#modules

1 messages · Page 157 of 1

rustic sage
#

how was everybody thankgiving. i know it's over, not even ask

#

I am looking for new friends to help me learn in the htb community!

#

if you wanna be my friend or have any questions send me a DM

vital adder
fossil crescent
#

if still stuck, feel free to DM

clear hatch
#

mimikatz x64 keeps spitting ERROR kuhl_m_sekurlsa_acquireLSA ; Key import at me and ive already changed releases twice. not sure what im doing wrong, can anyone help?

i was able to create my golden ticket via:
./mimikatz.exe privilege::debug "kerberos::golden /User:Administrator /domain:inlanefreight.local /sid:S-1-5-21-3842939050-<REDACTED-<REDACTED> /krbtgt:<REDACTED> /groups:500,501,513,512,520,518,519 /ticket:inlanefreight.local.kirbi" exit

but the error happens when I:
./mimikatz.exe "kerberos::ptt inlanefreight.local.kirbi" exit

clear hatch
#

@proud pine My direct question: Why doesnt this work?

proud pine
fathom pendant
clear hatch
fathom pendant
#

👍

clear hatch
#

honestly he couldve answered it. it seems most of you dont want to see other succeed. It's really sad to see it happening actually. its not just me. ive seen hundreds of people get discouraged by you and a few others here. It's not funny and honestly if you're not here to teach people something then why are you here? just to troll? get a life.

fathom pendant
#

It's about common netiquette

clear hatch
#

ah the "unspoken rules"

fathom pendant
#

And I have helped people in the past

clear hatch
#

you help who you want and you know it. im aware its not your job, but neither is being a mod here. i se 0 mod badge...

fathom pendant
#

People get discouraged by their lack of determination to work for the answer

clear hatch
#

ive seen you brush people off before you've even understood their question

fathom pendant
#

We tend to link to sources that worked for us

clear hatch
#

ive then helped those people

fathom pendant
#

If it doesn't work for them, then I guess it's a slightly different issue

clear hatch
#

they seeem to understand when you dont explain to them like they're stupid

#

calling people stupid actively in chat is NOT common nettiquette

#

ive SEEN you do it

fathom pendant
#

Congrats on helping people though

clear hatch
#

bye. have a good nighjt

fathom pendant
#

And those people are generally ones that have a specific history of certain questions

clear hatch
#

again, half the time, you dont understand their question

#

i think maybe you need to look inward friend

fathom pendant
#

Usually due to poor phrasing

#

But go off king

#

You're really showing me

clear hatch
#

this right here is my point exactly

#

that person was DONE with the lesson

#

their question was unrelated

#

YOU didnt understand

#

honestly i need not continue

fathom pendant
#

Or ORRR they seemed to still be stuck on that issue

clear hatch
#

hahahahah nope

fathom pendant
#

¯_(ツ)_/¯

clear hatch
#

you just refuse to listen. ¯_(ツ)_/¯

fathom pendant
#

Btw the mimikatz error might be a version issue

#

I've also seen other mentions of people having little to no issues with the x32 version

#

You assume I wasn't still gonna look into the issue you posted about

#

Because we're having this little difference of opinion

#

And you seem quite bothered by it

#

I make generalized assumptions based on a displayed pattern of behavior. Because I mostly can't be asked to have all fixes that have been posted already in this channel

clear hatch
fathom pendant
#

Difference of opinion

#

:) have a good night

#

Like I said, I found a potential fix for your Kuhl error in mimikatz.

#

If it works, nice, if not well shit

proud pine
fathom pendant
#

Also feel free to call me an idiot when I stumble through something here, I welcome it

clear hatch
proud pine
clear hatch
#

its part of the cpts path

fathom pendant
#

If rat was interested in helping you he'd tell you to dm

clear hatch
proud pine
clear hatch
#

i dont DM randoms

thorn urchin
#

Marcie and rat are both some of the most prolific helpers here

#

but doesnt mean youre entitled to their help

fathom pendant
#

Then there's the Goat of helping PayloadBunny

#

Truly an inspiration

thorn urchin
#

PayloadBunny has the patience of a saint

fathom pendant
#

Truly

clear hatch
#

yall need to hop off the high horses

thorn urchin
#

What high horse

fathom pendant
#

I was specifically replying to your @ to only apply to specifically doing that thing, not your question

thorn urchin
#

You need to stop crying about getting corrected

proud pine
clear hatch
thorn urchin
#

oh no someone told me which channel to ask my question in to get an answer boo hoo

clear hatch
#

bruh thats not even the issue

fathom pendant
#

Like I'm sitting here, unbothered by your criticism

clear hatch
#

again. people here dont want to see others succeed, they'd rather just waste their time

fathom pendant
#

I help people who ask good questions or provide enough context to assist them

thorn urchin
#

Marcie has indirectly helped like a quarter of people pass the exam by helping them with modules lmao

fathom pendant
#

And sometimes it's easier to tell someone "hey it's specifically this section/subsection"

proud pine
#

I was in the first 20 to pass, and Marcie helped ME when I was going through the course lol

fathom pendant
#

Because the course content is better than my dumbass

thorn urchin
#

Before I passed marcie and rat were some of the biggest people that cheered me on and believed in me. So not wanting to see people succeed is wrong

fathom pendant
#

Honestly though just focusing on my uni stuff for right now

#

Should have done this shit Monday

#

And been Ballin the rest of this week

#

I've also indirectly helped on modules that I have fully admitted that I haven't done or looked at

#

Just by being like "are you sure it's not c, b, a instead of a, b, c

#

¯_(ツ)_/¯

#

Though I will say with my full chest, they need to include a better command in the imap section of common services

#

People hit the Nil wall when they use the fetch command given in that module

#

I think it was one of my first Erratum posts

ornate olive
#

I may be missing a piece of information or a lack of understanding about how nmap works, but I am getting an error I do not understand. I keep getting the “failed to resolve” error when I attempt to scan a target

fathom pendant
ornate olive
#

Nmap -sV -sC -p- 94.237.48.48:46167

fathom pendant
#

I see your issue

#

Ports are defined in Nmap with -p

#

But also, Nmap won't get you too far with that question

#

You'll need to enumerate in a different way

ornate olive
#

Hmm ok thank you

rustic sage
#

Help with task 10

title Appointment

If user input is not handled carefully, it could be interpreted as a comment. Use a comment to login as admin without knowing the password. What is the first word on the webpage returned?

rustic sage
#

yes

fathom pendant
#

Then ask there

#

This channel is for Academy modules

#

Also @ornate olive that's a public_ip:port if that will help you move forward. Also it helps to say what Module and Section you're working on

ornate olive
#

Ahh I see, still learning the basics so it seems that was a fundamental issue in what I thought I knew about ips which is good to know moving forward 😆 . I’m working on Getting Started, Public Exploits.

fathom pendant
#

If you do Nmap you do ip -p port it'll probably give you a nudge, but generally speaking (unless told otherwise) public_ip:port it's gonna be a webpage

#

Http

fathom pendant
#

But you're not gonna run into public IPs too often

ornate olive
#

so from running a scan to see what services were running on the ip i got this

#

PORT STATE SERVICE VERSION
46167/tcp open http Apache httpd 2.4.41 ((Ubuntu))
|_http-server-header: Apache/2.4.41 (Ubuntu)
|_http-title: Getting Started – Just another WordPress site
|_http-generator: WordPress 5.6.1

#

what information from this do i need to use to find an exploit, i feel like im missing a connection in my brain here

fathom pendant
#

What service is running, maybe you can navigate it via a browser

ornate olive
#

wordpress?

#

i think im missing something here

fathom pendant
#

Http

ornate olive
#

yeah its running http so how do i use that information?

fathom pendant
#

...

