#modules

1 messages · Page 194 of 1

fathom pendant
#

Being honest, depending what kind of intern, you're not gonna reach a decent level of Competency in just a month, the cpts path itself can take ~ 3months itself

buoyant void
#

Random question, I'm doing the AD module and was wondering is there any issue with using evil-winrm to access the Windows attack host and run tools like Inveigh from evil-winrm? Instead of actually RDPing into the machine

fathom pendant
#

Inveigh sucks on cli stuff tbh

#

Evil-winrm also is just bad (but currently no alternatives)

#

But rdp is generally gonna be better for windows related tasks

buoyant void
#

Got it I tried it with evil-winrm just because RDP connection was absolutely awful, and it was decent but no interactive console on Inveigh like you'd have if you just ran it from the RDP which was annoying

fathom pendant
#

There's also 2 inveighs, the cool exe one and the ps1 script

#

The exe one is 10/10

buoyant void
#

yeah I tried the exe one from evil-winrm, but next time I'll just RDP to do it

fathom pendant
#

Also fwiw, if you're not already - use the tcp vpn pack

solar grove
#

Hello, I am about to finish the bug bug hunter path (90%) and then I want to continue on the Senior Web Penetration Tester path, do you think I should try to get an award in hackerone before I enter this or should I finish the SEnior web penetration tester?

fathom pendant
#

I mean the senior path is mostly an extension of the bb path

onyx dust
#

how would a h1 award help u pass the test? do they count for flags?

fathom pendant
#

If you want to practice on platforms like h1 no one is gonna stop you, and if that helps you feel validated with your learning then great!

onyx dust
#

i would suggest doing the senior web penetration path and then trying h1 because you will learn things and get to practice in a nice structured environment before trying it on h1 platform which has been publicly tested in many different ways.

#

it doesn't appear to me to be an extension of the bug bounty path inasmuch as it looks like htb's version of the burp cert

onyx dust
#

dont let any1 dull your sparkle

thorn urchin
#

Go for it if you think you can, but 20 hours a week is actually pretty low for someone wanting to speedrun the course

fathom pendant
#

^

thorn urchin
#

20 hours is what I was putting in when I didnt have much study time and was procrastinating

onyx dust
#

individuals learn at different rates and don't underestimate passion and curious people who have goals

thorn urchin
#

Not wrong, but people should be realistic about their own abilities

#

finishing CPTS in a month without prior exp would be a legendary feat

#

go for it by all means tho

onyx dust
#

they said they wanted to become intern level. that means you could do both at the same time considering intern level is up to the organization and what types of education and training costs for which they've tolerance.

#

it's up to your experience @thin parrot. put in the 20 hrs and see what happens.

#

it's better than 0 hours

thorn urchin
#

I agree with that

thin parrot
#

Keep in mind I have a cs degree so I’m not entirely out of the loop just some things I’ve never worked with. Linux for example I’ve barely touched till now

thorn urchin
#

also mb. I was reading as finishing cpts in a month, not intern level. Intern level 100% depends on the company like jinn said

#

interns can vary between total newbs to cutting edge research lmao

thin parrot
#

Yeah no way I’m finishing that. It’ll take me another 4-6 months to get through nearly everything

onyx dust
#

i did all of offsec labs + pg in 8 weeks then got oscp from it

#

it's doable if you're into it.

#

also that's like 10 hr a day too

little flint
#

where can i get kali linux for virtual machine?

onyx dust
little flint
#

what VM do i use?

onyx dust
#

lol

#

🥲

thorn urchin
#

<@&861185840277487616>

thin parrot
#

I’m not sure what the abbreviations are exactly but I’m doing this to get into pen-testing

soft cedar
little flint
thin parrot
#

^ I like vbox personally

thorn urchin
little flint
#

oracle virtualbox?

thorn urchin
#

sure try that

thin parrot
#

Yes, was very straightforward if I remember correctly

buoyant void
#

Virtualbox is great for getting started with VMs, I've since moved over to fully using VMWare Workstation Pro but I never had issues with Virtualbox

plucky latch
#

I use VMWare Fusion as I find it works best with my Mac

hot grove
#

you defintely want to try either vmware workstation pro (free) or virtualbox, those are very straight forward

fathom pendant
#

<@&861185840277487616>

thorn urchin
#

oh fuck its the carpet guy

#

bro you never gave me the price to hack a carpet

#

😭 ill never learn how much it is to hack carpets

vivid storm
#

cant pass this phase while running monitor.sh on nibbles:

nibbler@Nibbles:/home/nibbler/personal/stuff$ sudo monitor.sh sudo monitor.sh [sudo] password for nibbler:

it is asking for password. Any clue?

fathom pendant
#

use the full filepath

#

Your block is getting deleted because automod is seeing it as spam

#

If you link your account following #welcome you'll be able to post large code blocks

vivid storm
fathom pendant
thorny hamlet
#

Working on the RDP and SOCKS Tunneling with SocksOverRDP section of the pivoting and tunneling module I'm stuck - can anyone assist?

loud pagoda
#

Hey, I am new to hacking and started working on an easy box labeled Bizness. I am doing directory discovery with Gobuster. I have a decent computer and ran a discovery with the wordlist 'directory-list-2.3-medium.txt' It's been around 20 minutes running and the scan is only 23%. When y'all run discoveries, is this wait time normal?

thorn urchin
#

follow the instructions in #welcome to access the rest of the server where you can then ask in #boxes

loud pagoda
#

Arigato

vivid storm
vivid storm
# fathom pendant use the full filepath

here is what happens after using the full path

nibbler@Nibbles:/home/nibbler/personal/stuff$ sudo /home/nibbler/personal/stuff/monitor.sh
<er/personal/stuff$ sudo /home/nibbler/personal/stuff/monitor.sh
'unknown': I need something more specific.
/home/nibbler/personal/stuff/monitor.sh: 26: /home/nibbler/personal/stuff/monitor.sh: [[: not found
/home/nibbler/personal/stuff/monitor.sh: 36: /home/nibbler/personal/stuff/monitor.sh: [[: not found
/home/nibbler/personal/stuff/monitor.sh: 43: /home/nibbler/personal/stuff/monitor.sh: [[: not found
nc: getaddrinfo: Temporary failure in name resolution
nibbler@Nibbles:/home/nibbler/personal/stuff$ ls -la
ls -la
total 16
drwxr-xr-x 2 nibbler nibbler 4096 Dec 10 2017 .
drwxr-xr-x 3 nibbler nibbler 4096 Dec 10 2017 ..
-rwxrwxrwx 1 nibbler nibbler 4102 Feb 2 20:37 monitor.sh
nibbler@Nibbles:/home/nibbler/personal/stuff$

glass glacier
#

How many modules/sections do people aim to do a day/week?

vivid storm
fathom pendant
vivid storm
glass glacier
fathom pendant
vivid storm
glass glacier
vivid storm
fathom pendant
#

have the other one listening on 8443 as the bash revshell shows

#

:)

#

the error was in name resolution: meaning it couldn't reach the IP from the command

vivid storm
maiden field
#

Anyone having trouble spawning targets ?

plucky latch
#

Yup, been trying for 3 hours now

harsh path
#

Hi, Im doing intro to assembly language and i kid you not been stuck on "debugging with GDB" for a week now, I need guidance...Please and thank you

supple gorge
rustic sage
#

been away from Academy for too long and working back into it... I assume that purchasing say 500 cubes in a one shot is NOT possible. Is that correct?

#

shit nm

#

the giant green buttons didn't register

supple gorge
rustic sage
#

yeah i see that... it would hold my feet to the fire to simply subscribe 🤔

supple gorge
supple gorge
rustic sage
#

i think i would need right around the 500 but i could see myself going into addiction levels within a few months 😄

supple gorge
#

500 = $50... plat $70 or $60 somehthing for 1000

rustic sage
#

yeah i think it'd be $70

#

but the one-shot silver per annum is definitely looking tempting 🤷‍♂️

rustic sage
#

i don't need certs or pwn boxes though

#

i'll figure it out

#

i have a discipline problem i need to solve before monday 😛

#

n-hours-per-day / 2

supple gorge
supple gorge
rustic sage
#

nice -- maths 🙂

#

nah i'm thinking a minimum of 4 hours per day on HTB tho

supple gorge
rustic sage
#

i have to code too... there's a project i want to do over the next six months. also another 4 hours per day minimum

supple gorge
#

try not to chew more than you can hold... that may not help your discipline issue... but I have no qualification to say anything

#

Anyways, this is a modules channel, we have strayed long enough, although it is kind of related...

rustic sage
#

bruh i'm actually thinking of drawing up a schedule that starts with 1) make bed 2) shower 3) brush teeth... 😄

supple gorge
rustic sage
#

understood

#

thanks

thorny hamlet
#

Weird one here dude and dudettes, rdp session to an internal pivot host keeps dying periodically with this error:
"[05:11:49:143] [10220:10222] [INFO][com.freerdp.core] - ERRINFO_DISCONNECTED_BY_OTHER_CONNECTION (0x00000005):Another user connected to the server, forcing the disconnection of the current connection.
[05:11:49:143] [10220:10222] [ERROR][com.freerdp.core] - rdp_set_error_info:freerdp_set_last_error_ex ERRINFO_DISCONNECTED_BY_OTHER_CONNECTION [0x00010005]"

I am not initiating any other connections... are the target boxes shared?

