#modules

1 messages · Page 164 of 1

sterile epoch
#

alright I will do the mutated list

fathom pendant
#

just don't attack ssh

sterile epoch
#

and should I do it on ssh or ftp protocol?

fathom pendant
#

ftp

sterile epoch
#

ftp is locking me out

fathom pendant
#

ssh is slow as balls with cme

#

restart the target and wait a few minutes before trying

#

it shouldn't be locking you out unless you're doing some dumb number of threads

#

like I said though, i've had luck with 48, some people have had luck with 64

sterile epoch
#

i used
`crackmapexec ftp 10.129.x.x -u "kira" -p 'mut_list.list"

sterile epoch
fathom pendant
#

i believe i used hydra for it

#

if crackmap isn't working for you

sterile epoch
#

Can you provide me the password as its a task I have already done and not part of the current section. I am linking my original question

#

or is it out of rules?

fathom pendant
#

here's a [link](#modules message) to an early post that has a tool for bruting ssb

fathom pendant
#

¯_(ツ)_/¯

#

this section reuses credentials a LOT

sterile epoch
#

yea I am doing it rn. I just started to do it late. like from pth section

fathom pendant
#

iirc it's the question that asks you to get Will's password that has the hint for kira

#

if that's any consolation

sterile epoch
#

thanks a lot I can do it from there

fathom pendant
#

it gives you a more precise list to brute

sterile epoch
#

I just hate this module. brute forcing takes a lot of time

fathom pendant
#

patience is the name of the game ¯_(ツ)_/¯

sterile epoch
#

specially wills one

#

but fortunately I have will's pass

fathom pendant
#

well that wasn't the point i was making

#

i meant the hint directly points at a string you should mutate

#

with the custom.rule

sterile epoch
#

yes I get it in this line patience is what will make me mr.robot

fathom pendant
#

mr.robot is cring

#

ngl

sterile epoch
#

well I never finished it and watched it way before

#

so not a clear memory of it

fathom pendant
#

spoiler: ||it's revealed a lot of his interactions were from Schizophrenic episodes||

sterile epoch
#

but at that time I never understood anything so it might be cool

fathom pendant
#

oh and ||he falls in love with his sister||

sterile epoch
#

thank spoiler tags

fathom pendant
#

👍

sterile epoch
#

not gonna blow up a good memory

fathom pendant
#

the show is decent around it's midpoint

sterile epoch
#

its getting scarce these days

fathom pendant
#

but falls off towards the end

thorny heath
#

💀

sterile epoch
#

I finished just after the ecorp hack

#

then I stopped and never resumed

fathom pendant
#

but there's a reason most people dunk on the people that come in with unironic Mr. Robot profiles

shadow current
#

On the web attacks module on idor part i was able to do it because of the writeup but the thing is when i access the url the uid doesnt show unlike the one shown in the writeup and module. How should i be able to do this?

fathom pendant
floral drum
#

@fathom pendant

#

listen

#

im sorry

fathom pendant
floral drum
#

but anyway

fathom pendant
#

LMAO

floral drum
#

cyber tech

fathom pendant
#

fuckin not even masking the IP grab link

floral drum
#

yea u are good

#

nice

fathom pendant
floral drum
#

ik that

swift parcel
#

Hello

earnest flame
#

Omg is that the real admin

fathom pendant
#

oh nice that's the legit Admin

royal sigil
#

but my file get dowloaded

fathom pendant
#

prayge here to save the server

floral drum
#

hey anyone here that does modern web exploitation techniques module?

#

i would need a companion

earnest flame
swift parcel
#

I have problem my Facebook account

fathom pendant
swift parcel
#

Can you help me?

fathom pendant
#

read #rules before saying anything further

floral drum
fathom pendant
swift parcel
#

My account disable

floral drum
#

she studies in htb she doesnt works in facebook

fathom pendant
#

that sucks, but nothing we can do about it

fathom pendant
floral drum
#

no just like u

#

lol

fathom pendant
#

:P

#

and just to help some dumbass get their account back isn't worth any bit of trouble

acoustic owl
floral drum
#

no

fathom pendant
#

hi payload, you missed it - he tried to send a grabify link in chat earlier

#

funny stuff

acoustic owl
fathom pendant
#

literally didn't even mask the link

floral drum
#

and she irritates me

floral drum
#

even when i dont argue with her

fathom pendant
#

for the rev shell did you remember to change it to YOUR tun0 ip?

#

haven't done that module myself yet - but that's often my common issue is forgetting to change something

#

well then i wish you luck in figuring it out :D

floral drum
#

can anyone tell me that it would be good if i unlock this module for 12k cubes
crest cct inf preparation?

fathom pendant
#

it's not a module, it's a whole path

#

if you click the "x modules" button in the bottom left it expands what all modules it covers

floral drum
#

yea but should i get it for 12k cubes

solid python
#

That's your decision

floral drum
#

i bought it

fathom pendant
#

you don't pay the 12k outright, you pay it as you unlock and do modules ¯_(ツ)_/¯

floral drum
#

should i send u the pic?

fathom pendant
#

I do not care

floral drum
#

no u dont believe me

#

wait

fathom pendant
#

For instance I enrolled in cpts when I had like 40 cubes, it didn't charge me the 1900 cubes

#

And currently there are no modules that cost 12k cubes, tier 4 is like 1k

floral drum
#

i cant send in this channel

acoustic owl
floral drum
#

Alr

#

I sent the pic to marcieLee

orchid pine
#

in the privilige escalation module User Account Control section how can we know which methode we need to use cuz they didnt explain this part

latent glen
#

I believe the reason why so many people that are following the course are having issues with the DNS section is twofold:

  1. in the course it says to "echo "ns1.inlanefreight.com" > ./resolvers.txt", I don't know why it says that because it should be an IP. It is irregular because resolvers.txt should contain an IP address and therefore that would make it easier to understand.
  2. (and this is perhaps the most important reason) People are blindly copying and pasting the commands without first truly understanding DNS.

So I believe it is a mixture of both. SOmeone that truly understands DNS would notice that a resolver takes IP addresses and therefore change that command, but also HTB could change that in the course

fathom pendant
#

Which adds to confusion

latent glen
#

aaaah okay okay, I thought it should only take IPs

#

fair enough, thanks for that explanation

floral drum
#

@fathom pendant why dont u straight tell me that u are being jealous

latent glen
#

now can I ask you somehting, why does puredns not find the subdomain and subbrute does... using the same resolver and names list

#

I am trying to use puredns more because it seems ton be a nice tool

fathom pendant
#

I guess they use different methods

latent glen
#

thought so too

#

anyway, I can now finally say I fully understand DNS

#

it was always a bit weird and confusing

floral drum
#

bro dns is a lil confusing

#

i agree

fathom pendant
acoustic owl
latent glen
#

phone book for the internet helped a lot ahhaha

floral drum
floral drum
#

u dont see that right

fathom pendant
#

I've been correcting you throwing chatGPT answers at people

#

And misunderstanding what someone was asking for

floral drum
#

Xer0uS even this guy was here

latent glen
floral drum
#

he didnt tell me

prisma harbor
#

can someone help

floral drum
#

?

fathom pendant
floral drum
languid fjord
#

Let’s just both end it okay?