#

How do you access hackthebox

#

I'll give it a few moments to click

ornate olive
#

i get that part, ive had it open the whole time

fathom pendant
#

Yes but think, functionally, how do you get there

ornate olive
#

a url

fathom pendant
#

Mhm

#

And a url is simply a redirect to a public ip that's registered on public domain servers

#

In this case, the ip isn't registered so, how do you think you'd get there - knowing it uses http on a non-standard port

#

Http by default uses port 80

#

I'd suggest doing the information security Fundamentals path after this module

ornate olive
#

i definetly think there is gaps in my knowlege

fathom pendant
#

Did you figure it out?

ornate olive
#

im confused as to what you are asking

fathom pendant
#

So it uses http and you know the ip and port the http service is hosted on

ornate olive
#

enter the ip:port into the address bar?

fathom pendant
#

Yep, you may have to change browser settings, some browsers try and force https, which isn't running

#

But that's if putting it in the address bar doesn't work

ornate olive
#

i did that like 20 minutes ago i just didnt know thats what you were asking sadglas

fathom pendant
#

I'm taking the approach that you don't know what you're doing

#

That webpage contains all the answers to move forward and follow the section with msfconsole

clear hatch
#

golden ticket achieved.

acoustic owl
#

I did not have the problem with the ping, but my answer was not accepted

Were you able to solve it?

solar cradle
#

Hey everyone. I'm on the ACL Abuse tactics subsection of the Active Directory Enumeration and attacks module.
When setting a fake spn for the adunn user I keep getting a "constraint violation".
Been a few days and I can't figure this out. Anyone seen this before?

fathom pendant
#

Source: I asked google

#

So are you sure you're formatting the command correctly

rustic sage
fathom pendant
rustic sage
#

so I am doing linux fundamentals

fathom pendant
#

And?

rustic sage
#

and whenever I do uname -a

#

its asking me for what machine

#

what I paste

#

I dont know what to paste in

fathom pendant
#

There's probably a target machine for you to ssh into, first off, second do man uname and it will tell you what info is where

rustic sage
#

ok

#

I did it

fathom pendant
#

Or even which flag that will only give you what's asked for

#

man <command> brings up the 'man'ual page for a command that provides tons of info

rustic sage
#

Find out the machine hardware name and submit it as the answer.

rustic sage
#

I know what the name gives

#

I just dont know what it is asking me

#

like I know it is Linux

#

distribution Ubuntu

clear hatch
#

it's probably asking for uname -n ?

fathom pendant
#

It's actually asking uname -i

rustic sage
#

I already know the linux distribution

#

I am just doing it to raise my rank

fathom pendant
#

-n is network nodename aka what it looks like in the network

fathom pendant
#

Academy content progress isn't reflected on main htb site

clear hatch
rustic sage
fathom pendant
rustic sage
clear hatch
#

try l

fathom pendant
rustic sage
#

I am looking for dirs

#

What is the path to htb-student's home directory?

rustic sage
fathom pendant
#

Read the commands at the top of the page

#

If you do just cd or cd ~ you're dropped into the user's home

rustic sage
#

I did that got into the users home

#

now it asking me " What is the path to the htb-student's mail?"

fathom pendant
#

I believe you can use env for that

rustic sage
fresh compass
#

Hi, anybody who can help me in the Windows Privilege Escalation Skills Assessment - Part II privesc? I tried to exploit the kernel vulnerability but when I tried to start the service it throw an error NVM, it worked changing the payload

manic wolf
#

Been having a problem with all modules that require me to use RDP, the FreeRDP window opens, but it's just a black screen

#

"Loading Dynamic Virtual Channel rdpgfx"

fresh compass
#

hit enter

manic wolf
#

...

#

That worked

fresh compass
#

hahaha

manic wolf
#

But why? never had this happen before

fresh compass
#

I dont know why but sometimes a blank screen appears but the desktop environment is there

#

if you hit some key it loads properly

manic wolf
#

Well thanks for the help! Lol

fresh compass
#

No problem 🙂

fathom pendant
#

Screensaver claims another hacker

hazy grotto
#

Hey Marcie I need your help

#

@fathom pendant have you done windows priv esc?

fathom pendant
#

Nop

#

Taking some personal time to get some shit done

fresh compass
hazy grotto
#

Can i DM?

fresh compass
#

sure

slate creek
fathom pendant
slate creek
fathom pendant
#

Iirc I think it's actually that domain disclaimer that for whatever reason isn't showing

fresh compass
#

I didnt thought that it could be the screensaver

#

but when it happened to me I was really confused

upper wasp
#

Hi everyone
What is the best way to do CBBH and CPTS ? Annual subscription or 2-3 months of premium subscription and unluck the materials with cubes.

fathom pendant
upper wasp
fathom pendant
#

All modules have a skill assessment at the end, and most sections in modules have labs that reinforce what was just taught

slate creek
upper wasp
#

I assume lab access is unlocked with materials, but 3 months plat + exam voucher is equal to annual subscription. After 1 year you lose access to materials?

tranquil axle
#

everything you unlock with cubes you keep for life

fathom pendant
fathom pendant
#

Tier 0 is 10 back

woven summit
#

the police cant help with that
Roblox support will help

fathom pendant
woven summit
fathom pendant
#

Then the point is moot about correcting him now lol

#

Also there was a suggestion to contact roblox support after it was clarified

woven summit
#

Ok

fathom pendant
#

Reading is hard for hackers, it's a real problem Sadge

woven summit
#

Wdym

#

Is that aimed at me also I'm not even a hacker not that im wanting to learn it

fathom pendant
#

Literally not even a handful of messages down from the one you replied to was the suggestion (by the same person) to contact roblox support

fathom pendant
woven summit
fathom pendant
#

Cool, then bye

#

This isn't a gen chat either

woven summit
#

Where is the gen chat

fathom pendant
#

You need to link your main htb account to discord to access it

#

#welcome <- instructions conveniently here

woven summit
#

I don't have htb

fathom pendant
#

It's free to sign up

#

¯_(ツ)_/¯

woven summit
#

I'm wanting a loud ecoboost

fathom pendant
#

And I don't care lol

#

This channel is for discussion and assistance with the htb academy modules

woven summit
#

K

acoustic owl
fathom pendant
acoustic owl
#

Yes

modern epoch
#

Just completed the module NTLM RELAY ATTACKS and it's awesome!

All the contents were well crafted and explained. The final assessment will really test how well you absorbed the contents. It's great!

Congratulations guys for your dedication!

fathom pendant
acoustic owl
#

Congrats 🎉

fathom pendant
#

0.00% gang

rustic sage
#

Can someone help me with the module using crackmapexec? I'm stuck in the Skill Assessment section on the first question, I found the username list with --rid-brute from dc01 but I can't find any common password. Should I use some wordlists?

fathom pendant
#

Yeah probably

#

Start small and if all else fails break out rockyou

upper wasp
#

Both options seems good.. Annual or plat for cube unlocks

pine dune
#

Hi, I am having trouble spawning the machine for my tutorial

#

can someone pls help?

acoustic owl
quartz swan
#

Footprinting - Hard as part of CPTS Training

Questions:
||Completed this module, but I have some doubts after looking at some responses here.

  1. How would I know if my private ID_RSA key can be used for the root user? I would have thought that the key belongs to Tom only, and hence I would have thought I could only SSH with the private key with Tom only. Turns out it works for the 'root' user too?

  2. I had a lot of problem with regards to the last part. I know there is a MySQL service, but I couldn't Nmap any open MySQL ports. I even tried to start the service within SSH, but obviously that won't work. Why does running mysql in SSH works though? Can anyone give me a ELI5? Not sure why that is possible.||

Thank you!

digital junco
#

hello guys

#

<div class="field">
<label for="passwordInput" class="label">Senha</label>
<div class="control has-icons-left">
<input type="password" name="password" id="passwordInput" class="input" required placeholder="********">
<span class="icon is-small is-left">
<i class="fa fa-lock"></i>
</span>
</div>
</div>
<div class="field">
<label for="rememberBox" class="checkbox">
<input type="checkbox" name="remember" id="rememberBox"> Lembrar
</label>
</div>

        <div class="field has-text-centered">
            <div class="columns">
                <div class="column is-half">
                    <button class="button is-info is-fullwidth" id="loginButton">Entrar</button>
                </div>
                <div class="column is-half">
                    <button class="button is-fullwidth" disabled>Cadastro</button>
                </div>
            </div>
        </div>
    </form>
#

how can a change the <button class="button is-fullwidth" disabled>Cadastro</button> to allow create a new user?

muted root
reef isle
#

Anyone else here a beginner?

