#modules

1 messages · Page 174 of 1

shrewd hazel
#

ohhhhhhhhhh

sly dome
#

you don’t evn have to use FUZZ with ffuf

#

its customizable

#

lol

#

maybe is time for a walk or a rest

lusty thicket
#

Errors : 4984

#

strange

desert thorn
# lusty thicket `Errors : 4984`

Maybe its a problem that I use the pwnbox in my personal VM and not the web pwnbox (DDOS protection for certain IP ranges?).
FFUF quickly found the first few sub domains, but then really slowed down, and errors started to appear.

shrewd hazel
# sly dome lol

yea i need to go touch grass, been looking at screens all day

#

plus it looks like this needs a ton of time to run through anyway

desert thorn
#

@lusty thicket Can you maybe confirm that the command I used should work, or did you use another one?

desert thorn
# lusty thicket

Thanks for your help! I might have to try it out later with the web pwnbox...

desert thorn
#

I managed to find the relevant subdomain. For anyone that might be facing similar issues: try limiting the number of threads in use (I used only 1) and also limit the rate (I used 5 requests per second). Then wait for a few long minutes and you should find the subdomain.

fast onyx
#

Is there a place to report bugs? I got the flag for the repeating requests section but it keeps saying incorrect, I also saw on the forums that other people my have had a similar problem so JW

next bronze
#

module? make sure there's no extra space and refresh the page

fast onyx
#

@Xre0uS its the "Using Web Proxys" module. the more I look through the forum tho there might actually be two different "flag.txt" files so ill keep looking and try refreshing as well. Ill let you know either way

#

@next bronze Ya no bug, it was like a red herring flag lol Thanks for responding either way!

sly dome
#

H M and L stand for high medium and low, right?

next bronze
#

yep

sly kelp
#

I for iron

thorn urchin
#

T is for 'This is the modules channel lets keep it on topic'

tulip dragon
#

on "Pivoting, Tunneling, and Port Forwarding" the part "Web Server Pivoting with Rpivot" im stuck on the last question "Using the concepts taught in this section, connect to the web server on the internal network. Submit the flag presented on the home page as the answer." i have done it but still cant see the web page i even scanned with nmap and its not open etc... any help?

#

can't run website

static chasm
#

How should I write an email to the official or after-sales service? I need to solve some problems.

fathom pendant
compact patrolBOT
tulip dragon
lyric sigil
#

Hello, I'm having trouble finding the answer to this question, I'm hours away, I did exactly what was asked in the question, I've already redid it about 6 times, I even restarted the computer, but nothing shows me the name they ask for in the generated json file

this is the question

From Module: SOC Analyst

Section : Windows Event Logs & Finding Evil

part : Tapping Into ETW

Replicate executing Seatbelt and SilkETW as described in this section and provide the ManagedInteropMethodName that starts with "G" and ends with "ion" as your answer. "c:\Tools\SilkETW_SilkService_v8\v8" and "C:\Tools\GhostPack Compiled Binaries" on the spawned target contain everything you need.

#

I managed to generate the file, where there are some names with this ManagedInteropMethodName tag, but none that start with G, as needed in the answer, I did exactly as shown in the step by step, but nothing gives me the code, I don't know what else to do

fossil crescent
tranquil axle
pine dune
#

Hi

I'm having a port 22 connection timed out problem on the ssh to one of the boxes in htb...any suggestions would help

I have redownloaded the htb vpn file and also restarted the box a few times

hushed sphinx
#

Hello is there a #general where I can discuss about issues?

#

Offtopic

pine dune
pine dune
#

Academy

next bronze
#

section?

pine dune
next bronze
#

the target should be the same across the sections, were you able to ssh into it for the previous sections?

acoustic owl
fierce veldt
#

Anyone know why I would get username and password incorrect when trying to RDP into a machine for a lab?

civic zenith
#

@fierce veldt try putting single quotes around your username and password

fierce veldt
thorn urchin
#

most certainly just entering it wrong

#

what module and section is it and screenshot of your attempt to put it in

fierce veldt
#

It's the Active Directory Enumeration & Attacks - Domain Trusts Primer

I can't send screenshots but the command I use is this

rdesktop 10.129.188.199 -u 'htb-student' -p 'Academy_student_AD!'

steel gorge
#

I'm not getting an ssh timeout but I'm finding the brute forcing really slow. Re: https://academy.hackthebox.com/module/57/section/516

48.00 tries/min, 720 tries in 00:15h, 44880 to do in 15:36h
Following the directions for brute-forcing gave me 15 usernames and 3K passwords to try, so the box will easily run out of time before this is finished.
Is this expected or is this simply how long these things take?

fierce veldt
steel gorge
#

Thank you. I have -t 4 which was advised as the highest concurrent threads SSH can handle without dropping them

thorn urchin
next bronze
steel gorge
#

That's helpful, thank you.

fierce veldt
#

@thorn urchin and @next bronze I tried that as well. Even tried using the pwnbox lol

steel gorge
#

Switching it off and on again hasn't really helped, so I've just chosen the first username and it will just take as long as it takes

next bronze
fierce veldt
#

lol same command suddenly works. Cool, sorry for the trouble!

thorn urchin
next bronze
#

it take a while yeah, especially that section with multiple domains

fierce veldt
#

Also I think rdesktop wasn't working because it was defaulting to the wrong domain.

pine dune
next bronze
#

try with a target in another module, restart your vm, if all else fails, contact support

pine dune
#

ok ill try thank u

tranquil axle
steel gorge
#

Well the question does say to do that

Finally, try to brute force the SSH server shown above to get the flag.

#

As you now have the name of an employee from the previous skills assessment question, try to gather basic information about them, and generate a custom password wordlist that meets the password policy. Also use 'usernameGenerator' to generate potential usernames for the employee. Finally, try to brute force the SSH server shown above to get the flag.
That's what II'm on. I've got the wordlist and the password list

#

What is the hint I'm missing? I'm keen for this to not take so long 🙂

#

would I simply bruteforce the login page? That was the previous exercise

tranquil axle
#

There should be a ftp server running on the same host that is faster to bruteforce

#

If that’s the section I’m thinking of

steel gorge
#

I guess if the question wants me to bruteforce something else it should be worded something else other than "bruteforce the SSH server" 😅
Have others had this issue?

#

(I appreciate the help 🙇 )

tranquil axle
#

It’s a common point of criticism with this module

steel gorge
#

ah

tranquil axle
#

Some say it teaches you to think outside the box

#

But the password attacks module has some not-so-userfriendly questions

steel gorge
#

They come along now and again. I've been searching discord for this wording specifically to see if anyone has had issues. But "slow ssh" was a bit broad haha

tranquil axle
#

Ssh is notorious for being hard to bruteforce, so you can see this is a lesson of „only try a small wordlist or try something else“

steel gorge
#

nmap shows 22 and 25 open, not 21 🤔

next bronze
#

I don't think the skills assessment has a ftp to brute but can't remember

#

the estimated time is only if it went through all combinations, if it finds a match it won't take nearly as long

steel gorge
#

There was one where you bruteforced a login page and then pivoted to an FTP server, but that was via localhost.