fathom pendant
#

You're correct, I don't know what they're asking

floral drum
#

yea

fathom pendant
#

So clarifying will help

languid fjord
#

Move on prayge

prisma harbor
floral drum
#

ofc

fathom pendant
prisma harbor
fathom pendant
#

If you can't state it here then it's likely against the #rules

#

And I'll decline based off that

floral drum
#

@prisma harbor saw that, askin her is always goin down

floral drum
#

XD

#

btw leave her

fathom pendant
#

don't wanna deal with asking for help hacking a social media account ¯_(ツ)_/¯

solid python
#

Follow the #rules of the server and behave or you'll earn a swift ban

fathom pendant
#

Which is what happens in 99.99% of the instances here

solid python
#

This will be your only warning. peepoLove

prisma harbor
latent glen
prisma harbor
acoustic owl
acoustic owl
#

If it's a question about the modules in the Academy, then maybe. Otherwise, no. Just ask your question here.

fathom pendant
#

And you might be directed to the right place to ask

#

Save your braincells before its too late

faint python
#

hi, why might the answers from pvnbox not match the correct ones? I can’t match the answers from pvnbox and I can’t understand what’s wrong with the pvnbox course by entering it into Linux

fathom pendant
#

There's an intro to linux module that has you ssh to a target and run commands to get the answer

faint python
#

yes, I connected and entered the commands but the results do not match

final maple
#

Sorry to ask this in here, but is there anyone here who can DM me to help me with a problem I keep having in Kali? It is keeping me from making progress on the modules.

fathom pendant
faint python
latent glen
# prisma harbor can i dm u

you need to at least explain your issue here, and if we can help we will. Anything other than that won't run

fathom pendant
latent glen
#

so I gave dming him a chance out of curiosity and my guy is asking me about getting his roblox account back...

faint python
fathom pendant
#

It's pwnbox

fathom pendant
faint python
#

section linux navigation the second question pwnbox tells me that the file is on line 287 and the answer has a different number sorry for the translator, he was a little mistaken with the name pwnbox

fathom pendant
#

Ah translation issues

#

Link?

#

Nvm found it

faint python
#

Well, small, do you understand Russian?

fathom pendant
#

The question about index number yes?

fathom pendant
faint python
fathom pendant
#

This question requires you to be connected to the target ip. It does not work with just the pwnbox

#

The "instance" is a workstation. Not the target

umbral wasp
#

can you please help me in remmina password in footprinting I am unable to connect on rdp for mssql

umbral wasp
#

I fond alex password

fathom pendant
umbral wasp
#

Enumerate the server carefully and find the username "HTB" and its password. Then, submit this user's password as the answer.

faint python
umbral wasp
#

this one

fathom pendant
umbral wasp
#

yes I can access alex via rdp i also found important file

fathom pendant
umbral wasp
#

ok

fathom pendant
#

Yes, you do have the password

#

Before you even say it

umbral wasp
#

I have heard alex has not the permission to connect to mssql

fathom pendant
umbral wasp
#

ok let me try again

#

got it thank you very much

faint python
fathom pendant
#

Because that's likely the one on the pwnbox, not the target

#

Which is what it's asking for, the sudoers file on the target

faint python
fathom pendant
#

The 1360934 number is the index in the pwnbox

#

Not in the target

#

Your commandline before the command should read htb-student@nixfund:~$ if in the home directory of htb student

#

If it reads [vpn region]-[tun0ip]-[htb-ac-(numbers)@htb-(random string)]-[~] then you're running it from pwnbox

#

Shrimple as making sure you're actually running the command from the box

#

And not from your system

umbral wasp
fathom pendant
fathom pendant
#

It's about connecting to the target ip that does have the right answer to the question

#

Like I said: I just did this via the pwnbox and it gave me the correct answer, so I'd like to think I know what I'm talking about

umbral wasp
#

sorry my bad

umbral wasp
fathom pendant
#

just click on all the databases that you can find; they have table icons

umbral wasp
#

ok thank you

fathom pendant
#

once you find the right one it's as simple as right click and view

faint python
fathom pendant
#

you need to run that command from where you're ssh into htb-student

#

which is what i've been telling you

umbral wasp
faint python
urban valley
#

Password Attacks-Protected Archives: I'm having trouble getting the Notes.zip file onto my Kali. I've tried using python http server but it did not work. Any suggestions? Update: Understood why it wasn't transferring. File path in my wget syntax was wrong.

lusty thicket
grizzled schooner
#

Footprinting Easy Skill Assessment - I have the ||.listing|| file, I'm just not sure what to do with it... any hints would be great

grizzled schooner
#

I used ||wget -m --no-passive ceil:qwer1234@<ip>|| when I went to where it was installed there was nothing but I checked hidden files which gave me
||drwxr-xr-x 2 root root 4096 Nov 10 2021 .||
||drwxr-xr-x 2 root root 4096 Nov 10 2021 ..||

#

I'm just not sure if I'm supposed to put that somewhere

lusty thicket
#

login to the ftp server with valid creds and try ||listing hidden files again||

junior tinsel
#

Hello guys, can someone help me how can i speed up my vmware (it's so slow & buggy)

grizzled schooner
#

I've tried logging into ||port 2121 as a proxy|| while also being logged into 21. I use ||LIST -al LIST -a LIST -all|| and I only get Unable to build data connection: Connection refused. Am I missing something

grizzled schooner
#

more space

junior tinsel
grizzled schooner
grizzled schooner
lusty thicket
grizzled schooner
#

I am

junior tinsel
grizzled schooner
#

I use ||LIST -al|| to try and show all files but it refuses connection... I'm just a little lost, I don't really understand what it is I'm doing and I've gone back through the FTP module a couple of times... so I really don't know what I'm missing and I'm trying to understand

lusty thicket
spiral spoke
#

Hello! How can I turn off the real-time protection? I’m in Miscellaneous file transfer methods and, I’m connected through RDP but I can’t run ncat.exe because of real-time protection and I’m not Administrator:(

#

Actually it deletes the ncat.exe

fathom pendant
spiral spoke
fathom pendant
#

did you try running powershell as admin?

spiral spoke
fathom pendant
#

try using htb-student password for admin

spiral spoke
#

I’ve already done, I used htb-password (HTB_@acad…) and the url-password of pwnbox but it doesn’t work

fathom pendant
#

url-password?

#

your pwnbox password is never gonna be used by any labs

#

have you tried making sure you didn't miss the admin password in either the question or in the section text?

#

or it's somewhere on the RDP desktop/system somewhere

native turtle
#

Hello there I'm stuck with password attacks module, in specific network services part, I found an NFS Shares but when I try to mount I can't access it even with root user, my thoughts was in the share will be more info about what username use before start to brute force, or brute force is the only way for this section?

upbeat dragon
#

Hi guys, i'm stuck at Attacking Common Services - Medium, found an FTP port on 2121 but anonymous login does not work.. Any hint please?

sterile epoch
#

How do I crack faster with john. I wanna use my gpu too

spiral spoke
sterile epoch
#

can someone list me a syntax?

fathom pendant
#

if you're using a vm; it generally won't

sterile epoch
#

I am using wsl.