#

I’m a beginner and want to get started into hacking any tips

green blaze
#

do the intro to infosec academy path then go starting point then do boxes

#

and try not to overcomplicate it for yourself the more you just do stuff and try not to worry about how good or bad you are and what you should do next the better

fathom pendant
short hare
#

Stuck at AD Enumeration & Attacks - Skills Assessment Part I

Question:
Kerberoast an account with the SPN MSSQLSvc/SQL01.inlanefreight.local:1433 and submit the account name as your answer

I really can't find a clue to proceed further. Only accessed the webshell.
I don't know from where to get the username and password to rdp to the machine..!

Can anyone help to get started with????

woven summit
low roost
ionic summit
hardy meadow
#

Hello everyone! I am working on the AD enum and attack and I'm at the skills assessment 2. I'm running into issues finding the Admin hash. I've come across two from running mimikatz, dumping the sam and lsass but haven't found anything that'll get me onto MS01 as admin. Also if anyone would want to chat about how they identified the SeImpersonate issue I'd love to hear it, I found it by just trying everyting.

wet kite
#

The bruteforce module is kinda slow...
[STATUS] 76.16 tries/min, 2361 tries in 00:31h, 604791 to do in 132:21h, 4 active

Any way to speed this up?

hardy meadow
#

I think you can go up to 64. Try -t 64

low roost
#

i think <? is in the blacklist filter

next bronze
wet kite
plain coral
# quartz swan **Footprinting - Hard as part of CPTS Training** Questions: ||Completed this mo...

Regarding the use of an ID_RSA private key for the root user, it’s possible that the private key you have is indeed authorized for the root user as well, SSH keys are configured in the ~/.ssh/authorized_keys file of the user that you’re logging into. If Tom’s private key is listed in the root user’s authorized_keys file, then it will allow access. This can happen if Tom has been given root privileges, It’s all a part of trial and error, you’ll never know if you don’t try it..

plain coral
plain coral
fringe tiger
#

Hey y'all.
Is anyone else having trouble connecting to boxes they spawn up via ssh? It just consistently times out for me

plain coral
wet kite
plain coral
wet kite
#

ok, i'm just running Nmap real quick to see if a FTP port is open.

plain coral
hardy meadow
# plain coral Haven’t done that part yet but does `sekurlsa::logonPasswords /full` in Mimikatz...

Thanks for the reply! I just tried it and it didn't output the domain admin, just the mssqlsvc clear text. I'm running mimikatz on SQL01 under SYSTEM, and I think I'm doing something wrong because it seems like that is working for most and I'm stumped.

The only way I've been able to see the domain admin account is by pulling the sam, system, and security hive and running pypykatz, but that's just the mscached version and won't work.

hardy meadow
short hare
#

Hey @hardy meadow
Can you help me with AD Enumeration and Attacks Skills Part 1?

hardy meadow
zinc dove
#

Hi everyone! Can someone who has worked on "Analyzing Evil With Sysmon & Event Logs" module help me? So, on Detection Example 1, I'm having difficulties trying to hijack Windows Calculator using reflective DLL. I placed both files to a writable directory (under Desktop), but I did not get the "hellow from DllMain!" message. Instead, the Calculator started running. Am I supposed to use a tool to gain access to any of the file's config script to execute it?

rustic sage
#

Hey, What is this server for?

upper ruin
#

Greetings good people of HTB, I got a small question.
I am on module Shells and Payloads -> Laudanum section
I answered the first question.

Where is the Laudanum aspx web shell located on Pwnbox? Submit the full path. (Format: /path/to/laudanum/aspx)

Kinda stuck at this one. The operating system is windows, I am using kali to do the whole task.
I don't understant the question. Is there a specific aspx web shell that I have to search on my kali to be able to answer the question, or do I have to dig deeper into the stuff?

verbal dagger
#

Lol, I'm on the sql injection and accidentally found a flag meant for later in the course

upper ruin
#

ez

upper ruin
#

Be it, modules, certificates, or generally anything in the vast field of cyber security.

#

Everything here's ethical and done via lab environment.

short hare
#

Stuck at AD Enumeration & Attacks - Skills Assessment Part I

Question:
Kerberoast an account with the SPN MSSQLSvc/SQL01.inlanefreight.local:1433 and submit the account name as your answer

I really can't find a clue to proceed further. Only accessed the webshell.
I don't know from where to get the username and password to rdp to the machine..!

Can anyone help to get started with????

hardy meadow
short hare
hardy meadow
# short hare Sure

You were able to get the flag for the Admin right? Did you already set up a reverse shell to your attack host?

short hare
short hare
next bronze
short hare
next bronze
#

and what is the user for that webshell?

short hare
wheat scroll
#

Hello, I am following the XSS module

#

And I am in Phishing section

#

And when I put sudo php -S … in bash it doesn’t work

next bronze
wheat scroll
#

When I login I don’t receive the password in bash

#

And when I want to see creds.txt they said me that It doesn’t exists

#

Help me pls

short hare
next bronze
short hare
next bronze
#

you have system, you can do whatever you want on that

short hare
tight mesa
#

anyone might have an idea why RDP is not working in Pwn3d Enum & Attack AD Lab II?

thorn urchin
#

You dont have a GUI enabled

#

you cant use rdp headless

tight mesa
#

on the contrary, enable it beforehand

#

I ran this two commands beforehand :

Set-ItemProperty -Path 'HKLM:\System\CurrentControlSet\Control\Terminal Server' -name "fDenyTSConnections" -value 0

reg add HKLM\System\CurrentControlSet\Control\Lsa /t REG_DWORD /v DisableRestrictedAdmin /d 0x0 /f

#

in a pivot machine

strong bear
#

Hi, PW attacks module

foggy sail
#

Hi all,
Has anyone completed the last task of the "INTRODUCTION TO WEB APPLICATIONS" module - Next Step? Where you have to create your own simple web app (static web page + API + back end) and then test it for vulnerabilities and fix it!
I created a web app, but when trying to test/hack it, nothing (the methods posted during the module) works.
Could someone tell me why? Or tell me what testing methods are applicable for my web app?
Here is the link for my web app - https://github.com/Utmins/WebApp_PHP.git

storm hedge
#

Hello, I'm doing the dns lab for the common web services

#

I wasn't unable to find the dns flag through DNS requests

#

I found another way but I want to check

acoustic owl
raven gorge
#

Just finished AD enumeration and attacks and I loved it, I did actually learn a lot from this one, so much juice in here that I think that I'll stick to the subject for a while.

storm hedge
#

@acoustic owl I used dig to get the flag but I don't get any anwser for the flag record ( I don't want to spoil here)

#

I didn't work either with the automated tools

acoustic owl
#

You need to provide some information so that I can help you.
Was there an error message?
Which domain did you query?

solar cradle
upper ruin
#

Establish a web shell with the target using the concepts covered in this section. Submit the name of the user on the target that the commands are being issued as. In order to get the correct answer you must navigate to the web shell you upload using the vHost name. (Format: **, 1 space)
Shells/Payloads module.

Guys I am damn slow.
(Format: **, 1 space)

I found the answer
||iis apppool\defaultapppool||
But I have no idea how to fix it..
What is the answer supposed to be?

upper ruin
#

Will do , 1 sec.

#

Nope.

#

I thought of removing the same letters, so it comes down to ||is\apol||

arctic junco
fathom pendant
#

What section?

upper ruin
#

Antak Webshell.

upper ruin
#

Well, I am stupid.

fathom pendant
upper ruin
#

Yup.

