#modules

1 messages · Page 141 of 1

fathom pendant
teal breach
#

it said succeeded

fathom pendant
#

OK are you following the steps exactly as shown from the section?

#

The pivoting module walks you through EVERY step

teal breach
fathom pendant
#

Lemme double check the steps

#

So you started on htb-student, loaded the dll, yes?

teal breach
#

let me try to reset the target again

fathom pendant
#

Then connected to the first hop

teal breach
viral slate
#

It worked!
Thank you 🙂

fathom pendant
#

And ran the socks over rdp with admin?

#

And then started proxifier

teal breach
fathom pendant
#

When you launched rdp, did you get the message shown in the module?

fathom pendant
#

The whole "socksoverrdpdll enabled"

#

And you're transferring over the server.exe

valid nest
#

Question on Session Security - Skills Assessment.
So after all I got it working, but I am just curious.

If I access other minilab directories(e.g. api/userinfo) using the vulnerability, shouldn't I still be able to collect the cookies? || why is it has to be that specific profile page? ||

teal breach
fathom pendant
#

Also the images are weirdly out of sequence with the text sometimes

teal breach
#

thankyou for your help ! 🥰

fathom pendant
#

¯_(ツ)_/¯

sly dome
#

the vulnerability is just a open redirect + xss

#

to steal a cookie

#

there is not even CSRF involved

#

http://minilab.htb.net/submit-solution?url=http://minilab.htb.net/profile?email=julie.rogers@example.com this is the open redirect and then the Country field of the profile is vulnerable to XSS where you insert a payload to get the cookie coz it has no HttpOnly flag enabled

#

you dont need any php

#

and no because the XSS is in the profile page

fathom pendant
#

You're kinda going overboard my guy

sly dome
#

then you make the admin visit your profile with the submit-solution open redirect

sly dome
fathom pendant
#

This sort of explanation is basically spoiling it

sly dome
#

meh

fathom pendant
#

And you should probably be taking it to dms

sly dome
#

not the big deal this skill assessment

#

true

fathom pendant
#

Instead of basically spoiling a SKILL assesment

sly dome
#

anyways the solution is spoiled through the module

fathom pendant
#

Even if it is trivial

sly dome
#

in this specific case

fathom pendant
#

Plenty of modules do that

sly dome
#

yea

#

im sad 😦

fathom pendant
#

It's up to the reader to discern that

valid nest
#

Noted. Thanks for the help!

sly dome
#

@hallow kiln prayge

hallow kiln
#

You don't need | before 2>/dev/null

sly dome
hallow kiln
#

Does winrm take long? I legit don't remember

sly dome
#

i have 107 users times 1500 passwords

#

around 169000 combinations

fathom pendant
#

From what I see you're already verified

dusky niche
fathom pendant
#

Thought you were already verified earlier

sly dome
#

ahh no way they did this HAHA

#

how evil are HTB staff

fathom pendant
#

It's not that bad tbh

sly dome
#

do you know how to brute force winrm?

fathom pendant
#

Wait until you start using the mutated password list

#

Yes by using one of the tools mentioned

sly dome
#

netexec (aka cme) does not support threads

fathom pendant
#

Crackmap does support threads wdym

sly dome
#

there is no such option

#

under my help panel

#

also i looked for it in the wiki

fathom pendant
#

????

#

Literally right there

#

It's before you define the service

sly dome
#

yea true i was looking into winrm protocol

#

specifically

fathom pendant
#

Why are you using netexec?

wide oak
#

Hello everyone,

I'm diving into the "Documentation & Reporting Practice Lab" and find myself in need of a bit of direction on the first question.

So far, I've discovered some credentials on the NETLOGON smbshare using the command:
||proxychains smbclient "//172.16.5.5/NETLOGON" -U INLANEFREIGHT.LOCAL/asmith%Welcome1||
Given what I've found, I'm uncertain about whether I'm on the right track or if there's another piece of the puzzle I'm overlooking. Can someone provide a gentle nudge or confirm if I'm looking in the right direction without giving away too much?

Thanks for your time and assistance!

sly dome
#

i increased the threads but i see no difference

fathom pendant
#

It obviously still takes a minute

sly dome
#

also python threading is buggy

fathom pendant
#

You might also need to add -local-auth or something

sly dome
#

its a +0 cubes question

#

xD

teal breach
# fathom pendant ¯\_(ツ)_/¯

sorry for disturbing again
i try to remote to the targeted host but got the error (i already find on the search and see many people faces the same error)
i already try to run "Set-MpPreference -DisableRealtimeMonitoring $true" and make sure that real-time protection is off, but i still get the same error
did i miss something here ?

sly dome
#

threads appear to help

sly dome
#

docker run -v "$(pwd)":/opt:ro,Z vanhauser/hydra -L /opt/username.list -P /opt/password.list ssh://10.129.126.235 -t 64 am i chad enough?

lime atlas
#

why is connection to module labs so unstable? I have machine activated, I can ping and work with it for a few moments and after few minutes e.g pwnbox can't ping the target

#

like I'm slowly bruteforcing stuff and randomly the target is unreachable, my internet is really solid

fathom pendant
#

Are you running pwnbox and your own vm at the same time?

sly dome
#

+4k tries

lime atlas
#

pwnbox and connected with VPN

sly dome
#

xD this is unreal for an academy module

sly dome
lime atlas
#

mm

sly dome
#

you have 2 vpn instances for the same user

fathom pendant
lime atlas
#

well, I activated pwnbox cuz the connection was shit to begin with

fathom pendant
#

If you're gonna troubleshoot using pwnbox; turn off the vpn

lime atlas
#

mkay

sly dome
#

ohhh got it xD

#

17 minutes for ssh and working with 64 threads good to know

lime atlas
#

you're bruteforcing ssh?

#

cuz i am

fathom pendant
sly dome
fathom pendant
#

Lol if you're on the pass attacks module: enumerate first

sly dome
#

stop talking s**t

#

its the 1st section xD

lime atlas
#

bruhh, learning hacking through modules is messed up mann

sly dome
#

i tried enumerating nfs

lime atlas
sly dome
#

nothing more to enumerate

fathom pendant
lime atlas
#

oh lel, it succeeded 🤦‍♂️

sly dome
#

you have to use the full list

fathom pendant
#

C:\users

sly dome
#

i narrowed it still took 15 minutes

fathom pendant
#

there's also ssb ¯_(ツ)_/¯

sly dome
#

im gonna test it

fathom pendant
sly dome
#

but you cant specify user list, probably im doing a bash script

fathom pendant
#

A better tool for bruteforcing ssh

sly dome
#

fkn ssh protocol

#

o.O

lime atlas
#

why is it forced to complete 100% of the modules to get the cert?

sly dome
#

its fun

lime atlas
#

it's really not lol

lime atlas
#

I love doing regular boxes where vulns are unknown. Here you just read the text and copy paste commands

thorn urchin
#

I honestly think a lot more people would get humbled by cpts if they were allowed to do it without the course but I say hey let em get humbled

thorn urchin
sly dome
#

nah why this ssb tool is so cool

fathom pendant
#

Because someone said fuck you to ssh

sly dome
#

such a great input from madf0x

#

golang is unbelievable good for network scripting

elfin cedar
#

When I issue the command sudo -l , it provides a user with a list of commands they are allowed to run as root right?

thorn urchin
#

I got ssb from a friend when he did the module

elfin cedar
#

I dont get why my answer is wrong?

