#modules

1 messages ยท Page 158 of 1

mild sierra
#

Indeed it did. Let's go.

gilded patrol
#

@fresh compass i have problema too

latent cave
#

ok I'm not the only one ahah, thought I was going crazy! just as I was about to hit 50% in the pentester path lol

slate creek
#

darn, I can't even connect to the dashboard now...

latent cave
#

same here, I guess someone at HTB tripped on the power chord or something

slate creek
#

I think same, where are u at?

slate creek
upper ruin
#

Usually I would tryhard and do it within 2 months.

#

But I am in uni as well, so it's a bit challenging to manage.

#

So I'll just take my time.

slate creek
#

nice keep grinding, I'm at AD right now, really need to finish the whole course in 60 days, I have like 60% to go.

upper ruin
#

u2 g

slate creek
#

I am working full-time as well, taking care of toddler too lol tough time ๐Ÿ˜„

latent cave
#

if you full time it it's possible, i'm at fuff right now and probably will be done beginning of january

gilded patrol
#

@latent cave me too

fresh compass
slate creek
gilded patrol
#

It doesn't connect to the dashboard

latent cave
#

well if you have a backgground you're gonna go faster than me, this is my first foray in the world of IT/computer anything

slate creek
latent cave
#

ah nice, i'm planning on doing portswigger afterwards, how was it?

slate creek
latent cave
#

makes sense

slate creek
#

I feel HTB CBBH is really good too, I am planning to get an OSCP first, then do the CBBH and jump into bug bounty to practice. dunno how doable is that tho ๐Ÿ˜„

latent cave
#

as long as you keep to it and enjoy it, anything's possible, I learned that from the power rangers, so it has to be true

slate creek
latent cave
#

well it's still not working, I guess that's a sign I should go to bed lol. good luck to you all

gilded patrol
#

@latent cave jajajajaja

fresh compass
#

My lab spawn but I cannot get a connection

fresh compass
gilded patrol
#

Same, i'll come back later

#

Yes jajjaaja

fresh compass
#

me too, only us laugh that way ๐Ÿคฃ

gilded patrol
#

Jajaja well done

#

I thought it was because i wrote wrong, which also

elder crow
#

hello guys, anyone also have problems entering the academy platform, is down right?

gilded patrol
#

@elder crow yes! Look up

next bronze
#

rough day for the servers

elder crow
#

I see, for a moment when I was trying to resolve the domain dns couldn't find the address... I thought there was something with my connection but I see there isn't

main schooner
#

guess someone hacked the box

#

back up

eternal arch
#

still waiting for my target to spawn ๐Ÿ˜ข

main schooner
#

yeah not happening atm it seems.

eternal arch
#

I had the luck for it to spawn like 1.5 hours ago.. but it was all jittery and eventually the connection just tanked

main schooner
#

you working on cpts or cbbh

eternal arch
#

oh no.. I'm just doing modules.. not yet working on any cert ๐Ÿ™‚

cedar void
tiny yacht
#

Academy its working fine again for me.

main schooner
tiny yacht
#

Again its not working :/

main schooner
#

ah well, portswigger time then

marsh salmon
#

Same here, the targets usually do not spawn at all and when they do I still canโ€™t iteract with them

elder crow
ionic summit
#

ahh! a late thank you sm

narrow solar
#

any help

spring trellis
#

Hi, I am stuck on Firewall and IDS/IPS Evasion - Medium Lab but am not able to figure out what the answer would be can I DM someone about it ?

gilded patrol
#

Does it work?

spring trellis
# gilded patrol Does it work?

The lab seems to work, but I am supposed to enumerate it but am not able to get the information required to answer the question

obsidian hound
#

hi

#

I am wanting to pass this step but I can't: Try running a sub-domain fuzzing test on 'inlanefreight.com' to find a customer sub-domain portal. What is the full domain of it?

#

I have tried several options

gilded patrol
#

@spring trellis thank you. I am with the CBBH, otherwise I would help you. Ask in the cpts section better.

umbral fulcrum
#

hey in "Locate a configuration file containing an MSSQL connection string." assessment 2 of AD

I can't find any file in any folder of the machines on the network...
am I missing something?
used ||smbmap|| with users: ||BR086|| & ||AB920||,
even tried ||rpcclient|| with ||BR086|| but nothing ...

fiery berry
proven pasture
#

Hello, folks. I was hoping I could please get some help with INTRO TO ASSEMBLY LANGUAGE. I am stuck on Procedures.
Try assembling and debugging the above code, and note how "call" and "ret" store and retrieve "rip" on the stack. What is the address at the top of the stack after entering "Exit"? (6-digit hex 0xaddress, without zeroes)
I have tried an objdump, disas, and breaks. I am not really sure what the question is asking. When I did the breat from _start and stepped through everything, I tried every hex there just to try and pass this; no matter what I tried I cannot seem to pass

obsidian hound
umbral fulcrum
fiery berry
brittle prawn
fiery berry
sly dome
#

splunk not working

#

Splunk - Discovery & Enumeration

#

open in nmap scan but cant reach the site

fiery berry
sly dome
#

yes

#

trying respawn

fiery berry
#

Then if it is still unreachable I don't know

sly dome
#

i have a mess in my vpn since the issue they got yesterday/this morning

#

gonna redo all

fiery berry
# umbral fulcrum ||net ||commands ?

I'm just suggesting you can use whatever command you are comfortable with, there isn't a straight way to accomplish something to reach the end goal. I suggested the net command cause is the one I'm comfortable with and once I have enumerated the user ||BR086|| I have noticed that he could help me getting the config file

fiery berry
umbral fulcrum
fiery berry
umbral fulcrum
fiery berry
unique palm
#

Im currently working on the module "using the metasploit framework". When i try to run eternal romance the target always times out. I am using PWNBOX. Anyone experienced issues too?

fierce cave
#

Yes, i have issues connecting to the boxes using RDP in the module "Password Attacks". I think there's a generalized problem

unique palm
#

oh alright. Thanks.

umbral fulcrum
lusty hearth
#

feeling stupid rn but where tf is the browser application in this vm I rdp to

#

nvm just used the cli, weird there are no desktop icons for it

steel ginkgo
#

can someone help me with dante, i've got good start but would need some nudge?

analog dock
analog dock
real cedar
#

Currently doing the Skills Assessment of "Windows Event Logs & Finding Evil". First task, I dont get. I have to detect a hijacking attack, I filtered a little. But when working on that corresponding section, I was able to find the answer because I executed the binary myself and knew what I was searching for. But now I just have a bunch of events. Should I go through them one by one?

I honestly find this whole module very confusing and frustrating. Maybe thats the reason, why I dont get it ๐Ÿ˜„ Would love a nudge via DM anyway to get any kind of learning effect into this.

EDIT: Managed to get the answer. But just with bruteforcing. I have no clue and no learning effect with this.

tulip dragon
#

getting these error

sly fiber
#

Working through the Active Directory module and at certain points it gives you ssh creds to connect to an internal Linux host.

