#modules

1 messages · Page 148 of 1

hot heart
#

lemme show you the output

#

one sec

sly dome
#

save it in a file idk

#

you are just being little dumb here @warped oasis

#

your hash is wrong btw

#

copy it from the output

#

from 7z2john

hot heart
#

These both returned nothing:
||┌─[us-academy-1]─[10.10.15.249]─[htb-ac-657630@htb-ruckg6ubhl]─[~]
└──╼ [★]$ snmpwalk -v2c -c public 10.129.223.58
Timeout: No Response from 10.129.223.58

┌─[us-academy-1]─[10.10.15.249]─[htb-ac-657630@htb-ruckg6ubhl]─[~]
└──╼ [★]$ braa public@10.129.223.58:.1.3.6.*||

sly dome
#

probably public is not the correct community string

#

go to the snmp section

#

read it again

warped oasis
# sly dome your hash is wrong btw

Now that was way more useful than telling me how dumb I'm being, feeling dumb enough over here. It looks like a $ got dropped inside the hash.

sly dome
#

you should not be copy pasting the hash in the hashcat command

#

get used to copy them to files

#

tell me if can crack it

warped oasis
#

yeah solved

hot heart
#

I'm pretty sure I've found Tom's credentials FINALLY

#

I'm taking a break after this lab 😭😭

sly dome
#

can i give you a tip

#

dont come over here after you feel a bit of overwhelming

hot heart
#

please

#

I'm not

sly dome
#

let your phone/discord pc app

#

you are

hot heart
#

I just wanted to show you that your advice helped

sly dome
#

and i know

#

ive been in your place buddy

#

i meant before getting it

hot heart
#

Oh

sly dome
#

you could have got it

#

alone

hot heart
#

thanks, that's motivating

sly dome
#

dont have to rush the labs

hot heart
#

you've rekindled the fire my good sir

sly dome
#

take your time

#

you tried one thing it didnt work you came over here

#

you did that like 5 times today

#

keep trying and understanding what is happening

#

why something works? why doesn’t? ask that type of questions

#

to yourself

#

and quality hours >>> quantity

#

just stop

hot heart
#

After this lab I'm going to start from the beginning and really engrain the information that's been given

sly dome
#

hopefully HTB servers are gonna be in the same place tomorrow

sly dome
#

you have been actively solving stuff for a lot of hours today

#

why not just stop

hot heart
#

becuase I want this lab done so I can I go back without having that itch of not having it complete

#

I won't be able to focus on the past material knowing that this one isn't complete

sly dome
#

ok but you can do it in a few hours

#

let the brain assimilate the concepts

hot heart
#

It is late

#

your probably right

#

Imma go at this for a little longer and then probably call it a night after 1000 failed attempts

#

I didn't even watch the world series I wanted this done so bad 😭😭

#

I think Imma swallow my pride on this one and just go back and relearn the material, thanks for the help @sly dome and thanks for the helpful tips

hot heart
#

Now I'm actually getting off 😂😂

#

night bois

slate creek
#

Hi All, currently on Pivoting, Tunneling And Port forwarding ---> SOCKS5 Tunneling with Chisel, I have created a Chisel binary and transferred it to the target pivot machine, when try to start a Chisel server on the pivot host I receive the error that says some libraries are missing on the machine as follows

ubuntu@WEB01:~$ 
./chisel./chisel: /lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.32' not found (required by ./chisel)
./chisel: /lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.34' not found (required by ./chisel)
honest ridge
#

@slate creek Its been a while since i did that but from memory i had to use an older version of chisel

sage rapids
#

Hello

fiery berry
slate creek
fiery berry
slate creek
#

thank you.

quick magnet
#

hi im stuck in AD skill assesment 1, question 6 Submit this user's cleartext password.

  • got hash but can't cracked
  • try to create lsass
  • try copy/move lsass to my linux but always fail
    any hint ?
fiery berry
quick magnet
fiery berry
quick magnet
rustic sage
#

@teal mountain

#

where is the main chat?

hallow kiln
#

also you just pinged a random person

novel matrix
tidal kelp
#

on Module: Web Proxies, Session: Zap Scanner
I've started zap from History tab I start Attack > Spider, and from the built in browser nothing happens when I try to click spider (add the ip) and start.
Get the following result. Feeling like I'm missing the alert to be looking for.
Am I doing something wrong with Zap?

white ore
#

Web Proxies. Hello Guys, How to setup FoxyProxy to only route traffic for a specific website. I added the IP on /etc/hosts with url proxy.htb so i want that BURP intercept traffic only for http://proxy.htb and not others website like https://youtube.com

fiery berry
hasty solar
#
acoustic owl
#

If you still need help, send me a DM

hasty solar
#

And try to help u

tidal kelp
#

sure

safe marsh
#

Module: HACKING WORDPRESS
Topic: Remote Code Execution (RCE) via the Theme Editor

Use the credentials for the admin user [admin:sunshine1] and upload a webshell to your target. Once you have access to the target, obtain the contents of the "flag.txt" file in the home directory for the "wp-user" directory.

Hi guys. I did not understand the part obtain the contents of the "flag.txt" file in the home directory for the "wp-user" directory. WordPress doesn't have wp-user folder elsewhere.

fathom pendant
safe marsh
fathom pendant
safe marsh
rustic sage
hallow kiln
rustic sage
sly dome
#

lmfao

hallow kiln
rustic sage
sly dome
#

yea pretty nice mate

#

thx for asking

rustic sage
#

👍

sly dome
#

should not the DC under the sections of AD enum & attacks have LDAP open?

novel matrix
#

Lets keep this to module discussion. This isnt #general 🙂

novel matrix
safe marsh
#

Module: HACKING WORDPRESS
Topic: Skills Assessment - WordPress

Hi again. I spawned and got an internal IP address. I am connected to edge-eu-academy-2.hackthebox.eu VPN. I am using a Kali VM on Virtualbox, managed to connect it to the VPN and tried to ping the target IP address. It's up according to ping.

I'm using WPScan for this assessment. Unfortunately, WPScan did not detect the IP address running WordPress. Why is that?

sly dome
#

being a domain controller

sly dome
#

if you did the ffuf module you have to know how to find it

safe marsh
sly dome
#

it is not ! little think outside of the box

#

i know what i say. i completed it

safe marsh
#

Hmm..It's quite weird. The questions are asking for WordPress details

sly dome
#

find the wordpress under the domain

safe marsh
acoustic owl
sly dome
#

🤣

#

its not there

#

domains can have directories and/or subdomains (virtual hosts in this case)

safe marsh
#

like editing the /etc/hosts file?

acoustic owl
autumn pilot
#

You could test your logic by trying it

#

From what I can see there are enough hints given that can help you

naive wadi
#

on the final question of the bloodhound module "Find the percentage of users with a path to GLOBAL ADMINISTRATOR. Submit the number as your answer (to two decimal points, i.e., 11.78). "

#

The query is killing me though

#

||MATCH (totalUsers:User {domain:'INLANEFREIGHT.HTB'})
MATCH p=shortestPath((UsersWithPath:User {domain:'INLANEFREIGHT.HTB'})-[r*1..]->(g:Group {name:'GLOBAL ADMINISTRATORS'}))
WITH COUNT(DISTINCT(totalUsers)) as totalUsers, COUNT(DISTINCT(UsersWithPath)) as UsersWithPath
RETURN ROUND(100.0 * UsersWithPath / totalUsers * 100) / 100 AS percentUsersToGlobalAdmins||

safe marsh
naive wadi
#

I'm using the hausec link

acoustic owl
naive wadi
candid lily
#

is HTB academy down?

sly dome
#

no

cedar void
#

"Check Carlos' crontab, and look for keytabs to which Carlos has access. Try to get the credentials of the user svc_workstations and use them to authenticate via SSH. Submit the flag.txt in svc_workstations' home directory. "

