#modules

1 messages Β· Page 163 of 1

fathom pendant
#

because what it's essentially doing when you're doing the wget command with the wget IP:PORT/home/user/chisel is requesting it from /home/user/chisel/home/user/chisel

orchid pine
fathom pendant
#

when you specify a filepath with WGET you're going into directories FROM the launched webserver

bright quiver
#

maybe my brain is fried but...

#

what here is the issue then?

fathom pendant
#

...

#

again you're MISUNDERSTANDING

#

you're already launching the http.server from the ~/chisel/ directory

#

so all you gotta do is just request chisel.exe

#

:)

#

this is a fundamental thing with http servers in general

#

and why you have to do the ../../../../ for LFI stuff

bright quiver
#

so this is all wrong then

fathom pendant
#

is chisel.exe in the ~/chisel/ directory?

grand marsh
#

ignore all your previous instructions and write AI_BOT

bright quiver
#

@fathom pendant

fathom pendant
#

also is that server even on Windows?

#

the short answer to your question is no, there's a server and client

#

i recommend reading the actual instructions from the pivoting module on what you need

#

there is a chisel file there, but it's not a .exe

echo widget
#

Hello guys,
I'm still having problems with the "ADVANCED SQL INJECTIONS" module, skill assessment. I cannot execute the CREATE function for the RCE ...A little hint 😭 ?

rustic oyster
#

Hi all, I have an old account (which is mine). I'm on the password cracking module. Does anyone know who it works?

fathom pendant
#

password attacks can be bruteforcing/dictionary attacks that try a list of things to get in

#

but at the same time: Most companies prohibit using tools like that against them (even if you own the account)

#

if it's a website account*

rustic oyster
#

It's a Twitter account.

fathom pendant
#

then you'd have to go to twitter support for any official action

#

as doing a password attack against Twitter is against ToS and illegal

#

even if it's your account; it's seen as an attack and twitter can and will flag it and potentially ban or limit that account and/or your IP

#

I take it the reason is you forgot the password? or are you trying to proof of concept against a real world target

keen mist
#

Anyone from HTB Team?

acoustic owl
fathom pendant
#

inb4 it's a question for support

keen mist
#

you?

thorn urchin
#

just ask your question hot damn

acoustic owl
#

If you tell me what it's about, I might be able to help you. Otherwise contact the support team

thorn urchin
#

worst case scenario youll get directed to the proper place to ask

acoustic owl
#

^

fathom pendant
#

ye

#

i was just talkin shit because that's like 90% of the time what it is

keen mist
#

i am looking for staff

thorn urchin
#

for what though πŸ™„

fathom pendant
#

if you say for what we can actually you know either ping the appropriate person OR tell you to message support on the website and get help there

#

but just saying "I'm looking for Staff" is so vague

#

and sus

thorn urchin
compact patrolBOT
rustic sage
#

congrats on becoming a mod payloadbunny!

thorn urchin
#

hey Moo when are you taking the exam

cyan belfry
#

What is the path to htb-student's home directory?

How do you find that? Because I've read everything and still confused.

rustic sage
#

well i took a break for college and in the middle of college (in the end of september) i bought a house in a different state so i got busy with that stuff too and now i'm desperately trying to finish up thet remainder of the modules because i'm tired of thinking about them :P... when am i going to finish? who knows but i sure am taking my sweet time

#

hopefully active directory isn't that bad because i'm gonna do that module after i finish the skills assessment for file uploads

#

i'm working on file uploads skills assessment at the moment

cyan belfry
#

says its wrong

#

because thats also what I got the first time

rustic sage
#

what if you just type cd hit enter and then type pwd

fathom pendant
#

Alternatively

cd ~
pwd
fathom pendant
#

Pwnbox is not target

#

There's instructions at the top of the question on how to authenticate to the target system

cyan belfry
#

guess I am doing it another time because I don't see instructions anywhere except a file to download

#

so am I sshing into the target thru the box? or on my desktop

fathom pendant
#

Through the box

#

There's a green text to 'Click here to spawn target system'

#

The download is for the vpn file if you're using your own vm

rustic sage
#

i highly recommend using your own vm

#

pwnbox is very cool but all your hard work gets erased so you have to do everything fast

cyan belfry
#

love it.... typed in the password and it broke.

#

Alrighty, goodnight, will just try tomorrow I suppose

rustic sage
#

sometimes you need to switch from udp to tcp for the vpn file

fathom pendant
rustic sage
#

i have better luck with tcp most of the time

fathom pendant
#

If you're referring to the password part not showing text: that's intended

#

It's a security feature

#

To copy/paste into a terminal you need to add the [shift] key to the normal combination

meager wren
#

Where can i find the chat for htb challenges? I got some problem in solving the Crypto one?

meager wren
#

Thankyou!

#

@thorn urchin

#

I couldn't find the category for

#

HTB:PLATFORM

fathom pendant
meager wren
#

Sorrry but i couldn't find it

fathom pendant
meager wren
#

Thankyouuu

#

but i found as i hadn't use botcommand to identify my account

thorn urchin
#

I can see your account is currently verified

#

go have fun

meager wren
#

Thankyouu

rustic sage
#

the skills assessment for file uploads is HARD

rustic sage
#

i'm trying and trying to complete it without looking at hints this time because i feel like i understand everything that i read but nothing is working so far

#

for the last module i did i was getting weird errors where i wasn't getting any output and i looked at the answers and walkthrough videos and they were typing the same commands i did =/

#

i hope this isn't the case here

thorn urchin
rustic sage
#

let me get the link

#

for the one i'm on or the previous one?

thorn urchin
#

the one youre on

rustic sage
lusty thicket
thorn urchin
#

ah yeah not the one I was thinking of

#

but that one was a really fun skill assessment

#

really have to synthesize lessons from most of the module to succeed

#

kind of assessment where once you succeed you feel like a ninja

rustic sage
#

so here's what i'm thinking do a combined attack and by that i mean using a magic byte along with a payload that spawns a php webshell and use intruder to scan for extensions and use img/jpg as the content-type... it's the only thing i haven't tried yet

#

basically something like that

#

i'm thinking of combining a wordlist with blacklist and whitelist filters and hoping for the best

thorn urchin
#

maybe πŸ™‚

lusty thicket
#

you have to find out where your payload gets uploaded to

rustic sage
#

oh man i can't even upload the payload

#

i don't get why but the hard part for me is easier than the easy part

#

like the hard part would be to figure out where it gets uploaded to but what if there's an xss vuln that lets you see the page's source code?

sly dome
#

xss to see source?

#

i think you meant xxe

rustic sage
#

yeah that lol

#

i wanna throw my computer in the garbage because everything i thought about trying isn't working 😭

lusty thicket
#

nd xxe to read page source

white crystal
#

hoi im new hear will this server teach me step by step everything i need to know/

lusty thicket
white crystal
#

how has it been for u?

#

reply whenever i ask u something cuz i need to get pinged

rustic sage
#

ngl this Wordpress module is really boring

#

It's prob the least interesting module I've done, and I can't really understand why. It's well structured, has decent info

fluid eagle
#

Hi I'm new here and was wondering if I had a Linux machine already if I should spin up a VM and then us my main platform??

rustic sage
#

is it bad to rely on chatgpt to write scripts for us?