#

(root) NOPASSWD: /usr/bin/******

thorn urchin
#

whats the question

elfin cedar
#

What command can the htb-student user run as root?

#

so I type sudo -l

#

I tried inputting it different with, with full path also

thorn urchin
#

its gunna be the /usr/bin/** or whatever the real tool name is

elfin cedar
#

yes I did that

#

omg

#

I tried it again and it worked

#

Im sorry

thorn urchin
#

probably had a space or something

sly dome
#

gonna take a rest

#

for the password attacks kek

hallow kiln
#

isn't it fun kek

sly dome
#

nah but marcie humbled me hard

#

ssh took 30 seconds with narrow list + ssb

hallow kiln
#

awesome

sly dome
#

and hydra 3 minutes which is 6x

#

with 64 threads **

hallow kiln
#

ssb is definitely much faster for ssh, but to be fair, it's very unlikely you'd be bruteforcing ssh out in the wild

fathom pendant
#

It's because of how it handles its threading

fathom pendant
sly dome
#

yea nowadays ...

hallow kiln
#

which it should be, but ya never know

sly dome
#

know what is fun now? hydra from docker comes without rdp

#

i dont have it installed what a moment

hallow kiln
#

I stick to installing my tools lol

sly dome
#

dude how broken is rdp, you just begin with it and it gets you the whole section

rotund urchin
#

yeah shit is annoying.

hot heart
#

sup bois

#

May I get some help on the footprinting module? DNS section

fathom pendant
#

Ask your question

hot heart
#

please**

#

Well I'm pretty sure I already have the answer

#

But it won't let me submit it

fathom pendant
hot heart
#

lmao

fathom pendant
#

Anyway whats the question

#

Like what question is it specifically

hot heart
#

Do you want me to put it in here? Or is that considered a spoiler, its the first question

#

I've done everything successfully but I don't know how to submit it as the right answer

#

I'm pretty sure I have the answer for 1, and 2

#

Do you want me to post them in here ? And see if theyre right?

fathom pendant
#

No need

#

Does your answer for q1 start with n, and for q2 is it l337 sp34k

acoustic owl
fathom pendant
#

^

hot heart
#

Okay let me try harder, and let me try smarter and I'll be back

fathom pendant
#

Also the outputs for some have a trailing.

hot heart
#

Okay thank you, Imma try again

fathom pendant
#

So if the answer to both my questions was no: then you're wrong :D

shut wraith
#

FILE UPLOAD ATTACKS

Skills Assessment - File Upload Attacks

Try to exploit the upload form to read the flag found at the root directory "/".
I have used burp repeater to try and submit a payload within a .svg image file.

Can anyone help please?

acoustic owl
shut wraith
sly dome
#

are you intercepting the right request? big_think_onion

#

try harder

fathom pendant
#

Well did you confirm .svg files are even accepted?

sly dome
#

obviously no, the vulnerable endpoint was different

#

it’s something that starts with u

shut wraith
#

Thanks guys I'm trying harder atm

brazen hinge
#

Hi, anyone who has completed the Skills Assessment II of NoSQL Injections?

sly dome
#

how much time does it take to brute force the FTP under the mutation section? jesus christ HAHA

#

5k tries already

#

[STATUS] 774.29 tries/min, 5420 tries in 00:07h, 88642 to do in 01:55h, 45 active 💀

#

one thing im not sure why but ssb could not get the correct one. and i used the mutated with the custom.rule they provide under Resources

hallow kiln
#

myeah, that's the one that takes forever

sly dome
#

if it reaches 20k tries im just reversing the order of the list xD

#

imagine it is on the 25k 💀

hallow kiln
#

proobably a bad idea, based on what the pass is

sly dome
#

fkkk

#

im little mad about ssb

next bronze
#

is it the password attack module? yea that's the most frustrating one to do for me

sly dome
#

it should have found it

#

it tried the 94k passwords in under a minute

next bronze
#

but if I remember right, if it's taking hours, you're proably doing something wrong

sly dome
#

im at 12k tries in 14 minutes

hallow kiln
#

yeah, I checked, don't reverse it lol

sly dome
#

used 64 threads but only 45 survived

sly dome
#

great

#

target died

#

gonna just cut the list

#

who the hell designed this module

#

this section at least

hallow kiln
#

yeah, the large wordlist is not needed to teach the concept imo

sly dome
#

94k come on

#

and they chose the right one probably above 25k

hallow kiln
#

could have kept the list to 20k for example

sly dome
#

yea

#

the rule itself is 900 lines long

#

when the best rule used out there is best64

hallow kiln
#

or something customised based on the password policy

sly dome
#

w.e.

#

just w8

#

lets see some ippsec

#

kay not that bad at the end

#

18 minutes

#

~17k tries (?)

hallow kiln
#

yup

undone narwhal
sly dome
#

its ok to use 64

undone narwhal
#

Just saying, 64 Never worked for me in that section

sly dome
#

it worked for me in all the questions i answered till now

undone narwhal
#

Yeah for me as well except for that section

sly dome
#

@thorn urchin did this happen to you? if the list is too long it just give false negative

sly dome
thorn urchin
sly dome
#

ah for real?

thorn urchin
#

the defaults are honestly too aggressive for a lab imo lol

sly dome
#

i even used 300 threads

thorn urchin
#

its a con that its too fast. Not a perfect tool even though I like it

sly dome
#

yea

thorn urchin
#

Id try like...100 or 50 even

sly dome
#

but it found it

#

with a smaller list containing the password (a.k.a narrowing the original list with some OSINT )

#

gonna keep using this

next bronze
#

anyone has done the crackmapexec module? need some help with the skills assessment question 1, I had gotten a list and pretty sure I found all of them, I filtered out all the non users and did password sprays but didn't find anything

tight mesa
#

hey, anyone can let me know if for grab the AMProductVersion did use this command let Get-MpComputerStatus

hallow kiln
#

yep

tight mesa
#

hmm ok., weird cuz the number grabbed is not accepted as a valid answer

hallow kiln
#

strange, what number are you getting? DM me

warm sand
#

hey did you get to figure this one out? i've been looking into the same and could not find the information following what's in the module.