I don't see the file that they use in the module example for crontab that you would use when searching for 'svc_workstations' . So would I use the available script thats in the output of the command 'crontab -l'?

https://academy.hackthebox.com/module/147/section/1657

fiery berry
cedar void
#

Well I only follow that module because until the 4th question , word for word its been following what is exactly in the module. And I have not. I probably would use a cat command for that

hallow kiln
#

then go ahead

cedar void
#

Now I see it

quick crane
sly dome
#

i think they should add ldapdomaindump to the AD module, it parses the info in a nice HTML format

#

this is 2 cool

hallow kiln
#

Yeah, it's pretty neat

sly dome
#

but the module itself is long enough xD

hallow kiln
#

True, and they can't possibly cover every tool

sly dome
#

but they covered enum4linux which imho is meh

#

i think this is about own methodology after all

#

but cool !

naive wadi
sly dome
#

btw how do i remove bloodhound data 😆

naive wadi
sly dome
#

dont see the button

#

im under the neo4j web dashboard

naive wadi
#

wrong place

#

go into bh

#

and do it there

sly dome
#

might be blind

#

HAHA

#

oh i see it now

#

thx

naive wadi
sly dome
#

i can also switch it

naive wadi
#

if you have pro version

sly dome
#

nice

#

ohh nvm then

naive wadi
#

otherwise you can only have 1 db

sly dome
#

i have the zip files so is ok

naive wadi
acoustic owl
naive wadi
#

thanks

rich yoke
#

please.

acoustic owl
digital junco
#

hello guys

#

I have one problem with the hashcat module

#

the question: Identify the following hash: $S$D34783772bRXEx1aCsvY.bqgaaSu75XmVlKrW9Du8IQlvxHlmzLc

#

I use the hashid and says that is wrong, i look at the hashcat ref and got the same...

#

I tried many different variations of answers and it didn't work either.

balmy ember
#

I have also determined SSh is open

acoustic owl
candid lily
#

can anyone give me a hint for password attacks medium

#

i looked around for files but couldnt find anything interesting

#

i got the ssh but dont know how to proceed

#

anyone?

#

im still stuck

tame ivy
#

Does anyone completed a Citrix Breakout Section in Module Windows Priv Esc?

candid lily
#

ok i got something

dense axle
#

Windows Event Logs & Finding Evil - Skills Assessment, someone is stuck on it too ?

#

DLLHijack seems like a complete fucked challenge

#

PowershellExec was easy

vale badger
#

is there any hint for INTRO TO ASSEMBLY LANGUAGE Skills Assessment task 1

small steppe
#

Module: PIVOTING, TUNNELING, AND PORT FORWARDING
Section: Skills Assessment
Question: In previous pentests against Inlanefreight, we have seen that they have a bad habit of utilizing accounts with services in a way that exposes the users credentials and the network as a whole. What user is vulnerable?

I was attempting to transfer files to/from || 172.16.5.35 || and my attack host but I had not been successful. Went back and (with the help of some hints from the channel here) tried a number of things. Finally figured out a way to get the files back to my attackbox.

||However, in the middle of that process, one of the potential fix actions I tried was getting a reverse http callback with an exploit and its been failing. While my direct issue is addressed, I've created an itch and I don't know how to scratch here. So steps taken: generated an exploit for the target host, transferred the exploit to the target host via the pivot host, started a msf listener on my attack box, opened a ssh reverse tunnel on the pivot host; and, ran the exploit on the target host. No call back. I triple checked the IP's and ports on the exploit, handler, and tunnel. No sure what I'm missing here.|| Any insight would be welcomed.

sturdy otter
fathom pendant
sturdy otter
fathom pendant
#

Which if you look up hashcat example hashes, there's only one

shrewd hazel
#

on the getting started module with web enumeration, i was able to get the test credentials needed, but im confused on how to use them to login/get to flag from terminal

fathom pendant
#

Just go to the webpage in Firefox

shrewd hazel
#

no way to do it from terminal?

fathom pendant
#

Technically yes, however, that's not the point. There's a login form you can enter and boom you're in. You can't 100% rely on terminal for everything

shrewd hazel
#

ahh gotcha, fair point

tight mesa
#

hey guys I'm stuck with the last question from Attacking Domain Trusts - Child -> Parent Trusts - from Windows any hint would be appreciate it....

rich yoke
#

who completed this Bad grades challenge ? sombody can help me to get flag on this challenge.

fathom pendant
fathom pendant
covert jetty
#

Hi there.

Is there any room/machine/lab I can use in order to demonstrate the first 3 Pentest phases?

Recon

Scanning

Gaining Access

Thanks in advance.

fathom pendant
#

Most boxes do 2/3 there really isn't much recon on htb labs

pulsar willow
fathom pendant
pulsar willow
#

well, it's honesty

fathom pendant
pulsar willow
#

well, don'

#

figure then

fathom pendant
#

All you've said is some cryptic half AI generated nonsense that doesn't make any sense at all to anyone

tame ivy
#

Hello Everyone!

**Module:LInux Priv Esc
Section:Sudo
**

I tried everything in this section, doesnt work at all, searched for sudo version exploit, but there is no even gcc or make command on the box, checked sudo -l, and there just ncdu that is not on GTFOBins(also search in google), could anyone help please???(completed everything on this module except this section)

fathom pendant
#

@misty schooner at no point did I give you permission to dm read #welcome and #rules

misty schooner
#

Sorry 😔

acoustic owl
misty schooner
#

Ok

tight mesa
#

anyone knows why the DCSync attacks with Mimikatz into attackind domain trust windows section not work?

tame ivy
warped cloak
#

ACTIVE DIRECTORY ENUMERATION & ATTACKS
Privileged Access
What other user in the domain has CanPSRemote rights to a host?
Used given cypher query:
MATCH p1=shortestPath((u1:User)-[r1:MemberOf1..]->(g1:Group)) MATCH p2=(u1)-[:CanPSRemote1..]->(c:Computer) RETURN p2
Only gets forend user but it wants a different one. What am I doing wrong?

fathom pendant
tight mesa
warped cloak
tight mesa
#

and lemme know if works...

pulsar willow
warped cloak
full mortar
#

Hello friends, I am in the Password Attacks Lab - Hard module and I have chosen david's password but when I enter the smbclient I get the following message

╼ [★]$ smbclient -U david%Q****y7! \\10.129.202.222\david
session setup failed: NT_STATUS_LOGON_FAILURE

#

try with smbmap, crackmapexec, smbclient even try to mutate the password and nothing

thorn urchin
#

are you wrapping the password in quotes

#

! is a special bash character that will get interpreted before it gets passed to the application

tight mesa
thorn urchin
#

which means the password smbclient sees and what you wrote arent the same

warped cloak
tight mesa
warped cloak
tight mesa
#

weird

tame ivy
#

@thorn urchin can i DM u?

thorn urchin
#

about

warped cloak
tight mesa
#

ok.

tame ivy
thorn urchin
#

just ask the question here

tame ivy
#

i asked too many times, no ones know i guess...