I am having issues where the creds don't seem to work. Has anyone else experienced this?

wet kite
tulip dragon
#

why none given example working

fathom pendant
tulip dragon
#

ok its time tosleep

thorn urchin
#

if it makes you feel better, theres someone making that exact same mistake on that section daily

#

its gotta be up there amongst the most common mistakes made in the whole course

fathom pendant
#

I made that mistake... after doing it correctly kek

thorn urchin
#

though not the funniest. That would be the rdp not hitting literally any button.

fathom pendant
#

"It was just working... oh"

wanton jasper
#

I am working on password attacks and I have created the mutated list for the zip file. This is where we are. No way I can wait that long lol. I have already waited 2 hours on it.

wanton jasper
fathom pendant
wanton jasper
#

Good advice

fathom pendant
#

This module gives you end goals but doesn't always give you the starting point

#

For one of them, you need to use a different user to extract the password of the user in the question

#

Also: save all passwords

#

This section reuses passwords and lab environments

#

All linux labs are connected and all Windows labs are connected

final root
#

In SQL injection module and I can't run mysql. When I try: mysql -u root -p
It says me this: ERROR 2002 (HY000): Can't connect to local MySQL server through socket '/run/mysqld/mysqld.sock' (2)

#

can someone help?

fathom pendant
#

Otherwise it's just trying to do it on your own system

final root
#

I'm trying this in hackthebox workstation on website

fathom pendant
#

mysql -S $ip

fathom pendant
tight glen
#

Send a screenshot of your full command

fathom pendant
#

What I said still works out

#

Without specifying -S it's assuming you're connecting to a localhost server

final root
#

I'm in thank you. I put mysql --host=... --port=.... -u root -p
and put the password and I'm in now ๐Ÿ˜„

fathom pendant
final root
#

aha ok, didn't know that

fathom pendant
#

And if it's default port, not necessary to specify

fathom pendant
tight mesa
#

hi y'all I'm looking for someone who's willing to help me with the question 11 from AD assessment II, basically I'd to discuss what I'm doing to see if I'm doing something wrong, anyone?

rustic sage
#

Guys what is the difference between machines and challenges on HTB?

thorn urchin
rustic sage
thorn urchin
rustic sage
narrow solar
crystal steeple
#

hello guys im stuck on the last question of the DNS section in footprinting module.

#

i tried to enumerate subdomains to get the FQDN but no host with the IP x.x.x.203 did show up

#

i also tried to use dnsenum with the subdomains i found but still nothing

#

any hints will be appreciated

fathom pendant
#

You should be using a fierce wordlists to find the right one

#

Step 1) dig axfr inlanefreight.htb @ip
Step 2) run dnsenum on those subdomains

crystal steeple
#

thank you very much !!! i found it with that wordlist.

prisma badger
#

is there a way to make proxychains nmap scans faster.
I've tried specifiying, retries, rates,parallels, min-hostgroups, and nothing changed -> prolly means its a proxy problem not an nmap one. Sorta at wits end if anyone could give me a direction on this subj or tips

fathom pendant
#

Eh Nmap doesn't play well with proxy

prisma badger
#

is it nmap or jus scannign in general

fathom pendant
#

Nmap scanning I forget the full reason for it

prisma badger
#

do u hav an alternative

next bronze
#

try with -sT -Pn

prisma badger
#

ive tried all relavent options alr

#

but ig im just asking if any1 has the same issue

slender shoal
#

Fun fact, you haven't tried all the relevant options if you don't have the correct answer ๐Ÿ™ƒ

prisma badger
#

relevant nmap flags*

thorn urchin
#

full normal speed nmap scanning including udp and icmp

thorn urchin
void shadow
#

There is also a decoy ip option in nmap
Haven't used it myself but read about it
Maybe it can be of use

thorn urchin
worn matrix
#

i am really trying to filter some packets on wireshark,and i do frame contains " word" but i get 0 results.The "word" its on a specific column,followed by some staff.It starts with Word, ... .... ... .Why i cant make this work?any idea how to filter the packets about a wordinside a column?

void shadow
thorn urchin
#

the decoy IP option is a legacy feature that hasnt been relevant since the 90s

void shadow
thorn urchin
#

Im completely serious that isnt hyperbole

#

What it was for was cause back then scanning wasnt a widespread common thing. So it actually made sense back then to log scan attempts as an early precursor detection for an incoming attack, sometimes even preemptively blocking IPs in the process. Decoy scans was designed to multiple your scan traffic with fake dummies so that it was harder for the net admins to filter out which IP was actually malicious. And if you were auto blocking scan attempts then a decoy scan could make the target DoS themselves by blocking important IPs so it deinsentivized auto blocking like that.

#

These days the entire internet is being scanned 24/7 so it makes zero sense to take such an aggressive stance on simple scans. So the entire point of decoy scanning has ceased to exist. The only reason it remains an option today is because theres not a compelling reason to remove the feature as useless as it is.

thorn urchin
#

<@&861185840277487616>

acoustic fractal
#

bro

#

I was just asking

thorn urchin
#

and what youre asking is not allowed

autumn pilot
#

please familiarize yourself with the #rules

acoustic fractal
#

where can I ask this question

thorn urchin
#

You dont

autumn pilot
#

careful with the language

thorn urchin
#

classic mad buddy come in to troll

acoustic fractal
#

ok name 5 books

gilded plaza
#

are u find the answer ?

fervent estuary
#

Hi guys. Iโ€™m completely stuck on the last section of the proxy module socks over rdp. When I try to connect to the pivot host I get a message saying either the remote pc is not on, not connected to the network or not enabled. Any advice or hints would be seriously appreciated.

hybrid timber
#

Module: Introduction to Splunk & SPL

I must be doing something wrong as I cannot for the life of me find the answer to the third practical exercise question. Can someone please help me to write the SPL query that will perform the necessary checks?

wet kite
thorn urchin
#

Some advantages to being an old hat that first started learning almost two decades ago lmao

wet kite
#

Oh nice thats quite a lot ๐Ÿ˜„

worn matrix
#

how can i report if someone changed the password in the lab machine?

#

he changed the password and throw us out

thorn urchin
#

the labs arent shared environments so that didnt happen

#

unless it wasnt a module lab in which case why are you asking in modules

worn matrix
#

not in a module.sorry where should i ask?

thorn urchin
#

Nowhere, just reset the lab and move on with life

#

but asking in modules is the obviously wrong thing. Youre already verified and can see the full server so you should know better

worn matrix
#

mb

thorn urchin
#

even general chat if you were totally clueless

golden kraken
#

anyone know if there's a walkthrough for the Windows attacks and Defense module? having difficulty

fathom pendant
#

There's not gonna be a walk-through for any module above tier 0

thorn urchin
#

A walkthrough would be useless. Finishing the module wont help you learn and understand any better.

fathom pendant
#

If you're having difficulty just ask your question here and redact any spoilers by either substituting usernames with [first initial]*

tight mesa
olive fiber
#

Pth

tight mesa
#

can I DM?

tight mesa
lyric oriole
#

I had a buddy tell me to get good I have to be glued to the computer 24/7 is that true

fathom pendant
#

Not really

#

Practice makes you better

fathom pendant
#

But when you're tired you're prone to make mistakes

lyric oriole
#

I donโ€™t get much time only a few hours a week,

fathom pendant
#

Ok?

#

I haven't touched htb academy stuff in a week

lyric oriole
#

Iโ€™m not sure if Iโ€™m learning or confusing myself

#

Iโ€™m in Linux right now

fathom pendant
#

Probably both

#

Part of learning is confusion

#

It means you're outside your comfort zone

worldly roost
#

You are a good motivational speaker
Keep it up buddy

lyric oriole
#

With computers thatโ€™s a def

#

Iโ€™m very lost but trying to make sense of stuff

fathom pendant
#

Well if you're doing a learning module on htb academy ask here

#

Most people will genuinely be helpful, a few will just be Dicks about it

lyric oriole
#

Iโ€™m not understand Linux at all

#

Understanding

worldly roost
#

Start with Linux module on academy
It is a great start for someone who is new to linux

fathom pendant
#

Htb academy has a linux Fundamentals module

thorn urchin
#

Install a generic linux distro as your new host. Use it as your daily driver. Whenever you have an issue or need to do something new, google how to till its working.

