#modules

1 messages Β· Page 195 of 1

quasi wave
#

I'm gonna do next section tomorrow

#

today has been very productive. hopefully I will get the next couple sections done tomorrow morning

#

I got two whole sections done today which is fabulous

#

ok good night yall

sleek moss
#

what was the updated tool for crackmapexec

autumn pilot
#

netexec

sleek moss
#

yu

#

why wont my hdyra work for smb in password attacks med lab

#

[ERROR] target smb://10.129.202.221:445/ does not support SMBv1

topaz latch
#

Hi Pedant,
It's still not working for me.
I waited more than 10 minutes after spawning the target before doing anything
Then when I started the lab I still got the same error.
I'll reach out to you privately to explain step-by-step exactly what I'm doing

#

Looking forward to checking this one out. Did you also do the Game Hacking Fundamentals module?

placid edge
#

on your impacket-smbserver whatnot

fathom pendant
tranquil axle
#

it basically means "hydra can only crack passwords on old smb versions, this server uses a newer version, please use a different tool"

sleek moss
#

when bruteforcing rdp shud i netexec or hydra and is there any special option

#

in password attacks hard lab is it Johanna or johanna

#

hard lab

placid edge
sleek moss
#

vcan anyone help

#

what wordlist for lab hard and is it johanna or Johanna

placid edge
#

same ones you have used for the cource

#

like mutated++

sleek moss
#

this shit taking so long frfr this aint bussin

ruby whale
#

It took forever to copy a file from hard lab to local machine, iykyk

ruby whale
#

Hurray πŸ₯³

heavy marsh
#

Anyone have issues with the revshell on Active Directory Skills Assessment 1? It's not working with any of the powershell revshells.

placid edge
#

what does the layout look like

hoary pulsar
#

Module : Pivoting, Tunneling, and Port Forwarding (Skill-Assessment)
Question : Any optional command here that might help me generate an lsass.dmp file using powershell? cuz mine don't work
command : rundll32.exe C:\windows\system32\comsvcs.dll, MiniDump <lsass PID> C:\lsass.dmp full

#

I reall don't want to generate using task manager cuz rdp so laggy

placid edge
#

i belive you can use impacket-secretsdump and crackmapexec for this also

next bronze
next bronze
next bronze
placid edge
#

@next bronze damn, sweet tool you made. Does windows detect the tool upon download or?

next bronze
#

nope, fully undetected

hoary pulsar
#

thanks thanks

placid edge
#

damn. Awesome!

hallow kiln
next bronze
#

thank you sir ❀️

marble raft
marble raft
next bronze
#

thanks! thanks

rustic sage
#

HTTP Attacks modules from the CWEE path
Log Injection

Have tried multiple different payloads, encoding methods, etc. and I can't seem to get it
||name=NAME%0d%0a1PAYLOAD&email=EMAIL%40EMAIL.COM&phone=NUMBER&message=MESSAGE'%0d%0a2PAYLOAD||

molten prawn
#

this machine makes me wanna cry. its so slow

#

im in attacking common applications module - thick client application section. the first task i have to do is taking away the delete permissions from the user cybervaca so i can get the .tmp and .bat file that the .exe app creates but even tho i do delete permissions, the files still get deleted. help would be appreciated. thanks

next bronze
molten prawn
#

i dont really wanna follow a walkthrough. the thing is, i believe im doing everything right in this step because its so simple. making a mistake is highly unlikely. but thanks. imma retry and if i did not succeed i will seek a hint or something

sly kelp
sterile epoch
#

any help why this is not working?

sterile epoch
next bronze
#

no dcsync rights

#

did you do token elevate?

sterile epoch
#

no I did not do that. I do not think its in the section but let me check again

next bronze
#

yeah don't do that, are you logged in as the right user

sterile epoch
#

yes I am in htb-student in the windows host

next bronze
#

I don't remember what user you're supposed to use, try resetting if it still doesn't work

sterile epoch
#

this one is from the morning

next bronze
#

you need to use the adunn user no?

sterile epoch
#

I have used adunn from linux host

rustic sage
#

guys i need help with the documentation & report module. i've found some users & password combination and the ip i have to use to connect in rdp is 172.16.5.5 but every try results in error. some hints or help?

next bronze
next bronze
rustic sage
#

if i show u in dm can u help me?

next bronze
#

you can just say what you've done here, put it in spoiler tags

rustic sage
#

how can i put these targs?

next bronze
#
||spoiler||

||spoiler||

manic onyx
#

Can anyone recommend some modules to complete before starting CWEE path?