#

Want screenshots in DMs?

fathom pendant
#

Just show a screenshot of the address bar here

upper ruin
#

Address bar?

fathom pendant
#

Url

#

The thing you're putting your webshell in

upper ruin
#

Yeah, just waiting for my gyazo to load.

fathom pendant
#

Don't need gyazo

storm hedge
#

@acoustic owl can i pm you?

fathom pendant
#

That's weird having IP/domain but whatever it works

upper ruin
#

||result ||

#

I doubt it's credential related.

#

Unless it has SPECIFICALLY to be <htb-student> user and pass.

fathom pendant
#

Did you add status.inlanefreight.local to your /etc/hosts

upper ruin
#

Uh..no?

fathom pendant
#

Then it's likely you're not on the actual correct upload page

#

So it's causing issues

upper ruin
#

How do I add it to /etc/hosts

fathom pendant
#

...

upper ruin
#

It was a joke.

#

No worries, let me re-do it.

fathom pendant
#

Please don't give me an aneurysm

upper ruin
#

Like that?

spring viper
#

it goes ip then hostname

#

if you see the pattern with 127.0.0.1 \t localhost can repeat it

upper ruin
#

Well, that's new. Lemme do that

spring viper
#

ip is probably not 127.0.0.1

upper ruin
#

Oop, yeyeyeye

spring viper
#

unless you are doing a port forward or something

#

which maybe you are I didnt look far enough up in the chat

upper ruin
#

Can I do 127.0.1.2

upper ruin
spring viper
#

the IP should be the box you spawned likely

#

the 10.129.x.x one

upper ruin
#

So I have to change it every time I spawn a new box?

#

In the /etc/hosts?

spring viper
#

ya

upper ruin
#

Yessirr.

#

Alright, lemme re-do it.

#

Thx g.

spring viper
#

sure thing hacktheflag

acoustic owl
upper ruin
#

But it gave the same answer as before.

spring viper
#

can you screenshot ._.

upper ruin
#

Yessir.

#

What would you like to see.

spring viper
#

what the issue you are having is

upper ruin
#

So this is the result:

#

Establish a web shell with the target using the concepts covered in this section. Submit the name of the user on the target that the commands are being issued as. In order to get the correct answer you must navigate to the web shell you upload using the vHost name. "(Format: **, 1 space) "
Shells/Payloads module.

Guys I am damn slow.
(Format: , 1 space)

I found the answer
||iis apppool\defaultapppool ||
But I have no idea how to fix it..
What is the answer supposed to be?

#

That's the task.

#

I will delete it afterwards as it contains the answer.

next bronze
#

what's there to fix? you got the answer, no?

upper ruin
#

It doesn't work.

#

And whenever I post the format here in dizzy, these little * fix themselves.

next bronze
#

what does't work

upper ruin
#

||iis apppool\defaultapppool||

#

That's the result from whoami.

next bronze
#

yea? that's the answer

upper ruin
#

Well, when input it doesn't work.

next bronze
#

did you format it according to the question?

upper ruin
#

I tried a lot of stuff. I just don't get how to format it.

next bronze
spring viper
#

and this question is in the antak webshell section?

upper ruin
#

I didn't have it in /etc/hosts before, same result regardless.

#

Yup.

spring viper
#

I dont think apppool is the right answer to that ._.

#

or at least its not what I have

upper ruin
#

I hope.

lucid fjord
#

i need 200 person

upper ruin
fathom pendant
upper ruin
#

Did it already.

spring viper
#

It could be that they have a different account run different instances idk

#

I just have a different answer in my notes for that

upper ruin
#

Wait.

fathom pendant
#

Instead of just status.inlanefreight.local

upper ruin
fathom pendant
spring viper
#

that etc hosts is right

#

are you sure you are looking at the right host

#

like that ip is what spawned when you started the assignment

upper ruin
#

Yep.

fathom pendant
upper ruin
#

I extended the time.

fathom pendant
next bronze
#

once you added the vhost, go to that vhost and upload the shell, it's simple as that

fathom pendant
#

^

upper ruin
#

???

#

It gave a diff answer.

fathom pendant
#

Yes

#

Yes

#

Delete that as its a spoiler

upper ruin
#

It worked :D

#

Thank You guysss <3

fathom pendant
#

At least you learned what vhosts are now

upper ruin
#

I just don't get how there's difference between <ip> status--and just the status--

fathom pendant
#

Because they aren't the same

#

At all

#

Because that's not how vhosts work

upper ruin
#

I know what I will be reading this night.

#

Want me to delete the wrong answer , that's a bit above in the convo?

fathom pendant
#

Ip redirects to the default web location, however when you add it to /etc/hosts with the right subdomain/vhost it tells the web service to direct you to that set of files

upper ruin
#

I see now.

crystal steeple
#

i'm on footpriting module, just finished the cloud section , and im really amazed by how a single mistake can lead to a company falldown

upper ruin
#

Well...yeah.

crystal steeple
#

the amazon ssh keys leaks are crazy

fathom pendant
upper ruin
crystal steeple
fathom pendant
#

One dumb user/one misconfig

upper ruin
#

The hard lab would seem easier than the medium.

fathom pendant
#

Humans aren't bright

crystal steeple
upper ruin
#

That's why they r humans.

crystal steeple
#

lol

upper ruin
#

I got it all documented.

#

Won't spoonfeed.

#

But I would give you advice.

#

That's what I enjoyed most, the medium lab.

#

Like...of all HTB as of now.

crystal steeple
#

alright man ! i will definitely hit you up if i need some assistance about the labs !

crystal steeple
#

HTB Academy is so well structured

upper ruin
#

It iss.

crystal steeple
#

and i also love how they teach stuff with tons of examples

upper ruin
#

Mhm.

#

It's detailed as hell and I love it.

crystal steeple
#

makes studying fun lmao

upper ruin
#

My parents r yelling at me for not sleeping while doing HTB X_X.

fathom pendant
upper ruin
#

I would take that any day for 12 hours rather than regular university.

upper ruin
fathom pendant
crystal steeple
#

i'm also a student and i only do HTB and some alternatives, the uni courses are shit

upper ruin
#

Lol, someone tried to invite.

#

I study info systems and programming.

foggy sail
crystal steeple
#

im on my first year uni , we aren't even studying shit about cybersecurity lol

upper ruin
upper ruin
#

And I can't do a lot.

crystal steeple
upper ruin
#

For some reason the rConfig has default admin:admin credentials.

upper ruin
crystal steeple
upper ruin
#

Will do, kind people.

fathom pendant
#

Also getting rest is important

#

It helps your brain retain information

upper ruin
#

I am excited for the 10 days of fun.

#

I hope it doesn't melt in the meantime.

crystal steeple
fathom pendant
#

If you go into it exhausted to all hell or don't pace yourself you will fail

upper ruin
#

True.

fathom pendant
#

Just being blunt

upper ruin
#

I got an exam tomorrow, I am actually going to sleep. Leaving the php web shells and live engagement for tomorrow.

fathom pendant
#

Tired = mistakes, mistakes = frustration, frustration = stagnation, stagnation = failure

upper ruin
#

"Tired = mistakes, mistakes = frustration, frustration = stagnation, stagnation = failure "- Marcie 2023

#

Anyways, gn lads. It was fun talking.

#

I will be back soon.

fathom pendant
#

I always step away when I start getting frustrated or start making too many mistakes

crystal steeple
#

also ,don't forget to stay hydrated lol

upper ruin
#

🌵

crystal steeple
supple gorge
#

UNDERSTANDING LOG SOURCES & INVESTIGATING WITH SPLUNK- Introduction To Splunk & SPL (first module), 3rd question:

Navigate to http://[Target IP]:8000, open the "Search & Reporting" application, and find through an SPL search against all 4624 events the account name that made the most login attempts within a span of 10 minutes. Enter it as your answer.

How is the answer the actual answer? I used bucket... looking at the hint, I have no clue how they expect us to use range(). What I'm saying is, my search yielde din diffeent accounts with a higher count within a 10m span than the answer account

#

Is this the right channel to ask? or should I go to cdsa?

hardy meadow
acoustic owl
acoustic owl
supple gorge
supple gorge
#

how would range be used in splunk? are the parenthesis included?

hardy meadow
supple gorge
acoustic owl
median vine
#

👀

supple gorge
reef drift
#

hey there, i'm just finished this module

supple gorge
#

Using Splunk Applications : Access the Sysmon App for Splunk and go to the "Reports" tab. Fix the search associated with the "Net - net view" report and provide the complete executed command as your answer. Answer format: net view /Domain:_.local.