#

Easiest way to learn Linux

fathom pendant
#

It's hard to find something in linux that isn't documented, or in some ask forum with your same issue

#

Most of my fixes I've found on askubuntu

next bronze
#

chatgpt for basic commands is also generally okay

lyric oriole
#

I will have to check out, I think itโ€™s the basic computer knowledge I lack

fathom pendant
#

Also when googling, if you can, avoid being too specific with the distro, most of the time "how to do x in Linux" will suffice

tight mesa
thorn urchin
#

the arch wiki too

fathom pendant
#

Like someone the other day mentioned some sort of error that amounted to "you're doing it wrong kek "

thorn urchin
#

because the arch wiki assumes youre trying to fix some obscure 20 year old system running inside a shoe box off dialup still and will give you the most intricate and hyper specific fixes to solve an issue

fathom pendant
#

Though that was a windows/ldap error

fathom pendant
#

Also sometimes the issue is the tool you're using is a new version, and the command no longer works the same

thorn urchin
#

9 out of 10 times an archwiki fix works no matter what your setup is

tulip mortar
#

Getting Started > Pentesting Basics > Public Exploits
I've scanned using nmap, and see a few services running (chargen, ssh, ldp, upnp). My initial thought is to target OpenSSH 8.4p1.
When using searchsploit openssh it comes up with ~ 6 results. (searchsploit openssh 8.4p1 has 0 results.) I then start using Metasploit: search exploit openssh

At this point, it shows one result: unquoted_service_path

Looking at the options for unquoted_service_path, it seems to all be local (i.e. I can't target the remote server). Any thoughts outside of the hint on where I should continue?

woven copper
#

the other ports , udp scans

next bronze
fathom pendant
thorn urchin
#

Youre provided a public IP and port

tulip mortar
#

-_- Thank you three...

thorn urchin
#

absolutely do NOT be full scanning the IP and trying to run random exploits against it!

#

thats a REAL box

#

only be testing the provided port

#

dont accidentally commit a crime while learning lol

next bronze
#

I think they've accounted for people scanning the full ip

fathom pendant
#

That's not the point

tulip mortar
#

I would certainly hope so

thorn urchin
next bronze
#

that's indeed true

thorn urchin
#

You only test the scope of whats provided or else youre committing crime

tulip mortar
#

It's a good point to be made -- and may even warrant an addition to the lesson

fathom pendant
#

The point is you're given a public ip and port

fathom pendant
tulip mortar
#

A reminder never hurts

#

Also, to clarify, I never ran any random exploits against the server

#

(Or any, for that matter)

next bronze
#

it doesn't matter here since it's a test environment, but in the real world, don't throw anything against targets which you're not cleared to attack

tulip mortar
#

Of course

pure sorrel
#

Is there anyone here able (or rather willing, since I bet most are able) to help me fix my VM. I've been working for 2 days now on a lab and only now realized it was my vm that wasn't working. The pwnbox works but often blanks on me and I have to refresh the page.

I did nothing to the vm that im aware of but I guess I must have changed something in the config files unintentionally

thorn urchin
#

Usually the first thing I do after a new VM install and update is create a new snapshot to act as my 'baseline' and I revert to that if something really breaks

#

VMs are meant to be semi disposable

next bronze
#

always make a golden copy

thorn urchin
#

especially with hacking distros where youre likely to be installing and messing around with bleeding edge unstable software

pure sorrel
#

I suppose, I changed it around a bit for better workflow and have some notes (a while ago when it was still working fine) but I suppose i can do it again

#

And yea, I always forget to snapshot fresh installs. One day I'll learn. Maybe today is that day

thorn urchin
#

no better incentive than immediately after suffering for not doing it

spring viper
#

i lost my vm with like 125 boxes or something and learned to always make snapshots

#

was able to recover the notes but had to rebuild all the tools FeelsBadMan

thorn urchin
#

any important data should be backed up or synced off VM

spring viper
#

ya i use obsidian on a different box now for my notes

#

was still a cherry tree homie then

#

but in hindsight it helped me learn a lot more making a vm build with more experience understanding what the tools do and stuff

tulip mortar
#

I figured out the exploit for that section. Thank you @thorn urchin , @fathom pendant , @next bronze
I'm more than a little embarrassed for making the mistake I did and wish there was a gentler approach to correction, but lessons learned.

thorn urchin
#

Fear does the heart good

#

and congrats and GL in future sections

weak kindle
#

In the "Windows Event Logs & Finding Evil" skill's assesment question no3. It asks to determine the process that injected into the process that executed unmanaged PowerShell code. Any hints on that? I revisited all the sections, kinda stuck here! Any help is appreciated

supple gorge
trail obsidian
#

DETECTING WINDOWS ATTACKS WITH SPLUNK - Detecting Ransomware. I've modified the splunk search for file deletions and the number doesn't seem to be the correct answer. I've tried filtering out some things and tried several different numbers and no go. Is there something I'm missing here? Feel free to DM.

weak kindle
supple gorge
# weak kindle I got my answer, thanks anyways

Hi, how did you do skill assesment question 3, just curious since I went back to it to try and figure out how to give hints

My hint would be to go back to module, see the example log, then try to manufacture something that would catch it.

weak kindle
weak kindle
short hare
#

AD Enumeration & Attacks - Skills Assessment Part I

I want to find the IP of MS01

Can anyone pass the nslookup command for it , i tired many ways but not working

next bronze
#

there are a lot of ways to get/dump dns records, the simplest is just to ping the hostname in a domain joined computer

rustic sage
#

noobie here that needs some help

#

โ€œList the SMB shares available on the target host. Connect to the available share as the bob user. Once connected, access the folder called โ€˜flagโ€™ and submit the contents of the flag.txt file.โ€

I am having trouble with the smbclient command. I cant login with the given credentials (Bob:Welcome1).

I input < $ smbclient -N -L \0.0.0.0 > followed by < $ smbclient -U bob \0.0.0.0\users >
and then used โ€œWelcome1โ€ passkey but it is not going through and throwing an โ€œNS_STATUS_ERROR_CODEโ€ at meโ€ฆ

Anyone else having this issue or find a solution for this?

short hare
#

and section

rustic sage
next bronze
#

either use \\\\ip\\share or //ip/share

short hare
rustic sage
rustic sage
#

in that case what even is an ns status error?

next bronze
#

probably cause the syntax is wrong

rustic sage
#

ok so how do i go about this then because i am literally following what htb is telling me to do

short hare
rustic sage
#

yeah

#

thanks

short hare
#

welcome

short hare
next bronze
#

I've already replied to you earlier

autumn pilot
#

there are a few ways of getting the IP, just recall the basics

rustic sage
#

hey wsp guys ๐Ÿซก

short hare
warm tartan
#

Hey everyone I've had a weird issue with Elastic Stack from the SIEM module. I pulled up the pwnbox in my browser and it says to access Elastic Stack through "http://[target ip]:5601" . I'm starting to feel stupid cuz it just wouldn't connect. Has anyone had this issue before?

fathom pendant
#

Give it like 5 minutes

olive fiber
vital adder
#

read the #rules keep spamming shit like that and you'll get the ๐Ÿ‘ข up your ass

misty current
#

<@&861185840277487616>

barren root
#

I seem to have issues with getting Splunk to work in
Module: Attacking Common Applications
Section: Splunk - Discovery & Enumeration

From what I gathered from the information in the module and later my nmap scan, is that splunk webserver should be accessible on port 8000 of the target machine. When I attempt to I get this:

barren root
#

are ... ah fook you're right I got so used to it being http I didn't even bother. Thanks.

sly dome
#

any time

latent cave
#

hello everyone, I'm doing the ffuf Skills Assessment and I'm fuzzing for pages. Is it normal that as soon as I add a subdomain, ffuf gets ridiculously slow? I added them to /etc/hosts...

candid lily
#

need help on this

sly dome
#

help with what exactly, what have you tried

candid lily
#

i tried converting the displayed date into epoch time using python datetime

#

then got md5 hash of it and compared it

#
import datetime
import hashlib

for offset in range(-100000, 100000):
    total_seconds = round(datetime.datetime.strptime("2023-11-28 12:33:05pm", f"%Y-%m-%d %I:%M:%S%p").timestamp()*1000) + offset
    hash = hashlib.md5(f"htbuser{total_seconds}".encode('utf-8')).hexdigest()
    print(hash)
    if hash == "5b1c00978e854710fb95c5438dcf54ee":
        print(f"Found it!!! {total_seconds}")
        break
sly dome
#

i solved it with bruteforce

#

but i dont remember exactly from the top of my head

#

can check later

candid lily
#

whats wrong with my approach

#

imma try to use hashcat lol

#

LOL it worked

#

wtf the token is not being accepted

sly dome
candid lily
#

but these token are not being accepted why

sly dome
#

let me try find my python script

candid lily
#

even this is not working :(

#

im losing patience im just gonna bruteforce the tokens on server now

#

nvm i just realised i cant

quick magnet
#

hi im stuck on module Using Crackmapexec skill assessment question 2.
Gain access to the SQL01 and submit the contents of the flag located in C:\Users\Public\flag.txt

already got 2 user a* and s* but i don't know what next move.
any hint ?

candid lily
#

what ever i do it doesnt work wtf

quick magnet
#

have u try more than and less than 1 sec

candid lily
#

yes everythiing

quick magnet
#

what i remember i was collect token and hit api in different script

candid lily
#

this too doesnt work

#

this module is garbage

quick magnet
#

try +-2

candid lily
#

maybe it my frikin internet, imma try from pwnbox

#

pov: htb trying to make you rage

quick magnet
candid lily
#

it doesnt work in pwnbox either

#

predictable token more like impossible to predict token

quick magnet
#

its possible

candid lily
#

i tried so many different methods, none of them works

narrow solar
#

good day friends, i am at Skill Assessment Broken Authentication, i finally got to the ||support ||account but cant find the admin panel, and hint please

candid lily
#

?