#

Module:LInux Priv Esc
Section:Sudo

I tried everything in this section, doesnt work at all, searched for sudo version exploit, but there is no even gcc or make command on the box, checked sudo -l, and there just ncdu that is not on GTFOBins(also searched in google).completed everything on this module except this section)

thorn urchin
#

They added that section after I did it

tight mesa
#

anyone, know what could be the error?

thorn urchin
#

but it's extreme unlikely that they added ncdu to sudoers for no reason

#

so its very likely the path, I would suggest digging through the man pages for ncdu to see if theres any functionality that could be leveraged or dangerous if you had elevated perms

tame ivy
#

yeah i know it, i can examine a /root with sudo ncdu, but i cannot open a file, move, or spawn a shell with this binary

tame ivy
thorn urchin
#

yup

tame ivy
#

thats very funny bcs i did 99% of course and cannot finish this things just bcs there is a way that i see, like rabbit hole, and asked too much time in discord and nobody know this fking sh1t

#

comedy...

thorn urchin
#

I got a few minutes at work, let me poke the section real quick

thorn urchin
#

I did it

fathom pendant
#

kek that was quick

thorn urchin
tame ivy
thorn urchin
#

nah just looking at the help from running ncdu

#

the 'hard' part is actually getting sudo to run it as root. Getting shell is the ez part

tame ivy
#

thank you a lot

thorn urchin
#

np

sly dome
#

imagine the skill issue when he completed it in 2 minutes

tame ivy
sly dome
#

i dont think so

#

just analyze what you have

thorn urchin
#

reading is OP is all

sly dome
#

literally an option to spawn a shell

thorn urchin
#

I actually couldnt find that option in the regular man pages lol

#

but built in help is OP

sly dome
#

with the ? key probably

hallow kiln
#

I remember I just googled it

#

found the option

thorn urchin
sly dome
#

🤷

#

reading issue along with enumeration issue have to be the most common ones

tame ivy
tame ivy
thorn urchin
#

np

warped cloak
# tight mesa ok.

reset the machine, did the same exact thing, and NOW it works. sometimes these machines just dont work properly. thanks for the help

sly dome
#

rests

tame ivy
sly dome
#

… 🤦

tame ivy
hallow kiln
#

Rushing through things is really not recommended

fathom pendant
#

You'll end up dropping info

thorn urchin
#

Everyone progresses differently

#

but I know that as much as I desperately want a job switch, Id have a lot harder of time being stressed out if I NEEDED a job by X date

hallow kiln
#

I think if it's a matter of NEED, you take whatever you can get, not try to break into pentesting

fathom pendant
#

^

#

The job market is trash rn

#

You're better off going into tech support or low level and transitioning to cybersec

hallow kiln
#

100%, it will improve eventually, but for now it is what is

#

CPTS is not something that can be rushed I feel, personally at least

tame ivy
# hallow kiln 100%, it will improve eventually, but for now it is what is

I’m kind of in no hurry, I started at the end of the summer, all this time I was taking a course and playing machines at HTB, and then I wanted to start the exam, but then it turns out that I have to finish everything with 100%, and it feels very different when you do a real case or you pass an exam (there you get 100 percent perfect, but here the modules are already boring and monotonous)

hallow kiln
acoustic owl
tame ivy
tidal kelp
#

have questions on the module **ATTACKING WEB APPLICATIONS WITH FFUF ** filtering repsonses on size says "Filter HTTP response size. Comma separated list of sizes and ranges" Doesn't that meant for example that "ffuf -w /opt/useful/SecLists/Discovery/DNS/subdomains-top1million-5000.txt:FUZZ -u http://83.136.253.102:52466/ -H 'Host: FUZZ.academy.htb' -fs 0-900
" would get me repsonses in the size between 0-900?

fathom pendant
#

-fs is an exclusion iirc

#

-ms is a match

#

The -f{x} in ffuf is a filter out

tidal kelp
#

so if I would like to filter for > 900 , what should I use?

fathom pendant
#

Well if your filtering out 0-900 then all other results will be greater than 900

thorn urchin
#

<@&861185840277487616>

fathom pendant
#

<@&861185840277487616> wouldn't be surprised if other channels

thorn urchin
#

Woulda been sooner but discord kept jumping around and making me tap on the wrong tag

fading oracle
#

hi guys!

#

i have some troubles with aquatone in the Attacking Common applications module

#

i followed the module very strictly

#

i tried researching this error but no luck so far

#

has anyone encountered this problem?

acoustic owl
#

Which directory are you in? Do you have write access?

fading oracle
#

i have /opt

acoustic owl
#

A user normally has no write permissions in /opt
Try it with sudo

fading oracle
#

i tried no luck

#

if i try to do it another directory

#

it says no target found

acoustic owl
#

Copy web_discovery.xml into your home directory

#

Then run
cat web_discovery.xml | sudo /opt/aquatone -nmap

fading oracle
#

same:(

#

tried with the gopath too

fathom pendant
#

Aquatone is also no longer being updated or maintained I thought

fading oracle
#

uhh

#

thats bad

#

yeah i see last release from 2019

#

2nd question form this module needs the aquatone

#

...

fathom pendant
#

Last updates were in 2019, I don't recall though having issues with it

hallow kiln
# fading oracle same:(

Error's different this time, haven't done the module, but are you sure whatever's supposed to be in the web discovery file is there?

fathom pendant
#

^

fading oracle
#

yes

#

it is an nmap output

fathom pendant
#

And your Nmap output was created using -oX?

fading oracle
#

sudo nmap -p 80,443,8000,8080,8180,8888,10000 --open -oA web_discovery -iL scope_list

heady sundial
#

Is there a way for my flipper zero to make fake networks that find data? (this is for LEARNING)

sudden blaze
#

Module:Active Directory Section:Enumerating & Retrieving Password Policies Question:What is the default Minimum password length when a new domain is created? (One number) Done so far: rpcclient getdompwinfo, crackmapexec but everywerhe 8 chars long

fathom pendant
#

You should probably read up on flipperZero docs if you wanna figure it out

fading oracle
#

i would jump to pwnbox but since aquatone need chrome right? on pwnbox there is none if i am correct

fathom pendant
#

It's chromium

#

Which is usually installed under burp

fading oracle
#

this error on pwnbox

#

what i am supposed to do?

fathom pendant
#

locate chrome

fading oracle
#

configure pwnbox?

#

there is none

#

i guess i have to install it

#

i installed it on Pwnbox

#

like this it works

#

...

fading relic
#

This helped me greatly!

tawdry vapor
#

hello, can someone help me with this error?

#

Active Directory module, Attacking Domain Trusts - Child -> Parent Trusts - from Linux

wary tendon
#

Attacking smb. Can’t download id_rsa to log in as ssh does anyone know what I am missing to get the file

fathom pendant
#

Skills

#

What is the error you get?

wary tendon
#

So when I log in as ssh without idrsa it gives permission denied but does not get to password entry

fathom pendant
#

I meant when you try and download the id_rsa

wary tendon
#

When try to download via smb only read permission

fathom pendant
#

Then open the file and copy/paste

#

¯_(ツ)_/¯

fathom pendant
wary tendon
#

I don’t think it was letting me open it either

#

Is there a command to open a file to read it in smb

#

I’ve been looking online

fathom pendant
#

Should be like open or type or something

#

Or more

#

¯_(ツ)_/¯

wary tendon
#

Ok thanks I’m assuming so I’ll try it

#

I though I had to find a way to download it but if I can read it then yea for sure copy

fathom pendant
#

I dont know what module you're working so can't be more specific

jade shoal
undone narwhal
#

Hint: ||payloadallthethings||

cedar void
crude rain
#

oracle TNS

turbid yoke
#

Were you able to figure any good resources to help with this module? I guess I'm dumber than I thought, but so far the material feels like " 1 +1 = 2, now go ahead and resolve this college level algebra problem" lol...

river cedar
# dense axle PowershellExec was easy

Mybe we can help each other. I was able to figure out everything else but second PowershellExec challenge. You game? For dll, I ran a getwinevent on unsigned loaded dll.

cedar void
timber pendant
#

Doing linux fundamentals & have question " How many total packages are installed on the target system?
Tried 'apt list --installed | wc -l' and I feel like thats it but the box disagrees..Any suggestions?