vital adder
#

also you may want to remove how you got the user list due to spoiler

next bronze
#

ah gotcha, thanks!

arctic junco
long flint
#

hi guys, for the command injection skill assessment, is the module asking for a clean result of command injection? because I can read the flag, but the output is messy since it is combined with errors. Here's an example of what I mean with another command. ||Error while moving: mv: cannot stat '/var/www/html/files/uid=33(www-data)': No such file or directory||

acoustic owl
abstract frigate
#

😋

spring lily
#

Web Attacks: Bypassing Basic Authentication, the web app doesn't accept HEAD request, can someone please fix it.

spring lily
#

nvm got the flag but not the way intended

primal eagle
#

for some reason on the hard machine in password attacks the samdump2 tool does not work

lusty thicket
#

but you could use other tools

primal eagle
#

yea i used secretsdump

paper plaza
#

Hello, i found the flag in Footprinting SMB but not accepted .

lusty thicket
#

that’s a great tool!

lusty thicket
paper plaza
#

yes

lusty thicket
paper plaza
#

lol ok i found

wooden summit
#

hey ppl. greets to all!
I 've been setting up a listener to pivot through Nibbles (1st box @ GettingStarted Path) .
I was doing all other related tasks having the listener running on the shell and then an IP came up.
The IP was unrelated to the tasks at hand. (nope sorry haven 't kept the IP, just killed the terminal window)
Someone else poking around? Thoughts?

sly dome
#

pivoting at GettingStarted?

#

such an advanced topic to get started

#

<@&861185840277487616>

steep tusk
#

wait

#

i was*

#

i didnt

sly dome
#

rule 4

#

Keep it legal.
Do not request, suggest, perform, promote or in other way or shape discuss illegal activities. We respect and follow the Discord ToS as well as the HackTheBox ToS, and do not hesitate escalating matters appropriately, if we deem it necessary. If in doubt, ask a Community Administrator before posting or don’t post it at all.

steep tusk
#

i need help in fixing some proxy errors in my beta website

#

ok im sorry

sly dome
#

also the topic of the channel is totally unrelated to your message

steep tusk
#

i dont even know what modules are

sly dome
#

that happened because you forgot to read

steep tusk
#

i told my friend about my website errors then he invited me to this server

sly dome
#

he probably trolled you

steep tusk
#

@simple siren

acoustic owl
upper ruin
#

Hello, kind people. I am stuck on the Footprinting medium lab. I logged in as admin and I am into the SQL database. I gotta find the HTB profile + submit the password as an answer.
I found colmun: ids,names, password.
How can I change the entries?

SELECT TOP 200 id,name,password
FROM <table>
ORDER BY <column> DESC;
(I modified the query cmd, but it gave no results)

Am I on the right path?

rustic sage
#

Hello, I am a beginner , I wanna learn cybersecurity stuffs to fight hackers

acoustic owl
rustic sage
#

Are there unethical hacking here?

acoustic owl
upper ruin
#

No, everything is done within a controlled environment.

rustic sage
#

Good

acoustic owl
rustic sage
#

So , I am 15 and what should I do in this website?

upper ruin
#

Well, there's a lot to cover.

acoustic owl
rustic sage
#

Hacking kinda sounds bad

#

Can we call it cyber hacking?

#

Do I need to code here

upper ruin
#

Sigh... call it authorized intrusion within a computer system.

upper ruin
rustic sage
upper ruin
#

What do you mean by "what can we do against hackers?"?

rustic sage
#

Like yk, I was hacked alot of times before and I wanna do something against the guy who hacked me

upper ruin
#

Well, you could set up edr on your device.

#

Revenge isn't an option.

hallow kiln
#

Report it to the police, use strong passwords, don't click or download anything suspicious

upper ruin
#

Just configure your PC better and try to run diagnostics.

#

These as well.

upper ruin
sly dome
#

no need for commands

rustic sage
#

I was hacked in discord

upper ruin
sly dome
#

any time

upper ruin
#

How can i select those 200?

#

Is there any setting or a button?

sly dome
#

the right table is kind of visible but let me know if u cant find

#

right click on the table

upper ruin
#

Can we take it to DMs?

sly dome
#

let me spawn the target

#

sure

rustic sage
#

I was hacked on discord once and I found the guy who hacked me, what should I do

rustic sage
#

I mean on discord, but now I am safe

#

Who is the top rank in this sercer

#

*server

exotic basin
#

Notes.zip

acoustic owl
#

What do you mean by Top rank?

#

@rustic sage

rustic sage
#

Like the best ethical hacker here?

acoustic owl
#

there is no ranking

keen compass
fading olive
#

Hello, stuck on the Footprinting module Medium Lab.

What I did so far:
I ran a normal nmap scan in which I found ports 111, 135, 139, 445, 2049, 3389 open. I quickly recognized the nfs system running on port 2049 and I proceeded to connect to it. I got many IT_tickets, all of them empty except one which I opened.
It turned out to be a conversation giving the full configuration for a smtp server, plus domain names and a username and a password. I tried connecting to this smtp server using telnet, port 25 and 465, I also tried using openssl, no luck. I also tried connecting via smb with no luck.

I know there is supposed to be a sql database because the hint mentions it and it's been mentionned in many questions on this channel before, but from my nmap scan nothing makes me think of a sql server.

I would appreciate any help or hints !

tame ivy
#

Hello there,Module:Password Attacks,Section:Network Services,has brute-forced everything, but on smb when connecting to the share, there is nothing, and it prints NT_STATUS_NO_SUCH_FILE listing *
could anyone help pls?

fading olive
analog dock
rustic sage
#

@swift tendon

swift tendon
#

Bruh 🗿

tame ivy
hallow kiln
#

DM me so we don't spoil things

lusty thicket
cyan silo
#

Hi guys, i need a VM to hack on local, for a exam on my university. I need a simply one, no one extremely difficult. Anyone say how to find them?

sly dome
#

you should not try something on closed ports, people use to reuse passwords

fading olive
sly dome
#

maybe the smtp password is reused for his personal computer account

analog dock
sly dome
analog dock
#

Enumerated nfs, enumerated smb, then rdp as admin

sly dome
#

ahh true

#

i used admin pass to run sql as admin 🤣

analog dock
#

Also possible

sly dome
#

im a fan of FreeRDP while it has a lot of hate

#

hahahaha wondering why

analog dock
#

I use it too

sly dome
#

im running it smoothly

fathom pendant
#

Sometimes it errors out for no reason lol

barren apex
#

Attacking Common Applications > Application Discovery & Enumeration:
The report.html header isn't being accepted as the answer?