#

i hate this

narrow solar
#

let me find it, give me a minute

quaint hemlock
#

can someone help me with intro to assembly language : shellcoding tools? I already get the required shellcode, but when I enter the shellcode, it said 'failed to run shellcode'? thx

narrow solar
# candid lily i hate this
candid lily
#

i see no code in thar

quaint hemlock
#

can someone DM me and help me with intro to assembly language : shellcoding tools? I really have no idea how to generate the shellcode to cat for flag.txt, thank you

unique palm
#

On the "Password Mutations" Section in "Password Attacks" I created a wordlist using

"hashcat --force ./password.list -r ./custom.rule --stdout | sort -u > mut1_password.list"

and used hydra to brute force:

"hydra -l sam -P ./mut1_password.list ssh://10.129.138.117"

However no results. Am i doing sth wrong here ?

random cliff
#

Can someone help on AD Enumeration & Attacks - Skills Assessment Part II Q7: Submit the contents of the flag.txt file on the Administrator Desktop on the SQL01 host. I am logged in, with xp_cmdshell get a powershell rev. shell, but it seems there is no Desktop folder for the administrator user and could not read the flag. Tried to JuicyPotato, but no luck.

bright quiver
#

anyone give some advice on the footprinting lab - easy? I am trying to get in via FTP on port ||2121|| using this: ||ftp //ceil:qwer1234@10.129.114.126 2121 or ftp ceil@10.x.x.x 2121|| and all I keep getting when doing it is that fact that it doesn't ask for a password and when I do ls - it says ftp> not connected. Thoughts?

unique palm
bright quiver
#

@unique palm - i did try this ||wget -r --user=ceil --password=qwer1234 ftp://10.129.234.216 #Download all|| - but I received no results.

unique palm
#

try ||wget -m --no-passive ftp://anonymous:anonymous@10.129.14.136|| dont forget to change port

sly dome
#

@candid lily could u solve it

unique palm
#

@bright quiver worked ?

candid lily
#

no

#

i just moved to next one

#

i lost hope to solve it :(

bright quiver
#

@unique palm - right now it is sitting here

#

and I get a bunch of retries:

||-2023-11-28 15:28:52-- (try: 3) http://2121/
Connecting to 2121 (2121)|0.0.8.73|:80... failed: Connection timed out.
Retrying.||

sly dome
candid lily
#

yes please

upper ruin
#

Yo, guys I am at the Live Engagement on shells and payloads.
I have a question:
I used xfreerdp and obtained credentials for Apache Tomcat.
The problem is that the first target only opens up from the 10.129 ( where i used xfreerdp)
My problem is the following: How can I open up the 172.16.1.11:8080 if there's no search engine.
Do I have to use TOR?

rustic sage
#

Can anyone tell me how to keep my server save and How do hackers can hack my server so that i can be carfeful???

bright quiver
#

anyone have any issues with footprinting easy and grabbing files with wget? I keep getting eh above retry issues and nothing getting downloaded

upper ruin
#

try wget //<ip>/<filename>

#

Without using http/s

unique palm
upper ruin
#

Where are you at the moment, which section?

bright quiver
#

@upper ruin right now I am trying this ||wget -m --no-passive ftp://ceil:qwer1234@10.129.234.216||

upper ruin
upper ruin
#

I have my whole footprinting module documented, i can give u guidance.

bright quiver
#

@upper ruin the easy lab

upper ruin
#

Ah, one sec.

bright quiver
#

For some reason nothing seems to be working as usual...I am trying to get in with or retrieve files with port ||2121||

bright quiver
#

@upper ruin no - didn't try web

upper ruin
#

You can use gobuster to enumerate the sub/files.

#

You can maybe use gobuster on the IP with the specific port and get some interesting stuff.

#

Once you do that you could get to the directory list.

bright quiver
#

tried that earlier before reverting machine and it didn't grab anything - i cvan try again, but used basic ftp@victim IP and I got in with ceil/password and can ls -la

upper ruin
#

Did you try ssh with the credentials?

bright quiver
#

not sure what changed now, but couldn't do that before

upper ruin
#

Which ports are open?

bright quiver
#

||21/2121/22||

upper ruin
#

Good, which one of these you haven't enumerated fully.

bright quiver
#

@upper ruin i can see the|| id_rsa|| now - so I should be able to get in ssh after getting it

upper ruin
#

Maybe you can input the target ip in the search bar and try the usual stuff. index.html/ admin/admin.php

#

Yup, right path.

bright quiver
#

@upper ruin thanks for the advice/guidance...mind if I DM you if i get stuck going forward?

upper ruin
upper ruin
#

Ah..there's a catch.

bright quiver
#

@upper ruin thanks a ton

upper ruin
#

Should I dm it to you now, or later?

upper ruin
#

Ah, nvm that was other box.

#

You r good.

bright quiver
#

@upper ruin I think i have to chmod, but let me see what's what...oh that's what you mean lol ok

#

@upper ruin got in

upper ruin
#

Nicee.

#

Remember, you can always use advanced commands. ls -la is much better than just ls

bright quiver
#

yup - got flag....man that first portion made it longer than needed lol

upper ruin
#

yessirrr

upper ruin
#

Make sure to configure the services accordingly.

#

If you use ftp for example remove anonymous login.

#

Apply firewall with rules.

#

Zero trust ain't a bad idea.

#

EDR such as aurora won't be a bad start at the os that supports your server.

#

What else...depends on what you use it for.

rustic sage
#

and how can people hack into my server?? Will none will be able to hack if i use 2 step vrif??

upper ruin
#

2 step vrif can be bypassed

#

But it's hard.

#

we talk about 2fa, right?

#

Wanna make sure we don't misunderstand.

rustic sage
unique palm
#

I am in the module Password Attacks and attacking SAM. When i try to create a SAM dump it says you need higher privs? Anyone got a hint ?

fluid shadow
#

I am on the Password Attacks Module, section "Remote Password Attacks" any assitance would be greatly appreciated!

umbral fulcrum
#

need a bit help in the last 2 Q of the AD assessment 2

if anyone can help please

naive wadi
#

Doing kerberos moduel Unconstratined Delegation part and have this question "Compromise the Domain and read the content of \DC01\C$\Unconstrained\flag.txt"

#

I've ran rubeus to monitor for tickets, used the spoolsample to get the DC01 tgt, performe a dcsync with user ||brian.willis|| re-issued a ticket using their ntlm hash and then imported but still getting access denied

#

has anyone done this? Unsure where I am going wrong as methodology seems fine, but clearly making a mistake Edit: solved this, further user enumeration is required to resolve.

shrewd hazel
#

i need help with the last portion of getting started module, knowledge check. i am scanning the ip address, enumertating over it, im just stuck on what exploit to use or how to progress to actually gain the foothold

vital zephyr
#

Hi everyone, can anyone help me with the shell and payload module?

