#modules

1 messages · Page 147 of 1

blazing pelican
#

it took me way longer than it should have been but I learned so much while losing myself on its simple machines ^^

robust elk
#

i also cant message you

acoustic owl
#

The module explains every single step to you.

cursive glacier
#

What was the reason for the Citrix box in windows privesc being windows 7?

acoustic owl
#

The complete module is a walkthrough through the tasks. It shows you every step you need to take.
It is structured so that you can solve everything yourself after the path, but gives you more cool tips.

reef anvil
#

Hello all.
I'm stuck on
Skill Assessment - Broken Authentication
Assess the web application and use various techniques to escalate to a privileged user and find a flag in the admin panel. Submit the contents of the flag as your answer.
Could I get some help?

acoustic owl
reef anvil
acoustic owl
reef anvil
acoustic owl
dreamy solar
#

Hello I have a problem with this exercice : I listed the TCP and UDP ports, I understood that I had to use snmp but I cannot find a functional command in the memory aid. I did this: onesixtyone -c public 10.129.202.20, braa public@10.129.202.20:.1.* and snmpwalk -v2c -c public 10.129.202.20 but that doesn't lead to anything

reef anvil
acoustic owl
fiery berry
dreamy solar
#

I must admit that I don't know how to do it, do you have any suggestions for me to document? I searched in the course I don't see where he talks about it to retrieve the community channels

#

Please

fiery berry
dreamy solar
#

thank you

fiery berry
fathom pendant
#

I just looked

dreamy solar
tame ivy
#

Module:File Inclusion
Section:Basic bypasses
I have tried every combination of bypasses, tried also fuzzing it with Jhadix and other LFI wordlists(burp and ffuf) and always a illegal path, i have completed all module except this fking section, could anyone help pls?

tame ivy
sly dome
#

it works

tame ivy
sly dome
#

dont encode everything

tame ivy
#

nvm i found a payload, thank you

tacit topaz
#

Hi ! Someone can help me with the mssql part of the footprinting module ?

sly dome
tacit topaz
#

Oh ok, i didn't want to spoil so I was thinking of doing MP 😄
I'm on the MSSQL part, the last question is : 'Connect to the MSSQL instance running on the target using the account (backdoor:Password1), then list the non-default database present on the server.'
I'm connected to the MSSQL and I find one non standard DB and I find one table for this DB and I select everything in this table but I don't find any flag...

sly dome
#

reread it 🤣

fathom pendant
tacit topaz
#

Ah !

#

OK ! 😄

#

Thanks for your help !

rustic sage
#

ive a question

#

i know nothing about coding and hacking but im here to get started

#

is there a free course which is useful?

#

or i have to pay to actually acquire some meaniningful skill?

tacit topaz
#

They are some free modules on HTB academy, they are nice ! Also it depends of what interest you have...

#

I think free modules are very nice to discover different things, and after choose a path, and maybe paying for more

rustic sage
real meteor
#

Starting Points on HTB is a great start to PenTesting in my opinion

rustic sage
#

i tried to learn some python but im not very skilled

hallow kiln
#

if you're more interested in coding, this isn't really the place to learn, there's but a few modules on the basics

tacit topaz
real meteor
#

i agree, before HTB, i was a potato when it comes to Linux, but now im getting the hang of it, still a potato, but learning more by the hour

rustic sage
#

oh yeah linux

#

i need linux on my pc

hallow kiln
#

there's a Linux Fundamentals module

#

not on your PC unless you want to switch, you can run it in a VM

real meteor
#

you can go to the Microsoft Store and search linux

#

i reccomend Kali Linux, but Ubuntu is more User-Friendly

vivid socket
#

Yea WSL is pretty nice

hallow kiln
#

WSL? I wouldn't recommend that to a beginner

vivid socket
#

Fair point

rustic sage
#

so i can run linux as an application instead of an os right

vivid socket
#

The lack of a UI would be rough

hallow kiln
#

you can run it as a virtual machine in VMWare or VirtualBox

rustic sage
#

so do yall work on projects or sometning

vivid socket
#

I did come across a book that’s angled at being a starting point for folks who don’t know anything about anything. Working through it might be a good start?

real meteor
vivid socket
# rustic sage i see
ThriftBooks

Buy a cheap copy of Penetration Testing: A Hands-On... book by Georgia Weidman. Penetration testers simulate cyber attacks to find security weaknesses in networks, operating systems, and applications. Information security experts worldwide use... Free Shipping on all orders over $15.

real meteor
#

dont got the skills to work with others when it comes to Pentesting

rustic sage
real meteor
#

im still working on the starting points, so no

vivid socket
#

This was beginner friendly in that it doesn’t assume you know anything

vivid socket
#

It walks you through the basics of Linux and programming and setting up a vm

rustic sage
vivid socket
#

And then builds on that

rustic sage
vivid socket
#

Oh I mean like, it works from there towards the concepts of basic pentesting

tacit topaz
rustic sage
#

oh

rustic sage
real meteor
#

about 2 days, and im starting to understand things like NMAP, MySQL and john the ripper

rustic sage
#

im 16 is it a good age to start

tacit topaz
tacit topaz
real meteor
#

i started coding at 12 and im starting htb now at 15

rustic sage
#

will i be able to use anything i learn for working on a project for myself sorta

tight bolt
#

Do I only have two hours of pwnbox in a lifetime or per day?

hallow kiln
#

how you apply the knowledge you gain is up to you

real meteor
#

lifetime, BUT, and it a big but

#

you can run openvpn on your own machine to bypass that "2hour limit"

rustic sage
vivid socket
#

Yea the pwnbox is just nice cause it’s a custom built environment so you don’t have to finnick with it

tight bolt
real meteor
#

yup, pwnbox opens a new window on your browser that acts as a machine running linux, and openvpn is hosted form your own machine

#

like a 'window' to see what that virtual machine sees, and use it as your own machine to complete the questions

tight bolt
real meteor
#

you can go to the HTB site, Starting points

#

tier 0, and to the meow machine

#

you should see the option to use pwnbox or openvpn, pwnbox is click to start, but openvpn needs to be run on your machine

tight bolt
#

thank you

real meteor
#

if you need anymore help, feel free to DM me

sonic trellis
#

😉

real meteor
#

anybody got any idea why i cant access unika.htb

#

it just says ip took to long to respond

acoustic owl
#

Have you entered the domain in your hosts file?

real meteor
#

yup

#

and the same problem happens

umbral fulcrum
#

hey guy someone did "Attacking Common Applications - Skills Assessment II" that can help me ??

umbral fulcrum
#

I'm stuck a long time on the "What is the admin password to access this application? " question

#

I looked in the ||gitlab|| but didn't found anything, tried the ||basic password as well|| and nothing ...

rustic sage
#

stuck on the file inclusion module the file inclusion prevention part, not gonna lie i dont understant it at all or what im supposed to be doing can someone explain

umbral fulcrum
umbral fulcrum
cedar void
#

"Connect to the target machine using RDP and the provided creds. Export all tickets present on the computer. How many users TGT did you collect? "

At this point I just want to connect to the target machine. So does the certificate mismatch have anything to do with why I am unable to connect

??

https://academy.hackthebox.com/module/147/section/1639

acoustic owl
fathom pendant
umbral fulcrum
umbral fulcrum
acoustic owl
umbral fulcrum
acoustic owl
cedar void
rustic sage
umbral fulcrum
fathom pendant
umbral fulcrum
acoustic owl
rustic sage
sly dome
sly dome
tame ivy
#

Module:Attacking Enterprise Networks
Section:Web Enumeration & Exploitation
error when log-in on wordpress site(http://ir.inlanefreight.local), found a valid username and password and there is an error, can somebody tell me what is wrong?