#

and how to mention threads?

grizzled schooner
# lusty thicket `ftp ip port`

Ok, I managed to find ||authorized_keys, id_rsa and id_rsa.pub|| I've tried putting those in the ||.ssh|| directory and using ||ssh -i <file> ceil@<ip>|| and none of them work it keeps talking about ||WARNING: UNPROTECTED PRIVATE KEY FILE|| in which case I'm extremely lost on where I'm supposed to go

spiral spoke
next bronze
fathom pendant
#

^

#

wsl is also (in general) a mess

fathom pendant
#

when it's working fine, it's great

#

but i've found it breaks more often than it works

sterile epoch
fathom pendant
#

and that's ok that you like an inferior option

#

¯_(ツ)_/¯

sterile epoch
upbeat dragon
#

@fathom pendant quick question on Attacking Common Services - Medium. Is there a port besides port 21xx? because i'm really lost, -p- scan never ends

fathom pendant
upbeat dragon
#

All working fine.. Besides i'm not using a vpn file, using the parrot HTB machine

#

But lemme restart it just in cae

fathom pendant
#

Ah

#

Then I suggest restarting/changing region then in case it's being silly

upbeat dragon
#

Alright, will do. Thanks!

elfin arch
#

For some reason am getting this error while trying to solve bash module and the question goes Create a "For" loop that encodes the variable "var" 28 times in "base64". The number of characters in the 28th hash is the value that must be assigned to the "salt" variable.

cyan belfry
#

so I sshed into the system, but when I do ls to find other directories, I see nothing... and I am trying to answer this What is the path to htb-student's home directory

next bronze
grizzled schooner
#

thanks

next bronze
upbeat dragon
#

@fathom pendant changed region, all worked perfectly, found the new port, thanks!

elfin arch
cyan belfry
next bronze
native turtle
fathom pendant
native turtle
#

yeah

fathom pendant
#

Alternatively you can su to root and browse it

native turtle
#

already did

#

neither with Kali and root user it show always permission denied

fathom pendant
#

¯_(ツ)_/¯

#

Weird if it showed perm denied as root

native turtle
#

maybe was not the aim of the challenge but nevermind I figured out in another way

fathom pendant
#

Congrats on finding an alternate way

#

Gandalf the stinky kek

native turtle
#

😦

#

what u mean ahah

supple gorge
#

wireshark not working for IDS/IPS, Suricata rule Development Part 1

sterile epoch
#

any idea why I cannot find files that are there in my system

#

I have used sudo too

supple gorge
#

It says no matches found, so maybe it's not there?

#

try ls on the directory you think it is, might be, default

sterile epoch
#

/ means the whole system right

supple gorge
sterile epoch
next bronze
#

updatedb

sterile epoch
#

its taking time I guess its working

sterile epoch
noble musk
#

Hi there, I am looking for some help with the Whitebox Attacks Authentication Bypass using Type Juggling if anyone can help?

sterile epoch
next bronze
sterile epoch
#

ok

#

thanks

noble musk
sterile epoch
#

@next bronze I want some advice on cpts after I complete the path can we get in a vc so I could take some advice and pointers?

#

for the exam

next bronze
#

no I'm not here to do ted talks, you can ask in #cpts and we will be happy to answer, there are also a lot of existing resources/discussions on how to prep

sterile epoch
#

ok thanks anyways for the help on find

sterile epoch
#

its still not working

supple gorge
supple gorge
sterile epoch
supple gorge
#

can you try running find on that folder?

next bronze
#

*rockyou*

sterile epoch
next bronze
#

locate does partical match by default anyways, there's no need for wildcards

sterile epoch
supple gorge
# sterile epoch

so it worked... try using the absolute path of the folder and then slowly go a folder backwards until you got back to / which is what you originally tried.

interesting behavior.

next bronze
#

like I said, locate does partial match by default, there's no need to use wildcard, if you use wildcard it will try to match it with the stored path, which is the full path, so you need to have a * at the start and end

sterile epoch
#

and it looks perfect

supple gorge
sterile epoch
#

yes I could date it if it was so easy irl

supple gorge
#

sorry for not being of much help, glad you got it sorted 😅

sterile epoch
#

well you got me a step closer so thanks

#

and thanks to you xreous for the help on this matter

#

I will get back to the grind now

fresh seal
#

Hello. Sorry for the inconvenience in advance. I am very, very new to this world but I am very fascinated by it since it is something that I think is in great demand in the work sector. I'm starting with the modules to get started in Linux but many times I get stuck on simple things and I spend days on it. I would like to know if I have complete freedom to ask questions here without being discriminated against for my lack of knowledge.

royal sigil
#

just ask the question

hallow kiln
supple gorge
sterile epoch
#

any idea why its not working? It worked in the section example

#

I tried without sudo too and the result was the same

#

I checked the file using file utility and found there was no openssl use

brittle arch
#

Try using the password lists (or the mutated one) from the module resources.

sterile epoch
#

ok

fathom pendant
#

As i stated earlier: you use the mutated list pretty much all the time once you create it

supple gorge
#

I have a question in the IDS/IPS module Suricata.

The offset field is the n byte after... in the payload... does this mean after the tcp header information?

#

So, would offset start couting based on the blue highlighted, which is the section right after the tcp header info?

grizzled schooner
#

Not a direct module question, but rather a question about modules. Is it acceptable to do write-ups of skill assessments? I was going to put these on a portfolio to show growth for future employment opportunities, but was not sure if this was allowed

next bronze
#

not allowed unfortunately

grizzled schooner
#

Ok, not a problem, thanks

hallow kiln
grizzled schooner
#

That blows, wrote a whole write-up and went to post it, but figured I'd ask first because it's academy

hallow kiln
fathom pendant
#

Anything above tier 0 is considered paid content, therefore it's barred from having any writeups

grizzled schooner
#

Yeah no absolutely, that's why I thought to ask first

fathom pendant
#

Tier 0 they consider "free" due to you getting the cubes back

#

It's also listed in their ToS if I'm not mistaken

grizzled schooner
#

It might be, I just figured I would ask here because people respond quickly

hallow kiln
grizzled schooner
#

yeah no we don't want that lmao

grizzled schooner
#

lol

slender shoal
#

The best thing you can do is contact the authorities. We cannot help you. Please keep the channel on topic.

#

Keep the channel on topic.

supple patio
#

xD

grizzled schooner
slender shoal
#

There is if you verify your account.

supple gorge
slender shoal
supple gorge
#

WORKING WITH IDS/IPS

Snort Fundamentals

There is a file named wannamine.pcap in the /home/htb-student/pcaps directory. Run Snort on this PCAP file and enter how many times the rule with sid 1000001 was triggered as your answer.

Run snort on it w -A cmg in the end, there is a section in the end that says number of alerts (that's the right answer), but how how I be sure that all alerts were from the same rule, unless I manually count or use some other text matching, anyone had a more official way of doing it other than finding number and trying it?

fathom pendant
#

it's probably to do with what that sid is sniffing for; if so you can probably reverse engineer a way to do it in powershell and event logs

supple gorge
fathom pendant
#

I guess it's more of hitting the "i believe" button for most of it

cedar void
#

I am having trouble moving my lsass.dmp file from my windows machine to my attack machine.

||proxychains xfreerdp|| /||v:172.16.5.35|| /u:||mlefay|| /p:'||Plain Human work||!' /||drive:linux,/home/htb-ac||||-767577/Desktop /dynamic-resolution||
I also tried to physically copy the file and that did not work.

fathom pendant
#

are you copying it to the network drive that's created in windows?