What Sysmon App? I don't see it

rustic sage
#

Has anyone taken the Secure Coding 101: Javascript module? I'm interested in going deeper into JS security for my web security studies.

fossil crescent
#

Anyone do the Skills Assessment (1 or 2) on Intro to Whitebox Pentesting? Stuck on both. On SA1, have authentication, but cannot for the life of me figure out how to get code execution... (seems simple enough, but again, just not getting it). On SA2, went thru the sanitization/validation, and now it says "code injection should not be possible, even without sanitization or validation".... but at a loss on to do (excl the sanitization/validation). Please feel free to DM. Thx.

EDIT: Still lost on part-1, but broke-down and used a code analyzer on part-2 and while not (yet) solved, identified a clear problem.

obsidian hound
#

Try running a sub-domain fuzzing test on 'inlanefreight.com' to find a customer sub-domain portal. What is the full domain of it?

#

not work

iron hazel
#

Hi I just finished the Command Injection Skill Assesment Module. However I notice commands like base64 -d <<<sinebase64str and ${PATH:0:1} doesn't work on that server even on a php shell <?php system($_GET["cmd"]); ?> am I mssing something. Is it related how the server is configured? is it possible to disable things like ${PATH:0:1} and <<< from a linux level?

quartz swan
quartz swan
obsidian hound
rustic sage
fossil crescent
# rustic sage Hey dude, saw you did Secure Coding 101: JS a while back, any feedback on the mo...

Considering I had effectively 0 JS experience but was able to fumble my way thru it... I think it provided everything needed to succeed. Gotta pay, really, Really, REALLY close attention to what you're doing -- very easy to mess up and be at a loss as to why. Very satisfying to complete. And with that, I'll re-review that module in looking for what I'm missing on the second part of the intro to whitebox SA, thx.

rustic sage
#

Cheers!

next bronze
obsidian hound
#

according to the guide it is that way

#

what finds me is the following

#

www support my blog

rustic sage
next bronze
#

oh they changed the question from when I did it

next bronze
obsidian hound
weary torrent
#

hi guys i did intro to threat hunting with elastic's skill assesment.I have a question regarding task 3 which requires to Create a KQL query to hunt for "PowerShell Remoting for Lateral Movement". Enter the content of the winlog.user.name field in the document that is related to PowerShell remoting-based lateral movement towards DC1.) I was able to find the answer using hints given . However I am curious how I can validate 100% the command I have found was targeting DC1 since when I filter for destination.address I get 0 results

short hare
#

Still stuck on ACTIVE DIRECTORY ENUMERATION & ATTACKS: AD Enumeration & Attacks - Skills Assessment Part I

I am trying to transfer mimikatz.exe from pwnbox to that webshell given as default in the section
After running the command the above command why there is no mimikatz.exe in the directory I am transferring?

Stuck for more then a day..!!! Seriously NotLikeThis
Please help

next bronze
#

does the target even have scp installed? and doesn't antak have a file upload function? why take the extra steps

#

and are you still trying to kerberoast

short hare
#

let me show you

#

Is there a glitch or something
After this when i check /uploads no mimikatz.exe

next bronze
#

wat

#

I'm talking about the antak webshell, not the upload page

short hare
rustic sage
#

Hey guys I didn't really know where to go for this question but I'm having this issue where my VM isn't naturally routing to HackTheBox using OpenVPN. Default route is still the public ip and I have to specify the interface the vpn uses in order to get commands like ping to work....

short hare
#

sorry @next bronze for making a mess up

next bronze
#

got it?

#

and what's the point of using mimikatz there?

proven pasture
#

Hello, folks. I hope that this is the right place to ask this. I have been working on the Intro to Assembly, and I have been stuck on Conditional Branching for hours. I am not even sure what it is asking. I have tried everything that I could think of and read on the page. I am just stuck, and I was hoping someone could please point me in the right direction so that I can get the correct HEX.

rustic sage
# proven pasture Hello, there. I have not seen that happen before. Are you using Window's as your...

I'm using Kali Linux as the host. I am also using sudo when running openvpn. The site detects that I am connected and it is technically confirmed that I am connected when I execute a command like ping -c 5 -I tun1 [Ipaddress]. Pinging the target machine with the VPNs interface. That will work but it isn't viable once I get to commands like telnet as there is no way to specify the interface in that command, leading to a deadend with the lab...

next bronze
#
cmp rax, 10
jnz loop

first line compares rax to 10, if rax is 10, the zero flag will be set, the second line will jump if the zero flag is not set

supple gorge
proven pasture
next bronze
proven pasture
next bronze
#

did you put in the hex value?

proven pasture
next bronze
#

the answer should be the value of mov rax, 5 after modifying to break the loop, not the final value

proven pasture
supple gorge
proven pasture
next bronze
#

it's 3 characters, not sure where you got 4 from

short hare
# next bronze got it?

I went through the bad way, I realised now

What i was planning to do was this

Add-Type -AssemblyName System.IdentityModel
New-Object System.IdentityModel.Tokens.KerberosRequestorSecurityToken -ArgumentList "MSSQLSvc/SQL01.inlanefreight.local:1433"

Then crack the passwword with mimikatz. Got it its' worng way

rustic sage
# next bronze the interface will be selected automatically when you specify an IP for telnet, ...

It's always gone by the default route which isn't the one used for the vpn. Every command I've ran thus far I had to specify the interface or else it didn't work.

┌──(kali㉿kali)-[~/Documents/HTB]
└─$ ip route show                                    
default via 10.0.2.2 dev eth0 proto dhcp src 10.0.2.15 metric 100 
10.0.2.0/24 dev eth0 proto kernel scope link src 10.0.2.15 metric 100 
10.10.10.0/23 via 10.10.14.1 dev tun0 
10.10.14.0/23 dev tun0 proto kernel scope link src 10.10.14.163 
10.10.14.0/23 dev tun1 proto kernel scope link src 10.10.15.164 
10.129.0.0/16 via 10.10.14.1 dev tun0 
#

and then when I try changing the default to the vpns interface there is no internet.

proven pasture
next bronze
next bronze
supple gorge
proven pasture
next bronze
next bronze
proven pasture
# next bronze does 50x5=10?

No. So, that makes sense on why it is not the correct answer. I do have mov rax, 10, and I did not change anything else.

next bronze
#

you're supposed to change the number of mov rax, 10 so that the loop breaks, the answer is the number you change it to

#

that's it

next bronze
proven pasture
supple gorge
next bronze
#

it's at the bottom right of every academy page, if you don't see it, turn off adblock

proven pasture
#

I just guessed what the Hex was based on the "equation" you provided. I feel mighty foolish for not thinking through it better. Thank you very much.

proven pasture
supple gorge
next bronze
proven pasture
next bronze
#

anytime

supple gorge
iron hazel
#

Hi has anyway finished command injection module? I have solved the final skill assessment but would like to discuss cuz I think I solved it with necessary steps and can't get the ez method working.

rustic sage
vital adder
#

mods should really add verification to academy channels

#

read the #rules, keep asking for stuff like that and you'll get the 👢 up your ass

vital adder
next bronze
brazen umbra
#

HI I have some questions about dante lab which channel should i join can somebody add me to it.Appreciated

vital adder
hazy grotto
hardy meadow
#

Just curious how everyone is pulling their user lists for the AD enum and attack module. I'm not super great with bash so I couldn't figure out how to do it by that, so I had to do it by hand.

umbral fulcrum
#

hey I'm having trouble with the last Q in "AD Enumeration & Attacks - Skills Assessment Part I"

I think I need to use || Mimikatz - PowerShell Remoting with Pass the Ticket || but I having trouble with it, someone up for consulting ??

vale crescent
#

Can someone recommend me the best way to learn C for free?

raven gorge
umbral fulcrum
hazy grotto
#

Anybody know how to use the OPTIONS method in burpsuite?

fathom pendant
#

You use them very carefully (idk)

hazy grotto
fathom pendant
hazy grotto
twilit wharf
#

Cab anybody give me a nudge about where to look in the Windows Privilege Escalation Module, section "Other Files" ? cant find the password they are aasking for -.-

raven gorge
# umbral fulcrum not so sure what u mean ...