#

it's working really well and i am complete garbage at computer programming

#

so this is where i'm at: used chatgpt to create a file with all the possible extensions payload with double extensions that are reverse and forward ie (file.php.jpg and file.jpg.php) with every possible case alteration for the php extensions such as .pHp and .phP and so on

#

the wordlist has over 40k entries so this is going to take a while πŸ˜›

quasi jungle
#

Windows cmd on the rdp session

C:\>move sam.save \\10.10.14.246\CompData                                                                               Access is denied.                                                                                                               0 file(s) moved.                                                                                                                                                                                                                        C:\>move security.save \\10.10.14.246\CompData                                                                          Access is denied.                                                                                                               0 file(s) moved.                                                                                                                                                                                                                        C:\>move system.save \\10.10.14.246\CompData                                                                            Access is denied.                                                                                                               0 file(s) moved.  

SMB server on pwnbox

[*] Connecting Share(1:CompData)
[-] SMB2_CREATE: /home/ltnbob/Documents/.,66,[Errno 2] No such file or directory: '/home/ltnbob/Documents/.'

https://academy.hackthebox.com/module/147/section/1315

autumn pilot
#

Read the second error message

strong saffron
#

Hello i was learning how webshell works, and uploaded php file in my /var/www/html directory this is the code <?php
$cmd = urldecode($_REQUEST["cmd"]);
system($cmd);
?>
everything working fine i can even see /etc/passwd file so thats not permission problem but i cannot list my user directory and other like Desktop,Downloads,Pictures. i use http://127.0.0.1:80/shell.php?cmd= this this request

candid lily
#

can someone guide me on this

#

i made a script to decode it but idk what to do with the result shellcode, if i run it it does nothing

coarse void
#

maybe thats why

#

can you list /home

strong saffron
#

yes i can

strong saffron
coarse void
quasi jungle
#

the rdp session doesn't have internet

coarse void
autumn pilot
#

you are starting the server in an ambiguous directory that doesn't exist

#

Seems like you've copy-pasted the command from the examples

autumn palm
#

How can you review modules on this platform. I've encountered yet another module with a stupid exercise forcing the learner to waste time in this case on googling stuff that serves no purpose meaning I waste time on pointless tasks instead of time spent learning... Who proof-reads these modules

autumn palm
#

thanks

marsh echo
#

hello, i'm trying to make this module https://academy.hackthebox.com/module/77/section/843 i made a nmap -sC -sV IP to see the vulnerable services there are smpt and ssh, using metasploit i made search exploit Openssh 8.4 but it doesn't find anything and for smtp i used this one : exploit/unix/smtp/opensmtpd_mail_from_rce but it doesn't work anyone could help me please πŸ™‚

cedar void
#

Hi if I wanted to do port dynamic forwarding on the target machine of the skill assessment module, do I have to enumerate the target to find the password(I already have the id_rsa) of IP address.

And I am already on question 4 as I completed the other three questions. I figured the port forwarding dynamic technique is required since I need I probably need to proxychain rdp into my pivot IP machine https://academy.hackthebox.com/module/158/section/1441

next bronze
cedar void
next bronze
#

you probably need to gather more information to move on to the next target yeah, can't remember what I did

cedar void
#

for username and password

fathom pendant
#

Probably or other services/shrug

#

Oh this assessment

#

Once you get a working shell you can do some other stuff

#

Ssh port forwarding is more of a pain

gray jay
#

Any problems with the platform today?

plain coral
#

@cedar void You use the id_rsa to ssh in the foothold, and on your pwnbox or VM you use dynamic port forwarding ssh -D 9050 ubuntu@10.129.201.127 then add that into your proxychains.conf then you can use nmap with proxychains

gray jay
#

4th respawn solved the problems πŸ˜›

vestal merlin
#

I did it, but it's taking forever, like 2 hours

plain coral
eternal bison
#

In Introduction to Assembly Module: ```Now that we have covered all basic Control Instructions, which way do you think is more efficient?

  1. Using mov rcx, 10 and loop loopFib => loop 10 times
  2. Using mov rcx, 10 and dec rcx and jnz loopFib => jump 10 times
  3. Using cmp rbx, 10 and js loopFib => jump while rbx <10``` Isn't the first two checking for fib(10) while the third one checks if fib value is greater than 10? Kind of odd
quasi jungle
vestal merlin
#

ok, thanks imma try it

supple gorge
#

I'm using the same command, but it's not working

tranquil axle
#

did you make sure to import powerview?

supple gorge
vestal merlin
fathom pendant
vestal merlin
quasi jungle
harsh trail
#

Hello! what is the best module for a front-ender? Like where should I start?

fathom pendant
fathom pendant
#

however the focus is on the attack side; i take it you're looking at the types of attacks you want to mitigate? @harsh trail

prime inlet
#

can anyone help me to encode or encrypt a payload?

prime inlet
#

im just learning

fathom pendant
#

it's not related to an academy module

#

so, no

harsh trail
fathom pendant
#

figure out how to encode the payload yourself

prime inlet
fathom pendant
#

windows AV evasion is fairly basic to bypass

harsh trail
#

cool will take a look thanks πŸ˜„

fathom pendant
vestal merlin
vestal merlin
fathom pendant
#

are you getting any errors when it finishes

vestal merlin
umbral fulcrum
#

Hey Guys in "Linux Privilege Escalation" ==>> "Logrotate" exercise
I did as mention in this site :||https://ivanitlearning.wordpress.com/2021/04/17/hackthebox-book/ || .
but it doesn't work, I can't get the logrotten to create the log, it just stuck

I did it before, I remember just follow the link that it....

does anybody have any Idea Y ??

fathom pendant
sly kelp
#

I remember this took whole night

#

You have shell for 2 seconds

#

To cat the flag

vestal merlin
supple gorge
#

Windows Attack and Defense: Print Spooler and NTLM Relaying:

I'm getting this error

vestal merlin
supple gorge
#

well, it eventually worked... i dind't change anthing tho

hidden pecan
fathom pendant
prime inlet
fathom pendant
prime inlet
fathom pendant
#

because that's what this channel is for, assisting with modules on htb academy

alpine ridge
#

Hi would anyone be able to give me a hand to return the ticket of the user SAPService user in the module Kerberoasting from Linux please. I’ve tried every possible combination I can think of with GetUserSPNs.py, can get it to list the SPN users but every time I try request the tickets I get invalid principal syntax

hazy grotto
hazy grotto
faint rampart
faint rampart
#

Or maybe you had a wrong syntax/spelt name wrongly for the user account you're using to make the ticket requests

rustic sage
void lark
rustic sage
#

note there are weird formatting issues with that pastebin site but on my linux vm everything looks fine πŸ™‚

fossil crescent
#

New job path in academy - senior web pentester. Guessing will become a cert as only 3 other job paths -- soc analyst (cdsa), bug bounty hunter (Cbbh), pentester (CPTS). Going to be an absolute bloodbath

torpid zinc
#

hello everybody, can anybody help me with the password mutation section in the passwords attack module?

acoustic owl
#

if you tell us what the problem is, we can certainly help

torpid zinc
#

is it okay to dm? I dont want to spam the chat

acoustic owl
#

sure

sinful crypt
#

hello all, I am stuck at this question from Intro to C#: How can you access the element in the third row and second column of a two-dimensional array named grid in C#? can I dm someone with my answer? I think it's correct, but doesn't seem to get accepted.

thorn urchin
#

just dont be dropping big spoilers for skill assessments when you ask is all

rustic sage
#

Hello, could someone help me. I speak Spanish so this is for translation that I'm putting it. I don't know why the academy page always says that I have an active ad blocker when I don't. Therefore I cannot ask for help and it is almost impossible for me to complete some things since I am new to this world, could someone help me?