#

under "this PC"

lusty thicket
fathom pendant
#

the internal ip is fine i believe as that's a given address? if not then yeah

#

common tactics would be replacing username with first letter then * similar with the password

#

IPs can be hidden just by doing the first octet then the rest are x

#

172.x.x.x

#

for example

cedar void
cedar void
fathom pendant
#

that's not what he said at all

fathom pendant
cedar void
fathom pendant
#

because if you're doing proxychains you've already got your vm linked to the victim machine

#

if you go to "this pc" do you see a folder called "linux"?

#

that's where you need to drag and drop it to

#

you can't just drag and drop directly to the vm desktop; xfreerdp doesn't work that way

cedar void
fathom pendant
#

...

#

when you do the /drive:linux,/path/to/whatever/ it should create a share on "This PC"

cedar void
#

oh okay

fathom pendant
#

it'll be titled whatever you put before the comma

#

and have a green icon at the bottom of it

regal cosmos
#

Hello

cedar void
fickle thicket
#

Module: Password Attacks, Section: Pass the Hash (PtH)
"Using Julio's hash, perform a Pass the Hash attack, launch a PowerShell console and import Invoke-TheHash to create a reverse shell to the machine you are connected via RDP (the target machine, DC01, can only connect to MS01). Use the tool nc.exe located in c:\tools to listen for the reverse shell. Once connected to the DC01, read the flag in C:\julio\flag.txt." i managed to get the flag but i am confused about the julio user.

#

"Invoke-WMIExec -Target 10.129.204.23 -Domain INLANEFREIGHT -Username julio versus Invoke-WMIExec -Target DC01 -Domain INLANEFREIGHT -Username julio . i am able to execute code using julio account on both target DC01 and MS01

fathom pendant
#

julio is just another user

#

that's why

#

it's not much more complicated than that tbh ¯_(ツ)_/¯

fickle thicket
#

i am confused because the MS01 allows julio to execute code since the net users command in MS01 doesn't show julio inside. is it because julio is a domain user and not a local user?

fathom pendant
#

yep

#

domain user overrides local user

#

net users /domain i believe is how you'd check for domain users

fickle thicket
#

so i wanna confirm that if the MS01 host is connected to DC01 meaning it is part of the domain. then any domain user can execute code in MS01

fickle thicket
fathom pendant
#

limited code; it depends on their domain level rights

rustic sage
#

how can i tell if hackthebox connected to my vm

#

sorry i honestly didnt know where to ask

fathom pendant
rustic sage
#

yup

#

well i didnt do path but it looks like it worked

fathom pendant
#

and if so; when it finished did you see Initialization Sequence Completed

#

if that's the case: you're connected

rustic sage
#

yes thank you so much 🙂

#

sorry i have another question if thats okay

#

the openvpn thingy is for the victim machine? or the attacking machine

fathom pendant
#

openvpn allows you to connect to the victim machines

#

it creates a tunnel to the htb network

#

otherwise you're not able to access the target machines

rustic sage
#

okay so the attacking would be from the virtual machine that open vpn is running on?

fathom pendant
#

yes

rustic sage
#

thank you, i just got started on htb and i dont have too much experience with any form of linux

fathom pendant
#

if you're doing the main platform you'll need to verify your account by following the instructions in #welcome where more of the server will open up to you

rustic sage
#

im doing the academy, seemed more beginner friendly

fathom pendant
#

if you're encountering technical difficulties that don't seem to be a personal skill issue: you should message support

compact patrolBOT
fickle thicket
fathom pendant
#

also sometimes things are funky when doing pth like that

#

also check C:/Users

#

sometimes it's dumb

supple gorge
#

Working with IDS/IPS

Snort rule Development:

There is a file named log4shell.pcap in the /home/htb-student/pcaps directory, which contains network traffic related to log4shell exploitation attempts, where the payload is embedded within the user agent. Enter the keyword that should be specified right before the content keyword of the rule with sid 10000098 within the local.rules file so that an alert is triggered as your answer. Answer format: [keyword];

I got the rule to work... but not liking the answer.. put http_uri; before content and it worked... but htb not considering a valid answer...

EDIT: got it, it's in the right track, the "right" answer is in the same area.

final flint
#

I need some help with the password attacks module, specifically the question "Use the user's credentials we found in the previous section and find out the credentials for MySQL. Submit the credentials as the answer. (Format: <username>:<password>)" (5th section)

I have to use the credentials from the previous section, however I completed this a few days ago and have completely forgot what the password to user sam was. It wont even let me re-attempt the previous section to gain the password again. Could someone potentially dm me it?

lusty thicket
#

for the current section

final flint
#

I tried a hydra script to bruteforce the ssh/ftp service (as required in the previous section) but it returned the error "Unknown service: ftp://{box ip}

#

So i'm lead to believe its a new box for this section that doesn't include the services that were used to gain the password

lusty thicket
final flint
#

good point, but i'm not sure why I keep getting the error when I attempt to re-bruteforce it

#

nvm it looks I got the command working, thanks

lusty thicket
sterile epoch
#

for the Password attacks lab easy. I tried brute forcing it using the lists given in the resources did I do something wrong. it took arount 2 hrs to complete the attack and no result. Please help

#

there are only 2 services present ftp and ssh I tried doing it on ftp

final flint
#

Ive heard using 48 threads instead of 64 is better, as apparently sometimes with 64 it can skip over the correct user and password pairing

#

not sure if that is the solution or not though

naive wadi
#

doing the sql fundamentals lab and suddenly halfway through the Union injection the syntax is now injecting the characters cn before the single quote without explaining why?

#

does anyone know.

#

did you ever get an answer to this?! it's driving me insane how it's suddenly introduced with no explanation.

next bronze
naive wadi
naive wadi
lofty kelp
#

Hi guys, I'm new on hack the box and I was wondering why is nmap so slow? it can take 30 mins to scan a machine some times and it really slows me in my learning.

#

I usually use -p- -T4 -A

naive wadi
#

you are scanning all ports with -p- and running all checks with -A

lofty kelp
#

the port I have to endentify is over the first 1k

#

10 *

#

but if that's the reason I will try to solve it I thought it could that I'm scanning through my machine directly.

naive wadi
#

if it's over the first 1k ports you could use -p 1000-2000

#

you will need to check syntax though

#

if it's part of the top 1000 ports you can use

#

--top-ports=1000

#

you may be best to just run a nmap -p 1000-2000 initially and then enumerate the ports after the first scan

lofty kelp
naive wadi
#

that way you can narrow down your target

lofty kelp
#

I will try that.

#

👌

naive wadi
rustic sage
#

how to contact support about subscription

naive wadi
near gazelle
#

why in the most of the time when i try connect to the windows with the xfreerdp command its display me this error "reerdp_tcp_connect:freerdp_set_last_error_ex ERRCONNECT_CONNECT_FAILED [0x00020006]" its worked me seldom

naive wadi
# next bronze you can just ask here

Okay, so here is the question: On the union clause page it states that data types need to be compatible to be displayed at once, it also says that we have to export all the columns but to get the answer we can run ||select dept_no from departments UNION select emp_no from employees;|| which has an INT datatype and char/string datatype so conversion on the fly is happening and we are also not outputting all the columns, so what is actually happening?