#

(I did that one previously)

#

Thank you so much again @tranquil axle and @next bronze 🙇

#

So now I've got in 👍 and yes, there was an internal FTP port that I'm now doing another bruteforce on. Much faster (helps to be localhost haha)

next bronze
#

take note of which user should be mounting and copying shell

naive wadi
#

has anyone had any issues with a vm not playing well with the sqli docker instances? It's really strange as I can't seem to get a proper response from them. I have re-downloaded my vpn pack, checked my network settings and it just hangs. But vm instances e.g. windows modules have no issues. It's so strange. Also have no issues using pwnbox at all. This could be an entirely me issue but just curious if anyone else has had anything like this?

storm hedge
#

Hello, can anyonz help.me withe question submit the password of the sqlftp user from the ntlmrelay module.
I got a password for another user but I dont how to solve thos

storm hedge
#

The skill assesmznt section

next bronze
#

which question

storm hedge
#

I believe its question number 3

#

I was able before to get access to backup01 but I'm stuck afterwards

next bronze
#

check what you can access with those creds

storm hedge
#

@next bronze I tried them with crackmapexec and smb and the --shares option but I didn't see anything worth noticing

next bronze
#

no readable shares?

storm hedge
#

I noticed some readable shares on backup01 and sql03 but with other credentials

#

@next bronze I found BackupShares on Backup01 and SQlShare on SQL03.
Are those the ones?but I don't know where to go from there

#

Also sqlftp user is not a domain user afaik

next bronze
#

check what shares you can access with the credentails you have, one of them should be pretty obvious

storm hedge
#

@next bronze I found BackupShares and SQlShare on SQL03
I dont know if those are the one you're talking about?

next bronze
#

check what's in those

storm hedge
#

@next bronze I did but I haven't found something noticeable.
On SQL03, I wasn't able to download the zip file.

next bronze
#

why not

autumn pilot
#

You are getting ahead of yourself

#

Take the nudges that Xre0uS pointed at you

storm hedge
#

@next bronze I used smbmap but evrytime I try to download it I get a corrupted file

autumn pilot
#

Then use something else

#

You have all of the freedom available and tools to you

sleek moss
#

hi guys im on ffuf module and i sent out the ffuf -w -u etc tc and it finished fuzzing and its finished but theres no results apart from :: Progress: [81643/81643] :: Job [1/1] :: 197 req/sec :: Duration: [0:05:25] :: Errors: 0 ::

#

theres no results saying found bla bl

storm hedge
#

@autumn pilot I tried with smbclient and smbclient.py and I get access denied for the same creds

autumn pilot
#

All I can say is that you have everything that you need to go through that question

storm hedge
#

@autumn pilot ok, I will retry later, maybe I missed something on the command line or something.
I suck

#

I was wondering, the target system is pretty slow, I connect to is pretty slow.
Is that the case for youbas well

sleek moss
#

can anyone help

next bronze
#

the section would be helpful

main spear
#

Hello, i am doing the docker part of Linux privilege escalation and i'm trying to run docker but i have this error : ocker: Cannot connect to the Docker daemon at unix://var/run/docker.sock. Is the docker daemon running?

#

When i try to run docker with systemctl start docker i can't because i need the credentials of user lab_adm. So my question is : do i have to do lateral movment to this user ?

lusty thicket
#

docker start ‘container name’

#

is the right command

sly dome
#

you dont need to do anything

#

you log in via ssh and you can interact with docker directly

main spear
#

Ok thank you, but i dont get it. I use the command provided in the course because the docker.sock is writable but i have this error again

#

even if the socker is running

sly dome
#

docker -H unix:///var/run/docker.sock run -v /:/mnt --rm -it ubuntu chroot /mnt bash this command works for the PE

main spear
#

thank you

#

it is working

#

but i don't get it why it wasn't

#

i used the same command

sly dome
#

weird but can happen, try several times is the lesson from this i think

main spear
#

Yeah thank you !

fierce veldt
#

Anyone have any wordlist suggestions for

Attacking Domain Trusts - Cross-Forest Trust Abuse - from Windows

I need to crack a TGS and have tried a couple wordlists with no results 🥲

sleek moss
#

for htb and do the sub domain fuzzing for .inlanefreight.com

#

i receive hundreds of replies

#

is that normal?

misty current
misty current
#

x will vary btw.

fierce veldt
sleek urchin
misty current
misty current
sleek moss
#

oh i c dank

fierce veldt
sly dome
#

with TGSs not much to do apart from cracking ig

#

well yea apart from importing it to your kerberos session *

misty current
#

hashcat would have been complaining about it if that was the case. Weird it let you run the wordlists

fierce veldt
sleek moss
#

idk what to filter i filtered 403 and theres stil la ton of answers

next bronze
#

nope it's not filtering by response codes, filter by response size, check the section

sleek moss
#

it dont say anything

#

o wait nvm

#

portal is 0 bytes right

#

im not sure how else

#

it dont say

#

i got the answer and looke for response for 0 bytes but idk why it 0

#

[Status: 301, Size: 0, Words: 1, Lines: 1, Duration: 402ms]
* FUZZ: blog part of the example

fathom pendant
#

-f filters AGAINST the query, -m MATCHES the query btw

#

so -fs 0 filters out anything that is response size 0 (but you also have to consider 404 response size)

sly dome
#

i dont understand the documenting and reporting lab xd

sleek moss
#

nono i got the ans

sly dome
#

they ask you to crack a password from the ntds but that password you got it before if u sniff the network

sleek moss
#

but idk why the byte size was 0

#

i did -ms 0

cedar void
sleek moss
#

is there a reason why customer subdomain is 0 byte

next bronze
sleek moss
#

unless ur just meant to copy from the example

fathom pendant
cedar void
#

I tried manually typing the password too. I guess I will try once more

sly dome
#

not approach xd

#

you just need the right user/password

fathom pendant
#

that has worked for me

#

like i said

#

it can be dumb

sly dome
#

htb-student is not an user of linux machine also you dont need that for that section

fathom pendant
sly dome
#

the section is the dcsync attack

fathom pendant
#

literally in the first paragraph my guy

sly dome
#

can be then

#

i did everything in that module with ligolo

#

so i missed that part

fathom pendant
#

this is a good module to practice pivot tools, i agree though

#

it's just nice to do it as the module intended

sly dome
#

yea

fathom pendant
#

in the event that for whatever reason your tools won't work

#

¯_(ツ)_/¯

umbral fulcrum
#

Hey guy, Quick logic Q:
creating a fake SPN: "blabla/LEGIT" meaning that creating a fake service (blabla) is available to that specific objet (user) right?

#

so Y does it helps do to "Kerberoasting attack"?

next bronze
#

I could tell you but it would be more beneficial for you to read the materials again, check how a user can request a ST and how SPN plays a part in this

sleek moss
#

can someone tell me why the vhost ffuf not working on that ffuf module? ffuf -w /usr/share/wordlists/seclists/Discovery/DNS/subdomains-top1million-5000.txt:FUZZ -ic -u http://94.237.56.188:40406 -H 'Host: FUZZ.94.237.56.188:40406'

umbral fulcrum
autumn pilot
#

have you read the section/material?

umbral fulcrum
#

what sectoin do u mean?

sly dome
sleek moss
#

i c ok danke

next bronze
#

aint no way man, read all the sections relevant to kerberos if you don't know what a st is

sly dome
sly dome
#

maybe i should add T4

next bronze
#

yeah that's what I did

#

T4 should be good most of the time

sly dome
#

or maybe i should use the prepopulated scans

umbral fulcrum
#

U mean TGS?

sly dome
#

yes its the same as ST just an alias

#

TGS is the service that provides STs

#

Client uses the TGT to ask the KDC for a ST (Service Ticket). That ticket is provided by the Ticket Granting Service (TGS).

sly dome
umbral fulcrum
#

Well that was condescending

sleek moss
#

for parameter fuzzing GET that target ip is the exact ip for the parameter fuzzing?

umbral fulcrum
#

thax @sly dome

steel gorge
#

I'm having this exact problem. No combination of the two I found (comma separated, no space, space, etc), or them by themselves seems to be accepted

#

I've used full URLs, partial, with port, without port etc etc

#

Do I need to fuzz the answer to figure out the format it wants? Is this part of it? Lol

sleek moss
#

how do i add subdomains to vhost on /etc/host for ffuf?

steel gorge
#

OK I've managed it, it was *.academy.htb format. That hint really needs to be in the question

next bronze
sleek moss
#

yea i found vhosts but i cant access them

#

i added them to /etc/host

sly dome
#

its /etc/hosts

sleek moss
#

but it dont work

#

yea thats it

next bronze
#

what did you add

#

did you specify the port in your url?

sleek moss
#

danke

next bronze
#

should remove this, spoilers

sly dome
next bronze
#

is 172.16.5.225 not your own IP?