jaunty loom
fossil crescent
#

Anyone doing the Advanced XSS & CSRF? On the CORS Misconfigurations -- can't tell if the site is massively glitched, gotta really baby it, or just hit it lucky -- while I've gotten some test responses from the server, (a) not consistent, (b) every time I then try to go to the actual payload of course nothing. EDIT: Solved. Swear sometimes just gotta put out there that lost, then your mind can figure it out. Anyhow, (a) I def had an error I realized, and (b) still remain skeptical on if gotta baby the site, strike at the PRECISE moment in time, or what...

heavy marsh
#

The password attacks password mutation module is taking forever to crack. Is there a more focused simplified way to do this?

sly dome
#

~15 minutes

#

it took me 18

heavy marsh
#

It looks like I'm going to be here forever!

fossil crescent
sly dome
#

its not the one about cracking

heavy marsh
#

No, VM.

sly dome
#

any hashcat process i've done for the academy took me less than 1 second

heavy marsh
#

I have another laptop with a GPU, I might have to use that.

sly dome
#

dude

#

it is hydra

heavy marsh
#

1523 hours is a lot

sly dome
#

nothing related to GPU here

fossil crescent
#

Cracking would be hashcat (or john) -- brute forcing would be hydra.

sly dome
#

1st. Do no brute force SSH with hydra

#

There is FTP open

#

maybe FTP password is reused on SSH

#

you wont start on difficult stuff like bruteforcing SSH

heavy marsh
fossil crescent
#

So this is NOT cracking pw hash then? If the case, then yeah -- GPU, baremetal vs. VM, not gonna make a diff

sly dome
#

start on easier things like brute forcing FTP

heavy marsh
#

I'm on the academy module for password mutations

sly dome
#

brute forcing SSH is not doable

#

from hydra

#

xd

heavy marsh
sly dome
#

it tells you to log in with SSH

#

not to brute force SSH

#

FTP open is not a coincidence

fossil crescent
sly dome
heavy marsh
#

yeah, I misspoke

sly dome
#

go for FTP with maximum threads

heavy marsh
#

but it did tell me to use hydra for ssh

sly dome
#

-t 64

heavy marsh
sly dome
#

and

#

it is just teaching u it can be used for SSH

heavy marsh
#

hmmmm

sly dome
#

but why would they give FTP open

#

xD

heavy marsh
#

I'll try that then

sly dome
#

yes

#

it can take up to 30 minutes

#

it took me 18

fathom pendant
# heavy marsh

Read the question again it's asking you to find their password, then log in with ssh

#

Not brute force ssh

#

This module gives you step z and expects you to take logical steps between a and there

sly dome
#

there is a tool called ssb to BF ssh but it doesn't like long passwords lists

#

anyways, FTP is open here for a reason

#

good luck buddy

heavy marsh
#

Thanks

#

Just to make sure I'm on the right track, I'm using the password list and the rules list from the resources file?

#

It is saying 94044 login tries and around 5 hours

heavy marsh
# sly dome good luck buddy

Am I supposed to use the custom.rule file in the ZIP like the lesson instructed or should I just go with best64.rule?

fathom pendant
sly dome
#

cool then, just let it be 🙂

heavy marsh
#

yes, sort -u was part of the command

sly dome
#

nice nice

fathom pendant
#

You can use more threads

heavy marsh
sly dome
#

i didnt remember the amount of passwords

heavy marsh
#

yeah, I need to split it up and use more threads

fathom pendant
#

It is indeed 94k passwords

fathom pendant
heavy marsh
#

That makes me feel better

#

I'll just be patient

fathom pendant
#

This module is all about patience

heavy marsh
#

I appreciate the help, I was trying to be patient, I just wanted to make sure my commands were correct so that I didn't waste a bunch of time.

sly dome
#

its around the 17k

fathom pendant
#

As most suggestions have been to use a sed command to eliminate the first 17k passwords

heavy marsh
#

I ballparked it and deleted everything before 12k ish and did -t 64, it popped almost immediately!

#

Thanks again!

heavy marsh
#

For the password reuse/ default passwords I figured out the answer, but it was by guessing with the resources given in the lesson. How was I supposed to use the credentials from the previous section?

supple patio
#

Probably you should've brute forced the mysql service with default credentials which was local

fathom pendant
#

pika_sip you can do a simple thing to verify by ssh as user and attempting the logins manually

heavy marsh
#

I just used a couple of default creds manually while I was ssh'ed in as sam and one worked.

#

🤷‍♂️

tulip dragon
#

hey i am on Pass the hash module and i cant rdp to given machine

tidal kelp
#

Module : **Web Fuzzing ** - Skills assessment - Q: Before you run your page fuzzing scan, you should first run an extension fuzzing scan. What are the different extensions accepted by the domains?
Found two extension, am I missing something?
||Only .php and .php7 give 200 reply ||

tulip dragon
#

can anyone test if they can access the machine by rdp or not

#

Authenticate to 10.129.195.220 with user "Administrator" and password "30B3783CE2ABF1AF70F77D0660CF3453"

safe marsh
#

I guess you may freely reset the target

tulip dragon
#

its 3rd time i have reset it

safe marsh
#

did you reset it? make sure you can ping the ip

fiery berry
tulip dragon
#

but in next quest it does

fiery berry
tulip dragon
#

i tired with reminia and xfree rdp

#

here is my command

fiery berry
tulip dragon
#

xfreerdp /dynamic-resolution +clipboard /cert:ignore /v:10.129.204.23 /u:Administrator /p:'30B3783CE2ABF1AF70F77D0660CF3453’

fiery berry
#

try: /pth:<hash>

tulip dragon
#

ok

fiery berry
tulip dragon
tidal kelp
# fiery berry One it's giving "403 - Forbidden", that's a valid ext

aha, thought only the 200 was the calid ones. maybe I misinterpreted the text in previous session... "We do get a couple of hits, but only .php gives us a response with code 200. Great! We now know that this website runs on PHP to start fuzzing for PHP files."
not the clearest

fiery berry
# tulip dragon

If you read the following question you'll understand why isn't working. Being said, now you should have understood how to login without using RDP

rustic sage
#

Hiii

rustic sage
#

for a begginer would people recommend using the pwn thing on the site or to download my own stuff like parrot to the mac?

tulip dragon
# tulip dragon

its my mistake , i always ssh, rdp to machine before reading module 😅

rustic sage
#

I'm totally down for both tho I'm just wondering. Plus ik it'd help with the one a day pwn access

crimson walrus
#

Hey guys, has anyone done the Dante Pro Lab? I have a very simple question about it. Please hit me up if you have done it. Or if I need to ask in some other channel.

crimson walrus
#

i dont have access to that channel

acoustic owl
#

if you have no access, read and follow #welcome

cedar void
#

Did my post get removed? If so then why?

mossy nest
#

Hey Guyz, I'm doing the active directory attack module, I'm at the first skill assessment and I don't get how to Upload tools in the Machine.

#

Tried to copy \MyIP\share\MyFile

#

Tried to powershell.exe -c "(New-Object System.NET.WebClient).DownloadFile

#

Tried to Upload from the antak webshells

#

But nothing seems to work

fiery berry
oblique turtle
#

Hi, I am trying to figure out if you get cubes monthly with the Silver Annual plan. Does anyone know? Coin

hallow kiln
acoustic owl
acoustic owl
mossy nest
fiery berry
mossy nest
#

Thanks !

#

Get-ChildItem -Path C:\ -Filter PowerView.ps1 -Recurse -ErrorAction SilentlyContinue -Force helped me find my way

lime yew
#

Hi, i am on the module related to Windows Event Logs and there is a question i couldnt answer for myself.

See this command:

I understand the first 2 Lines.
The 3rd line wants to inject something in the Process with ID X. But was is the PoshCode in that Case? I think the PoshCode is something i wanna inject, but i am not sure how to get the PoshCode.