Assuming you already have access to ||tpetty|| then check its domain rights and you will know what to do, otherwise work around mimikatz or whatever tool you use to dump the same things

umbral fulcrum
thin harbor
#

Hi!
I recently encountered a problem in the module "ATTACKING COMMON SERVICES: Attacking DNS". Please tell me what is the problem?
I don't understand what the purpose of the assignment is. I found all subdomains. I tried to find some records on them, but I didn't find anything. I don't understand why the target ip is given in this task

fathom pendant
#

I.e. dig axfr inlanefreight.htb @ip

thin harbor
#

Thanks, but I tried to use this command, it doesn't work, it gives the following:
└─$dig axfr inlandfreight.htb @10.129.203.6

; <<>> ; <<>> ; <<>> ; <<>> ; <<>> ; <<>> ; <<>> ; <<>> DiG 9.19.17-1-Debian <<>> axfr inlanefreight.htb @10.129.203.6
;; global parameters: +cmd
; Transfer failed.

acoustic owl
fathom pendant
umbral fulcrum
hazy grotto
#

anybody see something wrong with this?

acoustic owl
hazy grotto
#

That didn't work either

#

Working on the Attacking Enterprise Networks, Web Enumeration & Exploitation, Steal an admin's session cookie and gain access to the support ticketing queue. Submit the flag value for the "John" user as your answer.

#

support.inlanefreight.local section

#

There's a ticket submitting forum, I'm supposed to enter that into the message box and catch it back with nc. I'm getting nothing back

umbral fulcrum
#

close it

umbral fulcrum
hazy grotto
#

What's the full name?

rare swan
#

sqlmap -r req-case3.txt --batch --dump --cookie='id=1' It doesnt attack cookie id - how can i manage with sqlmap to inject into cookie id

umbral fulcrum
umbral fulcrum
rare swan
#

Module: sqlmap Section:Running SQLMap on an HTTP Request

hazy grotto
umbral fulcrum
hazy grotto
hazy grotto
twilit wharf
umbral fulcrum
rare swan
#

@umbral fulcrum yes

umbral fulcrum
rare swan
#

i mean im using -r flag but its not attacking cookie id what i have to do

twilit wharf
hexed basin
#

hello, very stupid and basic question probably - how to setup vm in a way so its startup fresh instance every time?

#

not even sure how to look that up in google

acoustic owl
umbral fulcrum
hazy grotto
#

9000

acoustic owl
# hazy grotto

The module is structured like a walkthrough. Do exactly what is described there.

acoustic owl
hazy grotto
acoustic owl
short hare
#

Hey @umbral fulcrum can i dm you?
Need to ask something regarding the AD skill assessment part 1 ?

umbral fulcrum
short hare
umbral fulcrum
#

go ahead ...

quaint hemlock
#

hey, can anyone help me with 'intro to assembly language:conditional branching'? It ask me to give the hex value that breaks the loop, so I thought it would be ||10|| or ||0xa||, but I got that wrong, can someone help me with this?

rustic sage
#

Hey guys, so I was looking at doing a tier IV module but it appears to be 90 euros for 1 single module? Am I seeing this correctly?

tranquil axle
#

its 58 if you sub for platinum for one month and instantly cancel, but yes, it is that pricey for the IV modules

#
  • vat so I guess it becomes a bit more expensive still
eternal bison
#

Is it just me? I can't connect to any Splunk instances in the Academy module. I have tried from both pwnbox and my machine. Says connection has been reset, yet the port is open in nmap scan.

rapid sparrow
#

I need some help on this

#
 Connect to the target and enumerate the available network shares. What is the password of the Administrator2 user?
old fog
#

Is there a way to figure out how long an nmap scan could take?

analog dock
rapid sparrow
analog dock
#

Ok

rapid sparrow
#

I have already searched in all shares folder

analog dock
#

What module and section is it?

fair owl
#

Why doesn't HTB academy develop a mobile application (Android/IOS) PT modules

rapid sparrow
craggy steppe
#

Hello !
I'm doing the password attack module and i cant install pypykatz on my parrot os
Is there an alternative or a solution ?

sly kelp
misty current
#

There's nothing complicated, just following the commands in that section itself will lead you to the password.

umbral fulcrum
#

in "AD Enumeration & Attacks - Skills Assessment Part II" I went through the whole linux section but I can't C another use in the domain

what am I missing?
please...

pure sorrel
#

I'm doing Password Attacks Pass the Ticket from Linux, I can't get to the DC01 domain, I've checked the validity of the ticket, but keep getting a "dc01.inlanefreight.htb does not exist" error

heavy mango
#

anyone else having problems spawning target instances?

cedar void
#

Is there some glitch in the some of the HTB academy modules where you have to restart your virtual machine multiple times (or at least more than one) for your nmap results to show what port you need to use for that particular lab or are some machines just intentionally designed that way?

vital adder
#

if you are talking about the FTP section in the attacking common services module then yes that's a known bug for some time now but it's still a bug nonetheless

cedar void
rustic sage
gilded plaza
vital adder
gilded plaza
#

there is any help for that

rustic sage
#

Which one?

vital adder
rustic sage
#

It's better to mention the module name and section.

cedar void
vital adder
#

@pure sorrel and @boreal kelp ask your questions in the format of which module and section are you stuck or having issue on, what did you try and work or fail and what to you need help with

rustic sage
#

Got it. Just a sec.

vital adder
#

pls say module and section name not the id or url

gilded plaza
vital adder
#

great, but better if this is in your initial question

pure sorrel
# vital adder what did you try?

Password Attack module, section Pass the Ticket from Linux
Currently stuck on the question of reading the contents of julio.txt from domain share folder \DC01\julio

I've set host and proxy chain file, transfered the tmp file to my attackbox, exported the environment variable and added it to bashrc, set up chisel on both my attackbox and MS01

When I used impacted wmiexec or evil-winrm it can't recognize the dc01 domain

vital adder
cedar void
vital adder
rustic sage
#

||Use username anarchy on the user you found and use cupp, with the first name (first letter capital), second name (first letter capital), add special chars and use leet mode. Keep everything else blank/NO.||

gilded plaza
vital adder
vital adder
gilded plaza
vital adder
#

there should be one right with the Service Name starting with ||web|| but i no long have access to that module so i can't double check or can't confirm anything

gilded plaza
vital adder
#

🤷‍♂️ like i said you're out of luck with me lol, just wait for a bit someone will come and help

gilded plaza
#

are u know right servicesid bro ?

#

are u know that bro ?

#

i need the right answer plz

vital adder
#

beside annoying a couple of peoples you won't get anything much from spamming just wait and someone will help or if no help post your question here another time

rustic sage
acoustic owl
#

I have told you here what you should do

crystal steeple
#

hey guys, i just finished the smb section on footprinting module, everything went fine actually, but i don't understand why the path i found was given as a windows path and not a linux path structure

#

i mean i don't understand why the path is clearly displayed as C:...........\ but the answer should be formulated as a linux path structure

#

maybe i'm missing something ?can someone explain this to me

gilded plaza
fathom pendant
main inlet
#

Hello everyone, I'm still trying to get through the Public Exploits Section and I keep getting this error whenever I try to use GoBuster on the target.
I've been googling to try and figure this out on my own, but I seem to have hit a wall. Any suggestions?

golden kraken
#

any1 with WINDOWS ATTACKS & DEFENSE module done can you dm?

misty current
wet kite
crystal steeple
main inlet
wet kite
misty current
main inlet
misty current
main inlet
#

I even tried resetting PwnBox and spawning a new target machine, same error

wet kite
#

you need to add the port and the http://

#

and now you using a different ip address, you sure it is the correct one?