#

it's been a while but from my notes it seems that it's the attack box

sly dome
#

yea it is l0l

#

this was weird

soft dagger
#

hellooooo

next bronze
#

soon™, and wrong channel for this

soft dagger
#

which one "channel"

next bronze
soft dagger
#

okay

#

thanks

cedar void
next bronze
#

is that mimikatz an exe?

sly dome
#

cant find the command injection xD

#

this lab is driving me mad

#

i think im just going for the attacking enterprise one

cedar void
sly dome
#

anybody has found the command injection in "Documentation and Reporting"?

sly dome
misty current
#

There is no mimikatz.exe in your folder

next bronze
misty current
#

there's another folder named mimikatz, might be in there.

cedar void
#

What folder? Because its in the Tools folder

#

oh I think I see

misty current
#

just cd mimikatz; ls

sly dome
cedar void
#

mimikatz is the foldeer

cedar void
next bronze
sly dome
#

yea sometimes its so obvious i fkn miss it

#

i was like "why is cat in a website"

#

who the hell use cat to show web contents HHAHA

#

thx

next bronze
#

yep lol, I also overdid it but it's really just that

sly dome
#

its so unrealistic

#

but yea, lets continue

#

i dont feel like doing a report for this lab, what do you think?

#

i feel like investing the time in the black box approach for the Attacking Enterprise is better

next bronze
#

I think it's up to you, if you feel like your reporting skills are up to scratch then sure

next bronze
sly dome
#

i feel this lab a bit weird and "small"

#

ofc its just for a quick documentation and reporting module

#

i understand it!

next bronze
#

yep enterprise networks will be a lot more realistic

sly dome
#

i just have a personal workflow for my notetaking and all that

#

for example i dont use the "writehat" tool in it

sly dome
#

i will take 24-48h to finish it

#

after that maybe someone can do QA to my draft

next bronze
#

sure but only if you send it to me on confluence kek

next bronze
#

joking, I can take a look at it if you want

sly dome
#

sure buddy

#

better if the reviewer has the cPTS

#

thanks

misty venture
#

Hi there, can anyone have some tips for the Skills Assessment, task 1 in INTRO TO ASSEMBLY LANGUAGE ? I found a shellcode by modifying the code
(the same like a lot of people here : 4831c....0f05) but it just give me an access with a red prompt with no flags when i load it to
the target. The code seems good, i think the problem is when i run gdb but i'm lost for the moment.
Thanks a lot

misty venture
#

Thanks, i've already check that, i don't know if the shellcode must be loaded as it is or not. I've tried to inverse the bit but same results. I think i must re-read the entire module to be more comfortable with GDB😫

next bronze
#

no need to inverse, run it as it is, your output looks right from the few digits you sent

#

dm me what you got if you can't figure it out

misty venture
#

Ok, i will retry and if i'm stuck i will dm you 🙂 thanks a lot

wraith junco
#

Hello, module ATTACKING ENTERPRISE NETWORKS and section is Lateral Movement, i have a administrator group but how can i read the flag.txt file on the desktop. I cant dump any hashes about Administrator account, but i am in that group HELP pls !! (Also i cracked the kdbx file but password is incorrect so i cant rdp :/ ) PLS DM ME!

rustic sage
#

heyy guys

#

I'm new
well idk a bit about this

wide river
#

@knotty chasm just hit Ctrl U and you will see the code. The answer is right there

paper fjord
#

I hate to be a pain, but does anyone here offer coaching? I currently work as a bouncer and am looking to transition into CySec, Just finding it hard to find my feet. My Friend said HTB is a good starting place

#

Currently doing Intro to academy, and while I can make my way through the modules, I feel like I'm stumbling through rather than absorbing knowledge. Or is it designed to be that way and it'll become more clear as I progress?

slate trellis
#

Hi everyone. I was studying passthehash section of Password Attacks module and I am confused a bit. Can you explain me what is the difference between PassTheHash and OverPassTheHash in terms of mimikatz. In the sections, syntax for both methods is the same. Could you help me please?

next bronze
#

you authenticate directly using the hash with pth, with overpass the hash, you use the hash to request a kerberos ticket, and further authentication will be done through kerberos

slate trellis
#

Theoretically, yes. But is it done automatically by mimikatz? How does mimikatz differentiate between PTH and OPTH if I use the same syntax?

next bronze
next bronze
paper fjord
#

Fair point

oblique spoke
#

hello! i got stucked at Active Directory Enumeration & Attacks Assessment part 1, i found the another domain user by chance and i need to find the users cleartext pw. Is there any guess what to do now?

slate trellis
next bronze
#

from what I know, no

rustic sage
#

Stuck on "Windows Privilege Escalation Skills Assessment - Part I". Cannot get a revshell. Tried uploading nc.exe and using the commands from www.revshells.com as well as all the PowerShell one liners from there. Any hints?

oblique spoke
rustic sage
oblique spoke
next bronze
#

was asking for the question you're stuck on but yes that should work kek

next bronze
rustic sage
plain coral
rustic sage
next bronze
#

oh nice, might just be you got a new target, tcp is always more reliable though

magic python
#

Hi Guys, This is my first and newbie question .... from service scanning module I trying to reply the conclusion questions but I got stuck ti get the "bob" password for smbclient, the tip is the password is weak but I try so many without success, may I use hydra to brute force or is there an easier way ? If someone could put me on the way again... I would be very helpful.

wanton jasper
eternal tiger
#

hello

rustic sage
#

hi is there a general discussion chanel?

eternal tiger
#

hello

eternal tiger
rustic sage
eternal tiger
#

wats your name

magic python
eternal tiger
#

hello

acoustic owl
#

@eternal tiger @rustic sage This is not the #general channel.
This channel is about HTB Academy modules
If you want to access the #general channel, read and follow #welcome

turbid jewel
#

Hey

#

In the module Shell & Payloads, the live engagement, in the second hint it reveals the username and password of the blog

#

It's possible to get it without the hint? If yes, how

final mica
#

Section: Linux Priv Esc
Module: Polkit
I transfed the compiled version of CVE-2021-4023 onto target machine with scp. but i get this.....
htb-student@ubuntu:~$ ./poc
./poc: /lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.34' not found (required by ./poc)

plucky latch
#

Anyone having issues spawning target VMs today?

sullen torrent
#

so today i was doing appointment machine in starting point and it was based on sql injection. the solution was to use admin' # (so to make the rest of the line as a comment in php) but why didnt admin' OR 1=1 -- work?

#

anyone ._.

storm hedge
#

I asked earlier some help with the ntlmrelay skills assement.
It turns out the issue I was having was with smbmap only.

sleek urchin
final mica
#

inside the box?