umbral fulcrum
acoustic owl
#

Check all Functions on the Gitlab Page

umbral fulcrum
umbral fulcrum
#

but meterpreter doesn't have find command...

acoustic owl
#

You don't have to find a user, crack a password, just use the functions of Gitlab.

umbral fulcrum
pale flume
#

What designation do we typically give a report when it is first delivered to a client for a chance to review and comment? (One word)

#

Does anyone have one word answer for this question

fathom pendant
acoustic owl
pale flume
#

i tried using all possible designations but couldnt get the final answer

#

module 1 Post-Engagement

fathom pendant
#

Module 1 that's not a module name

pale flume
#

Module 1 PENETRATION TESTING PROCESS
Post engagement section

fathom pendant
#

Read the section carefully

#

The word is in there

pale flume
#

not able to find exact designation

fathom pendant
#

Yes but that's not what it's asking

#

Its asking about the report

#

In fact partial wording of the question is in the text

pale flume
#

ohhh got the answer

#

thanks for your support

fathom pendant
#

Learn2read :^)

restive hound
#

Can I get a hint for the skills assesment in Introduction to Threat Hunting & Hunting With Elastic. I am looking for || event.code: "13" || but I am not sure what else to add or how. I have tried a bunch of different ways of looking for, registry changes/modifications, start up folder being ran.. I know it's right in front of my face. Most likely just overthinking this. Thanks

acoustic owl
open jay
#

Hi, is there anyone that could help me? I'm do the HTTPs/TLS Attacks assessment. I have got a token by changing the cookie value to admin. But stuck at the redeem token.

umbral fulcrum
#

Hey Guys, I going crazy here (in
"Attacking Common Applications - Skills Assessment II")

I did all the Qs but the first one: "What is the URL of the WordPress instance? "
I don't C it anywhere nor it's connection to all the rest of the assessment ...
can someone please help

tame ivy
umbral fulcrum
tame ivy
umbral fulcrum
#

I know I got it few Q ahead but it doesn't give me the WP

fathom pendant
sturdy otter
#

any ideas? Cracking the NT with rockyou and hashcat was no problem. For fun I wanted to also crack the SHA1 Hash but hashcat gets quickly exhausted with same wordlist. I used hashcat -m 100 (raw SHA1) and ignored potfile. Shouldn't that be the same password just different algorithm? Or is Microsoft using another SHA1 based algorithm here? In the module it states both NT and SHA1 are the hashes of the password. Cant find something about that in the MSV1_0 official doc. Ty!

fathom pendant
#

But it's also entirely possible that this password is intentionally not in the lists

#

I also don't think it's raw SHA1, there's like 80 different sha1 related algos in hashcat

#

Didn't read your first part

sturdy otter
# fathom pendant Ntlmv2

mhmm weird, Ntlmv2 looks different. So I also guess this is some other variation of SHA1. But as long as I get the NT hash its fine for now

sturdy otter
fathom pendant
#

But tbh if you have NT hash you don't need to crack SHA1

sturdy otter
#

yes true, sometimes I just like to play around with the other information I can find hehe

fathom pendant
#

I think hashcat has an option to help properly identify the hash and mode needed

fathom pendant
sturdy otter
fathom pendant
#

I would say if you were presented two different sets of data from different tools I'd cross check. But since it's the same tool then meh

sturdy otter
#

yea

fathom pendant
#

Also if you're meant to crack that user as part of the module, delete the image 😉

#

As it's still a spoiler

sturdy otter
#

whoops yeah

#

sorry

fathom pendant
#

The general consensus with spoiler imagery is: if you're asking for help delete it after you receive the help

#

Especially if there was literally no other way to express your issue

sturdy otter
#

But Iam quite sure now this "SHA1" is not raw or something different, just took the password and converted it to SHA1 and its a different string

fathom pendant
#

Yeah it's probably one of the 75 sha1 related algos

sturdy otter
#

however lets go on with learning ;D

fathom pendant
#

Gl hh

distant moat
#

./ptunnel-ng: error while loading shared libraries: libcrypto.so.3: cannot open shared object file: No such file or directory

#

guys how to fix it

naive wadi
distant moat
#

the target not allow to use apt

naive wadi
#

Google python virtual environment

#

Also I'm just trouble shooting this one error you have, having context would help a lot

distant moat
#

okay

#

module : PIVOTING, TUNNELING, AND PORT FORWARDING session : ICMP Tunneling with SOCKS

distant moat
jagged swift
#

have a question, I wrote in the community help, but I will try here to. I'm on a staring modul, that I should download a VM but that VM that is offered is on Windows and one on Linux, the problem is that I'm on a mac. What is the best program to use if can't that prechoosen one? 🙂

rustic sage
#

do you mean the software that is used to run the virtual machines?

jagged swift
#

yes that is right

fathom pendant
#

Depends on the chipset used in the Mac, if it's m1/m2 then you want utm. Also iirc virtualbox or VMware do have Mac versions of their software

jagged swift
#

But I didnt see it, I was looking for VMware but only found windos or Linux

fathom pendant
#

5 seconds of Google

teal talon
#

is their anybody whos ready to help me a real quick

sterile epoch
#

any idea what am I doing wrong?

jagged swift
#

thank you @fathom pendant

leaden pond
#

Module: Windows Privilege Escalation
Section: Server Operators

I was able to obtain the NTLM hash for the Administrator password and crack it offline, but I can't RDP to the target using those credentials. I can still RDP in using the server_adm creds, but not the Administrator creds. Not sure how to get the flag from the Administrator desktop without being able to RDP to the target.

fiery berry
sterile epoch
#

I am getting incorrect answer error

fiery berry
sterile epoch
#

for the linux basics module

#

I was told to use the find command I provided the filename with extention, full filepath and only the filename in the answer but I get an error

autumn pilot
#

you need to ssh into the target

sterile epoch
#

oh

reef anvil
# acoustic owl The username is incorrect. On the website you will find hints || Something about...

Hello bro, appreciate your help
I've found valid usernames and passwords, exacts 4 extra logins ||support.it support.gr support.cn and support.us||, but there are no flags there when I login there.
Also I've obtain the way how session is cooks and wrote script to brutforce all possible roles like ||support.gr:admin||
also, tried the strings like ||administrator:administrator|| and all possible various of it, but no luck
Could I ask one more tip? 🙂

acoustic owl
acoustic owl
# tame ivy Just use Ligolo-ng

Which then has nothing to do with the task 🤷🏻‍♂️
But it will work, just like any other pivoting technique.

pallid geyser
#

hi ,where is the help chat in this server?

autumn pilot
#

can you elaborate

loud mauve
#

I am stuck at Automating Payloads & Delivery with Metasploit in the payloads and shells modules. Here is what I have done so far. I have run an nmap scan to discover the services running. The most exploitable services seems to be SMB. I have run the same exploit and I keep getting a ".... STATUS_ACCESS_DENIED: {Access Denied...." after running the exploit. What could be wrong or what am I missing am I even exploiting the correct service. Please help.

pallid geyser
#

I cant loggin ssh with an ip, im new, im in linux fundamentals and i cant login with ssh. When i try to log, it freeze withou response. Help please

fiery berry
pallid geyser
#

when i try to log, with ssh htb-student@<ip> , the temrinal doesnt show anything else

#

with connection time out

autumn pilot
#

<ip> is a placeholder for the IP of the target that you must specify

pallid geyser
#

im in a virtual machine kali linux

#

yeye i know i hve the ip, im in linux fundamental but the terminal doesnt show anything else

supple patio
pallid geyser
#

i hve to conect to the vpn and also ssh?

#

both?

autumn pilot
#

yes, this was explained in the introduction to academy module

pallid geyser
#

bruuuh didnt read it ty a lot

halcyon fox
#

Hi why when I try do one of modules sometime the questions unrelated at all ?

autumn pilot
#

some exercise would require you to use your analytical thinking

halcyon fox
#

You mean googling the new thing ?