#

Doing the "Pivoting and tunneling module" btw

heavy marsh
#

When are the active directory labs going to be fixed? Anyone know?

buoyant void
next bronze
#

that works too

heavy marsh
#

No, I went back to one of the ones further back in the AD section

#

I'm on "privileged access"

heavy marsh
buoyant void
#

You're a bit ahead of me but so far I haven't had problems connecting to anything, a bit slower than usual on RDP one time I couldnt even connect to the RDP but other than that it seems okay. Hopefully whatever the issue is gets fixed soon

plucky latch
harsh path
tranquil axle
#

If you installed gef it should show you where you are in the code and what value each register holds after each step

quick flax
#

what does "CN" mean here?

#

under the DistinguishedName: CN=htb

next bronze
#

common name

quick flax
#

ahhh

#

thank you

real delta
#

this server is english only I think

real delta
hot agate
#

I am a beginner

autumn pilot
hot agate
#

pls reaply

quick flax
quick flax
real delta
quick flax
quick flax
hot agate
real delta
# quick flax thanks

ya, no problem. AD gets confusing fast just a heads up. Everything has it's own concept and I mean everything lol

quick flax
#

but eventually it all makes sense

real delta
#

ya, have you tried messing with AD in python with things like ldap3 and impacket's Kerberos utilities?

quick flax
real delta
#

It's definitely a challenge lol.

quick flax
#

sounds like one 😂

quick flax
real delta
quick flax
#

damn 🫡

quick crane
#

In the GAME HACKING FUNDAMENTALS module, I downloaded the official Cheat-Engine tool and opened it successfully in Windows. However, when I went to load the problematic Hackman process, it could not be loaded, causing me to be unable to complete the module. Someone has encountered the same problem. Is it a problem?

real delta
quick flax
ruby whale
#

Module Password Attack - Section :Passwd, Shadow & Opasswd
I tried using mutated list and rockyou.txt both but still couldn't crack it.
Any nudge ?

fading ridge
#

How are the vpn connections?

ruby whale
#

For me I am able to spawn and interact with targets vpn-eu2.

ruby whale
#

I tried that one too waited for three hours couldn't crack it

#

This password module is the most frustating one.

next bronze
#

should be in the mutated list

soft cedar
placid edge
#

So i am doing a module where i need to go the the subdomain of gitlab.inlanefreight.local. Yet when i go there i get redirected to port 8081 that doesnt have anything on it. Anyone that could help me understand why this is happening?

Fixed it by clearing cache.

soft cedar
ruby whale
# next bronze should be in the mutated list

Sanity check
Created this mutated list
.\hashcat.exe .\inputs\Password-Attacks\password.list -r .\inputs\Password-Attacks\custom.rule --stdout -D2 -d1 > .\inputs\Password-Attacks\mut.txt use same to crack another section
word list contain 187775 words

ruby whale
next bronze
#

the hash should be right

next bronze
#

try --stdout | sort -u > pass.txt

ruby whale
#

root:$6$XePuRx/4eO0WuuPS$a0t5vIuIrBDFx1LyxAozOu.cVaww01u.6dSvct8AYVVI6ClJmY8ZZuPDP7IoXRJhYz4U8.DJUlilUw2EfqhXg.:0:0:root:/root:/bin/bash

ruby whale
soft cedar
ruby whale
next bronze
ruby whale
next bronze
#

hmm okay try again, you should only see english words for the candiates output in hashcat

ruby whale
#

I am not sure what am I missing, I am only getting 54550 words

soft cedar
next bronze
#

nah it didn't work for them because of some igpu thing

#

try mutating the list on linux maybe, since it uses the cpu anyway

ruby whale
soft cedar
next bronze
#

yeah try in linux then transfer out to crack in windows, you should get 94k words

ruby whale
#

I cant try that on linux , I have my attack box on VM 😦 not enough memory to allocate to hashcat

#

I think chick3nman might be able to help

#

It might be unrelated issue.

placid edge
#

anyone else seen this when using ligolo?

2024/02/03 11:05:13 [ERR] yamux: Failed to read header: remote error: tls: internal error
ERRO[0000] Connection error: remote error: tls: internal error 
FATA[0000] remote error: tls: internal error     
ruby whale
#

Thanks.

next bronze
#

technical issue, unlucky

#

give your vm a bit more ram if you can

#

or could've mutated the list in pwnbox I guess

ruby whale
#

I am not sure what is the issue 😦 , I was been at this for like 4.5 hours

ruby whale
ruby whale
next bronze
#

yeah maybe, well at least the cracking part works

ruby whale
#

Something funny going on with my hashcat xD

ruby whale
#

I hope such issues dont come during exam

placid edge
#

So i am trying to make ligolo work with a module here and i keep having issues.

┌───────────────────────────────────────────────┐
│ Interface 2                                   │
├──────────────┬────────────────────────────────┤
│ Name         │ ens192                         │
│ Hardware MAC │ 00:50:56:b9:ff:e3              │
│ MTU          │ 1500                           │
│ Flags        │ up|broadcast|multicast|running │
│ IPv4 Address │ 172.16.8.120/16                │
│ IPv6 Address │ fe80::250:56ff:feb9:ffe3/64    │
└──────────────┴────────────────────────────────┘

And i try to add the network route like: sudo ip route add 172.16.8.0/16 dev ligolo

But i keep getting this issue. Error: Invalid prefix for given prefix length.

ruby whale
#

this issues comes when to try to give incorrect CIDR range /24

placid edge
#

i dont get it. since the cidr i used was from ligolo

#

maybe ip issues idk

ruby whale
#

172.16.8.0/24 might work (but I dont any reasoning why it might work)

next bronze
#

you need to give the first ip of the subnet

#

so if you want /16 it should be 172.16.0.0/16 but that's usually way too wide

#

/24 is enough as mentioned above

ruby whale
#

@next bronze can I dm I have one query ?

next bronze
#

sure

steep kraken
#

need some help Exploit the target and gain a shell session. Submit the name of the folder located in C:\Shares\ (Format: all lower case) Module SHELLS & PAYLOADS . i have create a ||war|| file and uploaded it, but i cant get my reverse shell to the provided pwnbox

next bronze
#

is your lhost and port correct

timid steeple
#

Hello! I’m having a nightmare trying to get ODAT and SQLplus running on my Kali vm and was hoping someone could please help. 

Initially I did a new install gf Kali, everything updated and have all metapackages installed through kali-tweaks and get the following:

sudo apt-get install odat
Reading package lists… Done
Building dependency tree… Done
Reading state information… Done
Unable to locate package odat

I then spent the last night and all of this morning trying to install through the github page for Odat following the install instructions and despite trying several times and following the instructions I now get the following response when I try and run anything.

./odat.py all -s <target>
11:53:20 ERROR -: Impossible to load local configuration files in conf/ and to set driver_name: DPI-1047: Cannot locate a 64-bit Oracle Client library: “libclntsh.so: cannot open shared object file: No such file or directory”.