#

I'm stuck in the phpwebshell module, I follow all the steps described by the module, but I can't load the webshell on the site, the steps I take are these
-I download the web shell

  • I unzip it and see the 'webshell' file
    -now I go to the IP address that htb generated for me
  • I enter with my credentials
    -go devices->vendor
    --I open burpsuite and go to the proxy section
  • I open the browser settings and in the proxy section I set 127.0.0.1 with port 8080
    -I go to the web and add new
    -I enter the credentials and using the browse button I find the .php file
    -I save,
    This is where the problems begin:
    1, the page loads endlessly
    2, burpsuite seems to have done its job but the web page never stops loading,
    I don't understand what the problem is, can someone tell me where I went wrong and what? can you give me some suggestions?
    โ€‹
#

pls my friend, txt me

#

๐Ÿ˜ฆ

#

๐Ÿ˜ข

narrow solar
#

can anyone please help me, i am asking for 4 days now, i am at Broken Authentication username injection, tried to add the userid field but didnt work because of the oldpass doesnt match, tried to fuzz it, tried remove it, tried to change to GET method and changing the submet, but no luck so far

#

please any hint

vital zephyr
#

nobody give a fu.. about us bro

prisma harbor
vital zephyr
prisma harbor
vital zephyr
#

yh

prisma harbor
vital zephyr
#

sad reality

#

โค๏ธ

#

we never be a professional hacker

#

with nobody help us

prisma harbor
hallow kiln
#

Y'all need to be patient

prisma harbor
vital zephyr
#

till when we die

prisma harbor
hallow kiln
#

Someone who's done the module has to drop by to be able to help, people are volunteering their time to help others, you're not entitled to it

vital zephyr
#

I help people when they need it, not when I feel like it.

narrow solar
narrow solar
prisma harbor
vital zephyr
narrow solar
#

of course feel free

narrow solar
vital zephyr
#

shell e payload

narrow solar
#

its been a while, yes i did

#

oh i just saw ur message, give me some time

vital zephyr
#

can i please dm u?I like to understand where I'm wrong, to arrive at a solution

vital zephyr
narrow solar
umbral fulcrum
unique palm
#

anyone else got problems with PWNBOX rn? No matter what region i select it says no instances avaible

next bronze
verbal kraken
#

hey everyone, im having a problem with the hacking wordpress module "directory indexing" section. i get an error in every directory i try to visit

deep dune
#

Hello team, anyone knows how do i find the user, ip and pass of the Hackthebox so I can enter via ssh with openvpn and do my exercises?

ivory dock
thorn urchin
thorn basin
#

Hello i'm trying to hax NASA with html, what is the first step?

deep dune
#

@madfOx Im already connect to the openvpn in my terminal, whats next? because yesterday I had a "username" and password to connect via ssh

next bronze
#

follow the instructions in the module

deep dune
#

@next bronze im doing "Linux Fundamentals" "Working with Files and Directories" and I dont see any instructions... ๐Ÿ˜ฆ

next bronze
#

scroll down and spawn the target

deep dune
#

I dont see that option

#

thats whats driving me crazy

high hearth
#

Hi! Im a noob. Just starting with the first module. I cant launch the Pwnbox terminal for the first section. Did I read correctly that the servers are down?

next bronze
high hearth
#

Awesome! Thanks! ๐Ÿ™

umbral fulcrum
next bronze
#

then you don't have admin access

rustic sage
high hearth
next bronze
#

openvpn is used to connect your own virtual machine, if you're using the in browser pwnbox, that's not applicable to you

rustic sage
#

well im not sure now but i had similar problem and after i connect to htb vpn works fine,,, didnt use htb some time i had some project outside

umbral fulcrum
#

the server is fine ...

high hearth
#

Thanks @next bronze

#

So, if if I want to verify my account on Discord, Do I have to have a VIP sub? I cant find the Account Identifier in My Settings.

next bronze
hallow kiln
high hearth
#

Wierd. I cant find the identifier in the settings.

next bronze
high hearth
#

Ah. Perfect! Thanks!

next bronze
thorn urchin
#

its an extension

hallow kiln
thorn urchin
#

helps reading, esp for some types of dyslexia or adhd

hallow kiln
#

yup

next bronze
#

oh didn't know that, interesting

hallow kiln
#

there's some legit research on that and a special paid app for that lmao

#

but the extension is unrelated and free

#

don't reveal your token here

#

you need a / before the identify command

deep dune
#

sorry

hallow kiln
#

it's unique and personal to you alone

deep dune
#

but every time I wrote this "/" I get some kind of an error/warning

deep dune
deep dune
#

Thanks

hallow kiln
#

nice

umbral fulcrum
thorn urchin
#

Theres no identifier dupe protection so someone can steal your identifier and impersonate your account with an alt ๐Ÿ™‚ which could lead to your htb account getting banned on accident

umbral fulcrum
#

what is DA?

thorn urchin
#

Domain Admin

umbral fulcrum
thorn urchin
#

If thats a user you have access to is a DA then yeah

#

I was asking you a question, Im not psychic ๐Ÿ˜‚

#

If you have a DA user you can DCSync to get the DC admin hash. If THAT cant get shell then nothing will.

grand marsh
#

Getting error no available instances on all pwnbox locations

high hearth
#

Any recommendations on the best Linux system to install?

next bronze
#

if you're using it for hacking, parrot or kali

next bronze
high hearth
#

Thanks! @next bronze

grand marsh
#

is there like a server status page to check or is that a non-standard situation?

mystic spade
grand marsh
#

Gigachad

fringe crystal
#

Hey, guys, has anyone done "Credential hunting in Linux" section of the module "Password attacks" ?

thorn urchin
#

Nope youre the first person to ever attempt it, congratulations!

fringe crystal
#

I got it. Basically I was trying the username Kira (as the hint was saying ---> sudo hydra -l Kira -P mut_Kira_password.list -T64 ssh://10.129.202.64

#

But instead it should have been "kira"

#

Maybe the hint should be slightly modified ๐Ÿ˜…

fathom pendant
fringe crystal
#

Yeah should be ftp

#

Thanks I learned something new

fathom pendant
#

Hint gives you a person's name, often in linux environments the username will be lowercase

fringe crystal
#

I will keep in mind

fathom pendant
#

It's called using your noggin

fringe crystal
#

Yeah but sometimes when you try many things without success, your noggin works less and less

#

after a break it starts working again

thorn urchin
#

idk sometimes I find a weird sense of inspiration and insight when in the absolute pits of despair

fringe crystal
#

Same here

silk atlas
#

Pwnbox seems to be back up

fringe crystal
#

By the way, I am doing the penetration tester path and enjoying it so much

#

It's really well done

final mica
#

could anyone help with footprinting lab -hard?

analog dock
final mica
#

i found the private key

#

trying to ssh

#

asking for password

thorn urchin
#

what makes you think that key is for the root user

analog dock
#

Chmod 600 id_rsa

final mica
#

i did chmod 600

#

i tried bob and tom from the email

thorn urchin
#

its not root

analog dock
#

Where did you get the ssh key from

final mica
#

root was the last thing i tried

analog dock
#

From the mail?

final mica
#

yes

analog dock
#

Private key could be used to ssh to root

#

Are you sure the format of the key is correct? @final mica

thorn urchin
final mica
#

โ”Œโ”€โ”€(rootใ‰ฟkali)-[~/.ssh]
โ””โ”€# ls -la
total 20
drwx------ 2 root root 4096 Nov 28 16:26 .
drwx------ 9 root root 4096 Nov 28 16:26 ..
-rw------- 1 root root 3381 Nov 28 16:24 id_rsa
-rw-r--r-- 1 root root 563 Nov 27 16:42 id_rsa.pub
-rw-r--r-- 1 root root 710 Nov 28 16:03 known_hosts

analog dock
#

Itโ€™s in my notes

thorn urchin
#

mmkay

analog dock
#

Looks weird

#

And you run as root

#

๐Ÿ˜ฐ

final mica
#

yea this is just where i ended up at because it seems like i tried everything

#

๐Ÿ˜ฆ

analog dock
#

Anyways, check if the key format is correct

#

You donโ€™t need the key in your own ssh directory

#

Just copy the one you get from the mail

final mica
#

ohh

analog dock
#

Make sure itโ€™s in correct format

#

And use that

fringe crystal
#

@final mica Once you get the SSH key from the mail, save it as key.txt. Then rename key.txt as mykey.pem. Then chmod 600 mykey.pem