rustic sage
frozen mesa
#

ATTACKING WEB APPLICATIONS WITH FFUF
Skill assessment
Run a sub-domain/vhost fuzzing scan on '*.academy.htb' for the IP shown above. What are all the sub-domains you can identify? (Only write the sub-domain name)
I've found three subdomains, none of them is the correct answer. Anyone a hint?

next bronze
rustic sage
#

i thought to use ||rdp because the module gives me dc01 uses rdp connections||

next bronze
#

huh when did the module give you creds for the lab? the rdp creds is to access the WriteHat instance on the attack box

sterile epoch
#

I tried reseting both target and vm again. From linux host I am using ||adunn:SyncMaster757|| I am still getting the error

rustic sage
next bronze
#

oh right those, that doesn't mean you can access DC rightaway, you're supposed to work your way through the lab with the final goal being gaining DA

#

I hope you have completed all the previous modules in the path before this

rustic sage
plucky latch
#

For the labs using shared computers and the like, specifically AD Enumeration & Attacks - Skills Assessment Part II, when someone bricks one of the systems, how can you reset it? I was able to xfreerdp into it last night and this morning its erroring out, I reset my jump box, but how can the systems inside lab be reset? Or do I have to wait it out

next bronze
#

the labs are private

plucky latch
#

Even the shared Domain computers on the private network?

next bronze
next bronze
plucky latch
#

Good to know, then I bricked it and cant connect to it now lol , same issue but I am to blame

next bronze
#

you can just respawn it

languid wharf
rustic sage
frozen mesa
#

my command: ||ffuf -w /opt/useful/SecLists/Usernames/xato-net-10-million-usernames.txt:FUZZ -u http://faculty.academy.htb:37835/courses/linux-security.php7 -X POST -d 'username=FUZZ' -H 'Content-Type: application/x-www-form-urlencoded'||

The results are all code 200 and scrambled in the terminal. What did i do wrong?

next bronze
rustic sage
#

no only introduction to active directory 😦

#

i'll require that from my manager xD

next bronze
rustic sage
#

no they gave me a personalized playlist of modules

#

so i'm not stupid i only dont have some informations ahahah

next bronze
#

yeah no, that's a strange decision to only make some modules available

fathom pendant
#

The overview of a module will tell you which modules/concepts would be pre-requisite

#

The higher the module tier, the more likely there's gonna be assumed knowledge

#

So that the module can focus on teaching what it should be

rustic sage
snow ridge
#

Any hints for the ADVANCED XSS AND CSRF EXPLOITATION skills assessment? Been stuck here for a while now, would be nice to get some direction. ||I have found a way to upload javascript with upload form but that CSP is ruining my attempts and I have not found bypasses for it. Only payload I managed to load is this <html> <body> <form method="GET" action="http://vulnerablesite.htb:41264/users.php"> <input type="hidden" name="userid" value="3" /> <input type="submit" value="Submit request" /> </form> <meta http-equiv="refresh" content="0;url=http://vulnerablesite.htb:41264/users.php?userid=3"> </body> </html> and when I run it I get redirected and message that only mods and admins can promote users. So either that payload has some issues or admin/mod is not running that payload when they visit that file. I'm pretty sure that I have to leverage that upload functionality to get myself to moderator and then task management to get myself to admin. ||

tranquil axle
snow ridge
shrewd iris
#

NVM SOLVED

#

Dm please

woven copper
rustic sage
#

no extra spaces or new lines formed

woven copper
dusty path
#

Hey everyone, can anyone give me a nudge for Password Attacks Lab - Hard? I've found all the services, trying to bruteforce them with provided password list for user Johanna but no luck.

fathom pendant
#

did you try adding a flag like --local-auth

dusty path
#

Tried that, but it still takes way too long

topaz holly
#

Alright mutha fuckas let's get our streaks caught up!

fathom pendant
#

no

topaz holly
#

Do it. You know you want to see that number increase

#

Just one lil module

topaz holly
sleek moss
#

what wordlist for lab hard and is it johanna or Johanna

fathom pendant
#

try other wordlists: start with mutated, then regular, then rockyou

sleek moss
#

password attacks

rustic sage
sleek moss
#

it takes really long

topaz holly
#

They do

sleek moss
#

yea but is it joanna or Johanna

safe owl
#

Good evening. Who may help me with this module (SESSION SECURITY) please.
about (the new private window for firefox) isn't work but without (private mode) it's work

fathom pendant
sleek moss
#

it dont work i tried wit hnetexec and it went ofr hours

sleek moss
#

where athe things in hackthebox

frosty spade
#

need help stuck on ad enum and attack skill 1 question 4 ive managed to get a metrepreter shell on the webserver grabbed svcs pass but am unsure how to connect to ms01

#

any suggestions on what tools i should up load to the webserver snyone here an ad pro

sleek moss
#

guys im doing a hard lab how do i use the pwnbox to use the resource mateiral

next bronze
sleek moss
#

guys how do i use the resource files on my pwnbox

fathom pendant
#

you should be able to download and use them like you would from a vm

frank shale
#

i am just starting out. When i click Modules i get this: javascript: void(0);

sleek moss
#

so i login?