#

My understanding was we had to specify all columns but we don't have to with the command above so is the text just incorrect or have I missed something fundamental in it?

prisma spruce
#

Has anyone done the math for gold annual yet? If not, I can do the calculations later.

next bronze
#

and yes char and int type will be converted for the output

rare swan
#

Module: Attack Web Apps Section: Other Notable Apps ------- cant solve this task, because the connection is very unstable - dont think my internet is slow as it worked well in the previous tasks ------- can anyone starting this box to see if the ping command is stable? -- I know i mentioned this problem already

#

Actually tried different vpn files and also different internet connections (mobile and home), but problem persists!

#

Doing it with pwnbox -- no other solution

woeful stone
#

Hello, I'm new to the academy and I'm working through the Cracking into Hack the box module, I'm having issues with the HTTP lesson using eURL. I got the flag, but submitting it, I keep getting told it's incorrect, I chatted with the bot and reset the target, my machine, and my VPN but it keeps giving my the same flag and telling me it's incorrect. I have a ticket submitted, just curius if anyone else encountered the issue

next bronze
south glen
#

hey guys needed help in module: password attack , section : protected files ... i am not able to crack kira's password can any one help me with the wordlist i have to use✅

prisma spruce
#

22 tier 0 modules
12 tier I - 600 cubes
35 tier II - 3500 cubes
24 tier III - 12000 cubes
4 tier IV - 4000 cubes

Total cost up to tier II/III/IV= 4100/16100/20100 cubes

It's an infinite sum, (20% rebate = 1 cube is really worth 1.25 cubes), so divide the amount by 1.25.

Adjusted cost: 3280/12880/16080 cubes.

Tier II: 3 platinums + 1 silver + $10 = $232
Tier III: 13 platinums = $884
Tier IV: 16 platinums + $10 = $1098

Silver Annual (ignoring the cost of the cert): $280

You get back 22*10+12*10+35*20=1040 cubes. That's $68+$5=$73, so you will really be paying $207. You'll be saving $25, so it's not worth it.

If you had already done tier 0, you would be getting back 820 cubes. That's (820/1000)*$68=$55, so you would be paying $235. (Note that I use fractions here because you would otherwise you get into really weird scenarios because of the jump from gold->platinum. Ideally you would want to multiply everything as a scale of the platinum price in order to give a more accurate cost instead of one that makes HTB's offer look more favourable. I will be using this method from now on. )

Gold Annual (ignoring the cost of the cert): $735/$1050

You get back 22*10+12*10+35*20+24*100=3440 cubes. That's (3440/1000)*$68=$234, if you follow what I wrote above.

If you had done tier 0, you would be getting back 3220 cubes. That's $219.

If you're starting out from scratch and you have done tier 0, you're spending $516 with the discount price instead of $884. Go get it if you can't get a student subscription. You can use your remaining cubes on three of the four tier iv courses (to make things perfectly clear, the cubes you get back are baked into the price you paid. That's the $219/$234 above). This is a great price.

The non-discount price however, is awful. You would be paying $816 or $831. Are you really looking to save $53 or $68 so you can be forced to rush through things?

#

Should you upgrade if you're a student?

It costs $660 for the tier III modules, and you're getting back 2400 cubes. That's (2400/1000)*$68=$163. So it's still worth it at the discounted rate ($572), but not worth it at all at the non-discounted rate.

#

tl;dr: Go get gold annual now before the discount is removed. The price is hot garbage otherwise.

snow gorge
#

Could someone help me with

Navigate to http://[Target IP]:8000, open the "Search & Reporting" application, and find through an SPL search against all 4624 events the account name that made the most login attempts within a span of 10 minutes. Enter it as your answer. 

Currently I've tried bin, streamstats but I can't figure out how to use range(_time) <= 600

prisma spruce
cedar void
#

I didn't have this error yesterday when creating 'lsass.dmp' and I have no idea why I have it now. I am creating it on mlakeys machines of the skill assessment for the pivot section .

#

I tried googling the problem with no luck

#

I think I see the issue. I may have the wrong PID

fleet tide
#

silly subscription question: I currently have Silver annual, signed up just this July. How will they charge me if I upgrade to Gold while they have the discount? Is it Gold - Silver, ie 945 - 490 = 455?

acoustic owl
misty current
rustic sage
#

where do i ask for support with connecting VM to htb?

#

i ran openvpn academy-regular.ovpn

fathom pendant
#

run sudo openvpn /path/to/downloaded.ovpn (note /path/to/ is placeholder and downloaded.ovpn should be replaced with the ovpn file name you downloaded)

rustic sage
#

it says exiting due to fatal error

willow sky
#

Hi Guys, can i ask between the "Intro to whitebox pentest" and "Whitebox Attacks", which module is a good progression overall to oswe?

fathom pendant
rustic sage
#

shit it was js cause i didnt put sudo thats my bad

fathom pendant
supple gorge
shell ore
#

i need help 😅,
im having trouble installing crackmapexec while doing the password attacks modules

#

i used pipx but im getting:

    ERROR: Could not find a version that satisfies the requirement crackmapexec (from versions: none)
    ERROR: No matching distribution found for crackmapexec```
#

and when installing it from apt it's not working due to some python dependencies

fathom pendant
#

did you consider: installing the python dependencies

shell ore
#

yeah, but they cant be installed? like it gives me an error (due to wide system packages)

fathom pendant
#

have you considered updating/upgrading your system then>

misty current
fathom pendant
#

^

#

some of the devs moved over to NetExec

shell ore
#

oh

#

thanks guys, gonna check it

misty current
shell ore
#

appreciate it ❤️

cedar void
#

Can I dm someone regarding a question on the skill assessment from the pivot module?

tiny reef
#

In "Footprinting - SMTP" "Enumerate the SMTP service even further and find the username that exists on the system. Submit it as the answer. " I am using the correct wordlist and I have set out the timers from 5 to 10 to even 60 seconds with the provided wordlist.. still no user

fathom pendant
#

restart the box and try again

#

15-25 is the magic number

#

also are you using smtp-user-enum tool? or are you fighting with nmap scripting

tiny reef
#

Tried metasploit scanner and smtp-user-enum^^ I´ll try reloading the box

atomic wren
tiny reef
#

Ty, worked 🙂 @fathom pendant

prisma spruce
upper crest
#

Hello, anyone working/worked on the Game Reversing & Modding Skill Assesment ?

silver iris
#

Hey guys, i currently stuck on the last question of the "Pass the Ticket (PtT) from Linux". I have a root shell and found the keytab file, but i keep getting the error ||"kinit: Keytab contains no suitable keys for LINUX01INLANEFREIGHT.HTB@INLANEFREIGHT.HTB while getting initial credentials"||.
I´m running the command: ||kinit LINUX01$@INLANEFREIGHT.HTB -k -t /etc/krb5.keytab||

unique palm
#

im on the skill assesment in pivoting and tunneling. How do i get the lsass.DMP file from the internal DC to my attack machine? I tried to base64 it but the performance is just 2 bad and wont finish ....

rustic sage
#

guys im doing the linux fundementals module, the question is locate the path to the victim's mail

#

i did locate mail

#

and found /var/mail

#

and thats not it n idk what im looking for

near gazelle
#

Hey guys today i got many problem with the pwnbox and the openvpn. All time when i try to do remote with the xfreerdp igot error message and one day ago it is worked excellent today it didnt work even not once . And the problem with the pwnbox that ive got some traget ip i was should need to do nmap and it didnt find the hos and the version service. When i did nmap with no flag it work its show we the only port i need but when i add the -sV it not worked at all and i try many combination and many time and i also try it in the openvpn and the same problem i also try open nordvpn and change my state and nothing….pliz help its drive me crazy i pay for this web and i stuck with many problem!!!

rustic sage
#

then do sudo openvpn academy-regular.ovpn

#

sudo openvpn academy-regular.ovpn

faint rampart
rustic sage
#

idk how to do that sorry

#

i dont see it in my cheat sheet

faint rampart
rustic sage
#

the second one got the answer, but im not sure how

#

like i dont understand

faint rampart
rustic sage
#

cause when i cd into /var/mail and do ls theres nothing

#

but when i did the second command it gave me ||/var/mail/htb-student||

#

im not sure how i was supposed to find that

#

oh it was js supposed to be ||env||

faint rampart
shadow current
#

I need a nudge o webattack module final skill assesment i already found all 100 users . I know one of them is admin.