#

then, ssh -i mykey.pem tom@

final mica
#

okay thank you i will try

fringe crystal
#

No problem. Footprinting is no joke ๐Ÿ˜‚

#

It took me some days

next bronze
#

<@&861185840277487616>

final mica
#

i dont understand why this worked... i had the key in id_rsa file and tried to connect the same way

west rampart
#

damn, my BTC gone

jolly cradle
analog dock
#

Mine too

#

Smh was about to get rich

west rampart
#

i got scammed by @jolly cradle

analog dock
#

Who deleted

#

Thanks for ruining my life falcon

west rampart
#

yes

#

i could be rich now

jolly cradle
#

You're welcome

west rampart
#

thank you so much

jolly cradle
#

If you send me about 5 SOL I will triple it in the next 15 minutes only.

high hearth
#

@next bronze question... How do I connect the ovpn to my VM? I installed Kali on VirtualBox.

west rampart
jolly cradle
next bronze
fringe crystal
# final mica i dont understand why this worked... i had the key in id_rsa file and tried to c...

The .pem (Privacy Enhanced Mail) format for SSH private keys is often recommended for a few reasons:
Compatibility and Standard Format: The .pem format is widely recognized and compatible with many different types of software and systems. It's a base64-encoded format that includes the key itself along with additional information like the type of key, encryption algorithm used, and sometimes comments. This makes it versatile for various applications, including SSH, SSL/TLS, and other cryptographic needs.
Security: .pem files can store both private and public keys. They are often used for secure transmissions and can be password-protected for additional security. This means that even if someone gains access to your .pem file, they would still need the password to use it.
Ease of Conversion: If you have a key in another format, it's generally straightforward to convert it to .pem format using tools like OpenSSL. This flexibility allows you to use the same key across different systems and applications that may require different formats.
AWS and Other Cloud Services: Many cloud services, like Amazon Web Services (AWS), use the .pem format for SSH keys to access virtual servers (like EC2 instances). If you're working in a cloud environment, using .pem files can make it easier to manage and deploy keys.
Support for Different Key Types: The .pem format supports various cryptographic algorithms, including RSA, DSA, and ECDSA. This means you can use it for different types of keys, depending on your security requirements and the systems you are working with.
When using SSH with a .pem file, you typically specify the private key file with the -i option in your SSH command, like so:
ssh -i /path/to/key.pem user@hostname
This tells SSH to use the provided private key for authentication instead of looking for the default key in the ~/.ssh directory.

next bronze
#

holy wall of text

fringe crystal
west rampart
#

good night HTB

final mica
#

thank you

fringe crystal
#

good night ๐Ÿ˜ตโ€๐Ÿ’ซ

fringe crystal
analog dock
west rampart
#

you need to guess the correct address

jolly cradle
#

May the odds ever be in your favor

analog dock
jolly cradle
#

(should take like 10sec even with a potato gpu and hashcat)

#

or even jtr

fringe crystal
thorn urchin
next bronze
high hearth
fringe crystal
#

Ok ... But then I will just give a short and not exhaustive answer next time ...

thorn urchin
#

Yeah, and?

jolly cradle
fringe crystal
thorn urchin
#

chatgpt output is useless because if someone wanted a chatgpt response they can just use it themselves. Youre providing no additional insight to the matter.

next bronze
fringe crystal
rustic sage
#

can someone help on module 49. Identify one of the non-standard update services running on the host. Submit the full name of the service executable (not the DisplayName) as your answer.I have tried running Get-Process | select-object Processname, id but am not sure what non-stanard update service to ook out for. I am not familiar withall of them

fringe crystal
#

What is module 49 ?

rustic sage
fringe crystal
#

Uh, I still have to do that

rustic sage
#

xD

next bronze
thorn urchin
#

when in doubt start googling

rustic sage
high hearth
#

is telling me to enter this instead: openvpn /path/to/NameHere.ovpn
I also tried: sudo openvpn /path/to/NameHere.ovpn
and: sudo openvpn NameHere.ovpn

#

But it wont work

#

@fringe crystal

thorn urchin
gray merlin
#

Are you entering that verbatim? Or is NameHere replaced with the name of the ovpn file?

thorn urchin
#

and for that matter did you specify the right filename

high hearth
fringe crystal
rustic sage
#

guess its FoxitReaderUpdateService even though Foxit reader is a pdf editor

thorn urchin
#

you just gotta supply the path of wherever you put the file

fringe crystal
#

once it is into home/kali, then open the terminal and type sudo openvpn academy.ovpn

high hearth
#

Ah I missed that part.

rustic sage
thorn urchin
#

i usually leave them in downloads and just do sudo openvpn ~/Downloads/madf0x.ovpn

fringe crystal
#

it is easier if you put into home/kali because by default the terminal opens up in home/kali

next bronze
thorn urchin
#

Realistically if thats easier you should probably be doing linux fundementals first instead

fringe crystal
next bronze
rustic sage
thorn urchin
#

no

#

.exe refers to the PE executable file type. Its Microsoft windows exclusive

#

not counting emulation shenanigans or polyfiles

next bronze
# thorn urchin no

acktually if you have wine installed you cause run exe on mac ๐Ÿค“

thorn urchin
next bronze
#

damnit too slow

rustic sage
#

anyone else have a stuck taskbar? on windows at times even wiht autohide enabled

high hearth
#

@thorn urchin I am so sorry, but nothing works. I tried these:
sudo openvpn ~/Downloads/name.ovpn

#

and: sudo openvpn kali/Downloads/madf0x.ovpn

#

nothing works ๐Ÿ˜ฆ

next bronze
#

first thing, you need to know what your ovpn file's name is, you can't just copy exactly what the others have used, where did you download the .ovpn file to?

high hearth
#

Downloads

next bronze
#

okay, now run ls ~/Downloads, what's the name of the .ovpn file?

thorn urchin
high hearth
#

So, do I have to enter that whole name like it shows on the file?

next bronze
#

well there you go, use that name in your sudo openvpn command

high hearth
#

Ok. I was doing what the "Pending COnnection.." message was saying. But, let me try it this way

thorn urchin
#

That is the way its telling you

#

you just have to supply the full filename, its not psychic and doesnt know what file youre referring to until you tell it

high hearth
#

Alright! Thanks!
but this is very different than what you guys told me though

thorn urchin
#

I dont understand why you think its very different

#

you gotta supply the correct file name. That image is just using placeholders

high hearth
#

Alright! I understand now. I'll keep that in mind going forward. Thank you again.

thorn urchin
#

I used madf0x.ovpn because thats what mine is named lol

next bronze
#

you might want to start with the linux fundamentals module

thorn urchin
quasi wave
#

I'm trying to log into samba share on last section of Enumeration with Nmap module. I'm past the Nmap part and need help with figuring out the password

#

to the samba share

#

so I can log into it

#
โ”Œโ”€[us-academy-1]โ”€[10.10.14.144]โ”€[htb-ac-605555@htb-5rribmwn0c]โ”€[~]
โ””โ”€โ”€โ•ผ [โ˜…]$ smbclient //10.129.2.47/ -U us-academy-1
#

I tried adding in -L

#

and sudo

#

and its not working

fathom pendant
quasi wave
fathom pendant
#

When you do -L it lists the shares

quasi wave
#

I did that but it won't let me see the shares

fathom pendant
#

Also the user won't be us-academy-1

quasi wave
#
โ”€[us-academy-1]โ”€[10.10.14.144]โ”€[htb-ac-605555@htb-5rribmwn0c]โ”€[~]
โ””โ”€โ”€โ•ผ [โ˜…]$ sudo smbclient -L //10.129.2.47/
do_connect: Connection to 10.129.2.47 failed (Error NT_STATUS_IO_TIMEOUT)
#

ok hold on

#
โ”Œโ”€[us-academy-1]โ”€[10.10.14.144]โ”€[htb-ac-605555@htb-5rribmwn0c]โ”€[~]
โ””โ”€โ”€โ•ผ [โ˜…]$ sudo smbclient //10.129.2.47/ -L
Password for [WORKGROUP\root]:
fathom pendant
#