Could anyone please help guide me through getting this to work properly with library. I’ve trawled google and YouTube and no dice…

ruby whale
#

Try installing libclntsh.so

hazy grotto
#

@brisk socket Check your dms. I'll try to help quick before i leave.

ruby whale
ruby whale
timid steeple
tardy aurora
#

Because I can't enter your hacker box, you tell me an error, Networks

fathom pendant
fathom pendant
ruby whale
fathom pendant
#

huh. weird

timid steeple
ruby whale
#

Are you installing it on parrot ?

fathom pendant
#

do you get an error with installing those

timid steeple
timid steeple
# fathom pendant do you get an error with installing those

No errors on installation or any step of the process. Odat will then fire up on it's own but when you add a target machine to actually use it it errors out with

ERROR -: Impossible to load local configuration files in conf/ and to set driver_name: DPI-1047: Cannot locate a 64-bit Oracle Client library: “libclntsh.so: cannot open shared object file: No such file or directory”.

fathom pendant
#

Did you read the section iirc they give you a command to run if you get that error

timid steeple
fathom pendant
#

Took me half a second to find

#

It's likely a similar/related error to what you're experiencing

placid edge
#

how come i am in the administrators group but not allowed to view the administrator folder

compact halo
#

Running into some issue with the Password Attack module.
Specifically Remote Password Attacks > Network Services - I have the user and password but get denied when trying to view contents

rich radish
#

is anyone getting issues on the PIVOTING, TUNNELING, AND PORT FORWARDING module? the target is not spawning more than an hour already

compact halo
vivid storm
#

i am stuck at this point:

nibbler@Nibbles:/home/nibbler/personal/stuff$ sudo /home/nibbler/personal/stuff/monitor.sh
<er/personal/stuff$ sudo /home/nibbler/personal/stuff/monitor.sh
'unknown': I need something more specific.
/home/nibbler/personal/stuff/monitor.sh: 26: /home/nibbler/personal/stuff/monitor.sh: [[: not found
/home/nibbler/personal/stuff/monitor.sh: 36: /home/nibbler/personal/stuff/monitor.sh: [[: not found
/home/nibbler/personal/stuff/monitor.sh: 43: /home/nibbler/personal/stuff/monitor.sh: [[: not found
nc: getaddrinfo: Temporary failure in name resolution

any clue on how to pass this point?

rich radish
compact halo
wild helm
#

this is my first month ever using HTB and i gotta say it's been a complete mess trying to use the targets, they don't work half the time

compact halo
#

I'm having issues with the Password Attacks Module > Network Services: I get into smb but when I try to retrieve information about the dir, I get
Try "help" to get a list of possible commands.
smb: > ls
NT_STATUS_ACCESS_DENIED listing *
smb: >
I have tried the following command from outside of the smb share
smbclient \\10.129.202.136\cassie -U <pwnd-user>%<pwnd-pass> -c "ls"
smbclient \\10.129.202.136\cassie -U <pwnd-user>%<pwnd-pass> -c "dir"
both access denied since yesterday

fathom pendant
compact halo
fathom pendant
#

If it's a different user: yes

#

Each user for the services are unique

compact halo
fathom pendant
#

I believe the question says find the user for x service

#

And repeat for however many services

hallow kiln
languid fjord
snow ridge
#

In module Attacking Authentication Mechanisms, skills assements. I managed to complete it with this, but I have a question about it: ||First I created account with /register endpoint then used /login endpoint to get that token. Bruteforced weak secret, edited token's isAdmin to true. Then I went back to main page / and it asks for token. So I sent POST request with token as json in post data, but it did not work. Then I sent with GET request and it works. But how can GET request take data from request body? Its kinda new concept for me or at least very unusual and I have not seen it before.
My final payload to complete it

GET / HTTP/1.1
Host: asmt.htb.net
Content-Type: application/json;charset=UTF-8
Content-Length: 279