#

Idk such as netstat idk about and how related to IPv4

loud locust
#

Hi. In the last question in "Intro to Assembly Language" ("The above server simulates a vulnerable server that we can run our shellcodes on. Optimize 'flag.s' for shellcoding and get it under 50 bytes, then send the shellcode to get the flag. (Feel free to find/create a custom shellcode)"). I've optimized the shellcode, got it under 50 bytes, tested that it runs on my local system, but can't quite figure out how to get it to run in that terminal shell. I simply connect, paste the code and press "Enter"... and nothing happens. Is there something specific that needs to be done in this exercise?

cedar void
autumn pilot
#

review your command

#

read carefully the error and the question afterwards

fiery berry
cedar void
#

Yeah apparently their are two john folders

#

well that didn't work. I will read that error

analog dock
#

@cedar void are you in C:\john ?

#

And did you connect to the DC01

cedar void
cedar void
analog dock
#

So you got it now?

cedar void
#

yep. thans

#

*thanks

glossy delta
#

hi guys, i am stuck on the markup box, i have managed to get Daniels RSA key and inserted into a file, set permissions on the file but when i try and use this on ssh it always seems to default to asking for a password for daniel, i also sometime get an error indicating something wrong with the "libcrypto", i have tried converting the file format with putty but that still doesn't seem to do much, i think i am doing something silly no doubt but kinda hit a wall if anyone can point me in the right direction would be much appretiated

#

can't seem to upload a screenshot of the error

hallow kiln
#

Read and follow #welcome to gain access to the rest of the server, this is not the channel for this

glossy delta
#

sorry

#

what one is the best to post this?

#

ignore me, found it i think, cheers

hallow kiln
glossy delta
#

Cheers mate

hidden prairie
#

I referred 2 people and did not get any cubes

analog dock
#

They didn’t fulfill their duty in that case

#

It’s not a matter of just inviting them

tough crystal
#

Hello, I am stuck Linux Local Privilege Escalation - Skills Assessment -flag2 I see the flag2.txt in b**** directory, but i cant not find the credentials for that user so later I can log in, and cat the flag

candid lily
#

which Kira

#

im not doing the module in order so i cant find the kira

analog dock
#

Smh lol

candid lily
#

ok nvm i found it

warm drift
#

Please I'm Stuck on File Uploads Skill Assessment

#

anyone available to help?

sly dome
warm drift
#

I think I've found a working double extension bypass for uploaded file name but I thnk I need magic bytes manipulation I've tried adding php hello world code after it but still fails or get some weird base64 page

sly dome
#

i didnt get any base64 page

#

so i dont know

#

if you uploaded it successfully you probably got the magic bytes

#

hint: GIF magic bytes do not work

warm drift
#

I used jpg didn't see .gif in a js script I found while searching the site

sly dome
#

then you probably also find the path where it gets uploaded and the naming scheme

#

you have everything!

warm drift
#

no

sly dome
#

keep enumerating in that case

leaden pond
#

Module: Windows Privilege Escalation
Section: Vulnerable Services

I'm able to catch a reverse shell, but I don't have permission to access the Administrator desktop, even though I changed the execution policy in Powershell to unrestricted.

warm drift
#

I feel like I've seen all the pages and my problem is just with magic bytes to make my php payload print hello worldso I know it works

sly dome
#

how come you didn’t find the naming scheme and the upload path but you are executing it? o.O

#

you can reach me on DM to avoid spoilers

warm drift
#

ok

candid lily
#

hint: first try to fuzz all the allowed file extensions

flint helm
#

Anyone else having issues with the game crashing when running the script in the Scripting AoB section of the Game Reversing & Modding module?

hidden prairie
late urchin
#

Stuck on the "Intro to Assembly Language" skill assessment Q1.

"Disassemble 'loaded_shellcode' and modify its assembly code to decode the shellcode, by adding a loop to 'xor' each 8-bytes on the stack with the key in 'rbx'. "

So far i've been able to decode the shellcode so the one I have now starts and ends with "4831...0f05" but I can't get it to run and checking it with GDB shows a bad line but I can't figure out how to fix it.

karmic reef
#

Has anybody done the "Kerberos Attacks" Skill assessment? I could use some help on that

sly moat
#

how do i get more cubes without paying?

sly dome
sly moat
#

i did that and my friend completed the intro module

#

buy i didnt get any cubes

sly dome
#

wait 24 hours

#

also Tier II or higher only

#

intro module does not count

sly moat
#

oh thats unfortunate

brittle gorge
#

need help with AD Enumeration & Attacks - Skills Assessment Part II

Question #3

fps < 0.1 with RDP what to do :<

jolly solstice
#

Oh my! I’m still in the intro and about to give up soon 😭😂. Nah, I love it here but omg, I really need to utilise these brain cells of mine in a whole new way 😂😂.

misty current
brittle gorge
brittle gorge
jolly solstice
late urchin
#

Anyone able to give a hint on my question from earlier? still stuck on this damn Assembly question lol

mortal basin
sly dome
#

is it published??

mortal basin
#

just published 🙂

sly dome
#

lets go

#

tonight gonna be a good night

late urchin
#

sick

rustic sage
#

hii

#

anyone here?

#

@sterile hawk

#

anyone here??

sly dome
rustic sage
#

nvm

#

so i am new to the whole hacking and coding thing

#

i want knowledge

naive wadi
#

best get reading then

rustic sage
#

reading what

naive wadi
#

everything

rustic sage
#

from where

sly dome
#

annoying.

rustic sage
#

im just asking dude

naive wadi
rustic sage
#

i have some basic questions-do i have to know coding for ethical hacking, if yes what language how much i should know as a starter what things to download ,all of these things

late urchin
#

lolol

rustic sage
#

🤣

late urchin
#

python 3 is a good start

rustic sage
#

ik pyhon but what is python 3

#

i know a bit of mysql

#

💀

late urchin
#

....

naive wadi
naive wadi
#

then once you have read that if you have more questions, or they weren't answered, comeback but don't post in here. Post in #general

naive wadi
rustic sage
#

ok

rustic sage
#

in the website intrest im getting a lot of options

#

idk a single thing

fathom pendant
rustic sage
edgy edge
#

Someone solved "Linux Privelege Escalation" - "Environment Enumeration"? I cant submit the flag.. it says its invalid?

fathom pendant
#

Then you answered the question wrong :p

#

Or have extra spaces

#

Or a dozen other things

edgy edge
#

Well the task is
Enumerate the Linux environment and look for interesting files that might contain sensitive data. Submit the flag as the answer.

#

and I found the flag- but it says its invalid so

#

meh, I already got root access to the system

#

Nvm. LMAO.

#

This one was a bait flag

late urchin
#

man lol i've been stuck on this assembly question for going on 4 days now lolol i think my brain imploded at this point 🤯

hallow kiln
tidal kelp
#

Currenlty on AD > Skill Assessment Part 1.
Q5 " Find cleartext credentials for another domain user. Submit the username as your answer.". Trying the following || Upload secretdump.exe|| But get Server Runtime error each time.
Any hints?

tame ivy
#

Module:Attack Common Services
Section:Attacking Email Services

have found a user, trying to bruteforce with given pws.list, but hydra cant find any creds, could anyone help pls?

autumn pilot
fathom pendant
boreal crest
#

for sure you do

fathom pendant
#

Ah yeah that tripped me uo when I first did it probably is why I wasn't sure

acoustic owl
# mortal basin 🔥

Woohoooo, vautia has answered my wishes. 🤩
As soon as I have finished CDSA, I will continue with webpentesting.

late urchin
#

Just moved on to the Assembly Language Skill Assessment Question 2 and knocked that out quickly but still can't get question 1... last thing before I can move onto buffer overflow attacks...

hot heart
#

I am stuck on:
Enumerate the server carefully and find the flag.txt file. Submit the contents of this file as the answer.