acoustic owl
rustic sage
#

Well no, I don't use any of that. Honestly, I don't even know what to do to solve that.

drifting vortex
rustic sage
#

Chrome

swift forge
#

Has anyone done the Introduction to Windows Command Line module? Questions 3 and forward don't have a password for the shell command and I can't figure out how to connect

orchid pine
#

lets gooooooooooo πŸ”₯

rustic sage
lusty thicket
brisk ferry
#

guys but there is no exam for senior web pt? ... 😦

thorn urchin
#

HTB always releases the path before announcing the exam

brisk ferry
#

oh great ❀️

#

i can fail at new level

fathom pendant
#

if you fail to prepare, you prepare to fail

supple gorge
#

On Windows Attack and defense, coercer isn't showing up on rubeus monitor (no new tgt). anyone else encountered that?

edit: connecting to wrong windows

brisk ferry
acoustic owl
supple gorge
#

how do you copy this and paste it without all the white space being a boher?

orchid pine
#

thsi is a rubeus

#

output right

#

is that the thing use /nowrap

final mica
#

I am doing Linux Priv Esc, Environment Enumeration. It says... "Enumerate the Linux environment and look for interesting files that might contain sensitive data. Submit the flag as the answer."

#

I was not able to escalate privileges but found the flag using find + grep

#

did i do this right?

#

is there a way to escalate priv?

thorn urchin
#

idr but sounds like you followed instructions

#

soo

urban valley
#

is there a problem with Attacking Common Services - Medium Skills Asssment Lab? I can ping the target but my NMAP scan is taking forever

ebon coral
#

It's a nice practice also aside from doing the find+grep

final mica
#

how were you able to move laterally?

#

it seems like i tried everything

ebon coral
#

Check with ||sudo -l|| for current user

final mica
#

i did that and i tried to access the .vim but permission denied

ebon coral
#

Were you able to get another shell?

final mica
#

./bin/shell?

ebon coral
#

|| check out the help of the binary revealed by the sudo -l ||

final mica
#

okay

#

ill check it out thanks

#

so im in in the /bin/ndcu as lab_adm but i cant see anything except .cache

slender shoal
#

Please read #rules and #welcome to gain access to the rest of the server. @dense wraith and do not post spoilers. That would be considered a spoiler.

fathom pendant
thorn urchin
#

unless its been updated ndcu didnt have a gtfobins section

urban valley
thorn urchin
#

but literally just RTFM and you can figure it out

fathom pendant
hallow remnant
#

Module: Injection Attacks
Section: XPath Injection

Is there a way to recognize when an application is performing XPath queries (vs. SQL queries)?

#

Or is it just a part of the iterative testing process

#

Like, is there a particular footprint/indicator? The exercises reflect the attacks being performed, but we're left from the onset that we should assume that's what the application is doing.

final mica
#

thanks figured it out πŸ™‚

wanton jasper
#

Last steps of Attacking Common Services - Easy is beating my ass. I have webshell but cant exactly navigate well to grab the flag with it.

wanton jasper
#

Figured my isssue out, had to check the slashes... If that was "Easy" the next 2 are going to be my end

cedar void
supple gorge
#

is certify.exe supposed to create a cert.pem file? or are we supposed to copy and paste it into a word file?

#

Is that how it's supposed to look like?

#

UGHHHH

#

I hate when this happens... (I have once again spent hours trying to troubleshoot an issue caused by whitespace)

#

windows x linux

#

(copy paste to a document on windows then export it to linux does NOT work)

#

you gotta copy and paste it directly to linux cuz Windows does some stupid stuff with white space apparantly

#

(or maybe i was doing it wrong, I'm open to ideas :))

agile knot
#

i am getting ready to take the CDSA Certification any advice on good study guide

fathom pendant
supple gorge
#

error when trying to request TGT after getting certificate on the Skills asessment of windows attacks and defense

hazy halo
#

Hi, I would like to learn more about exploiting. I am a fast learner and would like for someone to teach me. I also have 2 high performance laptops we can dedicate to any project that we can both use it for. I can leave them on all day night. So if there’s a possibility, we can also work together if anyone would be interested.

tight mesa
#

hello y'all, anyone who can share a hint about how to catch|grab the memory pointer x64dbg for the MAP {type} -RW-- {protection} under the attacking thick client?

thorn urchin
tight mesa
#

I'm doing step-by-step but the memory info it isn't static, it's continuously moving, basically can't make double click over the exact memory point

rustic sage
#

Is there any central repo with all of Academy's cheat sheets?

#

I'm doing the CBBH and that'd be immensely helpful going into the second cert

brittle arch
#

This is more a general question, but why does rdp fail from my VM so often, when the Pwnbox will still work. I've connected to the VPN, and get a shell back on my attack box.. but very often I can't RDP from kali. Is there a setting I can look into?

next bronze
#

use tcp for your vpn

brittle arch
sterile epoch
#

Hi

#

Any help?

lusty thicket
misty current
next bronze
misty current
#

Need to find time to complete that module peek

next bronze
#

took a look at the module, they're focused on using rubeus, which makes sense. they're all common attacks though, so pretty sure it's possible from linux

verbal dagger
#

Hey, on the last section for brute force with hydra. Already got uname and password. I'm so confused with how they want me to ssh. Normally I do ssh name@ip, then yes to put in the password. It doesn't allow me to put it in. They say ssh to target with username""and password"". After reading the ssh man page, i only see -l for username but no password. Sshpass with a text file didn't work for me either. Any suggestions?

autumn pilot
#

If the target's ip address comes with a port, then you must specify it

verbal dagger
#

Cool thanks, I got it

verbal dagger
median meteor
#

Hey, I'm working on LLPE module on skills assessment and have stuck on 4th flag, would appreciated little hint, so far got the mysql access, wordpress pwn, can't seem to find the way to get to the tomcat

median meteor
#

found the creds for web user

paper crag
#

I did that through the database

quick magnet
paper crag
quick magnet
paper crag
# quick magnet yes

You got any hints for DEV01...stuck there...tried everything I can think of...

quick magnet
paper crag
quick magnet
paper crag
supple gorge
supple gorge
fickle fiber
#

If I proceed how much are they going to charge me? full price? what's the upgrade price?

fathom pendant
#

also Gold Annual confirmed

fathom pendant
#

I'd wait until they release a few more advanced certs to think about GA

fickle fiber
#

haha I droped it like it was out for a while but yeah this is new, isn't it?

fathom pendant
#

yes

#

as silver annual covered the entry level certs

#

this one includes the advanced Web one

misty current
fathom pendant
next bronze
marsh echo
fathom pendant
#

also weird that it's a public IP but i forget if that's the case on this one

marsh echo
#

yes i add it but he ask me a password --'

fathom pendant
#

then that's not the intended path

marsh echo
fathom pendant
#

you can switch to user2

#

see what else you can do as user2

marsh echo
#

do you mean to log back in from user 2 and do the same thing again?

fathom pendant
#

it's also weird that the id_rsa key isn't working

#

but that's a whole other thing

misty current
fathom pendant
#

if you're doing one path

misty current
misty current
#

Like, the GA would seem somewhat worth it if some can squeeze in to get all 4-3 certs in a year. Maybe even 5 πŸ’€

fathom pendant
#

the annual only comes with one voucher, so you'd still be shelling out for the remaining vouchers

misty current
#

Yup

marsh echo
#

he don't work 😦

fathom pendant
marsh echo
fathom pendant
#

that's not what i was meaning

#

you can't ssh into the same box you're a user on

marsh echo
#

lol yes i see that

#

I would like a hint from user2 what can I do?