{"token":"eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ1c2VyX2lkIjoiNjViZTU0MjY2YmEyYWQ3YWI1ZjlkYjZmIiwiZW1haWwiOiJhM0BhLmNvbSIsImZpcnN0X25hbWUiOiJhIiwibGFzdF9uYW1lIjoiYSIsImlzQWRtaW4iOnRydWUsImlhdCI6MTcwNjk3MjE5OCwiZXhwIjoxNzA2OTc5Mzk4fQ.W-ZX4q3Sl7WazBUGKLP6c1ARhuIPDbcpJRvZ6pl9r4U"}
```||
inner parrot
#

Sup hackers, I'm in the Java Deobfuscation module, in the first part "source code" I retrieve the flag but the answer its not accepted, I'm pretty sure I have the right flag, HTB{flag} (to avoid spoilers I'm not pasting the real flag), I already try to clean any spaces at the beginning and in the end, any clue what's goin on?

snow ridge
inner parrot
snow ridge
inner parrot
tranquil axle
inner parrot
snow ridge
manic onyx
#

Doing the intro to assembly module. How come I am able to access the value of RAX with the registers command but not manual inspection?

#

Actually.. is it attempting to load the content of the RAX as a memory address? How do I reference the register itself?

topaz latch
#

SOC Analyst Path
Windows Attacks & Defense
PKI - ESC1

I RDP'd into the kali machine and from there RDP's into the WS001 machine.
Trying to replicate the attack scenario but facing an error when executing this command: .\Certify.exe request /ca:PKI.eagle.local\eagle-PKI-CA /template:UserCert /altname:Administrator
The error is [X] Error sending the certificate request: System.Runtime.InteropServices.COMException (0x800706BA): CCertRequest::Submit: The RPC server is unavailable. 0x800706ba (WIN32: 1722 RPC_S_SERVER_UNAVAILABLE)
I checked services.msc and RPC service is running

Any help on this would be much appreciated

tranquil axle
potent ermine
topaz latch
cobalt osprey
#

im doing the nmap module and am tryiing to nmap a ip with all port flag (-p-) but it is taking forever, what should i do?

late galleon
#

anybody interested in studying for the OSCP with me hardcore?

compact halo
onyx dust
#

My old oscp training partner hacks for Tesla now. I'm good for it.

#

Lmk if you want to do some proving grounds boxes sometime

compact halo
#

Remote Password Attack (Password Mutation and password reuse):
the command given to mutate the password list in the resources file has over 94K lines once mutated. Instructions say to run mut_...list. Is this list intentionally supposed to be long in cracking the password for "sam" or did I do something wrong? Been running for about 25 minutes. Not sure if this is intentional or maybe I am doing something worng

ruby whale
#

94k is the correct length

#

Try cracking ftp service ssh is slow

compact halo
late galleon
#

oh not accepting friend requests

late galleon
#

I tried it once a couple years ago and failed

#

but im intent on becoming the best hacker I can be

#

so I need that cert

compact halo
#

Remote Password Attack (Password Mutation and password reuse):
Tried ftp and got loggin errors with crackmapexec and hydra dropped out disabled too many errors - any suggestions
my syntax:
hydra -l sam -P mut_password.list ftp://<ip>
crackmapexec ftp <ip> -u sam -p mut_password.list

late galleon
#

@onyx dust cant send you a friend request

onyx dust
#

must be F8

late galleon
#

oops

#

one sec

#

ok go for it @onyx dust

onyx dust
#

all set

plucky latch
#

Looks like a rule violation to me

chilly cosmos
#

Not related to modules

next bronze
#

<@&861185840277487616>

chilly cosmos
#

@next bronze I use that next time.

next bronze
#

yes please do

topaz latch
#

Same here lmao

proud notch
#

Currently working through password attacks on the following question "Examine the target and find out the password of the user Will. Then, submit the password as the answer." While waiting for my password search to go through I took a look at the hint and saw the SSH login for Kira. I was just wondering was anybody able to get this login using Hydra or through another method because bruteforce takes forever for me currently.

compact halo
fathom pendant
compact halo
#

Remote Password Attack (Password Mutation and password reuse):
Tried ftp and got loggin errors with crackmapexec and hydra dropped out disabled too many errors - any suggestions
my syntax:
hydra -l sam -P mut_password.list ftp://<ip>
crackmapexec ftp <ip> -u sam -p mut_password.list

warm portal
#

anyone else unable to get their targets to spawn today?

proud notch
proud notch
# fathom pendant 2 things: lowercase Mutated

So I used the same mutation that was given in the earlier section for Remote Password Attacks ||hashcat --force password.list -r custom.rule --stdout | sort -u > mut_password.list||

fathom pendant
#

Also, save passwords you find. They are helpful

topaz latch
#

SOC Analyst Path
Windows Attacks & Defense
PKI - ESC1


   ______        _
  (_____ \      | |
   _____) )_   _| |__  _____ _   _  ___
  |  __  /| | | |  _ \| ___ | | | |/___)
  | |  \ \| |_| | |_) ) ____| |_| |___ |
  |_|   |_|____/|____/|_____)____/(___/

  v2.0.1

[*] Action: Ask TGT

[*] Using PKINIT with etype rc4_hmac and subject: CN=bob, OU=EagleUsers, DC=eagle, DC=local
[*] Building AS-REQ (w/ PKINIT preauth) for: 'eagle.local\Administrator'

[X] KRB-ERROR (16) : KDC_ERR_PADATA_TYPE_NOSUPP```

Tried manually copying the .pem and .pfx files between linux and windows, tried resetting pwnbox, tried doing it on my own VM (EU server). Nothing worked. I got the .pfx file, copied it from Windows to Kali Linux.
proud notch
topaz latch
#

And on top of that the Kali Linux machine is super laggy, unresponsive, disconnects over and over. SUPER frustrating.

fathom pendant
#

Use a different available service

#

Ssh is super slow with hydra/cme

fathom pendant
proud notch
fathom pendant
#

Nope

#

Also second part of my hint

#

lowercase

#

Don't use "Kira"
use "kira"

upbeat island
#

I’m struggling in two question of hack the box Footprinting. In SMTP section I have use all wordlist to know Which users exist and also the version , when I summit the answer is incorrect

maiden field
rustic sage
#

trying to escape a string to execute command

said program runs

sh -c /usr/bin/sqlite3 /var/www/DoodleGrive/db.sqlite3 -line 'UPDATE accounts_customuser SET is_active=1 WHERE username="test";'

user can specify the username which is put in the username field binary is setuid and runs as root

fathom pendant
#

What module is this for?

rustic sage
#

its for a box actually not a module

#

I cant ask anywhere else because I do not have access

fathom pendant
#

This channel isn't for help with boxes

rustic sage
#

Ive tried using the bot to identify but its broken

#

I know it isnt but if anyone can help just do so instead of "just wait till you can use a propper channel" 💀

fathom pendant
#

"It's broken" did you message a mod/admin to get it sorted?

rustic sage
#

I have and just did once more

fathom pendant
#

Then just be patient: this channel's explicit purpose is for academy modules. There's channels for #boxes {boxes} and #challenges {challenges} once you're connected

rustic sage
#

if that is your way of saying you do not know then alrighty

fathom pendant
#

It's my way of saying you're not gonna get answers here

rustic sage
#

sure

fathom pendant
#

@slender shoal ^ can you help verify this mans

tawdry vapor
#

anyone can help me with Attacking Thick Client Applications?

rustic sage
#

appreciate it

fathom pendant
slender shoal
#

@rustic sage dm me

tawdry vapor
#

I've come this far

#

but i can't find this

cobalt trench
#

Completed the footprinting hard lab with little to no help at all. Small achievements

patent oak
shadow chasm
#

Hello, idk if im asking this in the correct channel but i just made a HTB account and it says i have to verify my email i didn't get any email and clicked resend and waited a few minutes but still got nothing, is there any way to fix this?

#

Oh nvm i just got it rn

shell nexus
#

i am in the intriduction sequence and have reached the "interactive part with taregt", yet when typing in the ip it keeps telling me it took too long to load, what do I do?

fathom pendant
shell nexus
#

it has the port included

shell nexus
fathom pendant
#

Reset the target

shell nexus
#

thanks that seemed to fix it

manic onyx
#

Can SeBackupPrivilege be abused to dump the NTDS remotely? Or will you need an active session on the DC?

hollow furnace
#

am i allowed to ask questions about retired boxes here?

hollow furnace
#

I dont have access to that unfortunately

fathom pendant
#

Then read and follow instructions in #welcome

inner orchid
#

which pro lab do you recommend to prepare for the CPTS exam?

fathom pendant
#

<@&861185840277487616> slipped through the cracks

#

Usually the links are auto yeeted by the bot/automod

chilly cosmos
#

@slender shoal Hello, Can i dm for a question

slender shoal
#

Sure

buoyant void
#

Why would password spraying with rpcclient result in more hits than when I do the exact same user list and password through crackmapexec? I know there's probably a simple reason for this

hot oyster
#

My discord account was unfairly disabled what I do ??

#

someone help me please

fathom pendant
#

Contact support

#

If an account was disabled ain't shit anybody can do for you

upbeat island
#

Enumerate the smtp service and summit the banner, including its version as the answer. // struggling

fathom pendant
#

Well one way to get a service's banner is with netcat

#

Another is to just connect to it

upbeat island
#

Enumerate the smtp service even further and find the username that exists on the system summit it as the answer // struggling.

fathom pendant
hot oyster
fathom pendant
#

Use the techniques shown in the section

upbeat island
#

Let me try and repeat it

fathom pendant
upbeat island
#

Thanks.

fathom pendant
#

That kind of thing breaches discord ToS as a whole

hot oyster
fathom pendant
#

And anyone who sells you that service is likely scamming you

slender shoal
#

Contact Discord support. We cannot help you.

#

Discord support are the only ones able to help.

fathom pendant
#

If Discord said your old acct broke ToS then there's nothing that can be done

hot oyster
#

But it was unfairly !!

slender shoal
#

@hot oyster I'm going to ask that you do not continue this. Contact support, as they are the only ones with the ability to help.

fathom pendant
#

Ok? Then appeal and ask for proof. Many people say they're banned unfairly

#

But aside from that then literally no one can help you.

#

I'm not skirting around some ToS by telling you: no one can help you

#

Anyone that offers that help is a scammer

hot oyster
#

oh ok

buoyant void
valid osprey
#

Hello everyone, could anyone help me with a window lifting exercise?

Other Files

  1. find the cleartext password for the bob_adm user on the target system.