Under the "Footprinting" module Easy lab.
I've ran the nmap scan and found 2 open ftp ports but was denied access for both of them.
I tried connecting via SSH and was denied access because I need the valid 'public' key. Does anyone know if I am even on the right track or should I be looking somewhere else or taking a different kind of route?

#

I've also tried connecting via other RP's but the credentials they've provided resulted in connection errors for all of them

thorn urchin
hot heart
#

Yes, I just ran out of time on my pwn box, so let me start a new instance and try again I'll show you the output

thorn urchin
#

Nvm, just checked myself

#

Read the lab introduction again 🙂

hot heart
#

Am I on the right track? I went over the lab intro and have tried tackling it from the beginning, but I still feel like I am running in circles

#

Are we supposed to know the domain name? Am I supposed to be utilizing inlanefreight.htb like the past exercises? Or is that irrelevant for this lab

thorn urchin
late urchin
#

finally got it after over 3 days 😄

thorn urchin
#

that needs to be applied to the services youve discovered

#

One of the services even has a clue to tell you to use the hint in the introduction

late urchin
#

i was deff thinking too hard lol

tame ivy
#

Module:Linux Priv Esc
Section:Sudo

i cant compile this exploit given in section, bcs there is no make or gcc on the box, also sudo -l gives a ncdu as root, i can run it but it just show a directories, could anyone help please?

polar tartan
#

Module: Web requests
Section: GET

I am having issue with solving the riddle. My target website is not loading properly and is not sending any requests when I hit the enter. I can also see that it's failing to load favicon upon loading website, what do I do? This is how it looks https://prnt.sc/4qu7uyGo5-UF and this is how it should look https://prnt.sc/elcllVzrObHp

hot heart
thorn urchin
#

Yup so theres valid credentials, time to use em

hot heart
#

But in order to enumerate DNS wouldn't I need the FQDN to utilize dns commands?

thorn urchin
#

ignore dns

#

you have valid creds

hot heart
#

I understand what you're saying, but I've already tried connecting via SSH and other remote protocols. The issue is that even with valid credentials, I'm still encountering a 'public key required' message during the SSH handshake.

thorn urchin
#

Cool, so move away from ssh

#

you've found other services

hot heart
#

ftp?

thorn urchin
#

Sure

#

trying valid creds on ftp is always worthwhile

hot heart
#

I've tried that but all the the commands I run inside the server just results in the same 3 output messages no matter what command I run

thorn urchin
#

which server, which commands, which output

hot heart
#

ftp 10.129.209.235 21
Connected to 10.129.209.235.
220 ProFTPD Server (ftp.int.inlanefreight.htb) [10.129.209.235]
Name (10.129.209.235:root): ceil
331 Password required for ceil
Password:
230 User ceil logged in
Remote system type is UNIX.
Using binary mode to transfer files.
ftp> ls
200 PORT command successful
150 Opening ASCII mode data connection for file list
226 Transfer complete
ftp> cd
(remote-directory) cd..
550 cd..: No such file or directory
ftp> cd ..
250 CWD command successful
ftp> put find.txt
local: find.txt remote: find.txt
local: find.txt: No such file or directory
ftp> quit
221 Goodbye.

#

Is this a spoiler?

sly dome
#

dir -a

#

what even is find.txt?

thorn urchin
#

just an attempt to write

hot heart
#

HAHA

#

I was trying to 'put' a file find.txt

#

to see if it would do anything

sly dome
#

always enumerate hidden files

thorn urchin
#

amusingly, your ftp there foes reveal the FQDN youre looking for(but still ignore dns)

#

But rafa is right, always check hidden files

hot heart
#

^^^

sly dome
#

and port 21 is a rabbit hole

thorn urchin
#

and if you find nothing on that server, try the other one

keen compass
#

hi, on LINUX PRIVILEGE ESCALATION > Linux Local Privilege Escalation - Skills Assessment : is there another solution to get flag4.txt (and flag5) without running an exploit that will directly lead me to root privilege ? (no spoil please, only a "yes, keep searching" or "no you need an exploit" would be great) 🙂

sly dome
#

ftp is one of the quickest protocol to enumerate

#

if you find nothing with a dir -a there is nothing

#

go next

hot heart
#

How would I be able to check hidden files if the server is refusing my commands

#

Imma go off what you guys said

thorn urchin
#

its not refusing your commands

#

its just your dir command didnt find any files to list

hot heart
#

okay

sly dome
#

my boy

hot heart
#

that makes sense

sly dome
#

if on 21 there is nothing

#

on 53 there is nothing

#

ssh needs key

#

its white and in a bottle

thorn urchin
#

I didnt want to spoil that theres nothing on 21, they should go through normal enumeration

sly dome
#

i know, my point is that enumerating an ftp server is a matter of seconds

thorn urchin
#

yeah but theyre def new and footprinting is an early module so a little patience with them is warranted

sly dome
#

ok

#

my bad

hot heart
#

I'll still go through the grunt work, but your advice is still useful for future purposes

#

so I appreciate it

thorn urchin
#

Its not like theyre acting dumb or being a jerk to those helping, this is normal learning steps

sly dome
#

ikik

#

ive been there

#

and i am

sly dome
#

see the pattern?

#

and never forget hidden files

thorn urchin
#

Ive def tripped over hidden files before 😭

sly dome
#

it hurts

hot heart
#

wow

#

so the repeated output was to throw people off ftp? 😂😂

sly dome
#

wdym?

hot heart
#

How it keeps repeating the 200,150, and 226 messages, or is that normal? Becuase initially I thought it wasn't taking my commands since all it was doing was repeating those same three messages everytime, but in reality that is just the normal interaction experience with a ftp server?

#

I found the keys btw thanks

#

@sly dome @thorn urchin

thorn urchin
#

Thats normal ftp stuff

hot heart
#

gotcha

thorn urchin
sly dome
#

this is one of the situations you have to Google what you dont understand

#

you would have found that wikipedia article in that case, but dont misunderstand me, asking here is also valid

hot heart
#

No its not that I didn't understand them, it's just I was expecting the command line interface to behave differently

#

Like when I ran the put command or any other command it was weird that it was just returining those ftp codes and nothing else

hot heart
#

Found the flag 😅😅

dusk torrent
#

hi guys i've finally completed the footprinting module (😭 ). i just wanted some clarification on the hard lab. we do a ||UDP scan ||because the question hints the server in question is a ||DNS server ||and ||UDP ||is often used for that yes? or no

#

just want to make sure it's not a right answer wrong formula situation

fathom pendant
dusk torrent
fathom pendant
#

If you read the ids/ips evasion section under dns proxy section it explains it more

fathom pendant
#

You can't

#

You mean clear answered questions?

#

Thats too bad bc you can't

#

Because I personally haven't seen a button to reset progress, and every time I've seen it asked - the answer has been no

#

You can always just go back through a module, spawn the target, and attempt without looking at the questions too much

#

¯_(ツ)_/¯

carmine hill
#

HTTP Attacks completed! If anyone needs help with this, just dm me

honest ridge
#

Hi, Im trying to run blood hound and it wont login, ive started neo4j then run bloodhound but it wont connect? tried opening the localhost<port> for neo and changed user/pass to just admin, but it just wont allow me to connect to bloodhound?

thorn urchin
honest ridge
#

ummm not really lol. altho waiting now.

thorn urchin
#

neo4j warns you when it starts that it may take a couple minutes before applications can connect to it

honest ridge
#

on bloodhound port is 7687 but loging into nero4j is port 7474. is this normal?