#

Okay nvm. In this case the poshcode is just base64 encoded PowerShell Code.

cedar void
fathom pendant
cedar void
#

oh that may be it

dreamy solar
#

Hello I have a problem with this exercice ( SHELLS & PAYLOADS Antak Webshell );

fathom pendant
#

Did you edit the webshell properly?

dreamy solar
#

yes this ?

fathom pendant
#

There's another one that you need to edit, the ip section

#

The section even tells you :)

forest kayak
#

Hi, I'm lookign for apropriate place to discuss old HTB challenge (Crypto / Rookie Mistake).

boreal crest
#

Heyo! Anyone here used the w3m terminal browser with burpsuite proxy?

forest kayak
forest kayak
#

Got it! Thanks!

wraith spoke
#

ACTIVE DIRECTORY ENUMERATION & ATTACKS // Attacking Domain Trusts - Child -> Parent Trusts - from Linux. I got the hash but when i enter it in the answer box it does not say it is okay. can someone tell me the format for the answer

next bronze
analog dock
#

Great question

rustic sage
#

Linux Privilege Escalation > Python Library Hijacking: None of the directories in the PYTHONPATH containing psutil appear to be writable to htb-student user and it seems that htb-student doesn't have permissions to modify path. Am I missing something here?

rustic sage
#

nvm--figured it out

dapper locust
#

Are there any HTB Academy servers/boxes down atm?

boreal crest
#

Hey guys! I'm getting a very weird problem with Pivoting (on the Attacking Enterprise module) and I was wondering if theres anyone here that can helP? Please PM me if possible, Im fairly certail I have setup everything right

spiral hinge
#

Anyone know privelege escalation for Grandpa Machine?

dapper locust
#

Or are there any Admins/mods that could check the status of one? I can't connect to the web server of one that is pingable; it's stopping me from cleaning up unfinished mods

acoustic owl
spiral hinge
#

Cheers, Ill go to #welcome and see how to get in 🙂

#

I have HTB Enterprise so I cant see my identifier?

spiral hinge
#

How can I get the identifer and get access to the no access one?

acoustic owl
#

Maybe the support can help you (green bubble)

half inlet
#

can anyone help me with an issue in metasploit? Im trying to solve a module, but this exploit that is required has two variables (RHOST and RHOSTS), but when I set one it also sets the other, but I need the two variables to be different IPs:

msf6 exploit(linux/http/50064) > set RHOST 172.16.1.5
RHOST => 172.16.1.5
msf6 exploit(linux/http/50064) > set RHOSTS 172.16.1.12
RHOSTS => 172.16.1.12
msf6 exploit(linux/http/50064) > options

Module options (exploit/linux/http/50064):

   Name       Current Setting  Required  Description
   ----       ---------------  --------  -----------
   PASSWORD   demo             yes       Blog password
   Proxies                     no        A proxy chain of format type:host:port[,type:host:port][...]
   RHOSTS     172.16.1.12      yes       The target host(s), range CIDR identifier, or hosts file with syntax 'fil
                                         e:<path>'
   RPORT      80               yes       The target port (TCP)
   SSL        false            no        Negotiate SSL/TLS for outgoing connections
   TARGETURI  /                yes       The URI of the arkei gate
   USERNAME   demo             yes       Blog username
   VHOST                       no        HTTP server virtual host


Payload options (php/meterpreter/bind_tcp):

   Name   Current Setting  Required  Description
   ----   ---------------  --------  -----------
   LPORT  4444             yes       The listen port
   RHOST  172.16.1.12      no        The target address


Exploit target:

   Id  Name
   --  ----
   0   PHP payload


msf6 exploit(linux/http/50064) > 

If it's needed, I'm working on module https://academy.hackthebox.com/module/115/section/1139, questions 4 & 5. I am trying to run the 50064 exploit to gain access to the Inlanefreight Gabber website on host 2

Edit: I solved it by ||using a different payload (specifically php/reverse_php)||, however, for the future, how do I fix this issue with RHOST and RHOSTS?

mossy nest
#

Hey guyz, I'm trying to do the first skill assesment in ActiveDirectory attack

#

But after uploading a mimikatz using antak I can't make it work (it seems the reverse shell, or the antak shell can't work in its embed format)

#

So I tried to Kerberoast it from my Linux Machine, but it seems I'm doing something wrong ( I'm currently using the administor hash extracted from sam/system/security ) to try to use the GetuserSPN.py which is'ntworking

#

Any nudge ?

upbeat osprey
#

Hello, where can I ask for help about academy modules ? It is currently for Intro to Forensics

half inlet
upbeat osprey
#

Okay, so I'm currently stuck for the first question of the Rapid Triage & analysis section where I have to find the new name of the renamed uninstall.exe. I searched in many ways with the Zone.Identifier but I could not find the information

distant moat
#

I have a problem with living off the land and question “Utilizing techniques learned in this section, find the flag hidden in the description field of a disabled account with administrative privileges. Submit the flag as the answer”

I used a net and qsquery with filters commands

I found users: jessica, krbtgt. Guest but i dont see any flag.

#

module : ACTIVE DIRECTORY ENUMERATION & ATTACKS session : Living Off the Land

fathom pendant
upbeat osprey
mossy nest
#

Hey, I'm trying to use getuserspn to kerberoast the machine in first skill assessment of Active Directory Attack Module

#

GetUserSPNs.py -dc-ip 10.129.156.4 INLANEFREIGHT.LOCAL/Administrator -hashes LM;NT hash of the admin found using sam secret system key

#

But can't make it worked

arctic junco
#
manic wolf
#

Having trouble with the IMAP/POP3 part of the fingerprinting module. I selected the inbox which has the flag mail, but if I use fetch with the "all" flag I don't see the flag

fathom pendant
#

Use 1 fetch 1 body[]

manic wolf
#

Thank you, will try

#

I never found that syntax anywhere I researched

#

I'm gonna have to take good notes on this, wouldn't wanna waste time during the cpts exam looking up IMAP syntax lol

fathom pendant
fathom pendant
manic wolf
#

Really? I tried hackstricks then looked at atmail, asked an AI search engine which also retrieved information from atmail

#

Seems like I should have paid more attention to atmail, my fault for just skimming the page

wraith spoke
#

the luck i have, kali failed to install, now pypykatz won't install on parrot.. making a win10 iso to install mimikatz...

thorn urchin
#

Not the place to ask, this is for module discussion only

#

ftr I dont know of any challenges that can be beaten with only hydra. Itd have to be a super lame challenge

marble raft
#

Any tips on the last question on the Skill Assessment of Understanding Log Sources and Investigating with Splunk?

Navigate to http://[Target IP]:8000, open the "Search & Reporting" application, and find through SPL searches against all data the process that started the infection. Answer format: _.exe

Tried a variety of process names, tried various techniques shown in the module but for some reason all of them are wrong.