I believe it's doing the PSSLite technique, but the Set-ExecutionPolicy Bypass -Scope Process command showing in the session doesn't work, is this the right way to finish, or is it mapping the files in search of the password?

cobalt trench
#

Information Gather - DNS "What is the first mailserver returned when querying the MX records for paypal.com? "

#

Im gathering the MX record and inputting what Im finding but Im not sure if the format is correct. It keeps saying incorrect.

soft cedar
#

what question is that?

cobalt trench
fathom pendant
#

:^)

#

nslookup may give you the result in a diff order

cobalt trench
soft cedar
#

do you get diff results without adding the dns resolver?

cobalt trench
fathom pendant
#

always good to double check but if you're satisfied and want to move on go for it ¯_(ツ)_/¯

cobalt trench
tawdry vapor
#

anyone can help me wiht Exploiting Web Vulnerabilities in Thick-Client Applications? I can't download fatty-server.jar

tawdry vapor
#

anyone??

fathom pendant
#

@fickle sparrow your messages are getting yeeted by automod

#

you'll need to link your htb labs account following #welcome to post textblocks/images

fathom pendant
#

also for formatting textblocks

#

put ``` in front and behind the block

#

what module is this for

#

also are you sure you can write to the directory you launched ftp from

#

usually it gives you a local: permission denied message but idk about Passive mode

#

you also didn't answer: which academy module is this for

fickle sparrow
#

thanks

fathom pendant
#

also be wary of posting info from machines: as they can be considered spoilers

#

it could be that you intentionally can't download that file

marble raft
#

Has the spawning targets issue been fixed? I'm doing the updated part on Windows Privilege Escalation - Citrix Breakout and i'm having some troubles spawning the target you're supposed to RDP in

fathom pendant
#

it seems like it's still intermittent; better than before - switch vpn regions

marble raft
minor dome
#

i hop everyone you become good person and hapy

cobalt trench
#

Active subdomain enumeration - I added the IP to the hosts file with the DNS name and used nslookup to get the FQDN but it says unable to connect to server

marble raft
fathom pendant
#

using the IP works fine

fathom pendant
#

that the lnk points to

cobalt trench
fathom pendant
#

sir

#

you need to do nslookup -type=NS inlanefreight.htb ip

tawdry vapor
fathom pendant
fathom pendant
# tawdry vapor this

i haven't done this module so i can't guide you; also as a sidenote - don't dm without asking

ruby whale
#

One dumb question but how do you exit xfreerdp full screen 😅

fickle sparrow
fathom pendant
cobalt trench
#

I didnt know you could do xfreerdp full screen

fathom pendant
#

yeah; it's one of the many options

ruby whale
fickle sparrow
cobalt trench
#

thought full screen only worked on rdesktop

short hare
#

Stuck on:
ATTACKING COMMON APPLICATIONS: Attacking Thick Client Applications
Question: Perform an analysis of C:\Apps\Restart-OracleService.exe and identify the credentials hidden within its source code. Submit the answer using the format username:password.

With x64db done this as per module.

But when I use strings it says

Can anyone help with this section. It's really something that is wired

fathom pendant
#

like +clipboard to ensure clipboard functionality

ruby whale
short hare
#

@tawdry vapor Have you done the thick client section?

ruby whale
#

From now onwards using Dynamic resolution

fathom pendant
ruby whale
#

Yes

#

@fathom pendant have you completed the whole path ?

fathom pendant
#

no

#

been busy with life

buoyant void
#

Would there be any reason I'm suddenly having trouble connecting to any machine via RDP with xfreerdp? I'm currently in the Active Directoy Enumeration & Attacks module and I haven't been able to RDP using xfreerdp at all, the authentication happens and then I just get a black screen. Remmina is working perfectly though so I'm wondering if theres some setting in xfreerdp I should be including since the machines I'm trying to connect to are part of an AD environment?

short hare
buoyant void
heavy marsh
#

AD Enumeration & Attacks - Skills Assessment Part I Target is not spawning.

#

Any news on when they are going to fix the AD labs?

#

Or does anyone know which servers work?

tight mesa
#

anyone can connect to the pwned machines?

#

I'm receiving this error message :
[21:32:07:799] [8606:8607] [ERROR][com.freerdp.core.transport] - BIO_should_retry returned a system error 32: Broken pipe [21:32:07:799] [8606:8607] [ERROR][com.freerdp.core] - transport_write:freerdp_set_last_error_ex ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D] [21:32:07:799] [8606:8607] [ERROR][com.freerdp.core] - freerdp_post_connect failed

fathom pendant
tight mesa
fathom pendant
#

it also just looks like xfreerdp being dumb, sometimes that happens

tight mesa
#

I tried with remmina same result

fathom pendant
#

idk then reset target ¯_(ツ)_/¯

tight mesa
#

LoL I tried from my Kali VM and my host with no success....

#

maybe today is not my study day, LoL

tawdry vapor
heavy marsh
#

AD Skills Assessment Part 1, cd command does not work

#

what am I supposed to do with this web shell?

fathom pendant
#

but you sure can dir C:\

#

<@&861185840277487616>

marble raft
#

For future reference in the Scripting AoB section of Game Reversing and Modding the last script doesn't work, and it does not work because the provided pattern on the AOBScanModule is not universal, you need to generate your own, following of course the examples given in the module. It's very important to read the Relative & Absolute Addressing section because without it you won't know how to spot the pattern needed.

slender shoal
fathom pendant
heavy marsh
#

None of the AD modules in AD Skills Assessment Part 1 webshell are working.

#

Where do I even start here!?

#

Looking back at the material I can't find anything about an Antak webshell

#

Can someone point me to that?

fathom pendant
#

is powerview.ps1 in the C:\ directory?

#

also why not work to upgrade the shell from a web to a full shell or enabling rdp

heavy marsh
fathom pendant
#

ok? that's not what i said though :P

heavy marsh
#

Don't know where to start with this one though.

heavy marsh
#

I can

#

t even CD with the webshell

fathom pendant
#

create a revshell

#

use like msfvenom or grab one from revshells.org and upload it to the webshell

#

webshells suck and are very limiting

heavy marsh
fathom pendant
#

i mean my dude, there was a whole module on shells way earlier on

#

not to mention there is a way to kerberoast SPNs i forget exactly which section, but there was a whole ass bit regarding SPNs

heavy marsh
#

I've barely just got the first flag!

fathom pendant
#

it literally gives you the SPN

#

but i think first and foremost: getting a better shell is more of a priority

heavy marsh
#

NOPE! lol

fathom pendant
#

for christs sake dude: read the error -> command not found

#

meaning whatever powershell module that would load the command isn't loaded in/imported

#

It's literally yelling at you that the command isn't found

shut quest
#

reviewed my notes for that module, slow down and read what marcielee is saying, you really should get a reverse shell from that web shell

fathom pendant
#

My first question once I saw where you tried to import the powerview module: is it in the C:\ directory?

#

just because you didn't see an error doesn't mean there wasn't one: webshells lack a lot of visual clarity for things

#

normally the error line would be deep red

fathom pendant
heavy marsh
fathom pendant
#

is ActiveDirectory loaded?

heavy marsh
#

How do I check that?

fathom pendant
fathom pendant
shut quest
#

yeah, i've learned a lot, totally would have done it differently now knowing as much as i do now

fathom pendant
#
#
heavy marsh
#

I am not following in any way shape or form.

fathom pendant
#

2 ways of using basic powershell to get the loaded modules :)

#

but imho step 1 should be just getting a reverse shell instead of working with a clunky web one

fathom pendant
#

👍 you can use an msfvenom reverse tcp payload

ruby whale
#

I wonder if julio.txt has any text root@linux01:~# smbclient //dc01/julio -k -c 'get julio.txt' -no-pass getting file \julio.txt of size 0 as julio.txt (0.0 KiloBytes/sec) (average -nan KiloBytes/sec
Password attack one the most annoying modules :p

#

My bad I might be missing something

fathom pendant
#

it happens

ruby whale
#

Doubt - why listing files on share show size 0 ?
maybe by trying what I missed I will be able to access the files, but not sure reasoning behind it

fathom pendant
#

maybe manually connect to it and don't run a command

ruby whale
#

But why cant we list it using the commands

fathom pendant
#

the text file shouldn't be empty

#

also are you sure the ccache isn't expired?

ruby whale
#

No its not

marble raft
somber lagoon
#

I have a question. In the scenario below, was it possible to do a PtT instead, rather than waiting for a successful paswword crack?

Scenario 1 - Waiting On An Admin

During this engagement, I compromised a single host and gained SYSTEM level access. Because this was a domain-joined host, I was able to use this access to enumerate the domain. I went through all of the standard enumeration, but did not find much. There were Service Principal Names (SPNs) present within the environment, and I was able to perform a Kerberoasting attack and retrieve TGS tickets for a few accounts. I attempted to crack these with Hashcat and some of my standard wordlists and rules, but was unsuccessful at first. I ended up leaving a cracking job running overnight with a very large wordlist combined with the d3ad0ne rule that ships with Hashcat. The next morning I had a hit on one ticket and retrieved the cleartext password for a user account. This account did not give me significant access, but it did give me write access on certain file shares. I used this access to drop SCF files around the shares and left Responder going. After a while, I got a single hit, the NetNTLMv2 hash of a user. I checked through the BloodHound output and noticed that this user was actually a domain admin! Easy day from here.

soft cedar
#

Weird, have you tried resetting the target.

ruby whale
#

I did try two ways

  1. updating KRB5CCNAME on svc_workstation as root and get julio.txt
  2. getting /tmp/krb converting it to julio.krb and then using Rubeus.exe to get same results
    Let me try resetting target
tranquil axle
#

They are both called ticket, so it can be a bit confusing

soft cedar