My problem are:
How would i know who is the admin on those 100 users.

How can i change the password of other account i know i need to change the request method to get but the problem is it says invalid token and i cant reverse the token so i can reproduce it for other user.

faint rampart
rustic sage
#

what does grepped mean

weary pasture
#

hello , can someone help me i can't access to the pwnbox . Every times i try to access it says that "You have used your pwnbox allowed time"

cedar void
near gazelle
boreal quiver
#

Ever figure this out?

rustic sage
near gazelle
bright quiver
#

For the ACL abuse tactic module section - to confim we are trying to get adunn's hash cracks not damundsen - correct?

shadow current
rustic sage
#

what is an index number?

crisp remnant
#

Can i ping someone for a bit of clarification on: ADVANCED XSS AND CSRF EXPLOITATION -> Enumerating internal APIs

molten prawn
#

need a little help with active directory attacks and enumeration module . im in the living off the land part , final question . the question says Utilizing techniques learned in this section, find the flag hidden in the description field of a disabled account with administrative privileges. Submit the flag as the answer. . i have found the user but i can not get the description of the user

gray lodge
#

Hey @molten prawn , I can help you

bright quiver
#

Can someone give me a hand with this issue for the ACL abuse tactics section? I have the hash, but when I try to run hashcat I get this error:

Hashfile 'hash.txt' on line 1 ($krb5t...73157395E492836B63EAF21830809B7F): Separator unmatched
No hashes loaded.

hashcat - hashcat -m 13100 hash.txt /usr/share/wordlists/rockyou.txt

molten prawn
gray lodge
molten prawn
#

thats great . imma dm you

sly dome
#

has someone do the maths for the new Path?

#

gold sub is the best here right

#

but even with the discount is too much xd

unique palm
#

Im on the last question of the pivoting and port forwarding skill assessment. Can anyone give me a hint how to get to DC ?

bright quiver
#

@sly dome got i - dived depper into it..I must have changed the format and removed a "$" in the midst of it

#

thanks

sterile epoch
worthy laurel
#

MODULE: AD Enumeration & Attacks - Skills Assessment Part II
QUESTION: (7) Submit the contents of the flag.txt file on the Administrator Desktop on the SQL01 host.
HELP: I get this error message. What is wrong with this?

prisma spruce
sterile epoch
#

what kind of math are we talking about?

prisma spruce
#

The analysis is probably the same if you switch to euros.

sterile epoch
#

lemme see what they are offering its a new tier I guess I have never seen

#

btw can you help me with my practical

#

I tried to brute force in Password attacks and it did not work

unique palm
#

Module Pivoting and Port Forwarding - Skill assesment
I started the SocksOverRDP Server on the ||172.16.5.25 ||machine and tried to pivot to|| 172.16.10.5 DC||. However i get a conn refused. Any hints?

Proxifier output:
[12.17 12:22:31] mstsc.exe (4820) *64 - ||172.16.10.5:3389|| error : Could not connect through proxy 127.0.0.1(127.0.0.1):1080 - Proxy server cannot establish a connection with the target - Connection refused

sly dome
#

im not interested in a web advanced one but in internal pentest one, like cpts+

sly dome
#

i hope they release also a discount with the cpts+

prisma spruce
sly dome
#

yes

#

for the cpts we dont have a name yet xD

#

but its 99% it will be released

orchid pine
prisma spruce
#

It's 6000 cubes + cost of cert then if it only uses the senior web penestration tester modules

#

So somewhere around $618.

sly dome
#

we dont have that info for the advanced cpts xD

fathom pendant
prisma spruce
#

web penestration tester

fathom pendant
#

yes advanced WEB

#

CPTS is about AD/lab, not web

fathom pendant
#

so CWEE is advanced bug bounty

#

advanced CPTS will likely include the t3 AD stuff

wide river
rustic sage
#

In the footprinting module there's a ton of information regarding enumerating domains with tools like dig and crt.sh, my question is in regards to the TXT records you find, what exactly can you do knowing that info, like is it possible to spoof the value in the TXT record or something?

orchid pine
#

i missed that whle reading in the github repo

fathom pendant
#

the TXT records generally are some informative record

prisma spruce
# sly dome we dont have that info for the advanced cpts xD

If it uses all the tier iii modules, and you are only doing the tier iii modules, it would cost you 10000. So 10 months of platinum+$210=$890 as some sort of maximum cost. But if it's anything like the CWEE, it'll probably be closer to $618.

fathom pendant
#

and there's no point of spoofing a txt record

prisma spruce
rustic sage
#

ah okay.

#

i guess the intent behind looking for them is just to find out what third party services the target is using

lusty thicket
sharp nexus
#

Hey, does anyone know how to use pacman for blackarch?

#

I'm trying to go through the fawn thing and I can't seem to install ftp

urban valley
#

Password Attacks- Pass the Hash (last question): if anyone is having trouble with the reverse shell, use Port 443 instead of port 8001 as shown in the example. 8001 is not working for some reason

supple gorge
#

Working with IDS/IPS, ayone ever done the skills assessment Suricata?

Add yet another content keyword right after the msg part of the rule with sid 2024233 within the local.rules file so that an alert is triggered and enter the specified payload as your answer. Answer format: C____e

I didn't need to add anything to the alert and it already worked... Then I went to wireshark, looked based on the current rule... and looked for anything that was C___e

That doesn't feel like the right way

real delta
rustic sage
#

I would follow that up with don't use arch anything if you new to linux

sharp nexus
urban valley
#

Is AD Enum/Attacks the longest module on HTB Academy?

supple gorge
#

CDSA has a 5 day module, but still less than the 7 day one

urban valley
#

windows priv esc is 4 days but it took me 3 weeks lmao

quick cloud
#

yeah thats a trend with these modules lmao

fathom pendant
brisk hemlock
#

Hi there 👋👋

#

does any of u know how can i hack a bank

chilly cosmos
#

No

quick cloud
#

Not possible

fathom pendant
#

Don't ask for illegal stuff

fathom pendant
brisk hemlock
brisk hemlock
fathom pendant
#

Before you earn the boot

brisk hemlock
prisma spruce
#

I should go through this room to see if there are any discussions of how long each tier iii module takes.

fathom pendant
supple gorge
#

MarcieLee, you're always around, what does it take to be a mod?

upper ruin
#

Examine the target and find out the password of the user Will. Then, submit the password as the answer.
Password attacks - Linux Credential hunting.
I found the password of kira, did an SSH, got trouble transfering the files, any ideas?

fathom pendant
supple gorge
#

I saw payload being upped to a mod, so I got curious

upper ruin
fathom pendant
#

Yes

upper ruin
#

I tired to, but there was some error code.