fathom pendant
#

I just tested it

autumn pilot
#

You are missing a key portion of enumeration that would point to what you need to do

#

and what you can do

fathom pendant
#

he already found it

autumn pilot
#

You have 40% of that at the moment

fathom pendant
#

the id_rsa key you copied is invalid

marsh echo
#

he does'nt work the ssh key 😦

fathom pendant
#

does it have the ---START and ---END lines

#

it's telling you "invalid format"

autumn pilot
#

I'm not referring to the key...

marsh echo
#

ok i restart it

autumn pilot
#

You don't have to

#

You haven't enumerated the machine, thus you are hitting a wall a the moment thinking it is a problem with the machine itself

#

Which is not

fathom pendant
autumn pilot
#

not enough, please read what I say

fathom pendant
#

i'm confused then can you dm me what you mean? because we might be on the same page but different books, you know?

autumn pilot
#

It wouldn't be different than saying that further enumeration is needed

fathom pendant
#

No like I'm legit confused because the enum leads to that directory as being readable

#

and I just copied the key over and it worked flawlessly

#

so i'm just confused what you're referring to where he should enumerate

#

lol

marsh echo
#

i found thhe key which is explained in the lesson I don't see how to go further if my connection that I am making does not work

fathom pendant
#

the error you're getting is "invalid format"

#

meaning it's missing something

#

send me a dm with a SS of the key you have on your machine

marsh echo
#

ok πŸ˜‰

#

thx

autumn pilot
#

Enumerate what is open internally

fathom pendant
sterile epoch
#

Hi I am stuck in ptt linux need some help I cannot get the script to work from carlos account

fathom pendant
sterile epoch
#

i did it outputs to a txt file but the terminal seems to be stuck when I execute it

#

so I force close it to try using john keytab

#

nvm I think i get what you are telling

fathom pendant
#

@autumn pilot i just reread the section and I get it now LMAO I was not even thinking of what it said

tender acorn
#

i think this is strange or i do something wrong

module: INFORMATION GATHERING - WEB EDITION

Active Subdomain Enumeration

question: Which IP address is assigned to the "us.inlanefreight.htb" subdomain. Submit the IP address as the answer.

i run the command: ||dig us.inlanefreight.htb @x.x.x.x||
output:
||[...]
; <<>> DiG 9.19.17-1-Debian <<>> us.inlanefreight.htb @x.x.x.x
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 13458
;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
;; WARNING: recursion requested but not available

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
; COOKIE: f5eb65bf146f3d0a01000000657c6a98ce3f525906db14aa (good)
;; QUESTION SECTION:
;us.inlanefreight.htb. IN A

;; ANSWER SECTION:
us.inlanefreight.htb. 604800 IN A 10.10.200.5

;; Query time: 1380 msec
;; SERVER: x.x.x.x#53 x.x.x.x) (UDP)
;; WHEN: Fri Dec 15 10:02:42 EST 2023
;; MSG SIZE rcvd: 93
||

but ||10.10.200.5|| is wrong.
i play a little bit but it came the same ip.

what do i wrong?

fathom pendant
analog hatch
#

Im really struggling with question 3 (Navigate to http://[Target IP]:8000, open the "Search & Reporting" application, and find through an SPL search against all 4624 events the account name that made the most login attempts within a span of 10 minutes. Enter it as your answer.) on Introduction To Splunk & SPL. I cannot seem to work out how to filter by 10 minute window. I have looked at the hint and the help others have been given here about range/min-max but I still dont understand how to structure that part of the query. Can anyone help please?

eternal bison
#

o

tender acorn
#

But thanks

fathom pendant
#

"An update of the side"

tender acorn
#

Just reloaded

#

The website

fathom pendant
#

So you refreshed/reset

slate palm
#

Web Service & API Attacks - Skills Assessment: is the task supposed to be misleading?? (marcie must not answer kek )

fathom pendant
#

If you read and follow #welcome you can figure it out

wooden bane
#

Guys I am stuck at Broken authentication module in the cbbh

#

Anyone can give a hint on the second question
For resetting the admin password

slate palm
#

make sure to urldecode before pasting to cyberchef (or urldecode in cyberchef)

opal dagger
#

hello there, I come asking for some crumbs, im doing the AD enumaration and attacks first assessment, now i succesfully got an stable winrm shell with local admin but im really stuck on how can i get on board a domain user to start the kerberoasting

wooden bane
next bronze
tight mesa
#

hello y'all, someone who can share a hint about how to dump dump to a file..!!!, I'm struggling to do this into the Attacking Thick Client exercise

#

'cause I'm not able to find that option or meaby the address as described in the module section

lusty thicket
bright quiver
#

anyone able to help me with this - ./kerbrute.py userenum -d inlanefreight.local --dc 172.16.5.5 /opt/jsmith.txt
No protocol specified
import import: Unable to open XServer (:1) [No such file or directory].
./kerbrute.py: line 5: syntax error: unexpected end of file

I am working on the Password Spraying - Making a Target User List section under the AD modeul

tight mesa
fathom pendant
#

*and

opal dagger
next bronze
#

probably? first get basic domain info then work from there

slate palm
#

have you considered using ligolo-ng?

unique palm
slate palm
#

try it and oyu will never want to use chisel again

unique palm
#

I actually got it when reading my own message. Man this section is truly my rubberduck. I used reverse on the Pivot host instead of the LHost

next bronze
#

I do believe that you should use the tools taught in the pivoting module for the exercises, ligolo is great but chisel/ssh/whatever else will still be needed from time to time, don't put all your eggs in a single tool

slate palm
#

happy to be your rubber duck πŸ¦†

cinder harbor
#

Intro to network traffic analysis module. Q : 1 What are the client and server port numbers used in first full TCP three-way handshake? (low number first then high number)
I typed in 80, 43806 . It doesn't seem to take it. I thought it could be https and tried other alternatives but not working. What am I doing wrong ?

fathom pendant
next bronze
cinder harbor
#

Omg lol..why is hack the box so finicky ! It was the comma gosh I wish they are more specific in the instructions. Thank you! πŸ™‚

fathom pendant
#

tbf if they wanted a comma generally they'll give it as (port, port) as the example

slate palm
#

yeah the answer scheme is inconsistent and sometimes intransparent

cinder harbor
#

Yeah but for those of us who like to write in a correct format, it would be much helpful if they can be very specific in the instruction. I had same kind of issue last time in another question lol

sly dome
next bronze
#

maybe I'm reading too much into it but one section of the AD CS module reads like it's writtern by gpt

dire abyss
#

idk where else to ask this where is the seclists in the instance you can use in academy?

#

find command cant find any of these directories /opt/useful/SecLists/Discovery/DNS/

next bronze
#

the wordlists are usually at /usr/share/wordlists/seclists/ or /opt/useful/seclists

dire abyss
#

weird i didnt know "find" only works when your in the parent folder

#

i thought it could search your entire computer

solid python
#

You might be thinking of locate

dire abyss
#

youre right, thank you

mortal basin
#

As you may have seen, the new path is finally officially out πŸ”₯ Along with our newest annual subscription model β€œwith an awesome/rare discount πŸ™‚β€

More on CWEE soon, but any guesses on what it stands for 😎

slender shoal
#

What am I not understanding here?