Just hit enter

#

It'll still show shares

quasi wave
#

I did and it didn't show any shares

#

there's something off here

fathom pendant
#

The section tells you some things to try

fathom pendant
quasi wave
#

ok hold on

fathom pendant
#

There's another flag to basically skip asking for a password

quasi wave
#

oh wow

fathom pendant
#

Also this section doesn't need smb login at all

#

The flag is a banner you get when you connect to the port

#

So, rescan the target - your only hint is non-standard

gray merlin
#

-N - don't ask for password.

bright quiver
#

Anyone know why or how to remedy this issue for the footprints lab - medium?

thorn urchin
ebon canyon
#

hi, im working on the live engagement for Shells & Payloads and every time i RDP into the foothold machine it times out and stops responding to pings

#

it was working completely fine yesterday, but now whenever i RDP in with the target IP it lets me into the machine, then a few seconds later it freezes up and the connection times out

#
โ””โ”€$ xfreerdp /v:10.129.247.64 /u:htb-student /p:HTB_@cademy_stdnt!
[22:38:13:381] [16214:16215] [INFO][com.freerdp.gdi] - Local framebuffer format  PIXEL_FORMAT_BGRX32
[22:38:13:381] [16214:16215] [INFO][com.freerdp.gdi] - Remote framebuffer format PIXEL_FORMAT_BGRA32
[22:38:13:396] [16214:16215] [INFO][com.freerdp.channels.rdpsnd.client] - [static] Loaded fake backend for rdpsnd
[22:38:13:397] [16214:16215] [INFO][com.freerdp.channels.drdynvc.client] - Loading Dynamic Virtual Channel rdpgfx
[22:38:40:031] [16214:16215] [ERROR][com.freerdp.core.transport] - BIO_read returned a system error 110: Connection timed out
[22:38:40:031] [16214:16215] [ERROR][com.freerdp.core] - transport_read_layer:freerdp_set_last_error_ex ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D]
[22:38:40:031] [16214:16215] [INFO][com.freerdp.client.common] - Network disconnect!
#

I've reset the target like... 5 times and it's the same result every time, I even got myself a fresh VPN file

#

ok i swapped my VPN file from UDP to TCP and it seems to be working now, please disregard

vast geyser
#

hello, Could anyone know this question format?

rich perch
#

Hello, I'm stuck on skills assessment question 1 of 'Intro to Assembly Language'. I've worked through and I think I have the correct decoded shellcode, but it doesn't work. When I run the shellcode, it just returns a weird red dollar sign and exits when I try to type anything. This is the code I added to the nasm code to iterate and xor the shellcode:

mov rcx, 14
lea rdx, [rsp]
loop1:
xor [rdx], rbx
add rdx, 8
loop loop1

Here is the shellcode I'm getting:

48bbe6714831c05044215348167e66af7c7ab51bbba72346bf264d344c5348bb5348bb9a4bb67743e771125310633620214d14d248bbd244c980c10444214831311f48834889e7484831c0b0c708e2f740b70148014831ffe64831d231f648894831c048b21e0f0531ff0f0583c03c48

I don't understand what I'm doing wrong, can someone help me? Thank you!

fathom pendant
next bronze
#

lol that question was phrased incredibly confusing, I've been using tmux for a number of years and it still took me a while to get it

rich perch
quasi wave
#

hi does anyone recommend a dns brute force domain list?

#

I'm using the DNS brute script or DNS Zone Transfer

slate creek
#

Can you please help me with this? I found 2 rights in bloodhound as well but cant clear the question.

fathom pendant
next bronze
#

and you can do the whole thing in cyberchef btw, there are a few steps but basically reverse the bits and xor it

misty current
quasi wave
hot saffron
#

has anyone gotten the options error cmd line 1 when opening openvpn? The file isnโ€™t corrupt, I updated the openvpn reinstalled the parrot os. Not sure what else to try

fathom pendant
hot saffron
#

Yes

fathom pendant
#

What's the full error?

hot saffron
#

Give me a sec Iโ€™ll show the terminal

fathom pendant
#

You won't be able to paste a screenshot until you verify your main account following #welcome

hot saffron
#

Options error: In [cmd-line] :1: error opening configuration file lab.ovpn

fathom pendant
#

Is it named lab.ovpn?

#

Are you in the same directory as the file

hot saffron
#

Yes an yes

#

Ls downloads then copy verbatim

fathom pendant
#

Are you using absolute or relative path

#

If you're in the same directory you don't need to specify path

#

And the website uses /path/to/ as a placeholder

hot saffron
#

Yea once I open download dir. I sudo openvpn lab.ovpn

#

Worked in past now I get the error

fathom pendant
#

That error usually means that it doesn't exist

hot saffron
#

I used killall openvpn command to

#

Make sure nothing was in use

autumn pilot
#

please keep the channel on topic

hot saffron
#

This is off topic?

autumn pilot
#

Fixing error messages related to the VPN is unrelated to the channel's intent

austere osprey
#

On the Attacking Common Services - Medium, do we have to get ftp access on port 2121 via brute force / anonymous access?
Just afraid I'm wasting time so would be nice to know if it's the wrong way lol (say nothing more than that of course! no spoiler!)

fathom pendant
austere osprey
fathom pendant
austere osprey
fathom pendant
#

Also their password is weak if you wanna try a smaller list first

austere osprey
#

Sounds good, I'm afraid from their brute-force so the real password won't be in the list lol

fathom pendant
#

All g

short hare
#

Stuck on AD Enumeration & Attacks - Skills Assessment Part I

Question:
Take over the domain and submit the contents of the flag.txt file on the Administrator Desktop on DC01

I have creds of svc_sXX and tpXXXX. Done rdp to svc_sXX and explored but didn't found a way to get to DC01

Can anybody help?

Just on the verge of completion of the module ๐Ÿฅฒ

umbral fulcrum
#

hey guy, I'm stuck on last 2 Q in AD second assessment to long,
don't know what I missed ...

need a little nudge please

next bronze
#

@short hare @umbral fulcrum check what rights the user has, you don't even need to check bloodhound, the question clearly tells you that, go back the the previous sections to find out what you can do with those rights

short hare
patent whale
#

Hello! Could anyone help me with the Attacking Common Web services module? At PRTG right now and no matter what, I cannot get a RCE by notification abuse. Tried different payloads, no result so far.

next bronze
narrow solar
#

for the 5th day, can anyone please help me, i am at Broken Authentication username injection, tried to add the userid field but didnt work because of the oldpass doesnt match, tried to fuzz it, tried remove it, tried to change to GET method and changing the submet, but no luck so far

candid lily
#

which is best tier 3 module? i can get only one with student sub so i want it to be worth it

candid lily
candid lily
#

when you reset your password

patent whale
candid lily
#

what have you tried so far

#

@patent whale

patent whale
# candid lily what have you tried so far

Tried the payload as shown in the module, and the original CVE blog. Tried | instead of ;. Tried creating the user and adding him to the administrators group, tried to just create aa user (single command). Tried pinging back, while tcpdumping icmp.

candid lily
#

';' works fine

#

which payload did you use

#

try to get a reverse shell

patent whale
#

Tried || test.txt;net user prtgadm1 Pwn3d_by_PRTG! /add;net localgroup administrators prtgadm1 /add ||, tried username and pass without any special chars (in case they break sth.). I wanted to try ping and the reverse shell would be the next step.

candid lily
#

try the reverse shell

patent whale
#

Maybe icmp is firewalled from the box.