Edit: Answer was right in my face the entire time. Tip from me would be to try establish an timeline, and re-create the steps taken by the attacker. The answer is discussed previously in the module.

dawn cove
#

Hi, I have a question about Dante prolab, kindly any one completed this lab, DM me

dapper locust
#

Could someone tell me the difference between 'http::////127.0.0.1' and 'http://127.0.0.1' what are the extra colon and double slash??

woven copper
#

hello there @lethal shard
did you find a solution, can a I dm you ?

cedar void
#

Am I suppose to find the kerberos ticket for linux01 in the temp directory ?

cedar void
# fathom pendant Nope

the linKatz tool can list all of the Kerberos tickets on the machine...just as long as you run as root?

fathom pendant
slow wind
#

Hey there what commands other than curl can let you download something from a web server

#

my mind is drawing a blank atm

fathom pendant
#

Wget

slow wind
#

thank youy

#

deosnt seem to have either on the system thanks anyways

fathom pendant
#

That's weird considering curl and wget are default on linux

slow wind
#

its freebsd

fathom pendant
#

Ah can't help ya there

slow wind
#

yeah gotta change my strategy

fathom pendant
#

You might be able to install it

slow wind
#

not a bad idea actually

#

thank you currently im just sending request to the root account

fathom pendant
#

Good luck on whatever academy module you're working on

slow wind
#

sense lab

fathom pendant
#

This channel is for academy modules on htb

slow wind
fathom pendant
cedar void
fathom pendant
dawn cove
fathom pendant
cobalt bone
#

anyone had any luck with "Attacking Common Applications - Skills Assessment I", I've located the bat file using ffuf and have listed the flag using the 'dir' command (using burp to url encode) however the 'type' command doesn't work? any ideas/hints? prayge

eternal tusk
#

How do I get access to HTB: Serious Discussions Channels, any idea?

eternal tusk
#

Thanks for your help!

proud notch
#

Hello,

I was working on Footprinting Lab - Easy and while I was able to find the flag easily using the ||ftp server with the non-default port|| I was wondering if there was a point in the prompt pointing out that the DNS server was open. Is there another way to solve this challenge simply by enumerating the DNS server, or does that eventually lead back to the original solution? If anyone would be open for discussion within DM I would love to learn more about it.

hot heart
#

Thanks @sly dome for believing in me, I finished the rest without any help. You were the last person I asked for help, and I appreciate the advice you gave me brotha

balmy ember
#

Noob totally lost on Nibbles. Read everything available still can't get to root.

heavy marsh
#

There's not a lot of instruction on setting up the smbserver.py script in the "Attacking SAM" module.

#

Where do I put the share?

#

Inside the path?

#

sudo python3 /usr/share/doc/python3-impacket/examples/smbserver.py -smb2support CompData /home/ltnbob/Documents/

#

is CompData a folder in Documents?

#

I am confused. The github doesn't have instructions either.

sturdy otter
heavy marsh
#

is the "Sharename" a folder in \SaveDir?

sturdy otter
#

CompData or Sharename is the Name you want to give your share. So on the machine you want to connect you call fe 10.10.10.46\CompData

#

you can name it whatever you want

heavy marsh
#

But do I have to make a folder or does the script make it?

sturdy otter
#

it will save it in the place at the end of the script fe. \tmp

heavy marsh
#

Thanks I'll try it

sturdy otter
#

sure

#

give it a go

heavy marsh
#

Same, "system cannot find the file specified"

#

Nevermind, the windows side was in the wrong directory

#

Just to clarify for anyone else that runs into the same problem. The Sharename is essentially an alias for the \SaveDir

#

It does not create a folder with that name inside of \SaveDir with the name of whatever you call your sharename

rustic sage
#

stuck on one of the modules and it advised that i click request help, so i did, was a channel/ticket made that im supposed to be able to see or is a mod going to dm me or how does that work

heavy marsh
rustic sage
#

Linux Buffer Overflow section of the Binary Exploitation module.

And okay thank you.

rustic sage
heavy marsh
#

I haven't made it to BOFs yet. I did them in TryHackMe, but not yet in academy.

boreal crest
#

Heyo! Anyone know how to reset bloodhounds neo4j db

spring compass
#

Hello everyone. Not sure if there's a proper process for reporting typos in the modules, but I found a very minor one under /9/section/48:

(Please see attached). It should read something to the effect of ..."handle different, sometimes adverse, situations where something does not work as expected"

#

@spring compass f'in newb

fiery berry
next bronze
boreal crest
#

community endition the one for linux GUI

next bronze
#

the docker version yea?

boreal crest
#

no im running it locally on Klai

next bronze
#

so legacy. are you accessing it through a browser?

boreal crest
#

This guy here:

boreal crest
sly dome
#

i tried CE but icons were not loading and pre-populated analysis queries neither

boreal crest
#

Damn sorry I cant post a screenshot on this channel

next bronze
boreal crest
#

I feel stupid, Thanks a lot!

hallow kiln
next bronze
sly dome
rustic sage
#

a

next bronze
next bronze
rustic sage
#

Im trying to verify but i cant

next bronze
rustic sage
#

I have a question do I not have an account in htb app if i have an account in htb academy or am i misunderstanding something?

next bronze
#

that's correct, the two accounts are not linked

rustic sage
#

ooooh

boreal crest
#

Hey how come I cant upload new artifacts now? It just keeps getting stuck at 0%

Sorry this is in relation to the bloodhound db wipe post above

rustic sage
#

thats why my "forgot password" was not working thanks for the help!

next bronze
next bronze
#

are you using the right collector?

#

the new sharphound collectors are for bloodhound CE and won't be accepted by bloodhound legacy

boreal crest
#

Ohh! So what collectors are?

next bronze
#

try 2.0.0

boreal crest
#

okay! Also do you recommend I use CE instead of legacy? is it easier + better in any way?

next bronze
#

no, I use CE more but a lot of stuff are missing there, unless you know how to write your own queries, sitck with legacy for now

boreal crest
#

Okay sounds like sound advice! Thank you!

tidal kelp
#

ON Module Login Brute forcing, Skill assessment - Website. 2nd flag:
Been running hydra forever. is rockyou.txt the wordlist to go for?

boreal crest
# boreal crest

So Im using Legacy v4.3.1 and SharpHound Collector v2.0.0 and it still gives me this weird error. You think it has anything to do with wiping the DB? maybe I should reinstall neo4j?

next bronze
#

there should be a message when you run the collector that tells you which version its compatible with, check if that lines up

boreal crest
#

Yup, says: 2023-11-03T01:17:24.4819880-07:00|INFORMATION|This version of SharpHound is compatible with the 4.3.1 Release of BloodHound

next bronze
#

try restarting both neo4j and bloodhound

boreal crest
#

did that, also reinstalled neo4j. Same issue. Thats weird tho

next bronze
#

try rusthound maybe? though I've never had a problem with it ingesting data from sharphound

boreal crest
#

okay lemme try that. Is it possible to use the bloodhound-python collector with proxychains? Thats worked the best for me always

boreal crest
#

Hey just tried rusthound and end up with the same issue, any tips?

autumn pilot
#

If the collector is a higher version, you won’t be able to ingest the data into bh

boreal crest
#

A higher version meaning? Ive used both SharpHound 2.0.1 and 2.0.0?

#

Also Just tried Bloodhound CE and It has no problem injecting the data

next bronze
#

2.0.0 should be compitable, but try an even older version

#

if not then there's something wrong with your bloodhound installation

boreal crest
#

okay, for now im just gonna run with bloodhound CE. Learn some custom queries

dreamy solar
#

Hello for this exercice there aren't a browser?

hallow kiln
#

type firefox in the terminal

rustic sage
#

yo

#

Can i ask a question about vmware and stuff

#

i get its not the right place but im stuckk and i think im close to figuring it out

next bronze
#

just ask

rustic sage
#

aight

#

ive been trying to setup vmware and parrot the las 4 hours

#

that didnt work at all

#

so im trying to setup kali now

#

problem is its a torrent not an iso

#

and i dont know what to do about that

#

im 100% new to this

sturdy otter
rustic sage
#

and just trying to setup a vm because im low on money and cant afford to pay for hbox rn

next bronze
rustic sage
#

mhm

#

im using vmware fusion on mac btw

#

im wondering if its just impossible at this point

#

some dude on another discord tried to help for 30 mins but nothing

next bronze
#

if you downloaded the vmware prebuilt vm, you'll get vmdk files, which are virtual disks, the OS is already installed for you, there should be an option in vmware to scan for VMs, try that

rustic sage
#

mind if i dm you?