ruby whale
#

Pass the Ticket (PtT) from Linux

ruby whale
soft cedar
ruby whale
#

I didn't use proxychains just impacket-wmiexec dc01 -k it was not able to resolve dc01

somber lagoon
sleek moss
#

guys my hcakthebox lab wont spawn target

#

how do i fix

soft cedar
sleek moss
#

shud i connect ot vp

#

beofre i clcik spawn??

soft cedar
sleek moss
#

ok is wiced from us 1 to us 3 t

soft cedar
#

yes and you would have to re-download new vpn file for that.

sleek moss
#

i c

ruby whale
sleek moss
#

ty

#

ir worked

ruby whale
#

@soft cedar resetting worked

ruby whale
#

Finally after going it at it for 4 hours + completed the section, resetting does help. 🙂

patent oak
#

Guys, on the Active Infrastructure Identification in Info Gathering. Working on VPN. Could grab the header with curl,so it's up. Can ping it but when I try to whatweb I keep getting connection refused for both IP or the .local domains it gives. I could see other people use the same command and get results on forum. I think I'm missing something about the setup here. I think I'm on UDP VPN if it matters. Help please 🥺

ruby whale
patent oak
patent oak
sleek moss
#

in on oass the ticket password attacks and how do i get ccache for linux

#

linux01

somber lagoon
# tranquil axle You need the TGT for pass the ticket, but in the scenario they only acquired the...

@tranquil axle you can. To achieve it you need to dump the NTLM hash with mimikatz, forge a ticket with the NTLM provided, and perform PtT attack.

See https://www.varonis.com/blog/kerberos-attack-silver-ticket#:~:text=With a Silver Ticket in,to do some major infiltration.

With a name like Silver Ticket, you might think it’s not as scary as its cousin the Golden Ticket – you’d be horribly mistaken. A Silver Ticket is just as nasty...

next bronze
sleek moss
#

in on oass the ticket password attacks and how do i get ccache for linux
can someone help

#

pass the ticket

somber lagoon
# next bronze silver ticket and kerberoasing are tow completely different concepts, to be able...

Yeah, from this scenario there is a system level access.

I have a question. In the scenario below, was it possible to do a PtT instead, rather than waiting for a successful paswword crack?

Scenario 1 - Waiting On An Admin

During this engagement, I compromised a single host and gained SYSTEM level access. Because this was a domain-joined host, I was able to use this access to enumerate the domain. I went through all of the standard enumeration, but did not find much. There were Service Principal Names (SPNs) present within the environment, and I was able to perform a Kerberoasting attack and retrieve TGS tickets for a few accounts. I attempted to crack these with Hashcat and some of my standard wordlists and rules, but was unsuccessful at first. I ended up leaving a cracking job running overnight with a very large wordlist combined with the d3ad0ne rule that ships with Hashcat. The next morning I had a hit on one ticket and retrieved the cleartext password for a user account. This account did not give me significant access, but it did give me write access on certain file shares. I used this access to drop SCF files around the shares and left Responder going. After a while, I got a single hit, the NetNTLMv2 hash of a user. I checked through the BloodHound output and noticed that this user was actually a domain admin! Easy day from here.

next bronze
#

well @tranquil axle has already answered it, you need a TGS/service ticket to PTT

#

also, silver ticket doesn't necessarily give you more access, since you need the NTLM hash to be able to forge one, it's more of a stealth/persistence thing

somber lagoon
#

@next bronze thanks tho.

tulip bobcat
#

Any updates on the connection issues?

shell nexus
#

I'm attempting an ssh login on a target, yet when it asks for the password i can no longer type any characters into the console? what do i do?

civic zenith
#

Alternatively try this:
Generate an SSH key pair on your local machine:
ssh-keygen -t rsa -b 4096

Copy the public key to the remote machine:

ssh-copy-id username@<IP_ADDRESS_OF_THE_REMOTE_MACHINE>
After you've copied the public key to the remote machine, you can now SSH into the remote machine without a password:

ssh username@<IP_ADDRESS_OF_THE_REMOTE_MACHINE>

shell nexus
#

all i get is an error saying missing file specifications

next bronze
#

you can't see the password being typed but it's still being entered, it's a security feature. just copy then ctrl shit v to paste

civic zenith
#

oh right^

shell nexus
#

does it ever explain that?

civic zenith
#

completely forgot about that sadglas

shell nexus
#
  1. copying from my machine into pwnbox isn't working as it never gives me the option to paste
  2. typing it out manually just tells me permission denied
civic zenith
#

fullscreen the vm and look in the bottom right corner

#

It allows you to copy commands over

shell nexus
#

thank you

civic zenith
shell nexus
#

i'm struggling with finding the way you can have all directory paths displayed as for my device it is dir

am i missing something?

broken lichen
#

.

hasty solar
#

Do u mind if I dm you I'm stuck there? In the DNS rebind portion of the lab

topaz locust
fathom pendant
lavish mango
#

Active Directory Bloodhound Skills Assessment Hint
Question: Find the percentage of users with a path to GLOBAL ADMINISTRATOR. Submit the number as your answer (to two decimal points, i.e., 11.78).
||MATCH (a:AZUser)
RETURN count(DISTINCT a) AS TotalAzureUsers

Looking up GLOBAL ADMINISTRATOR in Bloodhound and right-clicking 'Shortest Paths to Here' yield n Azure users.

(n/TotalAzureUsers)×100||

naive relic
#

hello ive just launched hack the box for the first time yesterday, and im doing one of the easy difficulty machines

#

anybody have advice or some sort of link to a tutorial i could use?

fathom pendant
#

2 things: there are no official/allowed tutorials for active machines
Second: this isn't the channel to ask for nudges on active boxes - #boxes is for that (read and follow #welcome to find out how to access more of the server)

naive relic
#

alright makes sense

lapis delta
#

Attacking WordPress module.

Problem: I'm attempting to use Metasploit in conjunction with the WordPress admin account to carry out the exploit. However, I'm encountering an error that halts the process. The specific message I receive is: "Exploit aborted due to failure: unexpected-reply: Failed to upload the payload."

Request for Assistance: Has anyone faced a similar issue or does anyone have insights on how to resolve this? Any hints or suggestions on alternative approaches to successfully upload the payload would be greatly appreciated.

frozen mesa
fickle sparrow
#

Did you setup the correct parameters on Set using metap ? @lapis delta

lapis delta
frozen mesa
fickle sparrow
faint rampart
# somber lagoon <@180397592524357632> you can. To achieve it you need to dump the NTLM hash with...

Mimikatz allows you only extract an nt hash from memory, and that would be possible if the account (service account) in this instance was a local account or has had a previous log on onto the machine, from my existing AD knowledege I dont think you can request an NTLM hash of a domain user just because youre system on a domain joined machine(unless of course you have the user's password you could get a ticket). You NEED the NT hash of the service account to be able to craft a silver ticket which is basically still a TGS that allows you to access the service whenever in a stealthy manner. In this scenerio the tester kerberoasted with SYSTEM to retrieve a domain account service ticket, that would only be good for cracking, and not in any way passing the ticket. We are really not the tester, and were not the ones doing the test haha so we wouldnt know other variables to factor in but the emphasis on the story was the use of custom rules to mutate wordlists and be persistent with cracking I believe.

rapid sparrow
#

I want to ask this one...

#

you found them on the two collection zip file from desktop?

chrome lotus
vale blade
#

Can you help me with advice on where to look in ABUSING HTTP MISCONFIGURATIONS Skills Assessment - Hard? I can't find the cache?

unique remnant
#

I have the same problem with the svg file upload.
I could trigger XSS but no XXE, I tried everything, even tried remote DTD, checked Hacktricks and PayloadsAllTheThings
I found the images directory by fuzzing so I am triggering it well (hence XSS works)

unkempt ether
#

PIVOTING, TUNNELING, AND PORT FORWARDING-RDP and SOCKS Tunneling with SocksOverRDP
i cant load SocksOverRDP-Plugin.dll because regsvr32.exe is detecting it to be a virus
i can't find the file exclusion list any other solutions beside disabling the windows defender?
im gonna go to bed now i will on this tmr

tacit jacinth
#

Has anyone ran into an error with Julio's flag on the Linux PtT module? Specifically the question "Check the /tmp directory and find Julio's Kerberos ticket...". I have retrieved the flag two different ways now, and the flag is never accepted. I see there was a comment made by another user last February complaining of the same thing.

mystic light
tacit jacinth
#

Yes

#

I have ensured there are no whitespaces or any other special characters. It is very clearly the flag. The module directs me to \DC01\julio\julio.txt (and i retrieve this file). It is as if the flag changed or is mistyped (or i'm seriously missing something)

soft cedar
fathom pendant
#

Alternatively, download and learn ligolo-ng

unique remnant
mystic light
wheat sinew
#

Where can one report typos on the page?

wheat sinew
#

Cheers

fathom pendant
wheat sinew
#

Will do.

#

🎉

unique remnant
topaz latch
naive relic
#

how to fix armitage exploit "connection with 'host ip' timed out"

rapid sparrow
#

Skills Assessment - Introduction to Digital Forensics
this is how to solve without using collections

solar zodiac
#

wow the relaying module is really good

#

🙂

#

I wonder if there will be any cloud modules

maiden field
shadow chasm
#

If I have the free version of HTB i can only use the web based parrot linux for 2 hours only and then cant use it again without VIP?

fathom pendant
shadow chasm
#

Ahh I see, and my bad

#

The issue is that i got a chromebook so is not possible for me to get a vm

fathom pendant
#

You can absolutely install a linux OS on top of one though

#

Chromium is just a shitty linux

shadow chasm
#

Ahh I see, ima see what I can do

kind turret
#

@maiden field @topaz latch Hello guys. I've spoke with our Labs Engineer and he told me everything works fine. You only need to wait 7-10 minutes before requesting any certificates.