#

and databases being bolt and neo4j am iment to leave all that as default?

thorn urchin
#

yeah admin port being different is normal. Idr thr default ports off the top of my head though

#

but presumably those two are correct

honest ridge
#

blood hound does green tick to show its valid etc, but yeah. just wont login

thorn urchin
#

if it green ticks then should be valid so the creds youre using must be messed up

honest ridge
#

dunno if that helps at all

thorn urchin
#

did you click login

honest ridge
#

lol yeap

thorn urchin
#

its something I have to ask with the kind of people that show up time to time

honest ridge
#

ohh dont get me wrong, im aa total nub

thorn urchin
#

did you change the neo4j password? Id be trying to login as that

honest ridge
#

yeah when logining into neo4j on browser it said click auth type user/pass then said change defaults (altho i tried logining into before changing) then changed to admin:admin

#

and still in neo4j browser atm

heavy marsh
#

I'm getting an error trying to run the iis exploit on the meterpreter module

#

Using a kali vm, tried pwnbox instance and got the same thing

#

I'm using (windows/iis/iis_webdav_upload_asp)

rustic sage
#

Like it's not vulnerable

heavy marsh
rustic sage
tidal kelp
#

Currently on module AD Enumeration and Attacks > skill assessment. Stuck on Q5 "Find cleartext credentials for another domain user. Submit the username as your answer."
Any hints.?

quick magnet
#

hi im stuck in AD Enumeration & Attacks - Skills Assessment Part I question 2,
i try reverse shell and doing file share from linux to shell.
try download PowerView.ps1 can't import-module.
try download mimikatz and rubeus but it cant use because its not folder.
i believe i need use mimikatz or rubeus but how i can get this folder from my linux ?

tidal kelp
#

You can upload files directly from the web shell

#

rubeus is your friend

quick magnet
#

i can't download directly

autumn pilot
#

find a directory to which you have write access

quick magnet
fiery berry
wooden summit
#

hey there!,
I m going through the
"Windows Event Logs
Windows Event Logging Basics" module.
Trying to use Remmina to rdp to the targer.
Although initial connection is made and I 'm landing on the desktop (logged in), after a couple of seconds it goes blackscreen and reconnection attempt #of20.
Tried to ping the target while this was happening and got no ping.
Terminated the instance, waited some, then rerun it.
Same result.

Maybe wait some more or am I doing smth wrong here?
(creds & domain are ok, checked like 5 times)

reef anvil
novel matrix
#

Hmm

fathom pendant
digital junco
#

hello guys

#

I need a litle help with an exercise of the ffuf module

#

the Fuzing GET parameters

#

I tried but I don't get any parameter after fuzzing

#

😥

elfin cedar
digital junco
#

yup

elfin cedar
digital junco
#

humrum..

digital junco
elfin cedar
#

That was my problem

digital junco
#

solved

digital junco
#

thx for the help anyway!

sudden blaze
#

Module: PIVOTING, TUNNELING, AND PORT FORWARDING Section: RDP and SOCKS Tunneling with SocksOverRDP

#

Cant login as jason:WellConnected123!

#

It redirects me to 172.16.5.19

#

Any hint?

fathom pendant
pale wraith
#

footprinting module is heavy... 🥵

brisk marlin
#

hey gyus

#

me new

sudden blaze
#

@fathom pendant A:htb-student B:victor C:jason

fathom pendant
#

Did you follow the steps properly

acoustic owl
hidden prairie
#

Bro I didn't get my cubes when I referred 2 ppl and they did onboarding

candid lily
#

how to stop this

#

printing sideways

last thunder
#

H

pale wraith
#

Am i too dumb for struggling everytime with the answers format on academy?

digital junco
#

hi

#

I need help with the ffuf module exercises (the last)

#

i fundo the extensions

#

the subdomains

#

but this question: "One of the pages you will identify should say 'You don't have access!'. What is the full page URL? "

#

I'm not able to solve

#

I also found 2 folders in the subdomains

#

but I'm not receiving any pages...

#

please help

fiery berry
digital junco
#

in all subdomains

#

that's why i'm stuck

fiery berry
fiery berry
umbral fulcrum
#

hey guy I'm in "Windows Privilege Escalation" ==>> "SeTakeOwnershipPrivilege"
and I didn't get the explanation there, they say if a user has "SeTakeOwnershipPrivilege" then I can use it and change it

but the user on the Q doesn't have it so how am I suppose to do the Q???
anyone have any tips??

fiery berry
tender turtle
#

I'm going through the network enumeration with nmap module and I'm supposed to scan and list the number of open tcp ports for one of the questions and I'm only finding 4 open ports, but apparently that's incorrect. Any idea on where I could have gone wrong?

digital junco
#

-p-

tender turtle
#

I tried that as well and I get the same four ports

digital junco
#

-sU

tender turtle
#

I just need the TCP ports

digital junco
#

are you sure?

tender turtle
#

" Find all TCP ports on your target. Submit the total number of found TCP ports as the answer."
Yeah

#

This is what I'm getting

Starting Nmap 7.93 ( https://nmap.org ) at 2023-10-31 14:53 GMT
Nmap scan report for localhost (127.0.0.1)
Host is up (0.062s latency).
Other addresses for localhost (not scanned): ::1 127.0.0.1
Not shown: 65531 closed tcp ports (conn-refused)
PORT     STATE SERVICE
22/tcp   open  ssh
80/tcp   open  http
111/tcp  open  rpcbind
5901/tcp open  vnc-1```
digital junco
#

change the -sT flag

#

it's full tcp but maybe "something" is blocking a full tree hay handshake

chilly kernel
#

Infact, even copying the command from the previous module, password spraying, the same password that previously did get a hit no longer does

#

wtf?

tender turtle
chilly kernel
#

solved.

umbral fulcrum
fathom pendant
#

There's a button to spawn a target to scan

umbral fulcrum
fiery berry
fiery berry
novel rover
#

Hi! I'm stuck (
"What is the customized version of the SNMP server?" Any hints?

novel rover
hazy grotto
#

Working on the AD module, section ACL abuse tactics

#

This part is confusing me. Is the creating a PScred object, the line that says Password here. Are we putting in the wley password? or the password we intend to change for damundson

umbral fulcrum
fiery berry
novel rover
hazy grotto
rustic sage
#

Hello

rustic sage
rustic sage
fathom pendant
rustic sage
#

Am so sorry

fathom pendant
#

We were all noob at one point

rustic sage
#

That’s True

soft jolt
#

Support, i'm having issues with the 'Windows Attacks & Defense Module', in the PKI - ESC1 Lab, when i execute Rubeus with the generated PFX file i receive this error -> KDC_ERR_PADATA_TYPE_NOSUPP

hot heart
#

Does anyone know if I am supposed to be utilizing ceil's account for the second lab in 'footprinting'? The medium one?

#

This is the question: Enumerate the server carefully and find the username "HTB" and its password. Then, submit this user's password as the answer.

fathom pendant
hot heart
#

Ok thank you, well in that case am I on the right track, I've tried enumerating the smb, nfs and ftp of the target IP and am having no luck

#

I've also tried the rpcclient but it's asking for a password which I don't have

hot heart
#

I found alex's credentials but his login isn't working for anything

fathom pendant
#

Think outside the box

#

Rpc isn't quite the answer

#

Think about the open ports, and what they actually correspond to

hot heart
#

Well I know we have rpc which you said isnt quite the answer, msrpc, netbios-ssn, microsoft-ds, nfs, and ms-wbt-server open

#

I already enumerated the nfs and came up with alexs credentials

#

let me try rdp

fathom pendant
#

As they correspond to specific services 99% of the time

hot heart
#

HAHA

#

his creds worked for ||rdp||

fathom pendant
#

Congrats now keep digging

distant moat
#

hi all .. I've started the ACTIVE DIRECTORY ENUMERATION & ATTACKS module and in the first question i'm stuck:

While looking at inlanefreights public records; A flag can be seen. Find the flag and submit it. ( format == HTB{**} )

I can't find this flag at all looking at the public DNS records for inlanefreights.com. Any tips ?

fathom pendant
#

Are you sure it's not meant to be inlanefreight.htb?

rustic sage
#

I've just completed the Documenting and Reporting module and from what I see they always use "The tester" when referring to themselves.