#

pwnbox?

sleek urchin
next bronze
final mica
#

okay thank you i will try that

sleek urchin
final mica
#

yea im dumb

final mica
#

i swear i tried to compile on target machine... but i guess i didnt try it for this module

#

thank you

wanton jasper
#

anyone having trouble getting targets to spawn?

next bronze
#

the Active Directory LDAP module could really use a rework or extra content imo, the length is rather disappointing for a tier 4 module, other tier 3 or even tier 2 modules have more content to learn and arguably better made/organised. it's probably one of the few modules in academy that can be done way quicker than the estimated time. and from the phrasing of this module it's quite clear that its supposed to be done before the other AD modules, which is odd and I doubt many have done that. it's still a decent module but can't be compared to the newer ones, at its current state it shouldn't be a tier 4 module

next bronze
#

I don't think it can be considered errors? 😅 just my thoughts on it

turbid jewel
analog dock
next bronze
#

fair enough

quick reef
#

hello

twilit ruin
#

hi

quick reef
#

has anyone completed protein cookies2 challenge

alpine ridge
#

Hi is anyone able to give me a hand with the ad enumeration module privellege access, last part leverage sql admin rights to authenticate to host and read desktop flag

fluid basin
#

Is this sentence from the intro to metasploit module confusing anybody else or is it just me? "Shikata Ga Nai (SGN) is one of the most utilized Encoding schemes today because it is so hard to detect that payloads encoded through its mechanism are not universally undetectable anymore. Far from it."

alpine ridge
fathom pendant
alpine ridge
fathom pendant
#

no

old notch
#

Can I advertise my ethical hacking community here?

alpine ridge
# fathom pendant no

Lol, doesn’t make sense to me tho how can I authenticate to a windows host that doesn’t have python use mssqlclient.py to then authenticate to an internal ip then read a file on that desktop

fathom pendant
solid python
#

Can I have some clarification on the "Packet Inception, Dissecting Network Traffic With Wireshark" module task

#

It states that you need to find the malicious actor in the live environment

#

however there does not appear to be any data relevant to that search in Wireshark-lab-2.zip

#

The answer to the first question can totally be found in that .zip

#

But the rest just leads to some confusing rabbithole

tight mesa
#

hello there & Happy New Year 2024, I don't wanna spoiler, anyone willing to chat about the Logrotate LPE exercise?

steep loom
#

If anyone has done the noSQL injection skills assemnt 2 can you please dm me? || I have a script that allows me to exfil the username though time-based blind injection, but when i do this.password instead of this.username, it no longer works || thank you!

silent sleet
#

anyone happen to know a HTB box that has a lot of ports open?

muted pulsar
#

You will need to import the module for powerview.ps1 before that command will work. It is in the tools directory of the machine you RDP'd into.

steep loom
river bridge
#

Hi, any tips for “ (Intro to Assembly Language - Conditional Branching)” ? I managed to avoid the loop but I don't understand which HEX value is expected in the response.

solid python
fathom pendant
solid python
#

Yep, it's on a seemingly dead interface but every now and then like 150 packets spin up

errant rover
fathom pendant
sleek moss
#

why are they doing the -H Content type, isnt it sent automatically without need for it specifiying? @htb[/htb]$ ffuf -w /opt/useful/SecLists/Discovery/Web-Content/burp-parameter-names.txt:FUZZ -u http://admin.academy.htb:PORT/admin/admin.php -X POST -d 'FUZZ=key' -H 'Content-Type: application/x-www-form-urlencoded' -fs xxx

lusty thicket
wind meadow
#

htb academy first hands-on question has incorrect question/answer..

#

good start for something i just burned $677 cdn on lol

cerulean grail
#

Can I get some insights about why the exploit in the "Public Exploits" module in the Pentester job path works? There was nothing in the NMAP scan for example that would imply that the web application uses that technology.

solar grove
#

Hello, dear people. In the INTRO TO ASSEMBLY LANGUAGE module, I "run" after writing "breakpoint _start" in the gdb debugger tool. But I get <_start+0> values in the results. Example output :
→ 0x401000 <_start+0> movabs rax, 0x21796d6564616341
0x40100a <_start+0> xor rax, 0x21449
0x401010 <_start+0> xor rax, rax

I solved the question but I wonder why this happened. (I found it by guessing because the question asked to find the start + 16 value.)

cerulean grail
sly dome
#

Attackin Enterprise network lab is taking +10 minutes to spawn

#

is that normal?

autumn pilot
#

please refrain from using caps

solar grove
#

@autumn pilot sorry I didn't pay attention

solid python
#

where the error is

wind meadow
#

ok sure

small sage
#

Stuck on the Splunk module, which account had most login attempts in 10 minutes. Tried making 10m timespan bins and sorting by count and account name, any help?

bright quiver
#

i am working on the web enumeration and exploitation section of attacking enterprise network...and i am trying to change the twenty twenty 404 template but i get this error...is this supposed to happen ?

"Unable to communicate back with site to check for fatal errors, so the PHP change was reverted. You will need to upload your PHP file change by some other means, such as by using SFTP."

tranquil axle
bright quiver
#

NVM....figured out the issue

small sage
solar grove
#

Hello, dear people. In the INTRO TO ASSEMBLY LANGUAGE module, I "run" after writing "breakpoint _start" in the gdb debugger tool. But I get <_start+0> values in the results. Example output :
→ 0x401000 <_start+0> movabs rax, 0x21796d6564616341
0x40100a <_start+0> xor rax, 0x21449
0x401010 <_start+0> xor rax, rax

plucky latch
#

Anyone else feel like complete idiots when doing some of these exercises, I spent 3 hours on one question and it deflated my ego completely

lofty rivet
fathom pendant
lofty rivet
next bronze
wanton jasper
#

I finished the AD section and I am building my own tools folder now before I do the assesments at the end. I have never really had to compile my own stuff so I am a bit lost on that. Anyone have some good resources on this topic?

fathom pendant
next bronze
#

get a windows vm, install visual studio

next bronze
wanton jasper
#

Its best practice to compile for yourself right?

next bronze
#

yes

fathom pendant
#

Yes it is best practice though

next bronze
shrewd hazel
#

I dont understand what this question is asking. I am specifcally confused by "use ZAP Fuzzer to fuzz the cookie for different md5 hashed usernames to get the flag" I think i went to the right url as stated and see the set-cookie for IP:Port/skills but a bit lost here on why/how the fuzzer is the answer. like what is actually occurring with the fuzzer

analog dock
shrewd hazel
#

set the fuzz location to the /skills/ part?

lusty thicket
shrewd hazel
#

ahh so i grabbed the wrong item here then

lusty thicket
shrewd hazel
#

got it, i think kek

fathom pendant
shrewd hazel
#

so now i would need to highlight that part and do a fuzz again on it

#

ahhh i think i see

#

now do i select the full value for cookie or just after "Cookie:"

lusty thicket
shrewd hazel
lusty thicket
shrewd hazel
#

i think im getting there

#

crap still off

fathom pendant
#

Careful with sharing your progress

shrewd hazel
#

?

fathom pendant
#

Could be considered spoilers

shrewd hazel
#

sorry, i just need some more help than what is presented in the academy site

fathom pendant
#

Just need to repeat those requests with each cookie

shrewd hazel
#

i did but im not getting what i need i dont think

#

all the items returned have same content length so something im doing is def off

lusty thicket
rustic sage
#

Hello

shrewd hazel
#

even though content-length appears to be all the same ?