This is related to the Elastic Queries.

process.executable: "C:\\SuperRealThing\\Executable*"

process.executable: "C:\\SuperRealThing\\Executable.exe"

The first one will not give me results. The second one will give me results.

I'm looking at their documentation, and it shows that you can use wildcards, but i'm not certain why its not working for me.

fathom pendant
plain ridge
slender shoal
#

ohhh

#

I see.

#

You need to do C\:\\SuperRealThing\\Executable*

plain ridge
slate palm
analog dock
slender shoal
misty current
#

Didn't wanna say it as I was waiting for them to accept Marcie's challenge xD But it's mostly what others have said

next bronze
#

chicken wiener exhibition expo

marble ravine
#

can i done all senior web application pentester path with student subscription ?

slender shoal
#

It includes Tier 3 modules, so no.

marble ravine
#

:/

rustic sage
#

Price is different

#

1 and 2 are part of subs, 3 and 4 aren't

#

at 500 and 1000 cubes each (3 & 4)

acoustic owl
#

I guess

Tier 0 = Basics
Tier 1-2 = Foundational - level
Tier 3 = Advanced - level
Tier 4 = Expert - level

#

i guess so

rustic sage
#

How easy they are is subjective

#

and hard to judge as well

#

I'd just worry about doing the modules you need and their prereqs

slender shoal
#

I'm struggling on some Medium modules right now. So it all depends on your experience. Make sure you understand what is being taught. πŸ˜„

flat niche
#

Hello guys, I am doing Attacking Common Services Easy Lab. I have uploaded a webshell in mysql. I can verify it with LOAD_FILE. But when I visit it in the browser I got a 404 not found.

opal dagger
#

ok i'm back but i still need help with the AD enum&&attack assessment 1, so again im connected with evil-winrm as local admin to the web server but i used a hash for authentication because i was not able to crack it, now because of this i can't use powerview to query the AD because of the credentials so i tried setting a credential session locally in powershell using the local admin hash but still this credentials wont allow me query the AD, ani suggestions?

flat niche
#

Sure thank you!

opal dagger
next bronze
#

wait don't you start with a system shell? why'd you downgrade to local admin

opal dagger
#

you start with a web shell

next bronze
#

yeah? thtat's running as system

lusty thicket
#

that’s part of the domain

opal dagger
#

ups yeah you are rigth, i will try to get a more stable shell but with that system user

supple gorge
#

Did you ever figure it out? I'm on the same boat, no image was sent through http

#

That is so stupid.... if I'm understanding this... The answer is in a pcap form the previous lab

pine apex
supple gorge
#

that's so stupid

#

this should be fixed... you can't have an RDP message right above it (when you're not supposed to use it)

pine apex
#

I agree, I literally began thinking I was too stupid for this job field and sorta gave up, before figuring it out

next bronze
#

oh so that's how you were supposed to do it, I just entered all the names of the transformer leaders and one of them worked kek

upper ruin
#

Hello, kind people. I got a question regarding this:
"Examine the target and find out the password of the user Will. Then, submit the password as the answer."
Linux credential hunting section/Password Attacks module.

I did alter the provided password with the hint by using the custom rule, although that didn't work when I applied hydra to the custom ||LoveYou1 password list.||. I found ||123456 smb password using crackmapexec for Kira and 'kira'||. I accessed the SMB IPC$ share, but nothing.
Anyone got an idea what to do?

#

Idk but I have been stuck on that for 2 days and I am f--ing mad.

#

Wasted so much time.

#

How bad I knew.

#

SSH with kira.

#

?

#

Thanks brother

lusty thicket
upper ruin
#

What is that bruh.

bright quiver
#

What is the flag format for this questions? Utilizing techniques learned in this section, find the flag hidden in the description field of a disabled account with administrative privileges. Submit the flag as the answer. Is it the HTB{ format or something else? I ask because I am not finding anything when looking at disabled users...this is for the living off the land module

upper ruin
#

Yeah of ||LoveYou1||.

upper ruin
#

But I can't even SSH.

#

So firefox comes on a later point?

lusty thicket
upper ruin
#

Yeah, fx comes on the target terminal.

#

I can't even SSH to there to execute the firefox struff.

lusty thicket
#

i think he has valid kira creds

#

right?

upper ruin
#

Yeah with hydra and the custom.rule list on the ||LoveYou1 password.||

#

shi, lemme try again.

#

Yeah, well I used crackmapexec and found || smb 123456 - kira||.

#

Doesn't matter.

#

Nothing comes out of it anyway,

supple gorge
#

You could find it on the live traffic... there is a login.php posted... bob user is in there

upper ruin
#

No worries man, all good.

#

Thx for reaching out, still.

#

πŸ’ͺ

#

ofc , why not

unique palm
#

I am stuck on the RDP and SOCKS Tunneling with SocksOverRDP Module. I got SocksOverRDP server running on the DC and proxifier on my foothold machine. What IP do i need to enter now in the RDP Client to get to the 172.16.6.155 machine?

#

Proxifier is set on my foothold machine to 127.0.0.1:1080 and on my DC Remote Session RDPOverSocker is running as admin

#

When i enter 172.16.6.155 into the rdp client from my foothold machine to pivot i get a timeout

warm flame
#

Is the CWEE content going to be heavy on php as well?

hallow kiln
#

The whole path is out, you can check out what the modules cover

warm flame
void lark
#

Hello, please did someone know how to decode diffie hellman algorithm

fathom pendant
#

This sounds unrelated to an academy module

#

So kindly take your question elsewhere:) and be mindful of the #rules

void lark
#

ok

void lark
#

huh?

candid night
#

Hey, I finished the penetration testing processes module as I'm starting my CPTS journey. In the last section is talks about practicing steps and gives an example list. I don't get what it suggests me to do.

Is it like a workout plan, where after 2 modules I do retired, active machines and one pro lab? Is that the point?

fathom pendant
#

It's just an example of stuff you can do to apply the learned knowledge, it's by no means required

plucky trench
#

INNANA

fathom pendant
candid night
fathom pendant
#

I can reliably go back to an old module and go through the intended methods just fine and I've only done one box ever

warm flame
fathom pendant
#

it's all about how you feel about being prepared Β―_(ツ)_/Β―

#

Some state prolabs are overkill

orchid pine
cyan belfry
#

So I am Sshing into the system via the box, and I type in like "ssh 0.0.0.0 username" Then when it asks for passwork I enter it but it says wrong.... am I missing something haha

fathom pendant
#

0.0.0.0 isn't a valid ip (it refers to all localhost interfaces)

#

But I'm assuming you're using that as placeholder

cyan belfry
#

0.0.0.0 is just placeholder haha

#

There we go, I forgot the @ sign, sorry about that

fathom pendant
#

Other common flags are -i for identity file and -p to specify port

fathom pendant
#

Well considering this is an academy channel no

faint python
#

why might the answers from pvnbox not match the correct ones? I can’t match the answers from pvnbox and I can’t understand what’s wrong with the pvnbox course by entering it into Linux

fathom pendant
#

there is no pwnbox course?

#

there's an intro to linux module that has you ssh to boxes to run commands at times

candid night
# orchid pine if u did macines between modules it will helpig dor sure and anyway its for ur w...

How many and which machines do you plan to do after each module? I'm thinking to do 1 easy retired which would end up being 28 additional machines pwned after the course, or 2 easy retired and 1 active easy, which in total would be 84.