#

to hackthebo

fathom pendant
#

idk what you're really asking Β―_(ツ)_/Β―

sleek moss
#

like the passowrd list its on module but i am using pwnbox

fathom pendant
#

you can right click, copy url

sleek moss
#

how do i get the password

fathom pendant
#

and use wget

#

that's just one way of doing it

frank shale
#

hello guys need little help

#

When i click HTB academy modules or path

#

i just get javascript: void(0);

#

This massage. what do i do

fathom pendant
#

if you mean when you hover over the button it says the url is that: that's normal

frank shale
#

no when i click modules or path

fathom pendant
#

make sure you have adblock disabled

frank shale
#

nothing happens. when i try to open in new page

#

it says javascript: void(0);

fathom pendant
#

either way contacting support should be your first step

frosty spade
#

@next bronze I take it I have to tunnel my traffic through the webshell? this part is lost to me the pivoting and tunneling module was completely busted when i completed it

fathom pendant
#

not discord

frank shale
#

Thanks alot it was adblocker

fathom pendant
#

(it's normally always adblocker)

#

some stuff on the site for w/e reason gets blocked by adblocker

next bronze
sleek moss
#

β”Œβ”€[us-academy-1]─[10.10.14.241]─[htb-ac-911632@htb-6k7z1oybsy]─[~/Desktop]
└──╼ [β˜…]$ crackmapexec rdp 10.129.202.222 -u johanna -p mutatedpas --local-auth
β”Œβ”€[us-academy-1]─[10.10.14.241]─[htb-ac-911632@htb-6k7z1oybsy]─[~/Desktop]

#

why dont this work it just enter and makes an ew shell cmd nothing happens

minor dome
#

where is the general channel

cursive cradle
#

you need to verify your acc to see it

sleek moss
#

when using pwnbox do i hve to connect ot the vpm

cursive cradle
cursive cradle
fathom pendant
#

the pwnbox is automagically connected to the vpn

sleek moss
#

also how can i copy and paste from my orig to the pwnbox it dont let me

fathom pendant
#

sometimes cme is dumb

#

ALSO if you're running the vpn at all on any other system while trying to use the pwnbox you will encounter issues

sleek moss
#

i c ok thanks and alos how do i copy nad paste on it

fathom pendant
#

there's a clipboard

#

but you should be able to ctrl+shift+v to paste in terminal

#

which is the default

#

your browser may ask you if you want to share the clipboard

sleek moss
#

no it doesnt let me paste

cursive cradle
#

the other is right clic and paste

fathom pendant
#

yeah pwnbox is really dumb a lot of the time

frosty spade
#

try to maximize it and on the tab theres a clipboard you can paste into

sleek moss
#

oh yes i c danke

frosty spade
#

or use a different browser

sleek moss
#

β”Œβ”€[us-academy-1]─[10.10.14.241]─[htb-ac-911632@htb-l0c4tmhlfz]─[~/Desktop]
└──╼ [β˜…]$ crackmapexec rdp 10.129.202.222 -u johanna -p mutated --local-auth
[] First time use detected
[
] Creating home directory structure
[] Creating default workspace
[
] Initializing FTP protocol database
[] Initializing MSSQL protocol database
[
] Initializing WINRM protocol database
[] Initializing LDAP protocol database
[
] Initializing RDP protocol database
[] Initializing SSH protocol database
[
] Initializing SMB protocol database
[] Copying default configuration file
[
] Generating SSL certificate
β”Œβ”€[us-academy-1]─[10.10.14.241]─[htb-ac-911632@htb-l0c4tmhlfz]─[~/Desktop]
└──╼ [β˜…]$ crackmapexec rdp 10.129.202.222 -u johanna -p mutated --local-auth
β”Œβ”€[us-academy-1]─[10.10.14.241]─[htb-ac-911632@htb-l0c4tmhlfz]─[~/Desktop]
└──╼ [β˜…]$ sudo crackmapexec rdp 10.129.202.222 -u johanna -p mutated --local-auth
β”Œβ”€[us-academy-1]─[10.10.14.241]─[htb-ac-911632@htb-l0c4tmhlfz]─[~/Desktop]
└──╼ [β˜…]$