vital adder
barren apex
#

im a mong

vital adder
#

apes together strong

leaden pond
#

Module: Pivoting, Tunneling, and Port Forwarding
Section: RDP and SOCKS Tunneling with SocksOverRDP

I'm trying to solve this exercise using ligolo. I've used ligolo for pretty much every other exercise so far in this module. I have successfully set up my pivot on the Windows pivot host provided in the exercise (internal IP: 172.16.5.150/16). Now I'm trying to RDP into the target at 172.16.6.155. I ran the command "sudo ip route add 172.16.0.0/16 dev ligolo" from my Kali VM, but whenever I try to RDP into the target, I can't connect. On all the other exercises I was able to RDP in no problem.

barren apex
leaden pond
fathom pendant
#

Granted been a minute

leaden pond
fathom pendant
#

I haven't used ligolo for these yet

#

So I'm not gonna be helpful for ya

barren apex
#

can you ping the host?

fathom pendant
leaden pond
leaden pond
vital adder
barren apex
leaden pond
vital adder
#

try this super quick

sudo ip route add 172.16.5.0/24 dev ligolo
sudo ip route add 172.16.6.0/24 dev ligolo
leaden pond
placid quest
#

@vital adder Can you please create a module that explains about ligolo I have had time using the tool

vital adder
#

i did lol

placid quest
#

Ok let me hope that the module will come out soon

leaden pond
fathom pendant
#

¯_(ツ)_/¯

leaden pond
#

No worries, I'll just go with SocksOverRDP for now. Thanks for the help!

fathom pendant
#

Yeah it might just be an issue with your first host session

vital adder
#

because the second target can't reach your attack machine you have to use the first target as a jump box but beside that everything should work fine

#

also with double you can't send ICMP

sly dome
#

with double?

vital adder
leaden pond
vital adder
sly dome
#

i have set up several home labs with up to 6 pivots

#

and i could ping through the 6 tunnels

vital adder
vital adder
barren apex
#

don't see why you wouldn't be able to ping if you have connection

sly dome
#

indeed you cant ping over a socks proxy

#

but you can over Gvisor network

vital adder
#

nvm ping work

sly dome
#

yea xD

vital adder
#

nmap just being weird

sly dome
#

no

#

read ligolo FAQ

barren apex
#

is it due to the proxy happening at level 5 an ICMP at level 3?

sly dome
#

it explains why it acts weird

#

it is all due to Gvisor behavior

sly dome
#

and Gvisor network is sane layer than icmp, like a VPN

#

this is why ligolo-ng is such a super tool

barren apex
#

youll have to use some kind of layer5+ host discovery tool that pings a protocol

sly dome
#

for host discovery when pivoting/tunneling through socks i usually do echo '' > /dev/tcp/IP/port

#

using most common ports

#

based on the exit code of the echo you can use afterwards a && operator and print HOST X active or something like that

leaden pond
sullen loom
#

hey guys, is it better to run an htb vm locally for learning instead of from the cloud? As it has kind of better performance?

fathom pendant
#

Depends on your threat model as you should generally be treating htb as a hostile network (even though you'll almost, practically never, get attacked via another user). But if you only need boosted performance then yea: locally

#

It also allows you to access things offline if needed

sullen loom
fathom pendant
#

Yes

#

It has the added benefit of, you can check your previous enumeration

hallow kiln
hallow kiln
leaden pond
sullen loom
hallow kiln
leaden pond
#

Yeah sorry I had started it a while before I took that screenshot

#

Seems like I need to upload a ligolo agent file to the final target (jason's machine) and runthe agent file from there. . . but that means I would already need a shell as Jason? In which case I could just read the flag? Feeling pretty confused.

fathom pendant
#

No

#

You you have to have it on htb-student -> Victor

#

Start at point a then go to point b

leaden pond
#

In past exercises, once I start a ligolo session with a pivot host, I can open a new terminal and connect to the final target right away. No need to start a listener or anything. This exercise seems different.

fathom pendant
#

Then c

fathom pendant
leaden pond
#

Oh!!! Got it. I was confusing Victor and Jason.

#

Lol in my head they were the same person.

fathom pendant
#

Ye

#

There's a reason I boiled it down the way I did

hallow kiln
#

it goes htb-student -> victor -> jason, yeah

fathom pendant
#

It's a skill I've learned

leaden pond
fathom pendant
#

It's the same way I take notes

#

I cut as much of the fluff out of it as possible and break it down to what the core solution is

fading olive
#

Hello, still stuck on the footprinting medium lab, I have used rdp to connect to the target using alex's credentials, and looking around the files in the machine I found the important.txt document containing the credentials for sa. I tried it on the mssql login window with no luck.
From the many comments I read on this issue it seems that you should use username spraying, so using the password with many different usernames and it's what I've been doing, I've been trying sa, admin, Administrator, root, alex, and I also tried all of them with WINMEDIUM\ as a prefix but nothing worked. Another comment suggested to change the credentials by writing "a" or "." instead of @ but it didn't work either.
Any help would be much appreciated !

fathom pendant
lusty thicket
#

use the credentials you found for that

fathom pendant
#

You really enjoy just telling people directly how to solve huh

#

Lol

lusty thicket
#

well he already found the credentials

rustic sage
#

hello i am a newcomer i need guidance

leaden pond
#

I'm having a tough time copying the ligolo agent file from either my Kali box or htb-student over to victor.

#

Had no problems getting it from Kali to htb-student

rustic sage
#

can i get help, i am 13

lusty thicket
rustic sage
#

i was jk

#

what should i rlly do

#

i need help

#

i got some things called machines

#

i am using pwnbox

fading olive
rustic sage
#

i need help

#

i am a beginner

#

i got machines

vital adder
#

stop spamming you'll will get the 👢

rustic sage
#

i need help

onyx cove
#

trolling

#

first u said ure 15 now ure 13

acoustic owl
rustic sage
#

it doest matter

#

i was actually trolling

#

i admit it alr

fathom pendant
vital adder
# leaden pond I'm having a tough time copying the ligolo agent file from either my Kali box or...

when using xfreerdp use the /drive tag to mount one of the directory on your machine as a mounted share drive on the target machine, something like this: /drive:home,"/home/(your user)/share-tools" and on the target you can access it from the normal file explorer or in \\tsclient\home\ with cmd

Note that you can actually run the agent straight from the mounted share drive: \\tsclient\home\agent.exe -ignore-cert -connect ip:11601

#

i use this method in my original screenshot and sorry missed your last ping but you after you create a tunnel you basically have to use it 🤣