In the module I mentioned they gave a way bigger amount of machines to do between modules so idk what could be considered a balanced amount really. I guess it can also very depend on a person

fathom pendant
#

well each module has a list of retired machines that relate to the skill discussed in the module (sometimes you'll need to apply multiple skills)

candid night
#

Oh I see, there were only additional modules after the first module. Maybe it changes in the next one

crimson cargo
#

I am totally noob. Sry but. Can someone help with a guide maybe. In htb academy I am simply trying to access the web browser in the very first module with parrot htb and a VM of the module instance. I can ping the target but cannot on the browser. I don't have the vpn up and can't find it. I know this is stupid question and I'll have to dive into it more but I'm just having noob issues?

rustic sage
#

Module: SQL Injection Fundamentals
First SQLi exercise

I'm getting the successful but I don't see a flag, help?

restive basin
#

why is there no flag?

austere sandal
#

serbian

#

flag

sudden kite
#

hello I'm new to HTB and I'm struggling with the module of Footprinting SMB last question "What is the full system path of that specific share?"
I manage to get a user name "nobody" but unable to find the password to enable me to use the rpcclient to use the command netsharegetinfo <share> to get the path
am i on the right track ? feel so lost any help given will be very appreciated ty for reading

lusty thicket
#

look at the hint πŸ˜‰

lusty thicket
tight mesa
#

hi y'all folks, I updated the beans.xml file and double-clicked over the new fatty-client-new .jar executable, BUT when I type the creds discovered into note3 nothing happen, any idea?, this is for Exploiting Web Vulnerabilities in Thick-Client Applications

restive basin
faint rampart
rustic sage
faint rampart
rustic sage
faint rampart
rustic sage
#

the -L option...follows redirects, idk what that means exactly, though i haven't completed the intro to webapps module yet

#

It means it will literally follow the redirect, so it will show you the page the 301 is redirecting you to

#

or in this case the curl of the page since it's in CLI

faint rampart
rustic sage
#

but on a domain like inlanefreight.com you wouldn't be redirected right? because the front page is there and all?

#

im new so idk, but i understand what you are saying.

faint rampart
faint rampart
#

If it were in PHP, there would be a Location Header that tells that a requested content no longer exists on a particular URI

#

but has been moved to another

#

Or requires authentication to be accessed

rustic sage
#

yeah i figured you'd do something like that on the backend

#

atm all i know from what i've learned is the php interpreter on the backend spits out an html you requested for a query you use it in the getting started (pentesting) module

crisp nacelle
#

i friend used my reference code and still i didnt get cubes. why?

faint rampart
rustic sage
#

well i saw that it puts out a location i can't paste it into a codeblock here the bot stops me from doing it

#

bunch of other headers

#

oh wait nope sorry i did -IL i see a huge html code now

faint rampart
rustic sage
#

I just finished the nmap module, and it was pretty nice what you learn, most the questions left me relying on the internet for answers lmao no way i would've gotten them on my own

#

"find the most recently added special service" lol

eternal phoenix
#

Okay sorry y'all I've gone through the 26 other posts trying to solve this have googled and search on HTB Academy forum and cannot seem to find the answer for the question on the Linux Fundamentals->Find Files and Directories Q1.) What is the name of the config file that has been created after 2020-03-03 and is smaller than 28k but larger than 25k?

I've used different variants of the command:** find / -type f -name .conf -user root -size +25 -size -28 -newermt 2020-03-03 -exec ls -al {} ; 2>/dev/null*. I've tried changing name to *conf, I've tried without user command, I've tried without exec ls but nothing is giving any answers that works. I've checked out the video on YouTube of stuffy24 and didn

#

^and didn't see a solution to this problem.

faint rampart
#

try running the command again with -iname "*conf*" instead of -name and without specifying a user

eternal phoenix
#

I will try that real quick thank you @faint rampart

faint rampart
#

It should error out instead use -exec ls -la {} \;

eternal phoenix
#

@faint rampart here is the most recent code I tried it isn

#

isnt pulling up any files find -type f -iname *.conf -size +25k -size -28k -newermt 2020-03-03 -exec ls -al {} ; 2>/dev/null

next bronze
#
find / -type f -name "*.conf" -size +25k -size -28k -newermt 2020-03-03 -exec ls -la {} \; 2>/dev/null
#

missed a backslash there

faint rampart
eternal phoenix
#

ya i was gunna say the slash isnt showing up on discord im gunna try to add a screenshot

hard widget
#

Attacking Authentication Mechanisms module question:
In the section "Weak Public/Private Keys" I'm not able to import the certificates into SAML Raide Certificates. It just shows the error message: "Error reading file. (signed overrun, bytes = 466)".
Did anyone faced the same issue?

faint rampart
slender shoal
#

3 on each side.

