytab contains no suitable keys for LINUX01INLANEFREIGHT.HTB@INLANEFREIGHT.HTB while getting initial credentials

hallow kiln
#

one minute, let me check notes to see exactly what I did

rustic sage
#

thanks

#

i used this command kinit LINUX01$@INLANEFREIGHT.HTB -k -t /etc/krb5.keytab

hallow kiln
rustic sage
hallow kiln
#

you're welcome

cedar void
#

For this module(https://academy.hackthebox.com/module/24/section/1574) i am playing around wih the urlretrieve python method since its a 'playground' section

Why isn't this command 'python3 -c 'import urllib.request; urllib.request.urlretrieve("https://raw.githubusercontent.com/Automedon/Codewars/master/8-kyu/5 without numbers !!.js", "test_js_too.js")
'

Downloading the actual javascript file my local machine rathern than taken me to what I think is the python command line?

tulip coral
#

Good Afternoon I having issues with local File inclusion skill assessment stuck whole day... can anyone lend some assistance

mossy hatch
#

Module name Password attacks
Section name :Pass the Ticket (PtT) from Linux
Question : Check the /tmp directory and find Julio's Kerberos ticket (ccache file). Import the ticket and read the contents of julio.txt from the domain share folder \DC01\julio.

I'm having issue with using the kerberos ticket in my local machine, i transfered the TGT of julio and put it in my env variable but the command proxychains impacket-wmiexec dc01 -k -no-pass does not work

rustic sage
mossy hatch
#

the TGT is already on the machine i just transfered it

rustic sage
mossy hatch
#

yes i did it properly

#

and i put dc in my etc/hosts file

rustic sage
# mossy hatch

two things, i would check the md5sum and verify they file you have on your attack box and the one you took from the target server are the same

#

i also didn't use the -no-pass flag

#

or forgot to write it down

mossy hatch
#

i think i'll just try on the pwnbox maybe it'll work

rustic sage
#

verify /etc/hosts because it doesn't know what dc01 is

#

if that doesn't work i'll go back to the module and redo it for you

mossy hatch
rustic sage
#

hang on i'll redo it

mossy hatch
#

thanks

mossy hatch
wooden summit
#

Hi there people,
General question:
Is an estimated ~2hrs a normal time for 'nmap <IP> -p- ' completion?

wooden summit
#

hm, then I should probably flag this differently, thnx @mossy hatch

rustic sage
#

let me go back and get a valid ticket

#

did you remember to install krb5-user

mossy hatch
#

yes i dit install it and make the changes

#

just i'm not sure which ticket to grab it may be that because there are 2 tickets

rustic sage
#

i would restart the lab

  1. transfer one of the tickets from julio || in /tmp || over. I just base64 encoded and decoded
  2. the file name needs to be the same as it was on the lab machine.
    2a) example: mine was named "krb5cc_647401106_r0zCZX" on the target so for me I had to export KRB5CCNAME=krb5cc_647401106_r0zCZX
  3. edit the /etc/hosts file on your attack box with the same IP and domains as it gives you in the module
  4. execute proxychains impacket-wmiexec dc01 -k as shown. if it says the ticket is invalid.. go back and get another one
rustic sage
mossy hatch
#

i'll try again thank you for the help

#

i didnt downloaded krb5-user actually on this machine...

rustic sage
#

Can someone help me with Logrotate in Linux Priv Esc? I've done the section as stated and have referred to the Github, but I get nothing returned.. Also confused as to why there is no config file...

acoustic owl
rustic sage
#

who can give me a hand with this question:

In the 'titles' table, what is the number of records WHERE the employee number is greater than 10000 OR their title does NOT contain 'engineer'?

from SQL Injection Fundamentals Module and SQL Operators section
I really would like to check if my query is right, that all

#

@acoustic owl Can I DM?

acoustic owl
sly dome
#

number and title are just tags i used, but in your case they can differ

barren apex
#

can anyone give me a hand on the file upload whitelisting task please

sly dome
#

tell us

barren apex
#

I cant get any filters to respond

sly dome
#

explain your context please

barren apex
#

made the various extension bypasses and I am fuzzing a post request with them, and no matter what I am getting
Only images are allowed

#

Have probably sent 2k requests and got nothing back

barren apex
sly dome
#

let me check notes

echo badge
#

what can i do if in my server (pwnbox) I try to connect to a port but it says "The connection has timed out" In any page i try to enter ( Its lesson "Interactive Section with Target")

sly dome
#

because its a common bypass

#

or you tried it in a wrong way

barren apex
#

im basically running the shown script with more file types and nothing is returning

sly dome
#

they teach you 3 techniques in the section

#

and 2 of them works here

barren apex
#

ill try and go more simple

#

think ive got carried away

hexed bison
#

Hello. I'm trying to do the Attacking Common Services - Medium assessment
Since yesterday I can't do my nmap scan as usual. It founds 4 opened ports then starts to slow down. displaying several messages like "Increasing send delay for 10.X.Y.Z from 20 to 40 due to 11 out of 12 dropped probes since last increase."
Is something broken or is it intended ?

sly dome
#

try to pass from "Extension not allowed" (which means blacklisted) to "Only images allowed" (which means whitelist behind)

barren apex
#

i was going too complicated on the list

sly dome
#

xD

barren apex
#

now to work out which ones work

#

thanks

sly dome
#

anytime

low tusk
#

hey guys i know this isnt academy related but uhm does anyone know how to unlock icloud?