Is this sorta like a resume where you want to avoid using "I"? Or does it not matter

fathom pendant
rustic sage
fathom pendant
#

Use First person

distant moat
fathom pendant
#

You're reporting on issues not writing a novel

fathom pendant
rustic sage
#

Okay thanks!

distant moat
fathom pendant
thorn urchin
sly dome
#

literally the first thing the section does gives you the flag

distant moat
sly dome
#

check trailing and leading spaces

distant moat
#

I got it.Thank youprayge

hoary pulsar
#

Footprinting Module : Lab Hard
Question : accessing tom via ssh using private key founded in imap/pop3 services. Do I have the right key or not?
Error Message while accessing via ssh : Permission denied (publickey).

#

Thinking of maybe the key I found is not tom's priv key lol.

tidal kelp
#

Web Proxies Module : Encodre / Decode
||To decode: 4x base64 -> URL||
Had to look up what to how to decode the string. How should I get to the conclusion that this is how to decode it? Am I missing something in the material

sly dome
hoary pulsar
#

yes chmod 600 id_rsa

sly dome
#

check you copied it correctly

sly dome
fathom pendant
hoary pulsar
#

yeah, copied it correctly as well. I'll double check might be empty spaces

hazy grotto
#

can i dm you

fading oracle
#

can i dm with someone about Web-attacks skills assesment?

hoary pulsar
#

okay lmao, troubleshooted it.
nano id_rsa gives error
vim id_rsa is the correct one
lololol

sly dome
#

what?

#

skill issue?

hoary pulsar
#

maybe lmao

sly dome
#

xD

hoary pulsar
#

weird tho maybe i go with vim now instead of nano

sly dome
#

shouldn't affect

hoary pulsar
#

yes sir :< now tried with nano as well now it works weird, skill issue fo sure

sly dome
#

xD happens dude !

#

double check always

hoary pulsar
#

yea, thanks thanks! 🙏

white ore
hoary pulsar
#

yes sir, done with the hard lab now tyty

rustic sage
white ore
hoary pulsar
#

format of the priv key that I copied lol

#

had to quadruple check it

white ore
sly dome
#

hahahaha

#

at least 3 times

hot heart
#

I've been enumerating alexs windows machine for a while now and can't find anything useful

#

I found the conversation between him and the 'operator' on his machine but it's only a notepad.txt so it doesn't identify the operator either

#

And I can't get into the MySQL application thats on the desktop either

sly dome
#

it is MSSQL

hot heart
#

Yea MSSQL is what I meant

#

Medium lab on Footprinting module

sly dome
#

sometimes passwords are reused

hot heart
#

I tried that

#

And its refusing my login

sly dome
#

try harder

#

there are more ways to use a password for a Windows application

hot heart
#

oh

#

I think I know what you mean

#

Nvm no I don't lmao

#

Am I on the right track at least?

sly dome
#

yes

#

if you have the password

fathom pendant
hot heart
#

I tried that, its denying me access

fathom pendant
#

You're not being specific enough: also make sure the logon mode is windows auth

#

To add on: sql service is only accessible via the lab, not external

hot heart
#

I've tried those too

#

and wdym its only accessible via the lab? Like from the pwn box linux machine? not including the xfreerdp machine?

sly dome
#

from the rdp session

hot heart
#

Ok I'm still being denied access

sly dome
#

right click > run as administrator

#

but you should be trying this stuff alone

#

in order to learn

hot heart
#

I know i've done that already

sly dome
#

it works

hot heart
fathom pendant
# hot heart

Are you using the special password found in an important text

sly dome
#

wrong password then

hot heart
#

I'm using the one associated with alex's account that I found on the ticket.txt file I found earlier

sly dome
#

enumerate the host

#

my boy

fathom pendant
#

Like I said earlier: start digging around

#

Sometimes passwords are in plaintext somewhere on the system, browse the files that he has access to

sly dome
hazy grotto
#

AD - Privileged access
Leverage SQLAdmin rights to authenticate to the ACADEMY-EA-DB01 host (172.16.5.150). Submit the contents of the flag at C:\Users\damundsen\Desktop\flag.txt.

So I RDP with the given creds, and im supposed to use mssql with a specific command but it almost seems like I need to do some kind of pivot or something? anyone have a nudge?

fathom pendant
#

You should be able to specify a db with sqlcmd

hazy grotto
fathom pendant
hazy grotto
fathom pendant
sly dome
#

what do you mean

hot heart
#

I am in the MSSQL application but can't find any leads

sly dome
#

any leads?

hot heart
#

Like any further clues

sly dome
#

you have to be seeing a non-standard database

#

under Databases

hot heart
sly dome
#

those are standard

fathom pendant
#

kek automod gotcha ass

#

If there's a link use a backtick before and after

reef anvil
#

why I can not post anything?

fathom pendant
#

like this

#

Because what you're trying to post is getting flagged by automod

#

It's hitting a false positive for spamming probably

#

You can get around this by linking your main htb account to discord following the instructions in #welcome

reef anvil
sly dome
#

there are 5 valid user:password combinations

#

any of them let you tamper the cookie to get admin

reef anvil
sly dome
#

sry 4 users

#

are you logged in as any of those?

reef anvil
#

these what I found give me nothing, just regular pages, no flags inside

reef anvil
sly dome
#

just tamper the cookie 🙂

reef anvil
#

I did 🙂

sly dome
#

do it correctly

fathom pendant
#

Then you're doing it wrong

#

¯_(ツ)_/¯

reef anvil
#

||support.gr:support - NjhjOTI2MDA5MDYyMGU1ZjQ3MWVhYWVlY2IwYmNlNTk6NDM0OTkwYzhhMjVkMmJlOTQ4NjM1NjFhZTk4YmQ2ODI%3D||

sly dome
#

cool

#

then change to admin

#

and use the same encoding

#

and scheme

reef anvil
#

tried already

fathom pendant
sly dome
#

dont think so

#

how are you doing the md5 ?

reef anvil
#

to ||admin, administrator|| and many other similar like ||root, superuser||

#

$login_md5 = md5($user);
$role_md5 = md5($role);
$ooo = $login_md5 . ':' . $role_md5;
$sessid = urlencode(base64_encode($ooo));

#

this is php script I've created

#

it allows me to pass the cookie and I have the authenticated response

#

but no flags inside 😦

sly dome
#

come DM

hot heart
#

I'm still getting nothing

#

I feel like I've gone through a million files on MSSQL

sly dome
hot heart
#

I'll try again

sly dome
#

its a super suspicious database

#

it is in front of you

#

not even hidden

balmy ember
sly dome
#

ensure you are writing it correctly

balmy ember
#

I copied and pasted and also entered manually neither work

sly dome
#

those creds?

balmy ember
#

That worked but how did you know that?

sly dome
#

the question is

#

what creds were you using lol

sly dome
balmy ember
#

I read that section

#

Which file was it in

sly dome
hot heart
#

Thanks @sly dome @fathom pendant

#

I finally found it

sly dome
#

any time

hot heart
#

Does this come with experience or how did you know to search in that one specifically

sly dome
#

accounts?

fathom pendant
balmy ember
sly dome
fathom pendant
#

But also you should just be looking at EVERYTHING anyway

sly dome
#

treasure hunting = CTF

hot heart
#

yeah, but there are like a million files for the folders inside the accounts tab

#

you guys knew because the the one that had the ctf was in plain sight?

fathom pendant
#

I fumbled around each db until I found it

#

¯_(ツ)_/¯

hot heart
#

Okay I'm just making sure it was a process for you guys as well not just for me

fathom pendant
#

Attacking Common Services goes through the actual command line queries you can do

sly dome
hot heart
#

Cuz u guys make it seem ez

fathom pendant
#

It's all about your methodology

sly dome
#

for this exercise going for the command line is hitting yourself

fathom pendant
#

Mine is "gain access, look at all things relevant/that stick out"

sly dome
#

you open Databases folder, you see accounts database, you look tables, you open table

fathom pendant
sly dome
#

why would someone do it more difficult xD

hot heart
#

I did it via the create query

sly dome
#

good job but overkill !

hot heart
#

How did you do it?

fathom pendant
hot heart
#

I thought that was easier

sly dome
#

clicking with the mouse

hot heart
#

Huh?