#

on the victor machine call back to the first (htb-student) target instead of your machine

fathom pendant
rough crystal
#

Hi community, I'm stuck in the Windows Event Logs & Finding Evil module in the Tapping Into ETW section, I am replicating the example 2 to solve the question, I can not find the requested: "ManagedInteropMethodName that starts with "G" and ends with "ion".
My sequence of the attack is to run the Seatbelt script, and then run SilkETW to capture the records and finally filter into the etw.json, but it is non-existent, I don't know what I'm doing wrong

vital adder
fathom pendant
#

Yeah /drive is super useful

#

I almost never worry about it since I have my tools linked to my nginx web-server on my vm

orchid pine
#

hello guys hop you gius all doing good

#

wishing a good luck for evryone here

fathom pendant
#

I eventually wanna revamp it and make it look cool with links, been a minute since I dabbled in css and html

#

So fun side project

orchid pine
#

starting tosay some practice with ad in the main plateform hope is going to help me to practice my skills with ad

fathom pendant
#

The only real way to practice ad on main platform is prolabs

orchid pine
#

the active dircorty track not going to help ?

vital adder
#

not as good as some of the prolab will

#

but that's a good place to start

#

beware that some of the later box in that track will have some (let say) non AD stuff like phishing

leaden pond
#

Flag acquired! That was a lot of fun. Felt like I learned a lot. I really appreciate everyone's help. What a great community.

Also, I'm naming my firstborn child Victor.

mortal echo
#

Allahu akbar

fathom pendant
#

Well it looks like you're canceling something [the ^C denoting the sig-int]

stiff bone
orchid pine
fathom pendant
#

It's probably an issue regarding proxychains if I had to guess

vital adder
#

hint you are trying the right thing hence shit ton spoiler in that message

stiff bone
vital adder
#

i did that skill assessment with cme 6.0.1 so if you are using an super old cme that could be the issue (there was some issue with ldap stuff) but you can shoot me a dm and i'll help you troubleshoot

brazen hinge
#

Hello!, there are anyone who has solved the skill assessment II of nosql injection module? im only need to know how to get a ||time delay in server side javascript injection for mongodb||. Thanks.

vital adder
stiff bone
vital adder
#

sure and i can help you troubleshoot, i'm just asking you to delete the spoilers

vital adder
#

*in dms

rustic sage
#

bro

#

i am new here

#

what should i do with machines

#

i am in tier 0

distant moat
#

Module:attatcking command servise Session:attacking FTP I need get in the FTP server but the target keep disconnecting and I have reset it over 15 times What can i do FeelsBadMan

opaque sphinx
#

Hi

dull thistle
#

Hi community, I'm stuck on this question: Navigate to http://[Target IP]:5601, click on the side navigation toggle, and click on "Dashboard". Either create a new visualization or edit the "Failed logon attempts [Disabled user]" visualization, if it is available, so that it includes failed logon attempt data related to disabled users including the logon type. What is the logon type in the returned document?

balmy iris
#

For Splunk module ?

acoustic owl
#

What exactly is not working?

dull thistle
#

This is for Kibana, I don't understand what is required with the "logon type in the returned document". My query is the same as listed in the instructions

#

My logic was that by logon type, this means either the eventcode or the action

wary lance
#

what have you tried?

#

@dull thistle once you have configured Elastic search as per the lab navigate to the table and specify the "logon type"

#

0xC0000072 – "User logon to account disabled by administrator".

#

for your filter that error code is for disabled accounts

#

if you get the answer for the next one please DM me i've tried every combination need to go for a walk now to clear my mind

orchid pine
#

guys the machine on htb is it about acheving the domine comprimise or being a root

fathom pendant
fathom pendant
orchid pine
#

i know

#

but thers is

#

a diufrence between acheceing a domaine controle and being a systeme

fathom pendant
#

Yes

orchid pine
#

in the machine

fathom pendant
#

But this isn't the appropriate place for discussing this

orchid pine
#

sorry guys then its just most of the time doing acdemy thats why sorry

fathom pendant
#

Still learn the appropriate place to ask, especially since you have access to most of the rest of the server

keen compass
dreamy solar
#

Hello I search some help

fathom pendant
#

Sometimes Nmap doesn't give you all the answers

#

You saw in the vuln result a specific thing, just look at it manually

dreamy solar
#

Ok I hear it, I will try to find this

#

Ok I did find ! I don't think find this thanks

sly dome
keen compass
fathom pendant
#

Version diffs

shut wraith
#

FILE UPLOAD ATTACKS

Skills Assessment - File Upload Attacks

Try to exploit the upload form to read the flag found at the root directory "/".
I have used burp repeater to try and submit a payload within a .svg image file. But as you can see below, it doesn't get executed.

Can anyone help please? @sly dome are you available sir

brazen hinge
#

Anyone have solved Skill Assessment 2 for NoSQL injecttions?

woven copper
#

Just make your questions

undone narwhal
sly dome
#

also you are using wrong magic bytes for a svg body

#

its the same thing that happened to you the other day

shut wraith
#

I removed but now it's telling me only images are allowed. @undone narwhal @sly dome

sly dome
#

well

#

is an skill assessment

#

try to bypass those things

#

xd

shut wraith
barren apex
#

has anyone done the attack kerberos module?, is it worth doing if i have already done attacking AD module?

sly dome
#

or maybe i dont remember it correctly

#

but xxe is the right track

#

right now i dont have my notes

#

later we can see it

brave bear
#

Thank you very much, day has been saved!

flint chasm
#

Hi All
I got a problem with a second quest in Windows Privilege Escalation Skills Assessment - Part 1
I used Windows-Exploit-Suggester but there is no any CVE exploit in response which will works. I know that CVE-2021-1675 works in that case but don't know why Suggester does not show me that one CVE
Someone maybe know how can I find this CVE-2021-1675 by myself?
I also used winPEAS..

shut wraith
#

So close to completing. But skills assessment is too hard. I repeated everything that I did in the module. But it doesn't work

undone narwhal
shut wraith
shut wraith
#

It doesn't reject it but it also doesnt load it

undone narwhal
#

is your machine up?

shut wraith
#

94.237.48.48:52201

#

Did it work for you @undone narwhal

undone narwhal
shut wraith
#

After I send intercepted request it rejects the file

#

Exact same request but different response @undone narwhal

#

@undone narwhal that is the exact same payload that I had. And I still coppied and pasted and it didn't work. It just sends back a blank thing

undone narwhal
#

dm me

hallow kiln
acoustic owl
barren apex
#

They just started getting expensive after level 2 don't they....gotta work out what one I fancy

acoustic owl
#

It describes the attacks better than the AD Enum & Attack module.

acoustic owl
barren apex
acoustic owl
#

With the student subscription you can not do modules above Tier II

#

But also the modules Tier 0 - II are great

analog dock
#

Wtf does this have to do with modules

shut wraith
#

2 days to finish the skills assessment for this

sly dome
#

well done

#

wasnt that difficult

orchid pine
#

wtf im doing

#

im so sorry

analog dock
#

👍🏼

flat niche
#

Hello guys,
I'm dealing with the module "Password attack" task "Password mutations".
The task ask us to bruteforce the password of "sam" using the mutated password list.
I'm bruteforcing with hydra, but it shows that it will take 10 h to test enumerate all the passwords in the list.
Do anyone have some hints on this task?

hallow kiln
#

Hint: don't brute-force SSH, too slow

flat niche
#

Thank you!