#

Will do

candid lily
#

icmp works too

#

you are making a mistake probably

patent whale
#

That's the thing, I was not able to catch ping back, so I didn't move on to reverse shell. Will try hrader. ๐Ÿ˜„

fathom pendant
candid lily
#

what is your opinion then

fathom pendant
#

I haven't done any so couldn't tell you, but I'd pick one that's related to something that interests you

patent whale
#

@candid lily Tried 3 different PS reverse shells, no success.

candid lily
#

i want to pick one which has no other sources to learn

#

did you get icmp to work

patent whale
#

Nope. That's why I suspect no RCE is happening.

candid lily
#

maybe the problem is where you are injection, try to get icmp work, have a look at the CVE before it

patent whale
#

I did. And used the same payload.

candid lily
#

try using base64 ps revshells

patent whale
#

Tried already.

#

If I cannot get ping working, maybe I am not executing anything.

candid lily
#

are you sure thats your right ip ๐Ÿ˜…

candid lily
#

you have to click the bell icon

sly dome
#

through PRTG authenticated RCE you should be able to get a reverse shell or a ICMP trace (if enabled and allowed by both firewalls)

#

payload: abc.txt | <command here without special characters>

#

probably the dots are messing your command you can always use decimal notation for the ip

#

ping 168431491 = ping 10.10.15.131

#

tell me if need further assistance @patent whale

patent whale
#

Tried the searchsploit, got the script, grabbed the cookie, the script executed successfully, user not created...

#

Also, tried to get the ping using | and trying decimal IP notation. No callback.

#

Reverted the machine, no success.

fiery berry
#

in case you didn't yet...

patent whale
#

Metasploit worked like a charm. Now to analyze what has been happening.

narrow solar
visual ruin
#

Hi All, I am new to HTB academy. Can someone guide me. How can I know what is the right answer for a question in a module?

candid lily
candid lily
visual ruin
#

For example, โ€œwhat is the name of the first section of the module?โ€ My answer is โ€œInteractive Sectionโ€. But I am being told it is wrong.

candid lily
visual ruin
candid lily
#

you could find answers but you shouldnt

#

you should come up with the answer yourself by reading the content and doing some critical thinking

candid lily
visual ruin
#

Thank you

#

So can someone please provide a hind to very first question? What is the name of the first section of the module?

narrow solar
visual ruin
#

My answer is not working

candid lily
#

reset the machine and try again

narrow solar
#

omg ๐Ÿ™†โ€โ™‚๏ธ i thought that it wants the old pass for htbadmin, wow ๐Ÿ˜‚

#

thank you so much

candid lily
candid lily
#

i just retried it a while ago and i got the ping

patent whale
#

OK, Metasploit works, it uses ; and a command (base64 encoded meterpreter reverse shell in powershell). I did the same thing, just with plain tcp reverse shell. Not sure what I did wrong though.

subtle flicker
#

hello is someone having issues with Proxy Error in Attacking enterprise networks? I am trying to enumerate and login into ||blog.inlanefreight.local and ir.inlanefreight.local|| but i keep getting this error and it's frustrating because i'm not sure if i am doing anything wrong or it's the service having problems

fiery berry
subtle flicker
#

The thing is also enumerating is difficult because of that, i'm sure a set of creds is right because i was one time able to go further the login page but eventually it got stuck again with that damn error

#

For example || drupalscan || kept getting me 500 internal error when i ran the tool, i got results but i hardly believe they are reliable ones

royal grove
#

uhm guys

#

im new here wht am i supposed to do

unique palm
#

I am stuck on the "Password Attacks" Module on the section "Credential Hunting in Linux". Can someone give me a hint on how to get a foothold in the machine ?

harsh moat
#

do u know how to convert Certipy to a single .exe file? pyinstaller doesn't work with this

#

In certain env, python is not available and it's good to have a backup

manic terrace
#

Hi, I'm having trouble with the Nmap Scripting Engine question under the Netwrok Enumeration with nmap
I can find what I think is the vulnerability, but I am unable to get the flag. I use the line:
sudo nmap [target ip] -p 80 -sV --script vuln
to see
| http-enum: |_ /robots.txt: Robots file
but it doesn't give the flag that the question is asking for

fiery berry
hallow kiln
#

and what does this have to do with the modules

manic terrace
hallow kiln
#

just use the browser

sly dome
#

but without showing proofs is kind of difficult to debug

#

i tried and ping works with both notations

manic terrace
hallow kiln
#

By just browsing to IP/robots.txt

manic terrace
hallow kiln
#

How do you go to Google? Sure, not by the IP, but it's the exact same thing

manic terrace
#

oh, i didnt realize that was a capability! I see it now. Thank you

pale atlas
#

ur local ip address e.g. 192.168.0.1

192.168.0.1/robots.txt

slate creek
#

Hi All, Stuck at Active Directory DCSync, second Q, What is this user's cleartext password? I try secretsdump from my kali using
impacket-secretsdump -outputfile inlanefreight_hashes -just-dc-user syncron INLANEFREIGHT.LOCAL/adunn@172.16.5.5 get an error connection refused.
tried mimiktz after runas.exe :
mimikatz # lsadump::dcsync /domain:INLANEFREIGHT.LOCAL /user:INLANEFREIGHT\syncron but still can't see anything. I feel like I am doing something very wrong ๐Ÿ˜„ need some tips here thank you.

slate creek
real summit
#

Evening guys,
Module: Shells & Payloads -> The Live Engagement
RDP machine is super slow or it's just me?

hollow steppe
#

guys anyone know ? how to locate phone location using IMEI number??

thorn urchin
#

also IMEI is just a serial number, you cannot get location from it. Only carrier lock status.

hollow steppe
thorn urchin
#

I just said so

#

unless youre the gov ofc

sly kelp
#

Well Well Well

#

what are the rewards

vital elk
#

Pretty soon THM won't have anything unique

sly kelp
#

also guys it gives you special rewards

acoustic owl
sly kelp
#

let me check

acoustic owl
sly kelp
#

I guess it is will be aligned with new pathway

acoustic owl
#

I think there will be a Badge

acoustic owl
sly kelp
#

it says rewards

hallow kiln
#

I never liked the daily/weekly streak stuff, it just turns it into a chore where you have to leave things unsolved to have a source of points, or have to reset which is not even possible on academy

old plaza
#

But what are weekly goals

hallow kiln
#

It says it there, 30 points

sly kelp
#

i guess 30 rights answers

#

that makes you very hard working and goal oriented to complete modules

hallow kiln
#

Not sure without testing it out, maybe different answers give more based on cube rewards too

acoustic owl
#

30 answers? HTB doesn't have that many modules left for me lol

hallow kiln
sly kelp
sly kelp
acoustic owl
hallow kiln
#

I think it's not, but someone can confirm after they've done it

#

I imagine rewards could be cubes, so that might be worth it, but ultimately, not a big fan

sly dome
#

define weekly goal?

#

30 points

hallow kiln
#

No idea yet it what it means exactly

sly dome
#

xD

sly kelp
sly dome
#

what if you dont have 30 available points in tier 0-2 modules

hallow kiln
#

Sucks to be you, what if you're Bunny and have completed most of Academy period ๐Ÿ˜‚

sly dome
#

HAHAHA

#

they are being racists to ppl who dont have enough content in the academy to be done

acoustic owl
misty current
#

I wonder if points means the cube you get back after you answer a question.

#

Gotta find this thing out.

rustic sage
hallow kiln
#

Or points are assigned based on cube rewards, like 2 cubes back, 10 points or whatever, gotta check it out

misty current
#

Ah, seems like you just gotta answer 3 questions a day.

hallow kiln
#

Each question is 10 points?

misty current
#

Just got 10 points for a question from fundamentals category.

sly dome
#

huge

#

easy then

sly kelp
#

Yeah

hallow kiln
#

Lol, so is the 30 points weekly or daily?

sly dome
#

weekly xD

sly kelp
#

wekkly

#

lmao

misty current
#

Oh weekly.

hallow kiln
#

Lmao, okay

sly dome
#

they made it easy

sly kelp
#

you guys broke the system before it even started

acoustic owl
sly dome
#

for me since im working im finding really hard to have time for the academy

#

sad but im learning from real world

sly kelp
#

it is account toekn delete method if you can not keep up it will delete the account lol

sly dome
#

so im happy overall

sly kelp
#

HTB wildfire edition

misty current
#

Damn, 10+ for marking a section as complete?