rustic sage
#

Please

fathom pendant
#

For the last time: go to police

thorn urchin
#

<@&861185840277487616>

analog dock
#

Dude we already told you no

#

In 2 different channels. Just piss off

fathom pendant
analog dock
#

3 now yeah

wanton jasper
#

ban incoming lol

lusty thicket
rustic sage
#

Sorry bye

shrewd hazel
# lusty thicket strange

i swear that this is setup correctly for the fuzz attack to or else how would i be getting these responses

fathom pendant
lusty thicket
rustic sage
#

what is the fuzz attack?

fathom pendant
lusty thicket
#

google is your friend

analog dock
#

It’s specifically for insta

thorn urchin
#

fuck off

sleek moss
#

hi guys I am doing XSS module and when I execute <script>alert(window.origin)</script> on the page nothing shows up?

next bronze
shrewd hazel
shrewd hazel
fathom pendant
#

We don't wanna listen to a voice memo

lusty thicket
analog dock
#

Yeah Marcie would rather call with you

shrewd hazel
#

@lusty thicket @fathom pendant thank you i got it!!!!

fathom pendant
jolly cradle
shrewd hazel
#

ughhhh lol that rush when you finaly get it right lol

thorn urchin
#

np

fathom pendant
#

I heavily dislike personal interaction with people I dont know

novel matrix
#

hmm

tight mesa
#

sorry x my absolutely ignorance about this, but how can I find the version of glibc for Shared Object Hijacking exercise under LPE module?

final mica
#

ldd --version

cerulean grail
#

Does anyone know any good notes summary/cheatsheet for CPTS?
I was looking for something like that online to compare to my notes and make sure nothing was missing but couldn't find anything

next bronze
#

I don't think there are cpts specific cheatsheets around, but there are a lot of pentesting related ones. it's better to build on what you have

cerulean grail
#

I am. I just find it difficult to structure them in categories that would make sense to easily find what I'm looking for later, so I wanted to see how it's normally done.

#

I end up getting lost with all my notes when it shold be helpful. I watched a bunch of different videos on using Obsidian etc. and it just doesn't seem to click.

brittle arch
#

Can I chat with somebody about the (first) skills assesment in the Active Directory Enumeration Module (143)? I set up a pivot from the first machine, back to my attack host (VM with vpn). From that first machine I've got credentials for a user, and can winrm into a new machine, using a both ligolo-ng or chisel as a pivot. However, nothing I try to do to copy binaries from my attack box to the new machine works.. it doesn't seem to be connecting out through either pivot

next bronze
next bronze
# cerulean grail I end up getting lost with all my notes when it shold be helpful. I watched a bu...

I build my obsidian notes kinda like wikipedia, with crosslinks to other relevant sections or more detailed notes for quick acesss. and I use a plugin called quickswitcher++ which lets me search through all headings in my vault, and I can adjust the weightage of different type of headings, so I pretty much have my own search engine in the vault that lets me find any info I want within seconds, kinda necessary cause it has close to a million words total. but that's just personal preference, find a way that works for you

fathom pendant
cerulean grail
next bronze
next bronze
fathom pendant
next bronze
#

it's really good, basically google for my own notes

fathom pendant
#

i need to go back and condense; ad is really slowing me down tbh just because a lot is overwhelming me

#

like I absorb the knowledge but it make brain hurt

#

ungabunga run exploit

next bronze
fathom pendant
#

it's just literally how i absorb information

#

depending on the type/difficulty it exhausts me quickly

#

i am an info-sponge

next bronze
#

ah I see, I guess the best thing is just do it a lot, it will get a lot more comfortable as it goes on

fathom pendant
next bronze
#

yep there sure is a lot of shit

fathom pendant
#

but that's also why it slows me down; because I want to know what the command is actually doing

#

i.e. searching for what rights this user/group sid has over another object

next bronze
#

for the commands that aren't obvious what they're doing, I usually add comments to explain in my code blocks

fathom pendant
#

yeah

brittle arch
fathom pendant
#

apparently it has an enum script that works in much the same way linpeas does

#

saw John Hammond use it for Shakabrah Offsec Box

next bronze
#

oh cool, thought it's just a listener

fathom pendant
#

it's apparently got some neat features idk if it's in a repo for parrot or kali

#

aparrentlly you can just pipx install it

#

neat

rustic sage
#

bad idea to skip the linux fundementals module?

#

its pissing me off

#

its a 6 hour module and ive been on it for like 2 weeks

fathom pendant
#

what are you struggling with

rustic sage
#

the entire module is so hard to focus on

#

and i struggle with focus in general

unique finch
#

having issues with the metasploit module myself

#

the first question is a small ctf on using the eternalromance

#

the os should be windows 7 but nmap is returning differently

fathom pendant
unique finch
#

i wonder if this is an issue with the box

fathom pendant
#

it's based off smbv1

rustic sage
#

The SSRF part of the server side module is one of the most dense, confusing things I've seen in the course

unique finch
#

the exploit fails every time

fathom pendant
#

are you sure you're setting up the RHOST/LHOST correctly :)

unique finch
#

im using the target ip as RHOST

#

and im using the ip from ifconfig as LHOST

#

whis is the vpn addr @ 10.10.yadyada

next bronze
#

exploit fails or no session created? there's a difference

unique finch
#

no session

next bronze
#

wrong lhost ip

unique finch
#

im using kali wsl

#

is this an openvpn issue?

next bronze
#

think about what's the ip of the the target

rustic sage
unique finch
#

truly!

#

i dont know if im using the openvpn correctly tbh

#

at first it was all errors and now i can ping the box so i assume its working correct

#

ill fiddle with the lhost

next bronze
#

if you can run exploit against the target, your vpn is fine

unique finch
#

thats good to hear

#

im usually into reverse engineering and gamehacking so this cyber element is new to me

fathom pendant
unique finch
#

no

#

the first one is using metasploit to do the ctf

#

reverse shell

#

using eternalromance exploit

next bronze
#

what's the rhost?

unique finch
#

rhost is the target ip

#

my lhost is my tun0

fathom pendant
#

btw with msfconsole you can just do set lhost tun0 to have it grab it

#

instead of fully typing it out

unique finch
#

i see

fathom pendant
#

set lhost <interface>

unique finch
#

running it now

#

im getting execution expired error

fathom pendant
#

i swear you could set it, maybe not or a change happened but i've been able to successfully set it by just specifying interface

unique finch
#

no, it works

#

im just getting that error

#

it is not from using the interface

fathom pendant
#

nope it works just fine

next bronze
#

execution expired got nothing to do with setting the lhost tho, that's an error when running the exploit

fathom pendant
#

^

#

as i just showed: the payload works just fine

unique finch
#

weird, im using the default cfg

#

just changed rhosts and lhost

#

ill reset the target

fathom pendant
#

¯_(ツ)_/¯

#

you're using the psexec eternalromance yeah?