#

Yes that's ture maybe I should try other ports first

hallow kiln
#

Yeah, see what else is running

brazen hinge
#

HI, anyone has solved the skill assessment 2 of NoSQL Injection that could send me dm for help me. I get the way to extract information but i cant do any more. Thanks!

brazen hinge
#

I didn't want to provide details that could be considered spoilers, but in summary, I've found the 'point' in the responses from which I can infer data extraction. I can extract information related to the username, but not the password. For the password i only can get that 'this.password' exists, but nothing for the length o characters.

thorn urchin
#

Im pointing out that you havnt told what module this even is 😂

#

theres dozens of 'Skill Assessment 2'

brazen hinge
#

Oh bro jajajaja sorry i talked about No SQL injection. Thank you for telling me

woven copper
brazen hinge
#

@woven copper I founded the point some time ago and i can use for enumerate usernames and only can get one, the same that is in the placeholder in the login form

#

can i DM you?

woven copper
#

oh i remmeber , did you enumerate all funcionalities on the application ? beacuse i think there was a login , some password reset maybe ?, mm what could you do with that

brazen hinge
#

im trying in this moment with forgot password, but for now i only can extract information in login

woven copper
#

really interesting, so the inyection its on login , but you have a forgot password funcionality, also you have usernames , I have to ask , how do you think that a reset password funcionality works ? how it could be implemented ?

brazen hinge
#

only say that token will be sent to email address

woven copper
#

and when user present that token, how the application knows its a valid token ? come on man you got it , I'am not going to give you the answer.

brazen hinge
#

there is a form where i can send the token, but i dont have it

#

I will take a look at the token form.

woven copper
#

go try harder and if you still stuck feel free to DM me.

brazen hinge
#

thanks bro, i'll try

sly dome
#

but use the hint our friend provided

#

weird that latest FreeRDP version has a bug for PassTheHash

#

version 2.3 that comes with default Parrot/Kali mirrors works like a charm

#

but 3.0.0. is bugged, prop to developers

orchid pine
#

guys this cmnd is worng or what cuz its taking toolong and not giving annything back

quick magnet
#

hi i'm stuck on linux privilege section Logrotate
i try logrotten ./logrotten -p ./payload b*/a*.log
message Waiting for rotating b*/a*.log..
can't get reverse shell

tidal mango
orchid pine
#

guys if i have writedacl on the domain

#

can i add myself dcsyn rights

fathom pendant
tidal mango
orchid pine
#

i want to add those to my user

#

but the cmnd is taking like 20 min wtf

#

Xd

#

Evil-WinRM PS C:\Users\svc-alfresco\Documents> Add-DomainObjectAcl -TargetIdentity "svc-alfresco.local" -Rights DCSync

quick magnet
orchid pine
#

Guys

#

I want to try

#

GOAD-Light

#

Is it a good practice for Active Directory

#

Or its too hard like

#

For a beginner like me whos trying to practice the ad module

vital adder
orchid pine
#

XD

#

Game of active directpry

vital adder
#

oh that thing

orchid pine
vital adder
#

to be honest if you are a beginner just do the Dante prolabs

vital adder
orchid pine
#

they have a light one

#

ig like you said

sly dome
#

you need a base ubuntu host

orchid pine
#

ill just do the dane

vital adder
#

i mean if you look at the writeup some of not most of them is cover in the academy and ProLabs will 100% cover the rest

sly dome
#

go for Zephyr ma boi

orchid pine
#

i read and ig i need to configure alot of things

vital adder
orchid pine
sly dome
#

and

#

nobody was born as an expert

vital adder
#

you'll learn on the job lol

orchid pine
#

i just finished the module active dirctory and box forest and got to exited

#

im just asking like is ita good idea to go for it

#

to do zyphyer and dante

sly dome
#

finish the path 🤷

#

attacking enterprise has a good lab

orchid pine
#

u know i want to practice something like what i learned so i dont forget abou it

sly dome
#

do w.e. u like man

vital adder
orchid pine
#

ty guys

#

for ur help

tranquil axle
#

Dante has very little ad, but if you subscribe to prolabs you unlock them all for the month so you can try both, Dante and zephyr

fathom pendant
#

80% of zephyr is covered by CPTS (Allegedly)

naive wadi
#

In DACL Abuse I Password Abuse Section the final question " Abuse Marcos access rights to gain access to the gMSA account htb-svc$. Using the gMSA account credentials, read the contents of the flag at \DC01\GMSA\flag.txt and submit it as the answer. "

#

I have the hashes via ||gmsadumper & gmsapasswordreader|| but neither work? I have tried ||cracking|| & ||overpassing|| but it's not working

#

any pointers?

tiny reef
#

"Whitebox Attacks - Prototype Pollution PrivEsc" : I am following the chapter 1:1 but I don´t seem to get a pollution, hint in the right direction would be really appreciated

acoustic owl
naive wadi
#

I know it's a skill issue with something I am missing

acoustic owl
naive wadi
acoustic owl
tiny reef
#

I just got it 1 sec ago, indeed I had to dabble a bit with the payload 😄 Thanks though

next kelp
#

I'm learning digital illustration, and with that I want to learn how to make indie games. In your opinion, what is the best unity or unreal one?

fathom pendant
rustic sage
#

Hello , I am new here and I am a student, what to start with

tidal kelp
#

are there any tricks on get xfreerdp to utilize the screen resolution?

rustic sage
#

I am new here so I have no idea what to do and what to start with

fiery berry
rustic sage
#

Pls help me

#

Hello

fiery berry
tidal kelp
rustic sage
acoustic owl
rustic sage
#

Ok but how to destroy the machines

#

I don't know any commands

fiery berry
acoustic owl
fresh pier
#

Is there anyone I can ask about kerberos attack module skill assessment last question?

fiery berry
rustic sage
#

How to hack the first machine

acoustic owl
rustic sage
#

I ain't trolling or annoying anyone here

#

I just need guidance

#

I am being serious

#

I am confused

acoustic owl
rustic sage
#

Wth

#

So how come will I be able to destroy the machines

acoustic owl
hallow kiln
acoustic owl
rustic sage
#

Like yk random machines

#

Like practice machines

#

To test out hacking skills

#

Vpn and stuffs

hallow kiln
#

Test out what when you haven't started learning?