#

I did that and it gave me nothing

fathom pendant
#

Right click

#

:)

sly dome
#

right click > show entries

#

it is like 200 entries or something

fathom pendant
#

Yep

#

The hint talks about it

hot heart
#

wow 😂😂

sly dome
#

methodology -> click a lot of stuff

hot heart
#

I did over kill it

sly dome
#

its like fkn treasure hunting

#

the worst part of enumerating is looking through stuff, but it has to be done

fathom pendant
#

You still got the right answer

sly dome
#

yea Transact-SQL is super useful

#

but GUI's are designed for standard employees using MSSQL xD they dont like command line at all

fathom pendant
#

And truthfully there's only a handful of ways to get it, right click > view, query button, sqlcmd, create a dynamic port forward tunnel

hot heart
#

Nice

#

Thanks a lot

sly dome
#

the port forward is a sexy one

fathom pendant
#

Wholly unnecessary but funny af

hot heart
#

Imma act like I know what it is and then hopefully I'll run into it later down the road😂😂

fathom pendant
#

(It's mostly different techniques)

hot heart
#

Okay nice thats reassuring I'm just not there yet

fathom pendant
#

Yeah

#

And it's mostly just reading and following instructions

hot heart
#

Nice

#

I'm starting to realize how ambitious I was when I said I wanted to get the CPTS in a month😂😂

#

a little TOO ambitious actually

fathom pendant
#

You just need to beef up your methodology tbh

#

But that comes with practice

#

And even just taking notes properly can help

#

Don't just copy/paste a new command that's given to you

#

Break down what the individual components do

#

Such as, ssh user@ip [-i id_rsa]

#

And knowing how to use the flags to connect to nonstandard ports as well

#

:p

hot heart
#

Yea you've mentioned it before a while back and that's what I've been doing, and I can admit that approaching the material from that viewpoint has definitley increased my overall productivity and efficiency as a whole

#

Imma try and knock out the hard lab tonight so that I can finally move onto the next module tomorrow, wish me luck hombres

#

Any pointers would be greatly appreciated too haha

#

And again each lab stands separate from the previous labs right? So the credentials I found for HTB are irrelevant?

sly dome
#

anyone remember this part?

#

where did we identify that? i have been following the module thoroughly and didnt see

thorn urchin
#

idr, it might've been something you coulda spot with bloodhound but werent required to. I dont remember

sly dome
#

BH has not been used at this point

#

so im wondering why they write that

#

rpcclient maybe?

thorn urchin
#

hmm maybe

sly dome
#

or from the windows host

#

like net group "Domain Admins" /domain

#

has to be that

#

o.O

honest ridge
#

hey, anyone know this error?

lost shadow
#

recommed those slides to me plz. I.m loosing mind mind

hot heart
#

I'm already stuck on the Hard lab for the footprinting module

#

I've tried enumerating pop3 and Imaps as well as ssh, and havent gotten any luck

tight mesa
#

anyone who can give me a hand, is this command ||lsadump::dcsync /user:ACADEMY-EA-DC01\kbrtgt|| the right command to get the KRBTGT hash for the child domain?

balmy ember
fathom pendant
hot heart
#

And I know those are the ports that are open too

fathom pendant
#

It's noted as also being used for something else

hot heart
#

A backup server?

small sage
#

stuck on Intro to C# Skills Assessment, when trying to access the GetWordList() method I get this error
Unhandled exception. System.TypeLoadException: Could not load type 'Assessment.Words' from assembly 'assessment, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null'.
i've tried making sure the build architecture and dll architecture match, I'm pretty sure I have the dll linked appropriately. Not sure what else to check

fathom pendant
hot heart
#

I'm telling you lmao, but I'm trying to figure how thats a clue

fathom pendant
#

Well what section talks about that and a highly specific port

#

In fact there's an enumeration tool named after that port

hot heart
#

Okay let me try again

#

I see what you mean that the server has the function of a back up server, but I don't get how thats a clue when I'm getting denied access to begin with

#

Does this have anything to do with it?
||-----BEGIN CERTIFICATE-----
MIIC0zCCAbugAwIBAgIUC6tYfrtqQqCrhjYv11bUtaKet3EwDQYJKoZIhvcNAQEL
BQAwEjEQMA4GA1UEAwwHTklYSEFSRDAeFw0yMTExMTAwMTMwMjVaFw0zMTExMDgw
MTMwMjVaMBIxEDAOBgNVBAMMB05JWEhBUkQwggEiMA0GCSqGSIb3DQEBAQUAA4IB
DwAwggEKAoIBAQDEBpDfkH4Ro5ZXW44NvnF3N9lKz27V1hgRppyUk5y/SEPKt2zj
EU+r2tEHUeHoJHQZBbW0ybxh+X2H3ZPNEG9nV1GtFQfTBVcrUEpN5VV15aIbdh+q
j53pp/wcL/d8+Zg2ZAaVYWvQHVqtsAudQmynrV1MHA39A44fG3/SutKlurY8AKR0
MW5zMPtflMc/N3+lH8UUMBf2Q+zNSyZLiBEihxK3kfMW92HqWeh016egSIFuxUsH
kk4xpGmyG9NDYna47dQzoHCg+42KgqFvWrGw2nIccaEIX5XA8rU9u53C7EQzDzmQ
vAtHpKWBwNmiivxAz/QC7MPExWIWtZtOqxmfAgMBAAGjITAfMAkGA1UdEwQCMAAw
EgYDVR0RBAswCYIHTklYSEFSRDANBgkqhkiG9w0BAQsFAAOCAQEAG+Dm9pLJgNGC
X1YmznmtBUekhXMrU67tQl745fFasJQzIrDgVtK27fjAtQRwvIbDruSwTj47E7+O
XdS7qyjFNBerklWNq4fEAVI7BmkxnTS9542okA/+UmeG70LdKjzFS+LjjOnyWzTh
YwU8uUjLfnRca74kY0DkVHOIkwZQha0J+BrKSADq/zDjkG0g4v0vzHINOmHx9eiE
67NoJKJPY5S3RYWxl/4x8Kphx7PNJBPC75gYjlxxDhxdYu9a3daqJUa58/qOm6P8
w1P9nA6lkg7NopyqepulLAzIcqnTjb/nMD2Pd9b6vgWc3IqSfFreqjzshZ+FjNZo
zR+tR6z4TQ==
-----END CERTIFICATE-----
||

sly dome
#

anybody got BH community edition working ?