#

so something like that: gobuster dir -u http://94.237.49.11:xxxxx -w /usr/share/dirb/wordlists/common.txt

#

But you shouldn't need GoBuster in the "Public Exploit" section from Getting started.

main inlet
wet kite
#

just open the page and see what is displayed 🙂

#

i double checked the section for that

solid wedge
#

Can anyone help with SOC Analyst

acoustic owl
main inlet
narrow solar
#

good day friends, i am at Broken Authentication - Username Injection, tried to add the userid field, tried to remove the oldpasswd field, and tried to change to GET method, but still having "invalid credentials" i am stuck for some time now, any hint please

#

and tried to edit submit=doreset to submit=submit

#

i am not sure like should i brute the old pass or what, dont think this is the case

solid wedge
# acoustic owl What exactly do you need help with?

Hi I am currently in SOC lab Windows Event Logs & Finding Evil in the first section Windows Event Logs the first question wants you too RDP into the target but I don't know how to RDP. I believe the command I need to use is this Baldwin0374@htb[/htb]$ xfreerdp /u:Administrator /p:'HTB_@cad3my_lab_W1n10_r00t!@0' /v:[Target IP] /dynamic-resolution
I have tried opening a terminal in the pawnbox and using this but I must be entering it wrong

acoustic owl
solid wedge
#

ok

solid wedge
acoustic owl
solid wedge
acoustic owl
#

The commands discussed in the module are actually always correct. Sometimes an IP or a port must be adapted

solid wedge
umbral fulcrum
#

Hey, I have a Q regarding the "AD Enumeration & Attacks - Skills Assessment Part II"

in Q 4 I'm asked to use a common method to obtain weak credentials for another user, I guessing it's ||users spraying || with ||Password123|| or|| 12345678 || and so on, but I can' t get a users list.

so am I suppose to find online some sort of a users list or I'm missing something??

solid wedge
teal oyster
#

Hello, I just started Hack in the Box and so far only completed the module: Intro to the academy. I am an online college student, my major is computer science. I start programming one next month (end of December/beginning of January) and am trying to get somewhat of a head start. What module would be most beneficial to do next? I have not a clue where to go and would appreciate someone pointing me in the right direction. Thank you!

whole nexus
gray chasm
#

Hey, does anyone know why this happens? A few days ago I was connecting fine

[15:02:14:265] [21409:21410] [ERROR][com.freerdp.core.transport] - BIO_should_retry returned a system error 32: Broken pipe
[15:02:14:265] [21409:21410] [ERROR][com.freerdp.core] - transport_write:freerdp_set_last_error_ex ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D]
[15:02:14:265] [21409:21410] [ERROR][com.freerdp.core] - freerdp_post_connect failed

last thunder
#

Can someone teach me how to hack website because my ACC inactive and I need it back

acoustic owl
fossil crescent
#

For the Intro to Whitebox Pentesting SA, still extremely puzzled by Skills Assessment 2. Hint says ||code injection should not be possible, even without sanitization or validation||, but not running eval, ran thru a code analysis tool and it suggested the ||new Function|| bit could be bad, so removed it and code analysis is happy anyhow, but the patch checker still seems to think it's vulnerable, and it states using external modules (e.g.: safe-eval) is not allowed so...🤷 what am I missing?

EDIT: Resolved. The checker (if hints are enabled) will only show ONE thing that's wrong... I'd argue the order of it is not ideal (leading to my my spinning in circles) but should have realized it on my own. My problem was, and this is a hint that is sometimes given, it wasn't in my particular case as again -- ||it's gotta run clean -- no crashing||

teal oyster
hallow remnant
# acoustic owl I did not have the problem with the ping, but my answer was not accepted Were y...

Yeah, I finally got it solved after this:

https://forum.hackthebox.com/t/cannot-connect-to-pki-server-on-windows-attacks-defence-module-pki-esc1-section/301209

In your case, I think it was a date formatting issue:

MM-DD-YYYY

sly dome
#

in Attacking Tomcat what is the wordlist to use for the bruteforce xd

#

ok why it works now but not before

#

it depends XD?

#

wtf is wrong with this section? brute force only works in the 1st minute of spawned target

#

if this happens in exam im done

wet kite
#

firwall not active yet 😄 jk no idea actually

sly dome
#

i mean

#

the creds are correct since they are accepted as answers in the section

#

but not working in the instance to attack

#

this is kind of frustrating

#

ok, confirmed:

  1. spawn a new instance of the target
  2. log in with correct creds
  3. sign out of tomcat manager dashboard by closing firefox
  4. creds no longer work
wet kite
#

Currently working on "crakcing passwords with hashcat" section Cracking Common Hashes
Is it really just trying random rules and hoping for the best or is there something to narrow it down?

hybrid prairie
#

I'm doing the Windows Priv Esc Assessment i. I'm stuck on using command injection to connect back to my attacking box. (this is not covered in this module, nor have I learned how to do it). I've done some enumeration on the website but have been unable to connect back to my pwnbox instance. I have a nc listener set up on my attackbox to recieve requests. I've tried some versions of netcat (nc, ncat, netcat) with reverse shells, tried to curl a test file on an http server, tried wget, tried telnet. nothing is connecting back to my attack box. Am I doing this incorrectly?

undone narwhal
native oak
#

Hi all

#

I'm new to HTB

#

I got stuck with my first exercice FeelsWeirdMan

undone narwhal
wet kite
#

Is there an easy way to copy files from the Quests to the pwnbox? i usually use my own kali box, but the current question is like "use exploit located in /opt/ folder in the pwnbox.

undone narwhal
wet kite
#

yeah i ended up googleing the exploit and got it to my machine. was just wondering how you would get the provided 7z file to the pwnbox

native oak
#

Module : DNS Enumeration Using Python , section DNS Records and Queries , I'm stucked at question 1

fathom pendant
native oak
#

I tried but it's incorrect answer

fathom pendant
hybrid prairie
native oak
fathom pendant
#

And you have a way to load the shell? Such as navigating to the webpage the shell is on?

fathom pendant
# native oak

It's asking you to investigate all records, start with a zone transfer or other queries. Its asking fir the Unique Record

native oak
hybrid prairie
#

I'm currently on the website from the http port 80, injecting using the 127.0.0.1 & .... method, getting returns for things like 'dir', 'whoami', but when i attemmpt to curl/nc/wget anythigng back to mmy attacking machine I don't get any connections to a NC listener nor to an http server. I'm sure I'm missing something very basic, but again, haven't really done a a module where I'd leard how to solve this 🙂

fathom pendant
#

Well when you do something like a zone transfer you get all available records it's willing to give you if you have the name server

#

Nslookup will give you the name server to use with dig

#

dig axfr inlanefreight.com @name_server

native oak
fathom pendant
#

Weird

marble raft
#

Hi there! Can someone help me on the Skills Assessment on Introduction to Digital Forensics?

native oak
fathom pendant
#

You can do all

marble raft
#

Like, the module focuses heavily on volatily and zimmerman tools, and the skill assessment is on a tool they mentioned like 3 times

fathom pendant
#

But just as a note all/any requests are mostly deprecated

indigo dove
#

Hello there, anyone experimenting long times of waiting when spawning machines on the Academy?

rustic sage
#

couldn't spawn mine for a good 15min and just quit

#

went to read theory

fathom pendant
#

Weekends are generally rough on all htb servers

indigo dove
#

Allright, Im doing F5 + clicking again and it works after some tries

flint laurel
#

Can someone help nudge me on the module crackmapexec skills assessment.