rustic sage
#

Yea like

#

The starting point

tidal kelp
novel matrix
#

Let’s stay on topic please.

fiery berry
rustic sage
#

Like there's gotta be a tutorial

#

I just need the tutorial

acoustic owl
rustic sage
#

It says no access

acoustic owl
hallow kiln
#

First, you're in the wrong channel for starting point questions, read and follow #welcome. Second, there are walkthroughs and write-ups you can read.

fresh pier
acoustic owl
tidal kelp
#

thx for help!

fresh pier
# acoustic owl Just ask your question here

I've already obtained the user, but I'm unsure about the next steps. The hint mentions, 'If a user logs in, we can steal their identity.' Do I need to use Rubeus to monitor user login? but I rdp in and it use parrot terminal do I need to swap to use window or something ? I don't know what to do next

fathom pendant
fresh pier
acoustic owl
#

Check out C:\Tools

fresh pier
acoustic owl
#

This is the Question, right?
What's the content of the file: \DC01\Secret Share\flag.txt

acoustic owl
# fresh pier Yess

I have no idea where you logged in. The machine I used at that time was a Windows machine

fresh pier
acoustic owl
#

You have creds from ||annette.xxxx|| right?
If so, use xfreerdp from this machine to connect to the machine ||x.x.8.35||

fresh pier
next kelp
#

Knowledge is everything! In this world so hard and volatile

k8s 🏈 🏀 ⚽

cedar void
#

"Create a mutated wordlist using the files in the ZIP file under "Resources" in the top right corner of this section. Use this wordlist to brute force the password for the user "sam". Once successful, log in with SSH and submit the contents of the flag.txt file as your answer. "

https://academy.hackthebox.com/module/147/section/1391

hashcat --force password.list -r custom.rule --stdout | sort -u > mut_password.list

Did I do anything wrong here?

fresh pier
tidal kelp
#

currently on the AD/ Initial Enumeration of the Domain trying follow follow along and capture the network traffic. Feel like I'm must be doing something wrong. cause neither wirewhark or tcpdump gives me any output that suggest the ip range mention in the section... any ideas?

acoustic owl
fathom pendant
acoustic owl
fathom pendant
#

If it's > 90k then it's correct

cedar void
sly dome
#

jesus

fathom pendant
# cedar void

Did you use the custom.rule from the zip? And did you copy the syntax of the given command from this section

sly dome
#

it is correct

#

94k

sly dome
#

its told to you

fathom pendant
cedar void
#

I did use the custom.rule and password.list from the resource folder

fathom pendant
#

Sorry my network is being slow

#

Enumerate first on the target

sly dome
#

the dictionary is ok

#

go ahead

fathom pendant
#

^

#

You honestly ask a lot of questions without doing

cedar void
fathom pendant
#

Are you asking me?

#

You're this deep into the path, you should know what to do

cedar void
fathom pendant
#

They give you enough information

#

They shouldn't be needing to tell you to use Nmap at this stage tbh

#

It should be your first instinct. Even if you're given a service name

#

Pretty much all the modules up to this point have been centered around enumerating a given target

cedar void
#

Im on a learning journey and I am not going to know everything as I attempt to find solutions to my problems. Everyone doesn't reach their path the same way. Thats all ill say about that.

I used nmap and the relevant port shows me an rsa certificate and the info about the OS system.

fathom pendant
#

Step 1) enumerate

#

You got some info, figure out how to use it if possible

#

The modules roughly build off of each other to build your skills

#

If you're asking if you should do something, just do it

#

That's how you're gonna pass the exam, by trying different things

#

I do honestly believe you can do it. 99% of the people that are doing the path to completion can pass it.

#

The 1% are the people just infodump learning

lusty thicket
fathom pendant
#

Also, I know I come off as harsh at times, but it's because I genuinely want people to succeed

#

Like some answers seem snarky (because they are) or even just obvious answers

#

But I don't like just hand feeding the answer, especially if you just didn't try

lusty thicket
#

you can’t force people to learn

raw forum
#

Socrates: "I cannot teach anybody anything. I can only make them think"

cedar void
fathom pendant
#

It really helps

cedar void
fathom pendant
#

Must be Asian la

fathom pendant
#

2 + 2 * 3

#

Failure

#

You forget the pemdas

#

The answer is 8 la, you do the 2*3 first la

edgy copper
#

Hi Team, there is any channel for Dante Pro Lab? I'm starting work on it

fathom pendant
edgy copper
#

What do you mean?

#

I see, thanks!

naive turtle
#

Anyone experiencing any issues with pwnbox and rdp into targets at the moment? Mine just keeps disconnecting every 2-3 minutes

crude harbor
#

Hello Guys !

#

i'm in Footprinting Lab - Hard i found Credentiel of tom but i cannot connect with SSH i need keys ..

#

any advice or help ? thank you

hexed tendon
vital adder
vital adder
vital adder
hexed tendon
vital adder
#

i mean a page that exist like the index.html page, if you fuzz any parameter on there the code will always be 200 but the size will change if you hit something right or different so yes the -fs tag

steel lake
#

Hi! I'm going through the Active Directory LDAP module. I'm on the last page "Skills Assessment", and I can't get a stable connection to the target machine.
I tried:

  • connecting from my Kali VM using the VPN (I see nothing specific in my VPN connection logs)
  • connecting using the Pwnbox (I have unlimited hours)
  • resetting the target machine
    Connection issues look like this:
┌─[eu-academy-1]─[10.10.15.158]─[htb-ac-739180@htb-oyatrr7p1d]─[/opt/ldapsearch-ad]
└──╼ [★]$ xfreerdp /v:10.129.64.205 /u:htb-student /p:<the-password> /size:1024x768 /kbd:"Belgian French" /cert:ignore
[14:41:17:969] [4129:4130] [INFO][com.freerdp.gdi] - Local framebuffer format  PIXEL_FORMAT_BGRX32
[14:41:17:969] [4129:4130] [INFO][com.freerdp.gdi] - Remote framebuffer format PIXEL_FORMAT_BGRA32
[14:41:17:992] [4129:4130] [INFO][com.freerdp.channels.rdpsnd.client] - [static] Loaded fake backend for rdpsnd
[14:41:17:992] [4129:4130] [INFO][com.freerdp.channels.drdynvc.client] - Loading Dynamic Virtual Channel rdpgfx
[14:42:31:689] [4129:4130] [ERROR][com.freerdp.core.transport] - BIO_read returned a system error 110: Connection timed out
[14:42:31:689] [4129:4130] [ERROR][com.freerdp.core] - transport_read_layer:freerdp_set_last_error_ex ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D]
[14:42:31:689] [4129:4130] [INFO][com.freerdp.client.common] - Network disconnect!