#

(the command one just does RCE, not a shell)

unique finch
#

yeah

#

i reset the target

#

ill try it rq

sly dome
#

you are getting an error which is from the latest metasploit version

unique finch
#

what does the error mean?

sly dome
#

is this?

rustic sage
#

whats a non standard directory?

fathom pendant
#

a non-standard directory is a directory that's not there by default

#

i.e. a standard linux directory for users is /home/user/

unique finch
#

what does ||[*] No payload configured, defaulting to windows/meterpreter/reverse_tcp|| mean?

sly dome
#

nothing

unique finch
#

i see

sly dome
#

can you tell us the exact error 😂

candid spade
#

Holaa soy nueva en el servidor!!

unique finch
#

it gets removed

sly dome
sly dome
unique finch
#
[*] target - Target OS: Windows Server 2016 Standard 14393
[-] target - Timeout::Error
[-] target - execution expired
[-] target - /usr/share/metasploit-framework/vendor/bundle/ruby/3.1.0/gems/timeout-0.4.1/lib/timeout.rb:43:in `rescue in handle_timeout'
/us
#

there is alot more text after

next bronze
#

is your target even alive? ping it

unique finch
#

had to redact the target ip

#

yes it pings

lean compass
#

I have a question regarding the module:

  • Getting Started : Public Exploits

In this module you need to exploit a vulnerable plugin, namely:

  • Simple Backup Plugin 2.7.10 for WordPress

The only reason I was able to exploit it, is because the webpage basically tells you in plain-text about it in the form of a blog post. However I don't feel this reflects a real-world webapp, they don't announce their plugins and versions. I can't figure out a command that lets me find this plugin on the webpage.

I've just reset the target webapp here:
94.237.62.195:47057

What tool/command finds the actual plugin without just reading the title of the banner?

unique finch
#

i dont know if this has to do with using wsl + kex as opposed to a traditional vm

#

i can pop a kali vm onto kvm/qemu

fathom pendant
sly dome
#

i completed the module with debian wsl + exegol

fathom pendant
#

another L for wsl :) config/routing issues

#

potentially firewall stuff

unique finch
#

might be right

#

just disabled the firewall

#

sadly same issue

fathom pendant
#

also i recommend trying the other eternal romance which is just RCE

#

and change the COMMAND option to whoami /priv

lean compass
fathom pendant
#

there's a hacking wordpress module : but for the purposes of demonstration that's why it was so simple

#

they wanted the focus to be putting you in the mindset

lean compass
#

=\

unique finch
#

seems i will get the same error no matter the exploit used

fathom pendant
#

and you changed RHOST yeah?

#

to the new IP you spawned

unique finch
#

yeah, i use setg instead of set before

fathom pendant
#

i don't mess with WSL just because I like having an easily configurable virtual environment ¯_(ツ)_/¯

#

also copy/paste go brr :D

unique finch
#

true

#

im installing windows 10 on my desktop rn

fathom pendant
#

??

unique finch
#

not a fan of dragonised garuda

fathom pendant
#

wdym installing win10?

#

are you using a vm in a vm type deal or somethin?

#

saw you mention kvm/qemu

unique finch
#

yeah, i was going to use kvm/qemu and passthrough a gpu to use windows in vm and linux as host

fathom pendant
#

so you were using wsl; in a vm?

#

trying to make this make sense

unique finch
#

no, using wsl on my laptop

fathom pendant
#

ah ok

#

had me concerned you were doin some real dumb shit rn

unique finch
#

imagine windows10 vm using wsl

#

😵

fathom pendant
#

that's why i was confused for a sec

unique finch
#

it virtualizes the virtual

fathom pendant
#

btw: there is a vbox version for linux

#

¯_(ツ)_/¯

unique finch
#

what is the best distro for pentesting?

#

im just getting into this

fathom pendant
#

there is no "best distro"

unique finch
#

i've heard its just packages

fathom pendant
#

most will either use Kali or Parrot

#

(some will use BlackArch/Arch)

unique finch
#

i was using garuda blackarch

fathom pendant
#

but for the most part if you're using a debian based distro it's all the same

unique finch
#

but for htb using kali wsl

fathom pendant
#

personal preference mostly ¯_(ツ)_/¯

unique finch
#

i was trying to find a distro that looks like windows 7

fathom pendant
#

there's not really a distro that looks like win7

#

you can customize using a KDE

#

and google different KDEs to find one that might be similar

unique finch
#

im pretty new to the linux side of things

#

is that like installing a gui?

fathom pendant
#

basically

lean compass
# fathom pendant there's some modules that go over enum tools

I went through the various enum tools discussed prior to the module to see if any of them would show the Wordpress plugin.
Namely, cURL, whatweb, and nmap. None of them were able to enumerate the plugin that the "Simple Backup Plugin 2.7.10".
What tool would you have used? Or should I have downloaded a wordpress enumeration script for nmap?

fathom pendant
#

but it's not referred to

#

poor dude who's wall of text keeps getting yeeted

lean compass
#

the script for nmap?

fathom pendant
#

no

#

it's an actual tool

#

wpscan

lean compass
#

mm okay. so for certain services you need a specialized tool to see the associated plugins. There isn't really a catch-all?

sly dome
#

you can fuzz for plugins under the wp-plugins directory

fathom pendant
#

^

sly dome
#

with ffuf for example

fathom pendant
#

but again this is getting-started module

#

so you're not expected to really know all about these tools

sly dome
#

yes just continue 😂

fathom pendant
#

and i'm guessing for the sake of not mindflooding new users: they kept it basic

lean compass
#

I see, thank you.

fathom pendant
#

tbh @unique finch if all else fails: just use the in-browser pwnbox if you can

#

it works perfectly fine from there

unique finch
#

yeah

#

something about having your own pwnbox though

fathom pendant
#

yep

#

it seems like you have a grasp what to do: just the tool on your end being st00pid

unique finch
#

i dont even want a career in cyber sec, just want to learn more about exploits. more specifically windows kernel exploits

#

good for gamehacks

fathom pendant
#

eh there's really not many that focus on kernel exploits

#

idk about the game hacking modules

unique finch
#

more so into reversing and intercepting packets

#

there are many kernel escalation pocs on github

fathom pendant
#

RIP dude shorten your message at this point since it keeps getting yeeted

#

LMAO

fathom pendant
unique finch
#

it will delete it if you use ip adrr

steep kraken
#

i need help in SMB module : Find additional information about the specific share we found previously and submit the customized version of that specific share as the answer. i have used rpcclient but either i cant see the answer if its in front of me or im issuing the wrong commands ive used the commands in the module

fathom pendant
shadow anvil
#

Hi all,

don't think my earlier post made it through, not sure why it's not appearing in the thread.

But basically looking to see if anyone was able to provide a nudge/hint for the final question of the ADCS skills assessment.

Tried ESC8/11 to Dev and remote to DC - No good
Tried ESC7 as per the play in the lesson - No luck
Tried enrolling a cert with X (that he has permissions for) and approving with Y (given the group he is part of) - No luck

I feel that ESC7 is the path the assessment wants to go down, but i think im missing a vital step to get me over the line.

fathom pendant
shadow anvil
#

ah, it's prob #2 - went into a bit of detail about what i attempted to help detail what ive tried.

fathom pendant
#

it's not a or b

#

it's a AND b

shadow anvil
#

understood. thank you.

fathom pendant
#

also as a note

#

please refrain from using usernames and such in your requests for assistance

unique finch
fathom pendant
#

you can shortand users as t* or to* if two users share the same first initial

fathom pendant
#

@languid pulsar whomst the fuck are you? i didn't give permission to dm :)

next bronze
unique finch
fathom pendant
#

¯_(ツ)_/¯

#

you know the academy has a search feature right?