#

He also informed me that he will try to reduce the waiting time by changing the configuration of this lab.

rustic sage
#

HTTP Attacks from CWEE Path
Log Injection (CRLF)

I'm having trouble with the exercise, can't get the server to accept %0d%0a even though it's supposedly an introductory exercise with a very clear path to solving it. Any clues?

languid wharf
#

Yo, are there problems with the labs again?

coarse mauve
#

I'm having quite a difficult time with the Advanced Javascript Deobfuscation exercise in capturing the flag. I captured the hidden flag in the code but HTB states my answer is wrong. It has to be right based on the instructions followed in the exercise. Confused?! 🤔

marble raft
#

This is a really really interesting module, really makes things going but it's noticeable different than others. Not harder per se, but requires some knowledge in C#.

languid wharf
rustic sage
quasi wave
#

I am doing DNS section of footprinting module. I'm on question 2. So my AXFR queries show its possible to get zone transfer but I am having trouble finding the text for the text record. Can someone help me out? Please don't just give me the answer.

fathom pendant
#

you might need to dig an extra level deeper

rustic sage
#

Hey guys

sleek moss
#

can someone help with password attacks

#
  • 0 Use the cracked password of the user Kira and log in to the host and crack the "id_rsa" SSH key. Then, submit the password for the SSH key as the answer. idk where kira password is
#

Protected Files

fathom pendant
#

you got it from an earlier section of the module

#

Credential Hunting i believe

#

take this as a note: always save credentials you find

sleek moss
#

i cant find it do u have her pw

quasi wave
#

solved

fleet moth
#

So I just finished the "Introduction to Windows Command Line" module. It is really really cool, however there is one detail that makes it average. Last skill assessment question is:

" What user account on the Domain Controller has many Event ID (4625) logon failures generated in rapid succession, which is indicative of a password brute forcing attack? The flag is the name of the user account."

There are not that many ID 4625 Events on the host so I used:

Get-WinEvent -FilterHashTable @{LogName='Security';ID='4625 '} | Format-List -Property *

to check them in detail. I used all user account names that were mentioned in any of the events and none of them worked.

In the end the answer was a user whose user account name does not pop up in any of the Events on the host. 😡

fathom pendant
#

you used her password to do the credential hunting for will

#

:) easy recrack though if you wanna just throw the mutated wordlist at ftp

sleek moss
#

ic ok thank

fathom pendant
#

the question explicitly tells you to run check on the domain controller; not on the initial host

upbeat island
#

I’m stuck in a single question, they said “enumerate the custom script that is running on the system and submit its output as the answer”. How do I know what is the output // that is for SNMP

fathom pendant
#

you'll see script:: output

#

basically

script.sh
lines
lines
lines
output
upbeat island
#

Let me try once again.

#

Thanks.

fathom pendant
#

i believe braa might cut out the part where it shows the script being run

#

and just show

script.sh
output
upbeat island
#

Nope, It show me “message cannot be decoded”

quasi wave
#

now I'm on the last section of DNS

#

can someone give me a hint? I think I need to find another wordlist

#

am I wrong?

fathom pendant
quasi wave
#

this is for last question of dns section of footprinting

fathom pendant
#

is that the one where it has you use the tool?

upbeat island
#

Yessss I got it now. Thanks a lot

quasi wave
fathom pendant
#

if so: fierce wordlists are your friend

#

yes; subdomains of subdomains is your other hint

quasi wave
#

ok thanks

sleek moss
#

is chatgpt allowed for cpts exam

fleet moth
# fathom pendant are you running it on the domain controller?

There is only one host provided for this task, so i assumed that is the Domain Controller. The events with specified ID are there etc. It is just the events that should provide the answer are missing.

But anyways with Get-ADUser -Filter * one gets the list of all potential answers so it is not that bad.

I just write it here, so that the mods will update it someday. And so the peps struggling with this one, can get their answer.

fathom pendant
fleet moth
#

There is only one such question. And i can also see a reason why only one.

fathom pendant
#

and it explicitly tells you that it's the Domain Controller in that question (172.x.x.x)

fleet moth
#

For this one you are asked to connect to the specified host. The host is a part of the AD so you can get domain information from its console. If it was as you say, they would ask again to connect to the X.X.X.X host to do the task.

fathom pendant
#

meaning you need to connect to the DC (Domain Controller)

fleet moth
fathom pendant
#

it really doesn't. It explicitly tells you where to look for the answer

#

just because you misread it. doesn't mean it's written poorly

fleet moth
#

i am not a native sorry

quasi wave
#

I think I have solved the last DNS question I just have to wait for it to finish loading

fathom pendant
quasi wave
#

just waiting for it to show up

fathom pendant
#

ye

#

sometimes it's silly

quasi wave
#

I know its taking a while so I'm gonna maybe watch some TV or something while I wait for the thing to load

fathom pendant
#

it shouldn't take more than a few minutes btw

quasi wave
#

ok what if its taking 20 minutes or 15 minutes

#

wrong word list?

#

should I try different word list?

#

I tried both fierce wordlists and one was taking forever and the other one didn't have the answer

fathom pendant
#

like 5-10 minutes

#

should be the max

quasi wave
#

ok thanks

fathom pendant
#

the targets for academy seem to be acting weird

#

so it might take longer: but tbh if you're going at the wrong subdomain you're gonna get no answers anyway

quasi wave
#

ok got it well I am trying the for-loop one for the specific IP address

#

how do I know I got the right subdomain?

fathom pendant
#

do that first

quasi wave
#

ok

fathom pendant
#

because you're likely looking over one of the subdomains to bruteforce

#

:)

sleek moss
#

Howd o I login + 0 Use the cracked password of the user Kira, log in to the host, and read the Notes.zip file containing the flag. Then, submit the flag as the answer. password attacks

quasi wave
#

do I need to use the IP of subdomain or can I use same IP?

#

right now I am using the FQDN of a subdomain I think is it. I narrowed it down to 2 subdomains

fathom pendant
quasi wave
#

ok thanks

fathom pendant
quasi wave
#

and how do I know which word list to use?

#

is it same wordlist as previous or fierce wordlist?

fathom pendant
sleek moss
#

it dont work

quasi wave
#

ok thanks

fathom pendant
sleek moss
#

it says password incorect

fathom pendant
#

then you copied her password incorrectly

sleek moss
#

||L0veme||

#

not work

fathom pendant
#

if you just copied it from the hint in the Credential Hunting section: then yes it won't work

sleek moss
#

no i cracked the new password from the file

fathom pendant
#

it should work then ¯_(ツ)_/¯

sleek moss
#

Protected Archives

fathom pendant
#

so you have the .zip and cracked that password?

sleek moss
#

wait nvm i used the wrong pw

fathom pendant
#

:)

sleek moss
#

i thoght i had to use the cracked password from prev section smh thank

fathom pendant
#

then what would be the point of cracking the zip file?

sleek moss
#

it just for prev section to crack file encrypted i thought iw as new pw

fathom pendant
#

2 steps when examining things

  1. try a pw you already know
  2. bruteforce
sleek moss
#

ok thanks

quasi wave
#

ok solved the DNS section

minor dome
#

marcy u have good pfp

fathom pendant
#

ty i commisioned it a while back

glad citrus
#

I’m working through the foot printing medium box rn.

#

Stuck on something, but I think I’m close

celest haven
#

Hi Guys i'm stuck on this question on three days.Examine the target and find out the password of the user Will. Then, submit the password as the answer.|| Sometimes, we will not have any initial credentials available, and as the last step, we will need to bruteforce the credentials to available services to get access. From other hosts on the network, our colleagues were able to identify the user "Kira", who in most cases had SSH access to other systems with the password "LoveYou1". We have already provided a prepared list of passwords in the "Resources" section for simplicity's purpose.|| So far i've tried|| hashcat --force password.list -r custom.rule --stdout | sort -u > mut_pass.list|| and ||hydra -l kira -P mut_pass.list ssh://10.129.202.64 -t 64 and hydra -l kira -P mut_pass.list ssh://10.129.202.64 -t 48`|| I still don't get any match.Could someone give me some hint?

glad citrus
#

I found the NFS share, mounted to my local machine, but when I try to cd into the folder it says access denied

#

Is it a configuration issue on my end?

celest haven
#

No it' not.LoveYou1 won't login.

sleek moss
#

u need to mutate

sleek moss
#

a specific word and then maybe try to crack into using adiff service

fathom pendant
#

this is one of the few times su to root is actually a thing

glad citrus
#

Haven’t su to root on the htb parrot vm. Anything special to do it

fathom pendant
#

nope

#

just sudo su

#

you might get a bunch of strange letters

#

but that's just a weird thing in the bashrc file

glad citrus
#

Thanks @fathom pendant

fathom pendant
#

also

#

don't attack ssh; attack another service

#

services can limit your threads btw

sleek moss
#

Password Attacks Lab - Easy hint? i just use hydra on ssh using the pass mutated list right

fathom pendant
#

ssh is a slow service

#

try other exposed services

celest haven
fathom pendant
#

should get you there in a few minutes

celest haven
fathom pendant
#

also as a note: you'll want to save any and all credentials you find for this module

celest haven
fathom pendant
#

48 is generally a good bet for ftp threads

sleek moss
#

also shud i attack the easy lab with mutated passwords or no

fathom pendant
#

i believe the mutated list should work

sleek moss
#

i c ok thank

cursive cradle
#

so on the windows fundamentals module, on the "NTFS vs. Share Permissions" it says "Once the proper inbound firewall rules are enabled we will successfully connect to the share.", they don't say which ones so had to look for them, idk if it was intended that we knew by hand before but well, Ig is part of the learning to look for sadglas , maybe I didnt read something