What's the proper way to report that kind of issues? I've tried to find a proper "contact customer support" page on the HTB website, but didn't find it.
Thanks!

ornate vapor
#

how i can start in hacking infosec idk if its the same area

compact patrolBOT
vital adder
#

@ornate vapor read the #rules don't dm anyone here without asking first and nope learn what you want don't ask me about it

vital adder
#

HTB did have some connection issue lately so if the issue persist maybe reach out support

steel lake
vital adder
#

that site is for main platform not the academy also after killing the pwnbox wait a few min if things is still buggy

sly dome
#

are they trying to teach us to be patient when brute forcing with the password attacks Labs? 🤣

crude harbor
quick magnet
#

hi im stuck in linux priv flag5

  • already create reverse shell like in Attacking Tomcat section
  • sudo -l, /usr/bin/busctl
  • try to upgrade shell with python pty python -c 'import pty; pty.spawn("/bin/bash")'
    not working, any hint thanks ?
sly dome
#

double check your commands

crude harbor
tame ivy
#

Hello everyone, stuck in Web Attacks module,Section:Mass IDOR Enumeration, exercise is enumerate all files and find a txt, there a script also, but nothing returns me a txt file, im also done a manual enum with burp, there just pdf's, could anyone give a hint or help me pls?

sly dome
#

but imaps is indeed your goal

crude harbor
quick magnet
vital adder
sly dome
#

just curl all uid's and grep for .txt

vital adder
#

doing that part manually is so much easier but automation is fun lol

sly dome
#

yea this is automatic xD

vital adder
#

*semi

sly dome
#

?

vital adder
quick magnet
pearl matrix
#

Hi evereyone. I've a silly question. Someone can help?

vital adder
vital adder
pearl matrix
# vital adder if it's academy related

I'm in the Web proxies module on the Bug Bounty path, and I'm stuck on the 'Burp Intruder' session. Basically, it asks, in these words: 'Use Burp Intruder to fuzz for '.html' files under the /admin directory, to find a file containing the flag.' Here's my payload marker: GET /admin//§FILE§ HTTP/1.1, and this is the payload I used: Index.html, flag.html, htb.html, etc... (don't laugh at my poor and simplistic payload). The configurations are correct, but even so, when I start it, it only finds one page with a 200 OK response, which is the index.html (but every web page has that, so I think it might be a false positive). Here's a screenshot with the payload results:

sly dome
#

use a better list

pearl matrix
#

better? it is in usr/share/dirb/wordlists?

vital adder
barren apex
sly dome
#

i think common.txt

#

should work

#

the payload should be BURPPAYLOAD.html

#

basically follow the section steps

barren apex
sly dome
#

i have not

barren apex
#

Attacking splunk is not returning me any splunk lol

pearl matrix
barren apex
#

and thees no mention of vhosts

vital adder
#

oh i thought it would the thick client again lol

pearl matrix
#

But the marker is right? "GET /admin//§FILE§ HTTP/1.1"

vital adder
barren apex
#

sigh

#

thats 30minutes i wont get back

#

amount of times ive done that with HTB, there will be one random page that is HTTPs haha

#

thanks

crude harbor
sly dome
#

curl -k 'imaps://<IP>/INBOX;MAILINDEX=1' --user tom:<tom's password>

#

spoiler

#

delete

crude harbor
#

i got it but it's not enough because to access SSH you need key bra

sly dome
crude harbor
#

Ok

pearl matrix
#

But the marker is right: "GET /admin//§FILE§ HTTP/1.1"?

sly dome
#

use common.txt as list

#

and as payload use GET /admin/§FILE§.html

pearl matrix
#

ok i'll use it like u said

crude harbor
regal walrus
#

I hate furries

true marlin
#

guys i can you tell me something becouse im new in hackthebox, every modul has certification after you finish it ????

#

for example i ahve my firts modul SOC Analyst if i finisht it can i get a certification or nahh

rustic sage
true marlin
#

have any free certification

#

becours i have see 3 proffesional certification

#

but any other has?\

fathom pendant
#

Htb doesn't have any free certs

#

And relatively speaking the HTB certs are cheaper than their relative equivalent ones from other companies

heavy mango
#

Can someone who's done the Using Web Proxies module explain how the response intercept in Burp is supposed to work? First of all, the screenshots in the module don't match recent Burp versions, second, even when I found the correct settings, I'm not getting any editable HTML response the way it's shown

rustic sage
#

stuck on DCsync section in the ad module. trying to run powershell as adunn the use privilege::debug in mimikatz but i get this error (ERROR kuhl_m_privilege_simple ; RtlAdjustPrivilege (20) c0000061) anyone know why im pretty sure its the runas command because i type who am i in the newly spawned powershell terminal and it says htb-student

rustic sage
heavy mango
#

I have enabled response intercepting

#

nvm, hadn't enabled a rule for intercepting responses after request modifications

fathom pendant
#

To get a desired response

heavy mango
sly dome
#

i could complete the module with the latest version of Burp

#

just by following it step by step

heavy mango
#

yeah, I got it working now, it's just that the settings have moved, so the screenshots don't match what's in the program

true marlin
#

I forgat to say i say free where you have buy vip.monthly

fathom pendant
rustic sage
fathom pendant
#

And you don't even need to subscribe

rustic sage
crude harbor
#

Oh yeah just finished footprinting let's goooo pupexcite

rustic sage
crude harbor
#

i'm doing the path of Penetration Tester

rustic sage
#

same

crude harbor
rustic sage
#

no problem i say it cuz u need encouragement on this course it gets tough

crude harbor
#

good luck

#

dont forget to take break it's helpfull also for cognitive system

rustic sage
#

u sound like my girlfriend ☠️

crude harbor
#

bra :3

#

Just quetion how much hour per day you spend doing labs ?

rustic sage
#

I sorta drifted away from labs rn im focused on certs ive been doing this for like 3 years so i did alot of try hack me rooms

crude harbor
#

😮

#

i'm not even month doing this

rustic sage
#

Im doing the pentester and bug bounty cert then oscp

fathom pendant
#

Htb labs are far more challenging

crude harbor
#

Niiiice

rustic sage
fathom pendant
#

Htb easy = thm hard

true marlin
#

Thx

rustic sage
#

That sounded like a question

true marlin
#

I have complete some penetration tester and ethical hacking course

rustic sage
#

Was not a question i agree they are 🤣🤣

true marlin
#

So i have search for some bew chaengers

crude harbor
#

i ll go for CEHV12 next year so i'm warming up in HTB

true marlin
#

Nice

fathom pendant
#

Anyway