unique finch
#

i should probably stop using this chat as a gen chat then haha

#

just passing the time while i get my own pwnbox up and running i guess

fathom pendant
#

there is a gen chat if you follow #welcome instructions 😉

unique finch
#

sounds good

#

hopefully i can get through these modules on vmware with kali

fathom pendant
#

should be able to

#

¯_(ツ)_/¯

rustic sage
#

I know guys this maybe not the place to ask but

I wanna ask are the pro labs been updated like the scenarios of approaching flags, methods, etc? Because I did rasta labs and dante a while ago and I'm going for Zephyr and if I get stuck maybe try either lab again so just wanna know before I buy the subscription

fathom pendant
shadow anvil
next bronze
#

you can use another permission for esc7

shadow anvil
#

can see both E* and M--s permissions. Though I've tried to issue a cert from a template that T* could enrol in (didn't see any template that J* could).

next bronze
#

check what group J* is in

shadow anvil
#

k thanks. I'll check again now.

rustic sage
#

this is such the worst website

fathom pendant
rustic sage
#

because i clicked next for everything in the tutorial make it easier

#

anyways i am leaving now

storm mantle
#

why doesn't it connect?

fathom pendant
buoyant escarp
#

Vpn connected?

fathom pendant
#

but also ^

storm mantle
fathom pendant
storm mantle
fathom pendant
#

can you ping the IP

#

can you nmap it

sudden kite
#

em am i doing something wrong ? currently I'm doing the module: Password Attack/Password Mutation, i downloaded the file there is 3 files i mutate the password.list using the custom.rule given in the downloaded files. than i use hydra to tried and get the password for the user "sam" ? seem like its going to take 64hr? is there something wrong ? any help will be greatly appreciated

next bronze
fathom pendant
#

the prompt for kali was because they used sudo

next bronze
#

yeah that's what I meant

storm mantle
buoyant escarp
storm mantle
#

Yes

fathom pendant
#

from the quick screenshot

#

you are using wrong IP

#

xD

buoyant escarp
#

Sneak peek screenshot

storm mantle
sudden kite
storm mantle
fathom pendant
storm mantle
fathom pendant
#

ah

#

unstable connection

storm mantle
#

Already

#

Ok

#

Is it my problem ? )

fathom pendant
#

change vpn regions and download a new vpn (close and delete the old one)

#

also use the tcp

fathom pendant
#

your ping should now also be stable

sleek moss
#

is there any way tp change the background color of htb academy/

fathom pendant
#

not unless you use a browser plugin

#

i think there's one that some people use called lightreader

sudden kite
fathom pendant
#

(note ssh is super slow, you should almost never brute force it unless you have to, and even then don't and just cry)

#

there's a tool that's been mentioned for bruteforcing ssh - called ssb

#

haven't tried it

sudden kite
#

i will give it a try. initially i set -t 4 on ssh take 64hr now i set -t 48 and take like 3hr 🙂 haha but seem like attacking ssh just take too long

fathom pendant
#

use nmap to find open ports

sudden kite
fathom pendant
sleek moss
#

after using XSS strike to find a payload like '><dEtAiLs%0aontoGGle+=+[8].find(confirm)%0dx//

#

where do i inject the payload?

fathom pendant
#

if there's somewhere to input text maybe

sleek moss
#

yea its in the url

#

but where do i put my payload?

#

do i put it at the end of that?

#

'><dEtAiLs%0aontoGGle+=+[8].find(confirm)%0dx//<script>alert(document.cookie)</script>

fathom pendant
#

usually xss is done via a form on the page, but it can be done in url

sleek moss
#

i am but if i want to put my own script

#

to do something where do i put it

#

along with the payload?

fathom pendant
#

¯_(ツ)_/¯

#

does the section give more details?

sleek moss
#

no not really

fathom pendant
#

then figure it out i guess?

#

idk if that will be interpreted by a browser url

sleek moss
#

'><a/+/oNMoUsEOVEr+=+(prompt)``><!--document.write('--!><h3>Please login to continue</h3><form action=http://OUR_IP><input type="username" name="username" placeholder="Username"><input type="password" name="password" placeholder="Password"><input type="submit" name="submit" value="Login"></form>');document.getElementById('urlform').remove(); anyone kno why that dont remove the id urlform

fathom pendant
#

¯_(ツ)_/¯

#

it helps to give context on what module and section you're working on

sleek moss
#

xss phising

#

html comments dont affect the actual javascript too right only what it displays on web/

fathom pendant
#

is that the one where the question has you upload something to send?

sleek moss
#

or why does making html comment not affect the code? yes login form

fathom pendant
#

but isn't there a /send or whatever

sleek moss
#

he comments out a piece of the code on the website using a html comment but it doesnt affect the thing why?

#

no

fathom pendant
#

¯_(ツ)_/¯

#

as suggested by the module to understand it better: try viewing page source to see what it's doing

sleek moss
#

i c but also some of my payload shows up as text how do I remove it if I html comment it out it wont work anymore..

fathom pendant
#

well when you view-source it's gonna show that it injects it in-front of the html code

#

on a normal view it's not gonna show much

sleek moss
#

wdym

fathom pendant
#

also

#

there is a /phishing/send.php

sleek moss
#

ik i did it im just trying to make it look nice

#

document.write('<h3> this bit shows up in white text but how do i remove it

fathom pendant
#

¯_(ツ)_/¯

#

you should at least first test it

#

if you test it as shown: do you get login info

sleek moss
#

yea i got the flag it all works

#

but i just wanna make the text hidden

fathom pendant
#

don't worry about it

sleek moss
#

kk

fathom pendant
#

btw your copy paste shows `` instead of doublequotes here

#

or singlequotes whatever you're trying to do

sleek moss
#

thats the way it formatted

fathom pendant
#

just put it into a codeblock

#

i didn't change anything

sleek moss
#

wdym

fathom pendant
#

just made it easier to parse the different things for myself

sleek moss
#

oh i c

fathom pendant
#

using ```html at the top and then closing with ``` underneath it puts it into codeblock

sleek moss
#

oh i c ok danke

fathom pendant
#

also your URL payload doesn't include the html comment out at the end of the payload? unless that wasn't copy/pasted on here

#

btw i'd suggest deleting the code block since that's technically how to get the answer

#

😉

sleek moss
#

ll

steep kraken
#

DNS Module : What is the FQDN of the host where the last octet ends with "x.x.x.203"? 1st thing i did is run ||dig axfr inlanefreight.htb @10.129.181.78|| and got ||app.inlanefreight.htb. 604800 IN A 10.129.18.15
dev.inlanefreight.htb. 604800 IN A 10.12.0.1
internal.inlanefreight.htb. 604800 IN A 10.129.1.6
mail1.inlanefreight.htb. 604800 IN A 10.129.18.201
ns.inlanefreight.htb. 604800 IN A 127.0.0.1|| then i ran against each subdomain the 2 commands ||dig axfr app.inlanefreight.htb @10.129.32.216|| and ||dnsenum --dnsserver 10.129.32.216 --enum -p 0 -s 0 -o subdomains.txt -f /opt/useful/SecLists/Discovery/DNS/subdomains-top1million-110000.txt --threads 90 app.inlanefreight.htb|| but i cannot get the answer. plz help me

fathom pendant
#

"Dns module" pretty sure that's not the name of it

fathom pendant
#

Module btw is Footprinting

sleek moss
#

can someone help[ me with xss the blind xss

robust ingot
#

I got a question I am very new to hack the box. Should I do hack the box on kali linux (vm) or should I do it on my mac?

sonic arch
#

Hi can anyone please help me with Injection attacks module - skill assessment? I got to|| xml exfiltration || now I'm stuck.

misty current
sonic arch
elfin epoch
#

Hello everyone, could you give me a little help here? Im having this issue with xfreerdp since yesterday