#

i understand if noti just wanna get this over with so i can start learning linux basics again tomorrow

next bronze
#

sure go ahead

solid gate
#

And here again I sit. With the Password Attacks module wasting my time. FeelsBadMan

acoustic owl
#

While you wait for the password to be cracked, you can read another section or drink coffee, or even better, do both

warm drift
#

please does anyone have any good tips for enumerating php version that a site runs on I'm on File Incusions module so I'm trying to read the .ini config

#

keep getting undefined variable error

solid gate
#

You could use the file inclusion to try and read the php.ini, but sounds like you gotta fly blind for now. I haven't done the module yet, but have done a couple file inclusions with php on boxes. You can DM me if you want. 🙂

warm drift
#

I don't know if it's the right PHP version or not that I'm specifying directory of

solid gate
#

The module probably tells you where to look. From the top of my head I think it should be something like /etc/php/<version>/<service>/php.ini Where <version> is something like 7.0, 7.4, .... (see version list) and <service> is something like apache2, cgi, fpm or some such. Depends on the configuration of the server.

solid gate
warm drift
eager loom
#

Im having trouble getting vimtutor working

solid gate
warm drift
solid gate
#

But again, might not even be worth automating. You probably know the webserver. If it's apache, try apache2 for version, if its nginx try fpm. And for versions, you will likely succeed with a version between 7.0 and 8.0. Thats only 6 versions in total. So trying manually is likely quicker than automating it. 🙂

solid gate
#

You're welcome. 🙂

#

*apache2 and fpm goes in <service> of course, not version. Had that wrong in my last message.

wraith spoke
#

I keep getting errors on using mimikatz. ERROR kuhl_m_sekurlsa_acquireLSA ; Memory opening. googled it but cannot find a solution. any ideas how to solve it?

wraith spoke
#

I managed to get a lsass dump through the web application, cannot open it now though.

undone narwhal
#

do you have privileges to dump lsass process?

wraith spoke
#

apparently, I dumped it through rundll32

undone narwhal
#

You should do that in a elevated session, onty then it will work

#

and for this assessment you dont need to dump lsass process

undone narwhal
#

which user do you have access to?

wraith spoke
#

I just started, no acces but the webshell

#

did i run into a rabbithole?

undone narwhal
#

yes and no, get a shell first and then follow the questions asked in the assessment

wraith spoke
#

kk will try other routes 😄 thx

sinful verge
#

dedserver

weak stirrup
#

working on the Intro to Assembly Language skill assessment not sure how to input as the answer. I guessed I was supposed to insert the shell code in as a hex string. however, it does not fit in the length available. The code looks to push 14 things on stack that is 224 character of 'data' if you convert it to a hex string. the input box given to answer the question does not allow a string that long... I tried to just jam in whatever fit after a xor'd it and it hated my answer. What type of data am I supposed to be putting in the box?

woven copper
vast geyser
#

Hello,I have a question
The file upload modules says MIME type is Magic bytes
but according the wiki , I think MIME type is equal content type not Magic bytes.

sleek shell
#

How to get clear usernames list from crackmapexec output?

next bronze
tired flax
#

Hello guys someone can help me out with the module NTLM Relay attacks?

tiny yacht
#

Hi ! Anyone know how to modify that payload to receive /flax.txt ? I was trying few different ways and its not working 😄
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE svg [ <!ENTITY xxe SYSTEM "php://filter/convert.base64-encode/resource=index.php"> ]>
<svg>&xxe;</svg>

rustic sage
#

Little stuck on the file upload attacks module i have sent the request back with repeater and had no errors so the file should be uploaded i get a http ok message. But when i try to visit the file it says not found and im sure im in the correct directory because i checked the source code and forums

rustic sage
#

Theres two in the section for xxe use the other one

rustic sage
peak tapir
#

Hi guys How are you Hope you are doing well. I finished my ejpt certification and i'm confused what is the next step, I have fairly good knowledge of the basics (networking, os, etc..) except scripting I have only the ability to read code, I can't write, So what do you think guys do i have to improve my self be OS and scripting and stick to the basics, or I can jump toward PNPT.

tired flax
tiny yacht
acoustic owl
#

Take courage, you have nothing to lose

potent inlet
#

Guys, is anyone else having trouble connecting to the windows attack host in the "AD enumeration and attack" module (section: ACL Enumeration)? When I use xfreerdp it just gives me a black screen. Ive reset the target and the terminal 3 times but I just cant get it to work...

potent inlet
#

Holy, thanks.

#

Pressing enter multiple times worked

magic cosmos
#

Hello everyone,

Since yesterday I'm stuck on the module 'ACTIVE DIRECTORY ENUMERATION & ATTACKS' and more precisely on "DCSync" and "Priviged Access".

In the instructions it says:

"""
In this section, we will move back and forth between a Windows and Linux attack host as we work through the various examples. You can spawn the hosts for this section at the end of this section and RDP into the MS01 Windows attack host. For the portion of this section that requires interaction from a Linux host (mssqlclient.py and evil-winrm) you can open a PowerShell console on MS01 and SSH to 172.16.5.225 with the credentials htb-student:HTB_@cademy_stdnt!. We recommend that you try all methods shown in this section (i.e., Enter-PSSession and PowerUpSQL from the Windows attack host and evil-winrm and mssqlclient.py from the Linux attack host).
"""
However, when I try to connect via my Windows machine "MS01", the credentials indicated don't work.
Is there anything I haven't understood?

#

The credentials htb-student:HTB_@cademy_stdnt don't work when I run htb-student@172.16.5.225 on the RDP machine (Windows).

So I can't finish the module questions

hallow kiln
magic cosmos
hallow kiln
#

is it not prompting for a password?

#

is that the full command?

magic cosmos
#

Yes, it asks for a password "HTB_@cademy_stdnt"

hallow kiln
#

there's a ! at the end of the password

magic cosmos
#

Yes I know miss my copy and paste

#

But even with the "!" it doesn't work.

hallow kiln
#

you're sure it's pasting correctly?

magic cosmos
#

We agree that I simply need to connect via RDP to my Windows machine and from this machine I'm supposed to connect via SSH to the IP: 172.16.5.225 (which should be a Linux?).

ssh htb-student@172.16.5.225 password HTB_@cademy_stdnt!

hallow kiln
#

screenshots would be helpful, you should verify your account so you can post them, read and follow #welcome

magic cosmos
#

It's juste a simply ssh connection 🙂 but it doesn't work 😦

hallow kiln
#

if you paste the password in the terminal, does it paste correctly?

#

cause this really seems like a wrong password error

magic cosmos
#

yes, several times. I've been stuck since yesterday evening and I've repeated the operation several times.

#

I'll have to do some pivoting ? 😦

hallow kiln
#

my notes are very bare on how I solved this section, I did do pivoting though

brazen monolith
#

hi im new at hack the box. I already sign me in and downloaded the starting point data for Open VPN but don't know what to do now. Can anybody help?

tired flax
#

Guys someone did the Module NTLM Relay Attacks?
I'm a bit stuck in the Skill Assessment

hollow thunder
#

Can i get any help with the web attack skill assessment?

rustic sage
rustic sage
zenith gazelle
#

hey guys, i have some questions about the Silver Annual for hack the box academy, with who can i talk to, to get some responses ?

rustic sage
hollow thunder
eager loom
#

Ive been doing linux course on htb but ive been stuck now for a while trying to get vimtutor running. The error i get is: Error detected while processing command line:
E484: Cannot open file /usr/share/nvim/runtime/tutor/tutor.vim

hallow remnant
#

(whoops)

fathom pendant
hollow thunder
#

why are you being rude

hallow remnant
#

¯_(ツ)_/¯

#

Friendly fire!

fathom pendant
hollow thunder
#

rude to dvsii

fathom pendant
#

Oh that's just because he should know better lol

#

It's literally in the rules

#

Unless he was just in here cleaning some other mess up

hallow remnant
eager loom
hallow remnant
fathom pendant
eager loom
#

like ofc i have

#

ive read multiple forums

fathom pendant
fathom pendant
next bronze
eager loom
#

i am using nvim

eager loom
next bronze
#

I meant watching tutorials on using vim, does the same thing as using vim tutor

fathom pendant
#

Run :Tutor from within nvim

eager loom
fathom pendant
#

And that is?