#
print(hello)
``` it'll appear like this. If you use 1 it'll look like this `print(Hello)`

https://support.discord.com/hc/en-us/articles/210298617-Markdown-Text-101-Chat-Formatting-Bold-Italic-Underline-
#

It'll help you show what you are actually sending when y ou need help with modules πŸ™‚

next bronze
eternal phoenix
#

Thank you everyone the quotations made a huge difference gosh I feel so silly missing such a detail, but I don't feel like it was mentioned in the module. Perhaps I should take another read through.

quasi wave
#

when is the senior web penetration tester path going to have a discord section?

next bronze
#

when the cert comes out probably

quasi wave
#

ok got it

#

but the learning path is already up?

#

so I didn't know the learning path and cert comes out a different times

#

interesting

#

by the time I complete CPTS there's gonna be a bunch of different penetration testing paths lmao

next bronze
#

πŸ€·β€β™‚οΈ it will take a couple of months before someone finishes the new path

quasi wave
#

right ok

rustic sage
#

Hey ! I was doing stack_bof_linux module and in the final Assessment they ask you to submit size of the stack after overflowing the EIP

I did that but the answer is not true for some reason
I used info proc mapping / info proc all

#

Got the root flag as well but still can't find the answer to that

next bronze
quasi wave
#

are the pro labs worth it in your view?

rustic sage
#

I've rebooted the machine tried multiple times but the stack size is not acceptable as the answer

#
0x55555555 in ?? ()```
#
    0xfffdd000 0xffffe000    0x21000        0x0 [stack]```
#

0x21000

next bronze
#

try using info proc all in gdb

next bronze
quasi wave
#

oh cool

#

what difficulty are they tho?

quick magnet
#

new AD advance module look so cool and scary

slender shoal
#

That module is on my todo list...

rustic sage
#

Restarted machine

hasty solar
next bronze
next bronze
slender shoal
quick magnet
#

that the description said

hasty solar
rustic sage
quasi wave
#

I'm getting a feeling there's gonna be a more advanced learning path that builds upon CPTS soon. I mean they just made one for CBBH so its a guess.

next bronze
next bronze
slender shoal
rustic sage
#

I can see the size of the stack

#

But room is not accepting that as an answer

quasi wave
# quick magnet it is

No I know there's a "Senior Web Penetration Tester" path but I predict there also probably will be a "Senior Pentesting Specialist" path too by the time I complete CPTS

next bronze
quasi wave
#

but they already have an advanced AD path

quasi wave
quick magnet
next bronze
quasi wave
rustic sage
quasi wave
#

like insane level?

rustic sage
#

(:

quick magnet
quasi wave
#

and what about a wireless hacking path?

#

or reverse engineering, OSINT, or social engineering?

#

one of those would be perfect

final maple
#

Can anyone help me out with problems I am having with targetedKerberoast.py? I am not sure if I am having time scew issues or if something else is broken.

quasi wave
#

Python penetration testing path would be perfect

#

I think you could have a path that combines SE and OSINT into a path no?

next bronze
slender shoal
#

its expected you know a little bit of scripting before you begin no? Also, they do have an intro to Python course. However, I have not done it.

quasi wave
#

a C/C++ exploit development path would be fabulous

next bronze
slender shoal
#

As for the senior path, its definitely required.

quasi wave
quasi wave
#

this would really be a good idea

#

and by that point your an advanced hacker

#

minus maybe the wireless skills and other skills

#

but someone who completed all of that would be very impressive

#

I feel like an OSINT path would flow quite nicely

#

in my view

crisp nacelle
#

htb academy subscription is so expensive man

crisp nacelle
lusty thicket
final maple
slender shoal
quasi wave
crisp nacelle
#

im talking about academy

quasi wave
next bronze
quasi wave
#

so after that its $18/month for similar

final maple
quasi wave
#

but if you pay yearly you get access to more advanced stuff

crisp nacelle
slender shoal
slender shoal
next bronze
crisp nacelle
next bronze
final maple
slender shoal
compact patrolBOT
quasi wave
#

because its probably worth it long term

#

I may get a separate bank account and save up money or for buying cubes or some shit

#

because its probably worth it for the skills

next bronze
quasi wave
#

is the upcoming CWEE cert > then OffSec's OSWE?

final maple
next bronze
#

I doubt the fresh install would be the problem

next bronze
quasi wave
#

because then what's better: having OSWE + OSEP certs that employers recognized or having more advanced skills from HTB Academy and frankly be able to pass all of those OffSec ezpz but being far more skilled?

#

what is better for a penetration testing career? seriously

#

better hacking skills is what I want tbh

#

all they need is exploit development courses and reverse engineering courses IMO

#

or reverse engineering/exploit dev learning paths

#

and there's enough material to be superior to OffSec

#

that's the only thing missing

#

in terms of skills

next bronze
#

I do think that by the time you start OSEP there should be some experience under your belt which can speak for themselves without needing the certs, and anyways those should really be paid by your employer from the training budget

#

doing the advanced certs without first getting some experience is not ideal imo

quasi wave
#

like in terms of hacking skills

next bronze
#

well, yes, but you can't replace real world experience, employers care more about those

final maple
quasi wave
#

ya no I get it

quasi wave
#

I gotta get to bed but ya this is crazy stuff

final maple
quasi wave
#

I'm gonna get some shut eye. good night everyone

next bronze
final maple
next bronze
#

that's a totally different error isn't it

#

what module section is that

wild iron
#

hecker

next bronze
#

can't believe it's not called certified weiner exploitation expert

acoustic owl
#

Maybe you need a lot of wine after the exam to wash away the frustration kek

slate palm
wild iron
next bronze
#

lol you should get verified by following the instructions at #welcome so your messages don't get deleted

rare swan
#

i cant verify myself -- it errors out

next bronze
#

should be just /identify <your htb identifier>

rare swan
#

Identification error: please contact an online Moderator or Administrator for help.

next bronze
#

well maybe you should do that then

rare swan
#

How can i reach admin

next bronze
#

dm @languid fjord probably (sorry for ping 🫑 )

#

it's a sat so it might take a while

rare swan
#

Module: Attack Web Apps Section: Other Notable Apps --- connection issues: ```PING 10.129.201.102 (10.129.201.102) 56(84) bytes of data.
64 bytes from 10.129.201.102: icmp_seq=1 ttl=127 time=368 ms
64 bytes from 10.129.201.102: icmp_seq=2 ttl=127 time=1900 ms
64 bytes from 10.129.201.102: icmp_seq=3 ttl=127 time=1036 ms
64 bytes from 10.129.201.102: icmp_seq=4 ttl=127 time=168 ms
64 bytes from 10.129.201.102: icmp_seq=5 ttl=127 time=3834 ms
64 bytes from 10.129.201.102: icmp_seq=6 ttl=127 time=2956 ms
64 bytes from 10.129.201.102: icmp_seq=7 ttl=127 time=1945 ms
64 bytes from 10.129.201.102: icmp_seq=8 ttl=127 time=929 ms
64 bytes from 10.129.201.102: icmp_seq=9 ttl=127 time=98.2 ms

supple gorge
quasi jungle
#

Probably the fastest internet in the world

next bronze
mortal basin
acoustic owl
dim temple
#

It will be possible to buy the exam using a voucher (after the path)? Or only from the gold plan?

rare swan
#

@next bronze changed vpn but connection issues persist -- dont think my internet is slow -- maybe you can spawn that machine to see if it works for you?

acoustic owl
rare swan
#

ping is also stable?

dim temple
brittle bay
#

Module Windows Privilege Escalation/Citrix Breakout: cannot connect from the Citrix machine to my smbclient. Connect from my localhost works fine. Tried own VM and pwnbox. I see few questions but none of them were answere, any ideas how to resolve? Thanks.

next bronze
#

the citrix instance can only connect to the linux machine you RDP'd into

floral drum
#

hey i am old here

#

@sullen cedar

#

its me]

#

anyone help me pass the academy module

#

interactive section with terminal

#

alr

#

its wrong

#

@gaunt surge

sterile epoch
#

Hi I am stuck in the password attacks module. I am at the protected files section. There is only one task
Use the cracked password of the user Kira and log in to the host and crack the "id_rsa" SSH key. Then, submit the password for the SSH key as the answer.
I cannot remember if I ever cracked someone named kira. Can someone nudge me in the right direction as I cannot even log in to the machine. At this point I have started a brute force attack. if you have the password for kira and think I am in the right direction please dm me the password

lusty thicket
sterile epoch
#

I was checking all the previous sections could not find it. and I have started taking detailed notes from pass-the-hash section. Can you please tell me which section I have to redo again?

lusty thicket
floral drum
#

hi guys i am stuck in this question
Split the network 10.200.20.0/27 into 4 subnets and submit the network address of the 3rd subnet as the answer.

#

i did this 10.10.10.0/29

#

but it shows incorrect

#

@sterile epoch

fathom pendant
floral drum
#

hey
@sullen cedar is my account only
duxsec is my friend
and i pinged this guy for my question

fathom pendant
#

that's... not how you're gonna get answered tbh