Got 3 users but u able to get the flag in SQL01 question 2

cedar void
#

Does anyone remember which module was about rdping into the Windows machine and changing to the 'Administrator' user?

cedar void
next bronze
cedar void
#

Not entirely sure

pure sorrel
#

I'm doing the Password Attacks Lab - Easy, and I found the user and password, but am having trouble connecting to both ftp and ssh. Ftp says connection refused, and ssh says permission denied (publickey)

I don't know what to do with the public key, I've tried solutions online like changing permissions and options in the config file. I know im missing something but I can not remember what

#

Any help would be super appreciated

next bronze
next bronze
cedar void
pure sorrel
#

So I'm supposed to be able to ftp in? That's good to know, I tried reconnecting but I'll keep trying

next bronze
#

I think they're saying that you should be able to login to ftp, I don't remember that part but if you have a username and pass, test them against all services

sly dome
#

i cant fkn spawn targets kek

pure sorrel
sly dome
#

@languid fjord take a look if you can, its not working . I tried with EU1 and EU2

#

good night hope tomorrow it would be fixed

languid fjord
#

Is it not working, or taking a long time to spawn

sly dome
#

for me never spawn

#

and when it spawns (if it does) it has like 20 minutes less than the usual 118

languid fjord
#

Poked our infra team about it

sly dome
#

thankss

limber wasp
#

can any one tell me what I might be doing wrong here. I was able to follow along and ' order by 1,2-- , etc, to figure out the number of columns. Which it gives you in the lesson anyway. Even when I try to union select the number of columns i get no response. it just loads. i've tried... cn' UNION select 1,user(),3,4-- -, (space of course) nothing. ive tried ' union select 1,2,user(),4-- , ' union select null,user(),null,null-- - and it just loads. am I missing something?

cedar void
#

Do any of you find yourselves doing some of these exercises and you think you are well on them and are progressing with learning hacking skills... but suddenly it gets hard quickly? That is how I felt with the Common attack services hard lab...mainly with the last question of that lab

rustic sage
#

Best path anons

woven copper
#

Are we all having issues spawning machines?

next bronze
#

yes, seems like academy machines are struggling rn

next bronze
next bronze
loud marsh
#

Hi buddy,
I have been working to learn cyber sec from about 1.5 yrs
I am preparing for OSCP after 1 year

Please someone can guide me and be my mentor for the journey 🏆

I assure the journey will be very joyful and full with surb knowledge we share

fathom pendant
slender shoal
#

do cpts

#

if you understand you'll pass oscp with 0 issues.

#

the most you can do is learn how to learn on your own.

lyric oriole
#

Is it bad I find Linux challenging

next bronze
#

we all start somewhere, use it more and you'll get the hang of it

lyric oriole
#

I feel like I get stuck forever on the questions

cedar void
lyric oriole
#

At times. I think. I’m a truck driver with limited and various computer knowledge. I only get to play with a few times a week

#

I’m trying tho to do all the classes and keep practicing

next bronze
#

hey, that's pretty cool that you're trying this, keep going, it might take some time but you'll get better as it goes on

lyric oriole
#

I’m hoping so, it’s the orders that I’m searching but I hope it all comes together

cedar void
lyric oriole
#

Yes. I feel like what I read don’t apply to the questions completely

#

I feel like I have alot to learn outside the commands

loud marsh
lyric oriole
#

I’m hoping by throwing myself in I’ll learn more than just commands, I need to be able to picture how everything works I guess

next bronze
#

if you need help, just send a message here, people will be willing to help, provided you have done your due diligence of course

hard widget
#

Can someone help me in modern web exploitation techniques? Im stuck in the xss part

#

I tried for 3 days

hard widget
hallow remnant
#

WINDOWS ATTACKS & DEFENSE
Skills Assessment

My attempts to replicate the steps shown in performing PKI - EC8 aren't consistent with the results shown in the module. Namely, copying the Base64 output from the attained certificate into Rubeus is throwing an error:

#

The command ran, as written:

.\Rubeus.exe asktgt /user:DC2$ /ptt /certificate:<b64_here>

#

I'm not certain why Rubeus is throwing this error and would welcome help

misty current
# hallow remnant I'm not certain why Rubeus is throwing this error and would welcome help

I haven't started working on the module yet FYI.
The error "KDC_ERR_PADATA_TYPE_NOSUPP" means that the KDC is not set up for Kerberos authentication.

But, reading the below link, It might also be an indication that your targeted KDCs does not have certificates with the necessary EKU. So you cannot use your certificate to get a TGT
https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4771#:~:text=KDC_ERR_PADATA_TYPE_NOSUPP

pine apex
#

I'm doing "Intro to Networking and Traffic Analysis", I'm nearly complete the Wireshark portion. Following the instructions, I captured for 10 minutes and still found no image in the filter, unless I'm missing something.
Done it multiple times, any help would be appreciated
(I can't finish the module unless I find the image)

misty current
# misty current I haven't started working on the module yet FYI. The error "KDC_ERR_PADATA_TYPE_...

@hallow remnant Might be going out of the module's scope, but If it's a DC (assuming from the computer name), it definitely gotta have LDAPS and thus use Schannel. If that's the case, there's no need to use a smart card EKU and use the Schannel to use certificate authentication. There is a PowerShell script for performing LDAP whoami using certificates through SSL. https://github.com/leechristensen/Random/blob/master/PowerShellScripts/Get-LdapCurrentUser.ps1
Get-LdapCurrentUser -Certificate c:\Users\scriptie\potterDC.pfx -Server DC.potter.local:636 -UseSSL
Then, you should be able to use https://github.com/AlmondOffSec/PassTheCert and abuse further on.
Let me know if you're able to make use of it.

hallow remnant
#

Thanks though!

misty current
#

Ah, thought it was intentional.

rose stream
#

Why can’t I use other channels like pwnbox?

fiery berry
flint laurel
#

Can someone help nudge me on the module crackmapexec skills assessment.

Got 3 users but u able to get the flag in SQL01 question 2

harsh cape
#

Hey I’m new what do I do here

indigo dove
#

Hello all!! Any news about target spawining system?

umbral fulcrum
#

some one up for help in "AD Enumeration & Attacks - Skills Assessment Part II" Q 4:
"common method to obtain weak credentials for another user"

I got valid username but can't get the spraying to work ...
??

mild sierra
#

Hey, any idea why machines are not getting spawned? Been waiting for few minutes and still have the "Target is spawning..." message

acoustic owl
umbral fulcrum
candid lily
#

is htb academy down

umbral fulcrum
candid lily
#

yea but its taking "unusually" long

umbral fulcrum
#

yes it's happend some times

acoustic owl
umbral fulcrum
acoustic owl
candid lily
#

is it still spinning

umbral fulcrum
umbral fulcrum
acoustic owl
umbral fulcrum
umbral fulcrum
acoustic owl
umbral fulcrum
acoustic owl
#

No, you should test every user.

umbral fulcrum
#

with spraying?

#

hmmm...
seems like never ending job ...

#

thank BTW, I'll try it

acoustic owl
candid lily
#

it is still loading whats wrong

acoustic owl
# umbral fulcrum thank BTW, I'll try it

This could be a new user who has never logged in, it could be a user who uses such a simple password and has therefore never entered it incorrectly, but it could also be a user who regularly enters his password incorrectly...

umbral fulcrum
acoustic owl
candid lily
#

i just wanna know if its only for me or other experience the same

candid lily
#

oh okay i was worried problem was with my side

upper ruin
#

Yo, anyone else got trouble with a target being spawned?

#

Oh damn.

#

It ain't for me only.

candid lily
#

yep

upper ruin
#

Damn I am at the last section of shells and payloads.

#

And that happens.

#

shii

candid lily
#

proceed with next one then maybe

upper ruin
#

Would be wise to do.

#

But I don't wanna miss the Live Engagement.

#

So I will just be patient.

#

;p

candid lily
#

it is not missed, it is just postponed

upper ruin
#

Sounds good to me.

fresh compass
#

Today I'm having problems spawning the Documentation & Reporting Practice lab. Anybody having the same issue in the academy labs?

candid lily
#

its for all the labs

fresh compass
#

shit...

#

now I have read the previous messages, sorry 😆

tacit grove
upper ruin
#

POV: I can't enjoy HTB modules. (it's been my life the last 3 months)

#

It spawned oh my GOD.

#

Yeah, just don't cancel the process.

#

Lemme extend it for 2 hours.