eager loom
#

let me checl

warm drift
#

please help on file inclusions Log poisoning section question 1 i have shell but when I use pwd command it doesn'nt print out any output I have found flag which is question 2 but i can;t answer question 1 which is pwd command

fathom pendant
eager loom
#

okay i think its case sensetive

#

that can be the only thing

#

as its working now and hasnt been all week

#

but im sure ive tried both

fathom pendant
#

Most linux things are case sensitive...

eager loom
#

why u soo mad all time :((

#

im new i know i do stupid stuff sometime but im pretty sure i had tried both

fathom pendant
#

I'm not mad lol just low expectations

fathom pendant
warm drift
fathom pendant
#

And your shell is set up to take commands?

warm drift
#

let me rephrase there's page output of all the logs but there doesn;t seem to be pwd command output

warm drift
fathom pendant
#

Interesting

sly dome
#

probably is lost in all the log junk

#

resend the payload of the header

#

and try again and you will see it much probably

zenith gazelle
#

Hello guys, in the Silver Annual, they say "Exam voucher switching (applies to unused exam vouchers)" what thats means exacly?

And other question is the "Lab exercise guidance via Discord" what looks like, is like a coach, explains the exercise, give you hints ? i would like to know, if anybody here have any reviwes let me know !

sly dome
#

or send the header with some specific string like your name or something and then grep for that in the output

fathom pendant
fathom pendant
zenith gazelle
fathom pendant
#

Yep but you can swap that voucher out any time, provided you don't use it

#

Currently CBBH,CPTS,CDSA are the only certs on the platform

zenith gazelle
fathom pendant
#

You only get the option for guidance after failing the question multiple times

zenith gazelle
zenith gazelle
fathom pendant
#

I guess

#

I dont have silv annual

#

But that's how I understood the guidance to be

zenith gazelle
fathom pendant
warm drift
hallow remnant
surreal rain
hallow remnant
surreal rain
#

no problem. i was afk

hallow remnant
#

The matter appears to have been resolved

fathom pendant
surreal rain
#

.

fathom pendant
#

Thank you prayge

zenith gazelle
#

And does they have this help in the htb app ?

fathom pendant
sly dome
#

this chat >> guidance of annual

twilit jasper
#

What is the answer of the module "Introduction To The Elastic Stack" question 2? What is the hit number?

acoustic owl
twilit jasper
#

I have been trying for a long time

eager loom
#

anyone done the crest preparation on HTB and does it fully cover everything for the security analyst test by crest?

#

ive heard different things

acoustic owl
twilit jasper
#

Ok, if you know the question I am asking, I don't understand it said "execute the KQL query that is mentioned in the "Wildcards and Regular Expressions" part of this section". which KQL query it mentioned? I tried the user name, with *, with 5601, with 0xC00000072, etc.. none of these answer is right

#

to me, the question is not that clear, if you know the answer, please help me

acoustic owl
twilit jasper
#

908

acoustic owl
twilit jasper
#

do you know which query shoud put

acoustic owl
naive wadi
jade raptor
#

ls -h

wanton mica
#

Module: Attacking Common Applications
Section: ColdFusion - Enumeration and Discovery

Question: I can't use my browser to navigate to IP:5500 as detailed in the module. I see the note in the module that says the VM may take up to 90s to load, but it's been way longer than 90s and I still get a timeout message whenever I try to access the target. I can ping the target just fine.

Any guidance?

jade raptor
#

cd sudoers

wanton mica
#

Changed to root…still getting the same result

cedar void
#

Not sure why I am getting this error. I tried the solution chat gpt suggested when I posted my problem , but I cant alter the ssh2john tool apparently.

"Use the cracked password of the user Kira and log in to the host and crack the "id_rsa" SSH key. Then, submit the password for the SSH key as the answer"

wanton mica
#

So sick of these bs unsolvable sections…

sly dome
sly dome
wanton mica
# sly dome git gud

Lol this one is literally unsolvable though…can’t get to <IP>:5500 to save my life

sly dome
#

do you have a shell on the machine?

twin stirrup
#

Can i talk to someone about the broken authentication skills assesment. I will let you kniw how far i am in a dm

wanton mica
#

Nope. Didn’t even know I needed one…tried the first exploit I found in MSFconsole out of curiosity but no dice

sly dome
#

you dont

#

but to check if 5500 is listening

cedar void
sly dome
#

you cant change the code?

#

how is that

#

in pwnbox there is python2

#

python2 ssh2john id_rsa

#

also in pwnbox you can edit the code

cedar void
sly dome
#

then there is apt

#

i remember using python2 on pwnbox

#

install it or edit ssh2john

#

or use your own VM

#

so many solutions for a fairly simple problem

cedar void
#

I can't edited ssh2john and I don't want to download a VM

sly dome
#

you can

fathom pendant
#

Just install python2

sly dome
#

you have sudo rights on pwnbox

#

and you can install stuff

#

and you should install your own VM

#

sed 's/decodestring/decodebytes/' /usr/share/john/ssh2john.py | python - id_rsa

#

with that oneliner you only need read permission

cedar void
#

Oh okay

sly dome
#

try and let me know

#

but remember in pwnbox you are root

cedar void
#

Oh okay you are right. I should have added sudo at the beginning. But I got python2 install so I will use that

fathom pendant
#

It's just better to use python2 tbh because needing to change every 2john to py3 would be a pain

sly dome
#

doable but yea

#

python2 has its place still

wanton mica
cedar void
#

I tried typing locate 'john' to find the john keyword I need in the following quote: "john --wordlist=rockyou.txt ssh.hash" . ? and I also tried to go directly to the directory to loo for. No luck

drifting thorn
#

Hi everyone, I'm confuse with something in the binary explotation module. I'm writing my own shellcode but doesnt work.
this is my code :
global _start

section .text
_start:
mov al, 59 ; execve syscall number
push 0
mov rdi,'cat'
push rdi
mov rdi, rsp ; the pointer to the command cat
push 0
mov rsi, 'file.txt'
push rsi
mov rsi,rsp ; the pointer to the filename file.txt

mov rdx,0
syscall

mov rax, 60
mov rdi, 0
  syscall
sly dome
wanton mica
sly dome
#

any time

cedar void
sly dome
#

ssh2john parses the private key and extract from there a hash

#

once you have it

#

run john

#

john is not a python ASCII file

#

its a PE executable

#

iirc it’s written in C

cedar void
#

nevermind. I think I found it. in the bin folder I believe

sly dome
#

you can run it from anywhere

#

the route in the path

#

john —wordlist=path/to/wordlist hash

cedar void
#

I tried using just john and it said no command found

sly dome
#

you didnt

#

you used python2 john

#

and it is not finding any john.py xd

cedar void
#

oh I forgot word list

cedar void
sly dome
#

which section

#

password attacks probably mutated list

wanton mica
#

Yep, it’s official….this is an L on HTB Academy

cedar void
#

I tried mutated list, rockyou list , adding the flags list...nothing seems to be working for me

cedar void
#

when its not in the module

fathom pendant
#

It'll be in mutated list

#

And John is talked about in the module

#

Literally the section you linked talks about it

wanton mica
cedar void
#

I see john in the module ...but it doesn't say what to do when john isn't work as expected

fathom pendant
#

python2 [filetype]2john > [filetype].hash
john --wordlist=/path/to/list [filename].hash

hazy grotto
#

Anyone have any tips on how to make copy and pasting in tmux easier?
I've added the mouse option but when i hold shift and move to the mouse up to select more. Its stops at the top of the pane and wont go any higher