#

I cant make progress in CDSA modules

autumn pilot
#

If it takes more than an hour, then you are doing something wrong

misty current
autumn pilot
#

Well, again you are doing something wrong, none of the exercises takes significant amount of time

#

If it takes, then change the approach or vector

misty current
#

So, you know the usual flag format for HTB. ||Think how you can have your payload to just search for that format and get just that entry|| @sonic arch

misty current
autumn pilot
#

¯_(ツ)_/¯

misty current
# sonic arch Thank you

Also, have you tried getting the source code for the internal application? That should give you a better idea but again, the whole thing logic behind the query isn't complicated and can be done with assumptions of how the query code would look like.

elfin epoch
#

I need help in the module YARA & Sigma for SOC Analysts and other modules that need to use xfreerdp, Its isnt working as it should be, not connecting and having errors

elfin epoch
#

I get this errors everytime I go for RDP

#

that is needed to answer the questions

autumn pilot
#

check your credentials, if there is a special character somewhere make sure to use single or double quotes

elfin epoch
#

okay okay

abstract vapor
#

Hi, i used Get-DomainObjectACL command with specific user's SID in real environment, after hours still there is no output, is it how it works and takes too long? 🙂

elfin epoch
#

nvm I run it again and for some reason it worked

junior oxide
#

hi, i have been using the command "crackmapexec smb IP -u jason -P password.list --local-auth" in the attacking smb in attacking common services but i get no results any hints pls ?

turbid jewel
#

it's normal on the password attacks

#

the brutefoce smb taking so long?

#

i'm using metasploit to do so

abstract vapor
turbid jewel
#

the problem is other

#

i missed the success credential

junior oxide
#

mostly it doen't take long for me to get the password when brute forcing

turbid jewel
#

i didn't set the option to stop on the first success

#

i'm feeling stupid

crimson walrus
#

Hey guys, I am currently trying to exploit a writable smb share on a domain computer. Can anyone point me to a module in the academy where I can read up on any techniques or procedures to try?

autumn pilot
#

you can plant some malicious files such as but not limited to lnk files, library files and other if you are expecting someone to visit it so you can capture its authentication request, you can also place a malicious binary that could be masked as legit one and upon execution to provide you with a reverse shell. Those are some options that you can think of and eventually excel on

crimson walrus
#

thanks a lot! Do you if any of these techniques are explained in an academy module? I guess there is no dedicated module for that but worth a shot.

autumn pilot
#

AD Enum & Attacks, CME, NTLMRelaying would have those not all but yea

crimson walrus
#

thanks you very much good Sire

blissful axle
#

hey guys

#

i have a problem where can i get some help please ?

solid python
blissful axle
#

okayyy

elfin epoch
#

is the academy support working?

blissful axle
#

jsp

robust ingot
#

I have a question I want to start a malware analysis lab on kali linux where do I find malware to use it on my vm?

elfin epoch
#

Im stuck right in this module: Hunting Evil with YARA (Windows Edition) can someone help me?

#

I tried to follow the setps but no results

weak stirrup
#

having trouble with "spawing a target" not working and just hanging (wheel spinning) for more then 5 minutes. I have tried multiple times ... anyone else having this problem?

turbid jewel
#

i had this on password attack a few minutes ago

#

but i refreshed the page and spawned it again

weak stirrup
short gulch
#

vm's today just dont work as expected

eager badger
#

anyone can help me with this error? Write-Output : Parameter cannot be processed because the parameter name 'e' is ambiguous. Possible matches include: -ErrorAction -ErrorVariable.

wanton jasper
#

had this happening last night, refresh and keep trying. It will spawn eventually

wanton jasper
#

No, the targets now wanting to spawn

#

your issue requires google

junior oxide
#

guys i have an issue in the attacking smb section in attacking common service ... when i try to brute force the user jason on smb using crackmapexec (with --local-auth) or when i try it with metasploit i get no result even though i use the attackbox and the password list from the resources is there anything im not doing right ?

#

nevermine i used the password list from other section lol

hollow socket
#

Hello, Can i Ask a question about challenge here ?

glad orbit
#

Someone can help me about "USING CRACKMAPEXEC - Skill Assessment" . Q2?

wanton jasper
#

Best method to copy the tools folder from the AD section? gonna be a big file

acoustic owl
hollow socket
acoustic owl
hollow socket
clever smelt
#

hi, same question. Did you figure it out?

next bronze
crimson walrus
#

Hey guys, do you know if the following Inveigh command is effectively equivalent to running responder (for capturing hashes):

Invoke-Inveigh Y -NBNS Y -ConsoleOutput Y -FileOutput Y

Alternatively, is it possible to use responder over proxychains somehow?

misty venture
#

Hi there, anyone who have tips pour the skills assesment 2, in "intro to assembly" please, i got the code (wrong) and a shellcode under the 50 bytes with no null bytes but nothin seems to work. I know that the flag on this ex is called "/flg.txt" so it should be ok with an unique register to store. Thanks

next bronze
misty venture
#

the original question is "The above server simulates a vulnerable server that we can run our shellcodes on. Optimize 'flag.s' for shellcoding and get it under 50 bytes, then send the shellcode to get the flag. (Feel free to find/create a custom shellcode)", i've re-read the shellcode requirement and i optimize the shellcode (it contains no null bytes and is under 50 bytes) but nothing seems to work

next bronze
#

easiest way to test it is either through gdb or make a /flg.txt file in your own system and run the binary

#

also, your shellcode will need to have null byte, you'll need it for the string terminator, and the read syscall number, the shellcode will work as long as they're at the right place

misty venture
#

ahhhh ok😇 thanks for the tips, i think i know where's my mistake

urban valley
#

AD Enumeration & Attacks: I'm trying to connect via RDP but nothing is loading. I've tried downloading a different VPN file, resetting the machine, adding inlanefriehgt.local to /etc/hosts, and tried Pwnbox but I can't connect to RDP?

next bronze
#

hit enter

urban valley
urban tinsel
# next bronze yep lol, I also overdid it but it's really just that

After having spend many hours on this topic I was also able to read the index.php file like you show in the Figure. Now I am trying to read bash history files for lab_adm user as well as files in the .ssh directory. No success. Is there a way to actually get a reverse shell on the linux box (IP = 172.16.5.127)? Thanks.

next bronze
#

command inject a url encoded reverse shell oneliner, that's it

turbid jewel
#

let me ask u guys something

#

topics like SAM and LSASS

#

are used frequently? cause i'm having a hard timing on that

#

of course that with a cheat sheet i could do it "easly" but understading the theory is the problem

next bronze
#

the reg hives stores hashes of local accounts, lsass stores credentials of currently logged in users

turbid jewel
#

thanks, maybe im overthinking the things

#

i'll try to keep simple at the beginning, maybe i the future i can deep a little bit more

timber basin
#

stuck on Nessus Skills Assessment if anyone can help, I am able to login to my personal created account but the credential scan is not working the scan is only lasting <10secs and no results, additionally the provided credentials do not work for me to view the precompiled scan results

fathom pendant
#

You need to connect to https://ip:nessusport

#

Ip being the spawned ip

shrewd hazel
#

am i suppose to use msf once i have the vulnerability for this one? or am i overthinking it. web proxies -> zap scanner

fathom pendant
#

As the targets are on an internal *172.15-16.x.x

slender shoal
#

@midnight kindle Do not post spoilers, ie the flag. If you need assistance post your question, but do not post the flag.

shrewd hazel
timber basin
#

@fathom pendant I am getting error trying to connect to spawned ip with 8834

lusty thicket
timber basin
fathom pendant
timber basin