#

Already did that part only wanted to know

frosty spade
#

AD Enumeration & Attacks - Skills Assessment Part I
how do i get a shell from the webshell wget doesnt work

mossy bison
#

Hey, so im having a problem with module 19 section 103, where i have to enumerate the ports and their services fine the service that cant be fully scanned and find the flag. Sometimes the port scan doesnt ever load but i have found a work around for that as it sometimes works and i can just write down the port status's, hopefully its a connection issue w me and htb or im just running to many enumerations and canceling them when packets drop?

fathom pendant
#

you should only ever need to run one nmap scan at a time

mossy bison
#

the issue here is that the nc -nv ipaddress port just times out

fathom pendant
#

my brother in christ

#

the answer is right there

mossy bison
#

the 220 htb thing?

fathom pendant
#

it times out due to inactivity

#

yes

#

220 is a status code :)

mossy bison
#

im try that again but a couple days ago i copy pasted it like 3 different ways and it was wrong

fathom pendant
#

2 things:
Delete the screenshot
the only thing that matters is the HTB{..} bit

#

make sure you don't have any spaces before and after

mossy bison
#

no spaces ok. thanks

fathom pendant
#

yep

#

220 isn't important; that's literally a response code, that generally means "I received your connection"

#
A 220 code is sent in response to a new user connecting to the FTP server to indicate that the server is ready for the new client. 
celest haven
fathom pendant
ruby whale
#

Last Password attack Lab to go , then I will be done with this evil module.

#

It is satisfying to solve password attacks lab after toiling through the sections.

celest haven
# fathom pendant try resetting the target; it's likely your attempts to bruteforce ssh with 64 th...

Hi mate after reseted the machine i runed for while still not getting the password.Are you sure is for attacking ftp on this one becuase this is for Credential Hunting in Linux not the Password Mutations becuase i remember on Password Mutations is use this method to attacked the ftp.But this for the question of Credential Hunting in Linux.So far all the hint is talk about the attack the ssh https://forum.hackthebox.com/t/password-attack-academy-credential-hunting-in-linux/267992

fathom pendant
#

Yes: I'm sure

ruby whale
#

Hey @celest haven which section are you working on ?

fathom pendant
#

The module has you reuse that mutated wordlist

soft cedar
celest haven
ruby whale
#

For kira you don't require whole mutation list, you need mutation of specific password.

celest haven
fathom pendant
#

but mutating the given info with the custom.rule from the resources works too ¯_(ツ)_/¯

celest haven
fathom pendant
#

Yes: and I'm reiterating that her password should be included in that same list of 90k + passwords

ruby whale
#

If you are trying to use mutated list @celest haven have patience it will take time.

soft cedar
soft cedar
celest haven
#

Do you mean mutated the LoveYou1 only

ruby whale
celest haven
celest haven
fathom pendant
celest haven
fathom pendant
#

That wasn't my question

#

:)

soft cedar
fathom pendant
#

Much like earlier in the module referring to getting the ssh password for "sam" but it's more efficient/better to attack a different service

celest haven
fathom pendant
#

Also, hitting ssh with a high number of threads isn't generally advisable

fathom pendant
#

normally ssh restricts the number of threads allowed

soft cedar
fathom pendant
#

Attacking ssh should generally be a last ditch effort

soft cedar
#

oh yeah^^

fathom pendant
#

Because in the case where ssh is configured to only allow 4 threads: this would take exponentially longer

#

Or in the worst case: DoS the server

celest haven
soft cedar
fathom pendant
#

The hint points to her also not being security conscious about her passwords

soft cedar
#

yeah but i mean for finding the password of will

fathom pendant
#

Hit a responsive service -> get creds -> check for reuse

fathom pendant
soft cedar
#

I understand wym^

fathom pendant
#

Yup. Its more that I'm advocating best practices rather than straight up saying not to do it

little bear
#

B33n w0rk1ng 0n W3b Pr0x13s l8l7 😉

Soon, I will not be afraid of the 1337 and will accept it. Trauma it shall be no moar.

fathom pendant
little bear
sterile epoch
#

I am in dcsync in ad enumeration. I am stuck at dumping lsa using both mimikatz and secretsdump
secretsdump.py -outputfile inlanefreight_hashes -just-dc INLANEFREIGHT/adunn@172.16.5.5

rustic sage
#

heyyyy we on the same question :> waiting on target to spawn tho

sterile epoch
rustic sage
#

I'm trying to use mimikatz instead of sshing into the linux machine on the network im too lazy for that.

#

but for some reason mimikatz is not loading it gets stuck with no prompt >,< so i guess ill try the linux method

#

or maybe use proxychains .....nah too much work

#

yep im gonna use proxychains for some reason cant ssh into the linux machine either

quasi wave
#

hi where do I find the footprinting wordlist provided as a resource in the SMTP enumeration section of footprinting module?

#

I just need to know that and then I am gonna try to figure out the rest myself

soft cedar
quasi wave
#

I just see another button that says "download VPN configuration"

sterile epoch
rustic sage
#

nope but i got mimikatz to work as adunn with cmd

soft cedar
rustic sage
#

gotta use the user from the first question

#

powershell for some reason is dodgy

sterile epoch
#

I wanted to try the example ones cuz we found the creds to adunn in the last section

rustic sage
#

well adunn is just to do the DCsync

#

you use the DCSync to get the pass for the user from the first question

sterile epoch
#

ie inlanefreight/adunn

mystic light
#

i dont know how you all are setting it up, but if im attacking a DC via any bastion, i tend to opt for chisel.exe and proxychains from my kali machine.
just tried secretsdump, works great.

rustic sage
#

yes for secretsdump you were doing it correctly

sterile epoch
soft cedar
rustic sage
#

but it said access is denied my guess is the password you typed was typed wrong

#

prolly typed it too fast

mystic light
sterile epoch
quasi wave
#

how do I use a word list to enumerate users in Nmap or do I not use Nmap?

rustic sage
quasi wave
#

I googled it and I am getting results like smb-enum-users script

sterile epoch
rustic sage
#

because it says rpc_access_denied figured that only comes from incorrect user/pass.

sterile epoch
soft cedar
quasi wave
#

its for SMTP section of footprinting module. 2nd and last question of section

soft cedar
quasi wave
#

ok thanks

sterile epoch
#

can you try on yours?

rustic sage
sterile epoch
rustic sage
#

for one reason or another im not bothering to find out why lol

sterile epoch
#

you need to use the windows machine and use ssh like in linux

rustic sage
#

i did or let me try with cmd

#

instead of powershell

#

ok im in

#

dammit my life expired hang tight i gotta redo stuff

sterile epoch
#

bruh

rustic sage
#

its okay its the pwnbox that expired not the target

sterile epoch
#

increase the lifetime of both

quasi wave
#

I think I found answer but there's some silly syntax here I'm not getting:

┌─[us-academy-2]─[10.10.15.70]─[htb-ac-605555@htb-t8infzsaqy]─[~]
└──╼ [★]$ nmap --script smtp-enum-users.nse -p25 -MVRFY -U foorprinting-wordlist.txt -t 10.129.152.249
Argument to -M must be at least 1!
QUITTING!
sterile epoch
quasi wave
#

ok

fathom pendant
rustic sage
#

if you use the -just-dc flag it will spit out all the accounts like it should. But if you use the -just-dc-user flag it doesnt work for some reason

sterile epoch
#

whats the command you using?

fathom pendant
#

They serve different purposes

rustic sage
#

||secretsdump.py -outputfile inlanefreighthashes -just-dc-user syncron INLANEFREIGHT/adunn@172.16.5.5||

#

sorry it is hard to work with copy/pasting stuff here

quasi wave
#

ok I have a list of users do I just try each of them until I get it or is there a methodical way of doing it?

#

nmap gave me the users

#

in the form of a list

fathom pendant
#

Nope, the right flags with smtp-user-enum will only spit out one answer

rustic sage
rustic sage
#

oh crap it's 1:26 AM im going to bed. time flies when you havin fun

quasi wave
# fathom pendant Nope, the right flags with smtp-user-enum will only spit out one answer

the closest I can get is this:

└──╼ [★]$ nmap -p25 --script smtp-enum-users.nse --script-args smtp-enum-users.methods={VRFY} 10.129.152.249
Starting Nmap 7.93 ( https://nmap.org ) at 2024-02-05 06:33 GMT
Nmap scan report for 10.129.152.249
Host is up (0.0053s latency).

PORT   STATE SERVICE
25/tcp open  smtp
| smtp-enum-users: 
|_  Couldn't find any accounts

Nmap done: 1 IP address (1 host up) scanned in 10.02 seconds

Now I know if I use the -U and -t flags for the wordlist and IP address respectively that it should work but it doesn't.

fathom pendant
#

Stop using it with nmap

#

There's literally a normal tool called smtp-user-enum which works 10x better than nmap

#

And you don't gotta fight with figuring out script-args

quasi wave
#

ok thanks

#

well now that I started with the smtp-user-enum tool I'm making progress thank you

#

I'm gonna give it five or ten minutes to load

#

the scan yielded 0 results:

└──╼ [★]$ smtp-user-enum -M VRFY -U footprinting-wordlist.txt -t 10.129.152.249
Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )

 ----------------------------------------------------------
|                   Scan Information                       |
 ----------------------------------------------------------

Mode ..................... VRFY
Worker Processes ......... 5
Usernames file ........... footprinting-wordlist.txt
Target count ............. 1
Username count ........... 101
Target TCP port .......... 25
Query timeout ............ 5 secs
Target domain ............ 

######## Scan started at Mon Feb  5 06:41:42 2024 #########

######## Scan completed at Mon Feb  5 06:43:27 2024 #########
0 results.
fathom pendant
#

Might need to adjust the wait variable

quasi wave
#

I adjusted it to 10

#

we'll see if that does anything

fathom pendant
#

Maybe 15-25

quasi wave
#

ok hold on

#

10 still didn't do it I'm gonna try 20

#

its taking a while but that's what you'd expect from a 20 second per username wait time

#

found it it worked!

#

thank you so much

fathom pendant
#

It's because the service is slow to respond

quasi wave
#

are you still gonna be online in a couple of hours?

fathom pendant
#

Probably not

quasi wave
#

ok