cursive cradle
sleek moss
#

can anyone help it dont work

frosty spade
#

@next bronze should I use rpivot or chisel to pivot

next bronze
#

ligolo-ng

fathom pendant
#

this channel isn't for starting-point boxes

exotic dagger
#

Ah, sorry. I thought the one under multi-machine labs was like for a "networked boxes" version of Starting Point

fathom pendant
#

there are no "networked boxes" in starting point

#

the starting-point machines are their own machines separate from labs

sleek moss
#

should i use -t4 with netexec rdp

fathom pendant
#

idk what changing the threads to a lower count would do Β―_(ツ)_/Β―

sleek moss
#

RDP 10.129.202.222 3389 WINSRV [-] WINSRV\johanna:1234569 (STATUS_LOGON_FAILURE)
RDP 10.129.202.222 3389 WINSRV [-] WINSRV\johanna:1234569
RDP 10.129.202.222 3389 WINSRV [-] WINSRV\johanna:1234569
RDP 10.129.202.222 3389 WINSRV [-]

#

it stopped saying the error msg

exotic dagger
fathom pendant
exotic dagger
#

I see

sterile epoch
#

I did the dcsync attack with mimikatz but I am still having a issue on doing it with secretsdump.py

secretsdump.py -outputfile hashes -just-dc INLANEFREIGHT/adunn@172.16.5.5 -use-vss
Impacket v0.9.24.dev1+20211013.152215.3fe2d73a - Copyright 2021 SecureAuth Corporation
Password:
[-] RemoteOperations failed: DCERPC Runtime Error: code: 0x5 - rpc_s_access_denied
[*] Searching for NTDS.dit
[-] 'NoneType' object has no attribute 'request'
[*] Cleaning up...
#

I used the same credentials I used in mimikatz ||adunn|SyncMaster757||

sleek moss
#

crackmapexec winrm 10.129.X.X -u johanna -p mut_password.list
with --local-auth or without

sterile epoch
sleek moss
#

so is that no?

sterile epoch
#

depends on the task which one are you doing?

sleek moss
#

password attacks hard lab

sterile epoch
#

do it without it

sleek moss
#

WINRM 10.129.202.222 5985 WINSRV [-] WINSRV\johanna:12345604!
if it doesnt say error it stil lwokrs right

sterile epoch
#

dude spoilers

sleek moss
#

how its not the password

sterile epoch
#

and I think its not the answer

sleek moss
#

no i was just wondering if it doesnt say error is it still working

sterile epoch
#

try without mutilating the list

sleek moss
#

but does it work if it doesnt say error

#

like is it stil ltrying to login?

sterile epoch
#

when it works you will see [+]WINSRV\johanna:*****

#

not [-]

sleek moss
#

yea byt does it needs to have an error message

sleek moss
#

ok danke

#

bruh this aint raking it fr fr

ornate olive
#

I’m working on login brute forcing and I’m currently on login form attack, I believe I have the key but it’s not working as the answer

#

I’ve identified the password and user and I’ve gotten to the page that says β€œWelcome back Mr bill gates” and I see what appears to be a flag at the bottom but it’s not working in HTB

thorn urchin
#

made sure theres no extra spaces or anything like that?

sleek moss
#

can soeone give begigning of letter for password atack hard lab

silk dome
#

Help please. Noobie here

I'm doing the Web Enumeration.
The question is:
Try running some of the web enumeration techniques you learned in this section on the server above, and use the info you get to get the flag.

This gobuster command is taking an age to run and the box is likely to time out before it gets to completion. gobuster dir -u http://10.10.10.121/ -w /usr/share/dirb/wordlists/common.txt

Am I looking in the right place as I can't find a solution using the other methods.

brazen oasis
#

Good evening,
In your opinion, what is the best way to validate an OSCP certification: what are the modules to know and the sites that can also help us with this.
Sincerely

topaz holly
#

Can you search for text in this discord conversation? I want to ask a question but I'd rather see if it were asked before.

brazen oasis
chilly cosmos
#

I am doing the footprinting smb but 3rd question they are asking for password

next bronze
brazen oasis
next bronze
#

yes

brazen oasis
#

thanks πŸ‘

chilly cosmos
#

the VM is very slow

next bronze
#

choose the pwnbox server closest to you

topaz holly
#

I understand basic computer literacy just not discord. Haha. Guess mobile can't do it.

fathom pendant
#

Mobile can search

topaz holly
#

I don't understand how 😭 I can only see doing it by date and by people.

fathom pendant
topaz holly
#

I even tried searching "Mobile can search" and nothing lol

#

Can I search for words in messages within the channel? That's what I'm trying to do. And I'm sorry btw I really am not great at using discord.

fathom pendant
#

Yes

topaz holly
#

I just don't know all of its caveats

fathom pendant
#

in: channel "string"

#

It literally gives you the syntax

topaz holly
#

Okay it works. For some reason the messages option wasn't appearing.