#

With the python.

#

I will try again.

fathom pendant
#

You gotta specify python2 or 3

#

¯_(ツ)_/¯

lusty thicket
quick cloud
fathom pendant
quick cloud
fathom pendant
#

Or sit around and passively learn new things. I'm not afraid to try something as a "fuck around find out" if my thought was correct

#

Get answer: think of other ways to get answer faster, test, fail/succeed

upper ruin
fathom pendant
#

No

fathom pendant
#

^

upper ruin
#

will try

fathom pendant
#

Btw you didn't specify what the python error was

upper ruin
#

:|

ocean night
#

sudo

upper ruin
#

Aint got the pass.

#
  • the account isnt on the sudo list.
supple gorge
#

type object is not subscriptable is the error

fathom pendant
#

You're kira, you do have her pass

upper ruin
#

but she isn't on the sudoers list

#

lemme try, still.

quick cloud
ocean night
#

What do you mean?

fathom pendant
#

I dont recall having many issues with it

faint rampart
# upper ruin

If you feel like exploring, theres a metasploit module that works exactly like firefox decrypt with less stress.

upper ruin
#

Nope, she ain't on the sudoers file.

supple gorge
quick cloud
#

Like when a module says 7 days how many hours per day is intended

ocean night
#

Honestly, I don't know

upper ruin
#

There ain't no msfconsole installed.

ocean night
#

I'm not really involved in the content side of things these days

fathom pendant
#

Corporate training stuff

upper ruin
supple gorge
faint rampart
autumn pilot
#

If something is not installed, in this case a python module in the target. The smartest way to approach it is to adapt based on the situation

fathom pendant
upper ruin
autumn pilot
#

Understand what you need to extract and what files you need for the extraction

fathom pendant
#

^

willow pivot
#

I am working on the academy module for JAVASCRIPT DEOBFUSCATION :Source code and I have found the flag but it is not accepting it. Any advice?

sharp nexus
#

aw man, I kinda wanted to see if @brisk hemlock was going to get kicked

#

rip

upper ruin
fathom pendant
upper ruin
#

lemme try the msf thingy

autumn pilot
#

There is a file transfer module that showcases a few techniques to move files across machines

autumn pilot
#

Usually the simplest one is the most reliable, and it could be under your nose

upper ruin
#

bruh, out of all I forgot about netcat,

#

The swiss knife.

willow pivot
#

@fathom pendant i followd the article step by step and copied and pasted, also tried replacing | with {}

fathom pendant
fathom pendant
fathom pendant
#

You're just viewing the page source

willow pivot
#

@fathom pendant confirmed no extra spaces, the flag i got was in format of HTB|XXX_XXX_XXXXXXX

fathom pendant
faint rampart
ocean night
fathom pendant
fathom pendant
ocean night
#

All good, just being silly.

fathom pendant
#

Np

#

I have a theory on what they goofed

willow pivot
#

@fathom pendant still not taking it

fathom pendant
#

I just checked and yep, no obfuscation goin on

willow pivot
#

i am looking at the source for secret.js

fathom pendant
#

😉

real delta
#

not hard, get used to it when using anything arch based

willow pivot
#

*faceplam

#

@fathom pendant thank you!

ocean night
#

😆

fathom pendant
willow pivot
#

PEBKAC

fathom pendant
#

The later parts have you explore that code

#

You just did it prematurely

willow pivot
#

i swear thats never a problem XD

fathom pendant
#

That's what they all say

#

(The skill assessment will have you feel the same)

willow pivot
#

funderful

faint rampart
#

Does anyone else have this weird discord cache should I say false positive detection from windows defender?

fathom pendant
willow pivot
#

i wonder if that is related to discord being a datamine lol

fathom pendant
#

It could be that it's a cached line of code that is a backdoor that someone was showing you

#

Literally why you have to put your notes in an excluded folder for defender

#

Cause your rev shells will get flagged kek

faint rampart
#

Worth researching and playing around with tho 😅 thanks

fathom pendant
#

Yeah, you can likely fetch the cache file

faint rampart
fathom pendant
#

I keep my notes on host, in the event my vm dies or I need to rollback

faint rampart
#

Recently lost a note that had important commands because I changed the folder location and forgot to add it to the exclusion list 💀

fathom pendant
#

Iirc

faint rampart
fathom pendant
#

Planning to migrate to my Lenovo laptop I got from a school. Its got win10 pro on it: so big bonus to being able to do more; I have a software license through school so I can mess with Ms Suite stuff

willow pivot
#

one of the best perks free ms office, cheap adobe

faint rampart
#

Fortunately now theres sysreptor.

quick cloud
#

Installing windpws is alot easier now

#

with usb

fathom pendant
quick cloud
#

ohh

fathom pendant
#

speaking of I need to copy my win10pro key somewhere

faint rampart
fathom pendant
#

I'd sooner walk on broken glass than keep it on digital media tbh

#

might write an obfuscated code to type it out though, sounds like a fun project

rare swan
#

Module Web Attacks Section; Other Notable Apps ---- cant get a reverse shell, what am i doing wrong?

rustic sage
#

guys

#

sudo updatedb
[sudo] password for htb-student:
htb-student is not in the sudoers file. This incident will be reported.

#

my module mentioned the locate tool and i wanted to try it to find the file that my question requests but i got this, is it gonna get me banned or anything?

fathom pendant
#

that's just a standard message

#

it's not actually being reported to anyone

#

i don't think you need to do sudo updatedb you can just do updatedb

grizzled schooner
#

Doing Medium Lab on Footprinting and I'm lost, the hint says ||to use SSMS, but MSSQL is 1433, which isn't a listed port|| I have no shame in saying this lab makes me feel like this is the wrong career for me lmfao... can I get a hint for this

rustic sage
grizzled schooner
#

'ppreciate it

rustic sage
#

imo, if you feel burnt out that way, maybe go take a break, just lay down and watch netflix till you can fully problem solve again

#

i know thats not what you asked for though

fathom pendant
#

yep just checked the hint: it's accessible internally

#

gotta get foothold first then access it

dusk portal
#

Hi, I was wondering if anyone is having issues getting the proper output when trying the example on Module: XSS Basics section: Stored XSS? I can not get <script>alert(window.origin)</script> to work properly on http://SERVER_IP:PORT like it shows...

rustic sage
#

im getting confused on the linux fundementals section 💀

#

File Descriptors and Redirections on this section at least

grizzled schooner
#

Okay, cool at least I'm not going crazy, do you have any hint you can give me for foothold? I have tried everything that I can think of... I've ||mounted nfs shares, tried every smb tool I can think of, and tried to enumerate rdp and rpc|| I wasn't getting anything but I don't know if I'm missing something

fathom pendant
#

you're definitely missing something: check open ports and think what's open and how you can check them

rustic sage
#

what are Input/Output (I/O) operations

fathom pendant
#

i believe nfs is the right start

rustic sage
fathom pendant
#

...what does input mean

#

what does output mean

rustic sage
#

input from where tho

fathom pendant
#

the command line

#

where you input things

rustic sage
#

oh sorry

fathom pendant
#

and receive an output

rustic sage
#

i dont understand how that relates to File Descriptors and Redirections though

#

maybe i havent read enough

fathom pendant
#

you probably haven't read enough

#

the section kinda explains it too

#

it sounds like you read the first few sentences without reading the whole thing LOL

rustic sage
fathom pendant
#

take a break if you have to

#

no one says you HAVE to complete a module same day you started it

dusk portal
grizzled schooner
#

Marcie, I've ||mounted the nfs share that was present, I've had it for a while, knowing something would be there...|| but my problem is being able to access it cause its locked I've tried using ||chown and chmod|| and neither worked... am I missing something

rustic sage
#

okay i finished reading and i have a question

#

How many total packages are installed on the target system?