rustic sage
acoustic owl
low tusk
rustic sage
acoustic owl
leaden yew
#

For the Module: "Using Web Proxies", Section: "Proxying Tools", has anyone had any success with intercepting any traffic through ZAP? I've only been able to get Burp Suite to work.

solid quarry
#

Can someone help me on ntlm relay attacks question "Submit the password of the SQL user 'sqlftp'."? (solved)

rustic sage
#

Anyone available for Linux Privilege Escalation Sudo (0-Day)? Neither of the exploits shown work...

rustic sage
#

a

lusty thicket
#

a

undone narwhal
#

Module: Attacking Common Services
Section: Medium Lab

can anyone give me the other port i found ||ssh,dns, and pop3/s|| after tons of resetting i got ||2121|| but i was never be able to get that other port and yes I AM WAITING for the services to start before port scanning

undone narwhal
#

I couldnt get it even after resetting so many times

#

can you pls do that again😅

rustic sage
lusty thicket
undone narwhal
#

👍

rustic sage
undone narwhal
undone narwhal
#

can you send a Screenshot

rustic sage
#

I've statically compiled it, but it always returns ||“Sorry, user htb-student is not allowed to execute ‘sudoedit AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA’ as root on ubuntu."||

#

I even used ||sudo -l to switch to another user and try it, but same results ||

undone narwhal
rustic sage
#

I did complie it on my own machine

#

That is why the file is called hax and not sudo-hax-me-a-sandwich

undone narwhal
#

give me a minute ill spin the machine and ill let you know

rustic sage
undone narwhal
#

in the mean time can you try /bin/bash and then try running the exploit

rustic sage
#

That doesn't work either

undone narwhal
#

Im suggesting to change the shell

#

its working for me

rustic sage
#

so you transfered everything over and then used Makefile

#

let me try that

undone narwhal
rustic sage
#

That was soo annoying

#

Tbh it still didn't technically work with the Makefile

#

I still had to use my -stactic compiled one

#

but next time I'll bring the lib file over..

neat sky
#

hello all I am seeking help using NC to send shellcode i am on the "intro to assembly code-shellcoding tools" section and its telling me to connect to a compromised server using netcat but i have no idea how to use nc to send the code that i already generated to cat the flag.txt. just have no idea how to send the code via nc

mossy hatch
#

Module Name : Password Attacks
Section Name : Pass the Ticket (PtT) from Linux
Question : Use the LINUX01$ Kerberos ticket to read the flag found in \DC01\linux01. Submit the contents as your response (the flag starts with Us1nG_).

can someone help me i'm almost sure i have found the keytab and i used kinit but it does not work
my command : kinit 'LINUX01$INLANEFREIGHT.HTB' -k -t /etc/krb5.keytab

tidal mango
half inlet
#

Hi all, I was having some difficulty with the HTB Academy Hard Footprinting Lab (https://academy.hackthebox.com/module/112/section/1080)

||I was able to find Tom's credentials through the SNMP server, then use those credentials to access POP and retrieve an SSH key, however I am trying to use this SSH key to log in to the 'tom' user but it is not working (permission denied error) - I also tried the 'tech' and 'bob' users, as I saw those mentioned, but to no avail -- any pointers?||

tidal mango
half inlet
#

I believe they are set so just I can see them - I think if the permissions are off SSH will outright state that instead of just saying 'permission denied'?

half inlet
#

-rwx------ 1 jeremy jeremy 3381 Oct 2 16:45 id_rsa

half inlet
tidal mango
half inlet
#

weird

#

works now,

tidal mango
#

did you try dropping the single quotes and INLANEGREIGHT.HTB ?

mossy hatch
#

i'm dumb thanks it worked

uncut nebula
#

Hi guys! I'm stuck in the Command injection - Detection module. It says when adding any of the injection operators I should see an error. But...I don't
Could you nudge me in the right direction?
Things I tried:
||Took all the injection characters, and submitted in from the html form in both chrome and firefox with a payload like ip=127.0.0.1<FUZZ>
Fuzzed the form using burp suite with all the injection characters, both plain and encoded.
Read the index.php source code||

tidal mango
#

is the burp screen shot from your machine?

uncut nebula
#

from the pwnbox, but ywah

tidal mango
#

it appears to work?

uncut nebula
#

yeah, but the question says I should get an error when using an injection char, which i don't get D:

#

it says it should start with "Please"

uncut nebula
#

feels weird that I can get command injection. But can't trigger the error hahaha

fathom pendant
#

Because it looks like you're doing url encoding

uncut nebula
#

yup, on the last screenshot i used a encoded semicolon ;

fathom pendant
#

Try not url encoding

uncut nebula
#

oh thanks will try that 🏃

fathom pendant
#

When you're url encoding you're no longer "injecting"

tidal mango
#

Ok I have a question as well... on Pivoting, Tunneling, and Port Forwarding the ICMP Tunneling with SOCKS section, it wants us to use ptunnel-ng I cannot get the tool to compile on my box or on pwnbox. Has anyone done this module recently and have any suggestions?

fathom pendant
#

Just use discord search feature

#

Took me less than 5 seconds to find it

uncut nebula
#

I almost cried when it took longer using a new line , but still I couldn't trigger the error

fathom pendant
#

¯_(ツ)_/¯

uncut nebula
#

will do, thanks for the help!!!

fathom pendant
#

This is probably a case where you're thinking ahead

tidal mango
fathom pendant
#

❤️

#

types ls
why do files look familiar
fml I'm enumerating my own system not the shell