#

it works but the GUI is totally not user friendly unlike the classic bloodhound

#

sadly it is getting deprecated !

hot heart
#

Think you could help a brotha out decoding what Marcie said earlier? ^^

#

Please my good sir

marble raft
hot heart
#

I know I've read it a million times I don't get how that a clue when everything I've tried to enumerate it is being denied

#

And I see that your emphasizing the back up part

marble raft
#

Then take a break, and come back with another approach. Pentesting isn't easy, not everything works flawlessly. What you're doing in this module, in real life would take weeks. Take your time, this isn't a race. If we give you the way to stuff then you won't learn nothing, cliche as it may seem.

soft plume
#

Hey I have a quick question, when using nmap why would you want to include --disable-arp-ping, -n, and -Pn? Why is it important to disable arp pinging and ICMP echo quests?

hot heart
#

Or is this skill based 😂😂

sly dome
#

enumerate as you learned in the previous sections

#

nothing else

hot heart
#

okay so I'm over thinking it

#

lemme try again

warped oasis
#

Hopefully someone can tell me what I'm doing wrong here.. To preface, I'm working through the cracking passwords with hashcat module.

Whenever I attempt to echo the 7zip hash into a file, the hash gets changed and ends up starting with something like zbash9bash<...>. Trying to work around it, I save the text manually using notepad++, cat the hash and the command input ends up at the end of my hash on the same line and I feel like this is affecting my ability to run hashcat on the hash.

sly dome
hot heart
#

No I haven't even gotten past nmap

#

😂😂

sly dome
#

scanned udp in a correct way?

hot heart
#

I tried, but let me try again

#

brb

sly dome
#

ssh is usually a hole without creds, SMTP ports also need credentials since they are mail services

marble raft
# soft plume Hey I have a quick question, when using nmap why would you want to include --di...

You would use --disable-arp-ping if the network you're in has for example an router that answer every arp request, otherwise the scans would be useless because it will always result in ip addresses being up when they're not. The -Pn option is to skip host online check that nmap does, when breaking into windows machine it's advisable to use it because windows doesn't answer ICMP pings.

The other reason is performance, imagine you're running a scan on a /16 network, running the scan without the -Pn nmap would check for if the 65k IP addresses are online before scanning the ports.

sly dome
#

and since there are no more TCP ports

#

the meat has to be in the UDP protocol

#

nmap -sU -v --min-rate 2000 <ip> --open | grep -v filtered

distant moat
#

my rdp says [Loaded fake backend for rdpsnd] Black screen on rdp server

#

how to fix it

sly dome
#

for RDP i recommend doing it from your Windows host if u have one

marble raft
distant moat
#

xfreerdp /v:10.129.201.234 /u:htb-student /p:Academy_student_AD!

soft plume
distant moat
#

session : passwordspray from windows

#

module : ACTIVE DIRECTORY ENUMERATION & ATTACKS

sly dome
#

but i have xfreerdp installed manually

#

latest version

#

🤷

marble raft
#

Try enclosing the password into single quotes or double quotes like

xfreerdp /v:10.129.201.234 /u:htb-student /p:'Academy_student_AD!'

or

xfreerdp /v:10.129.201.234 /u:htb-student /p:"academy_student_AD!"

Or try updating xfreerdp as @sly dome said

distant moat
#

okay

sly dome
#

should not be a problem here, '!' is not a reserved bash character but just try xD

#

but as i said

#

use your Windows host to RDP

#

better compatibility overall

warped oasis
#

yes cracking passwords with hashcat module.

marble raft
distant moat
#

I got it [xfreerdp /v:10.129.201.234 /u:htb-student /p:"academy_student_AD!"]

#

thanks

sly dome
#

remove the double quotes

#

you should also get it

#

also the password is Academy_student_AD!

warped oasis
#

Cracking Miscellaneous Files & Hashes

I've extracted the hash from the 7z file but whenever I attempt to echo the 7zip hash into a file, the hash gets changed and ends up starting with something like "zbash9bash<...>" instead of "$7z$0$19$0$$<...>". Trying to work around it, I save the text manually using notepad++, cat the hash and the command input ends up at the end of my hash on the same line and I feel like this is affecting my ability to run hashcat on the hash. Running hashcat on the notepad++ saved hash it gives me a Token unmatched error.

sly dome
#

which tool are you using

#

7z2john?

warped oasis
#

yes

sly dome
#

just copy paste the ouput

#

and you have to change it a little

#

john format usually differs from hashcat

#

-m 11600 $7z$0$19$0$salt$8$f6196259a7326e3f0000000000000000$185065650$112$98$f3bc2a88062c419a25acd40c0c2d75421cf23263f69c51b13f9b1aada41a8a09f9adeae45d67c60b56aad338f20c0dcc5eb811c7a61128ee0746f922cdb9c59096869f341c7a9cb1ac7bb7d771f546b82cf4e6f11a5ecd4b61751e4d8de66dd6e2dfb5b7d1022d2211e2d66ea1703f96

#

example hash

#

the problem are the '$' signs

#

but you should just copy paste the output

#

7z2john <7z file>, that will output the hash you select it -> ctrl + shift + c if under linux terminal

#

or redirect it to a file

#

7z2john <7z file> | tee 7z.hash

hot heart
#

I'm still in the same spot, I've tried enumerating the open UDP port with no luck @sly dome

sly dome
#

if you still want to echo it, enclose it in single quotes @warped oasis

sly dome
#

use a correct nmap command, nmap -sU -v --min-rate 2000 <ip> --open | grep -v filtered

warped oasis
#

IDK, maybe it's a problem using wsl Ubuntu or something but my command:
hashcat -m 11600 $7z$0$19$0$$$9c7684c204c437fa0000000000000000$1098215690$112$106$7395978cad9ad8b18aef51ba2f9dcf909a1bff70d240b1c8e98dffabd352d69a1f37978e5df0179860d0fe4754721ae3cbbee1b558d93cd27e0b2959efe44a00305f982527d19584d62bcf8c23cf89e24fd19db844108e452a26d4a8343d504fc3063744d081db1492ea1cdef7a9b983 /usr/share/wordlists/SecLists/Passwords/Leaked-Databases/rockyou.txt

produces the error:

Hash 'zbash9bash3948c7684c204c437fa00000000000000000982156901206395978cad9ad8b18aef51ba2f9dcf909a1bff70d240b1c8e98dffabd352d69a1f37978e5df0179860d0fe4754721ae3cbbee1b558d93cd27e0b2959efe44a00305f982527d19584d62bcf8c23cf89e24fd19db844108e452a26d4a8343d504fc3063744d081db1492ea1cdef7a9b983': Separator unmatched

sly dome
#

enclose it in single quotes or save it in a file

hot heart
#

I tried that already, and I got the same thing as before ||161||

sly dome
#

nice

#

161 is a port you learned in this module

hot heart
#

I know its ||snmp||

sly dome
#

hashcat -m 11600 '$7z$0$19$0$$$9c7684c204c437fa0000000000000000$1098215690$112$106$7395978cad9ad8b18aef51ba2f9dcf909a1bff70d240b1c8e98dffabd352d69a1f37978e5df0179860d0fe4754721ae3cbbee1b558d93cd27e0b2959efe44a00305f982527d19584d62bcf8c23cf89e24fd19db844108e452a26d4a8343d504fc3063744d081db1492ea1cdef7a9b983' /usr/share/wordlists/SecLists/Passwords/Leaked-Databases/rockyou.txt @warped oasis

warped oasis
#

Hash '$7z$0$19$0$$$9c7684c204c437fa0000000000000000$1098215690$112$106$7395978cad9ad8b18aef51ba2f9dcf909a1bff70d240b1c8e98dffabd352d69a1f37978e5df0179860d0fe4754721ae3cbbee1b558d93cd27e0b2959efe44a00305f982527d19584d62bcf8c23cf89e24fd19db844108e452a26d4a8343d504fc3063744d081db1492ea1cdef7a9b983': Token length exception

hot heart
#

I tried running the commands they provided in the cheat sheet for it

#

to no avail

sly dome
#

you did not @hot heart

hot heart
#

I swear