what does it mean referring to packages

#

like what is a package, how do i search for it

fathom pendant
#

the target system is the system you're ssh into

#

dpkg is a command that comes to mind

rustic sage
#

i didnt see anything in ||dpkg for printing installed packages, only yet to install packages, i found on google "apt --installed list" and added wc -l to the end and the resulting number is incorrect, where do i go from here||

fathom pendant
#

probably a new line

rustic sage
#

i wanna find the intended solution if thats fair

fathom pendant
#

that is kinda the intended solution

#

yeah it includes the first line "Listing..."

rustic sage
#

okay thank you :)

fathom pendant
#

You can either inverse Grep to take it out of the output or do some other fancy stuff (which is honestly more effort than it's worth) to get it

#

but the start is apt list --installed

rustic sage
#

wait so how was i supposed to know the answer was 1 off if i didnt ask

#

or did i do something wrong to get it one off

fathom pendant
#

no you didn't do something wrong

#

two things you can do: answer is incorrect - do the command but instead of piping to wc pipe to either head or tail

#

if it's a new line error generally it'll be a blank line

rustic sage
#

you're smart as hell

#

sorry if my questions are basic or wtv im extremely new to linux except for using palera1n

fathom pendant
#

eh

#

i look at it as reinforcing my knowledge

fathom pendant
#

(ii in dpkg stands for "is installed")

#

something i found out while just fuckin around

hard widget
#

Guys, did you finished the Attacking Authentication Mechanisms module? I got stuck in the skills assessment, any hint?

soft plume
#

Hi, On Windows File Transfer Methos do I need to use the pwnbox or can use my own vm? It states Download the file flag.txt from the web root using wget from the Pwnbox.. Im assuming I have too but Im curious.

ocean night
#

You can use your own machine if you wish. Under your profile you can download the VPN profile in order to access your assigned Academy environment. Many module challenges do not require a VPN connection, but those that do are not limited to the Pwnbox for access.

soft plume
supple gorge
#

going on to the 4th weekly streak, anyone knows when the "win special rewards" will come?

grizzled schooner
#

Been trying to login to ||SSMS|| for Medium footprinting assessment, I found credentials through ||nfs share that haven't worked, and I've tried every combination of known admin logins... I also tried to move alex to administrator group / give administrator privileges and have failed to come up with a login...|| Can I grab a hint?

fathom pendant
#

there's an IMPORTANT FILE that has login info

#

that's the problem with most people they're given the end goal and don't realize there's steps in between

grizzled schooner
#

No you're not wrong, I've been exploring, just not in the right area

#

thanks for the hint

fathom pendant
#

i'm just saying in general when the question gives them the final step in the chain

#

and failed to read the whole section that has the steps in between

grizzled schooner
#

yeah fair enough

fathom pendant
#

a good portion of the sections are very much you can follow along

grizzled schooner
#

What a disgusting lab lmao, this took me all day

fathom pendant
grizzled schooner
#

lmao

#

this was deffo fun tho, can't say I could do it again tomorrow tho lmao

fathom pendant
#

for the hard lab; to give you an early nudge: read the description of the lab (the paragraph at the top)

lusty thicket
fathom pendant
#

it contains some nice keywords that can be useful to get started

grizzled schooner
#

wait what im confused, the password for the user isn't working lmfao

#

now im confused
edit: disregard, confused a letter

shrewd wasp
#

Hello, should I ask here about a problem or ask for someone to DM me for help?

fathom pendant
#

if it's for an academy module you're stuck on just ask

fathom pendant
grizzled schooner
#

through an ||rdp session||?

#

didn't work when I tried, idk what happened then

fathom pendant
grizzled schooner
#

Probably a skill issue but I'm trying to ||unmount the nfs share, and I keep getting thown device is busy buy nothing is running...|| am I missing something simple?

fathom pendant
#

are you currently in the nfs share?

grizzled schooner
#

no

fathom pendant
#

¯_(ツ)_/¯

shrewd wasp
#

So I am at Getting Started / "Knowledge Check"

So, I got administrator in the cms but the upload button doesn't work, either does msfconsole to upload anything

#

The button aint linked to anything

fathom pendant
#

try something else :)

shrewd wasp
fathom pendant
#

sirg

#

they're simply saying it's a skill issue

#

aka they were able to get the answer

shrewd wasp
#

Oh

#

I get it, but there's another way?

grizzled schooner
#

marcie, I restarted and literally just deleted it, does that leave it mounted still? lol

shrewd wasp
#

Yeap, got it, thanks Marcie

supple gorge
#

Malware Analysis, Dynamic Analysis, Noriben not wanting to work

fathom pendant
grizzled schooner
fathom pendant
#

you need to use one of the tools mentioned

supple gorge
fathom pendant
#

iirc

#

because the host needed to be bruteforced; also you're spoiling the content by providing the subdomain

#

the dnsenum tool bruteforces it's way to get a dns server that will give it the answer it's looking for

rustic sage
#

i'll delete the questions

fathom pendant
#

you point it towards the start SOA then it works it's way to get the rest

rustic sage
supple gorge
#

Anyone here ever worked with procmon and configuration files? I'm trying to figure out how to reset config to default

Edit: Idk how. the configuration for procmon for Noriben was giving errors... gave up on trying so just rest it

restive basin
#

first section, of the first module in academy and im totally stuck.

im following the writeup to the letter but i cant seem to get the flag. im able to get the download.php file but when i look at it, the flag that should be there...isnt

supple gorge
restive basin
lusty thicket
restive basin
supple gorge
lusty thicket
restive basin
#

when i do that it just hangs

#

been like that for 5 mins or so

supple gorge
#

same behavior for me

lusty thicket
#

strange

supple gorge
lusty thicket
supple gorge
#

The module practice is also giving the 301 moved permanently.

supple gorge
lusty thicket
restive basin
#

lol

lusty thicket
supple gorge
#

ok, fix

press reset

supple gorge
# restive basin

press yellow arrow to rest it, time left should go to 80 minutes. that'll fix it

restive basin
#

it went to 88 minutes and the same thing happens

supple gorge
#

Huh. Show command

I just did that and it worked for me

restive basin
#

just hangs and doesnt do anything

shrewd wasp
#

I got a question, how should I use something like linpeas or linenum if I cant download it in the remote target with wget or curl? Also the shell dies if I try to manually paste it

supple gorge
restive basin
fathom pendant
restive basin
#

it finished doing its think but i still get the 301 moved permanently instead of the flad

fathom pendant
#

using pwnbox as well and it works fine on my end

lusty thicket
fathom pendant
#

no 301 error

restive basin
fathom pendant
lusty thicket
fathom pendant
#

not from the IP:port given

supple gorge