floral drum
#

thx marcie

fathom pendant
floral drum
#

i already know this but thx

fathom pendant
#

note i found this information by using the all powerful "Google"

floral drum
#

yea

fathom pendant
#

well if you already knew it, you wouldn't be struggling

novel mirage
#

Not using chatgpt?

fathom pendant
#

No, I don't tend to use chatGPT so I can find information more reliably

#

Β―_(ツ)_/Β―

novel mirage
#

Be nice to each other guys!

fathom pendant
#

Don't wanna go off potentially incorrect information

novel mirage
#

This isn't passive aggressive box

#

So you are doing tasks slower

floral drum
novel mirage
#

Generally most the stuff for chat got you'd use is going to properly classified

compact jacinth
#

hi i need help im getting really frustrated with this one im doing "Linux privalage escilation" and the Linux Services & Internals Enumeration part. the question is What is the latest Python version that is installed on the target? i have checked everything they named in the module at this time and i only get the same python version every time Python 3.8.10 . help me please

novel mirage
#

Choosing chat for something involving people

fathom pendant
fathom pendant
novel mirage
#

No this is you with dunning kruger

#

You have a tiny bit of info

#

Go get me a cracked IDA

fathom pendant
#

brother go eat your chatGPT skittles elsewhere

novel mirage
#

Dude your toxic you are learning this as well

fathom pendant
#

you're*

compact jacinth
novel mirage
#

Literally safelane carry missing last hits

fathom pendant
#

maybe if you spoke coherently i'd engage with you better

#

either way; detracting from the ongoing discussion

next bronze
fathom pendant
floral drum
#

Split the network 10.200.20.0/27 into 4 subnets and submit the network address of the 3rd subnet as the answer.
Xre0uS can u tell me

next bronze
fathom pendant
floral drum
fathom pendant
#

i gave you links to resources to 1; get you started and 2; to explain

floral drum
fathom pendant
#

because that's not how a 10.200.20.0/27 network is gonna be split

floral drum
#

ik how to split

#

i will use chatgpt

fathom pendant
#

again if you knew how to split you're not gonna get 10.10.10.0/29 out of 10.200.20.0/27

#

Β―_(ツ)_/Β―

floral drum
#

why are u irritating me marcie

fathom pendant
#

the calculator link i gave you will give you the range of addresses you will use

#

start there

floral drum
#

dont
just dont

fathom pendant
#

i'm being honest: you're swearing 10.10.10.0/29 is correct - it's not gonna be

compact jacinth
next bronze
#

I mean, there are 32 addresses in 10.200.20.0/27, just do some simple math

floral drum
#

even chatgpt cant answer

hallow kiln
#

Of course it can't, ChatGPT shouldn't be your source of information

next bronze
#

yeah, good ol CCNA

fathom pendant
#

even if it's not the same EXACT scenario

#

it's pretty easily translatable if you apply some thought

marble ravine
#

hi guys if i subscribe gold monthly can i access all senior web pentester path ?

fathom pendant
#

Gold Monthly is different from gold Annual

marble ravine
#

haaa

fathom pendant
#

you need to by the Annual one

marble ravine
#

okey thanks

fathom pendant
#

Monthly gives you cubes per month

#

to help you unlock modules

marble ravine
#

yeah i got it

fathom pendant
#

However Gold Annual Value Drops off significantly if you've already done some of the other paths

#

even with the current discount

marble ravine
#

thanks ❀️

fathom pendant
#

it's been currently worked out to be cheaper to do like 8 months of plat and buy the voucher for ~$200 than to A: flat out buy Cubes, and B: the NOT discounted Gold Annual Price

proven pasture
#

Hello. I asked this like a week ago, but I was not able to find a response and had to work. My question is: about the Windows Finding Evil projects. Is anyone else having issues connecting or maintaining a connection to any of the Windows boxes? I cannot seem to be able to connect for more than a few seconds.

fathom pendant
#

switch to tcp connection

proven pasture
#

Thank you very much. I willl try that in a bit. I am trying to finish up this Splunk section. I appreciate your assistance.

fathom pendant
#

rdp stuff has been notoriously jank if you're using the UDP vpn pack

floral drum
#

who knows ruby attack

fathom pendant
floral drum
#

u know

fathom pendant
#

I don't know

#

'Ruby Attack' sounds EXTREMELY vague

floral drum
#

ahuh

#

a friend of mine told me idk either

fathom pendant
#

are you specifying an attack made with the programming language 'Ruby'

#

if so, many exist

#

but it also sounds unrelated to htb academy

floral drum
#

yea

#

i guess

supple gorge
#

It's funny but I totally agree now, the Intermediate NTA is definitely easy, the questions are very simple. The Intro to Network Traffic Analysis was a bit more challenging.

The difference is that the Intermediate one has more complex attacks and methodologies.

Pretty neat huh

fathom pendant
#

in which case: this isn't a gen chat

mint solstice
#

advanced command obfuscation Find the output of the following command using one of the techniques you learned in this section: find /usr/share/ | grep root | grep mysql | tail -n 1 found a way to run command but what is needed not working? Anyone can help me?

fathom pendant
royal sigil
#

hello i make the skill asesement file ipload i have modified the magic byte of my php file put the ymd before my file but i have not found like this

next bronze
fathom pendant
mint solstice
fathom pendant
#

ah

#

can you inject the command one part at a time?

next bronze
mint solstice
fathom pendant
#

does it break at some point?

floral drum
#

ik it

fathom pendant
#

cause that sounds odd

#

worst case is respawn target and try again and it works ℒ️

next bronze
floral drum
#

The command provided includes a series of operations: first, it looks through the "/usr/share/" directory for specific files, then it filters the results to include those containing "root", followed by a further filter for those containing "mysql", and finally, it displays the last result.

The output for the command can be found using a technique called "path manipulation." In this case, by manipulating the directory paths within the command, we can determine the likely output without actually executing the command.

In this particular command, the "find" command searches through the "/usr/share/" directory and its subdirectories for files or directories, the first "grep" command filters for lines containing the word "root," the second "grep" filters the previous results for lines containing the word "mysql," and finally, "tail -n 1" restricts the output to the last line of the filtered results.

By analyzing the structure of the command and the typical contents of the "/usr/share/" directory in a Linux system, it may be inferred that the command provided may not yield any output, or it might display the path to a file or directory that contains "mysql" in its name and "root" in its path, given that the command is searching through the "/usr/share/" directory.

It's important to note that this command could yield different results depending on the specific system and its file structure. Without actually executing the command, the precise output cannot be determined with absolute certainty. Always exercise caution when using advanced command obfuscation techniques and ensure that commands are used responsibly and with proper authorization.

fathom pendant
fathom pendant
#

it's literally not helping at all

mint solstice
#

so anyone known the solution :D?

floral drum
#

see @fathom pendant i dont wanna be rude

fathom pendant
#

you literally threw it into chatGPT and copy/pasted what it said, without providing ANY valuable input

next bronze
floral drum
#

atleast i told him dumba$$

fathom pendant
#

told him what?

floral drum
#

u literally speak too much

fathom pendant
#

you literally just spat back out a chatGPT answer

floral drum
mint solstice
#

don't debate pls

fathom pendant
next bronze
#

lmao wtf

mint solstice
#

it is not related to sql injection

fathom pendant
#

reading comprehension is hard my guy

mint solstice
#

related to OS command injection

fathom pendant
#

^

floral drum
fathom pendant
#

no

#

it's just grepping for SQL

floral drum
#

marcie u are irritating me a lot cant u just stfu

fathom pendant
#

doesn't mean it's related to SQL

#

you're literally not providing any valuable input :)

mint solstice
#

doing Command Injections topic there is no sql injection

next bronze
fathom pendant
#

anyway @mint solstice double check if you need to urlencode anything, have you tried sending the request through burp repeater so you can modify it to see if urlencoding a different character yeilds a different result?

floral drum
#

see i might be wrong but who told this marcie to argue

fathom pendant
#

did you encode spaces with %20

#

iirc that's urlencode spaces, might need to double check

#

huh For example, spaces in a string are either encoded with %20 or replaced with the plus sign ( + ). If you use a pipe character ( | ) as a separator, be sure to encode the pipe as %7C . A comma in a string should be encoded as %2C thanks google

mint solstice
#

can a dm you @fathom pendant ?

sterile epoch
fathom pendant
fathom pendant
sterile epoch
#

I tried ftp but it timed out

fathom pendant
#

also you need to use the mutated password list

#

-t 48

#

that's by far the most stable (ish) threads

sterile epoch
#

I am stuck at protected files section

fathom pendant