Also mind you my mobile search feature seems to look very different from yours.

sleek moss
#

can someone help with begining letter of htb password attacks hard lab? i use mutated password and crackmap winrm

topaz holly
#

It not let me search members and media when I was first trying

sleek moss
#

with --local-auth

fathom pendant
fathom pendant
silk dome
topaz holly
#

We don't need to argue

sleek moss
#

do u remmeber beginng of wor

#

word for the pw

fathom pendant
#

Stop asking, you're spending what feels like a lot of time asking, instead of doing

#

There's a reason you're being ignored with your request

supple sparrow
#

do domain policies / user priv affect the number of logged-in users I can see during enumeration using cme's --loggedon-users

sleek moss
#

i am doig ive bee cracking it for an hour

fathom pendant
sleek moss
#

fo sho

fathom pendant
#

Did you reset the target to attack a fresh one?

sleek moss
#

no

chilly cosmos
#

that's why

sleek moss
#

wdym

#

why wud i reset it

fathom pendant
#

because sometimes the hosts die without actually telling you

#

or the services stop working

#

it's dumb

sleek moss
#

oh i c danke

drowsy narwhal
#

someone can buy me vip plz πŸ€“ πŸ₯° πŸ₯Ή

fathom pendant
#

just sanity checked @sleek moss the password is in-fact in the mutated wordlist

fathom pendant
drowsy narwhal
topaz holly
#

Yeah so I'm glad I got the search feature figured out on here.
Guys, you can try using that feature before you ask questions πŸ™‚

fathom pendant
topaz holly
#

Getting straight dogged on

lofty wave
#

As another nudge hint on this one. You can try using the echo command to view the files and the while command to read the flag file.. πŸ™ƒ

fathom pendant
#

also to add on @sleek moss i checked multiple services; they all return the password after a minute or two; CME doesn't have an RDP module, hydra does though

sleek moss
#

wat after a min?

#

bruh :dead:

#

i did crackmapexec winrm

fathom pendant
#

ye

sleek moss
#

crackmapexec winrm 10.129.155.35 -u johanna -p mutated --local-auth

hashcat --stdout -r custom.rule password.list > mut

#

do u c anything wrong there

fathom pendant
sleek moss
#

bruh

fathom pendant
#

otherwise the wordlist is like much larger

sleek moss
#

ty

fathom pendant
#

ye like twice as big

#

instead of 94k it ends up 188k

sleek moss
#

hashcat --stdout -r custom.rule password.list | sort -u > mu right

#

i c ty

fathom pendant
#

i thought something was off from the cheatsheet

#

which doesn't have the sort -u

sleek moss
#

danke

#

--lo

lethal atlas
#

been waiting for the target on windows priv esc to spawn for over an hour now.

fathom pendant
#

change vpn regions: it seems us-academy-3 is working fine for now

lethal atlas
#

yesterday I changed to 1 because of the same issue.

sleek moss
#

i instsalled parrot os with htb edition is it nromal to have this in shell when u first begin it automatically ]\342\224\214\342\224\200$([[ $? != 0 ]] && echo "[[]\342\234\227[]]\342\224\200")[$(if [[ ${EUID} == 0 ]]; then
echo '[]root[]@[]\h';
else
echo '[]\u[]@[]\h';
fi)[]]\342\224\200[[]\w[]]
[]\342\224\224\342\224\200\342\224\200\342\225\274 [][]$[]" - Parrot Terminal]\342\224\214\342\224\200$([[ $? != 0 ]] && echo "[[]\342\234\227[]]\342\224\200")[$(if [[ ${EUID} == 0 ]]; then
echo '[]root[]@[]\h';
else
echo '[]\u[]@[]\h';
fi)[]]\342\224\200[[]\w[]]
[]\342\224\224\342\224\200\342\224\200\342\225\274 [][]$[]" - Parrot Terminalβ”Œβ”€[sam@parrot]─[~]

#

or is there something wrong with my os

fathom pendant
#

just comment out the line with trap i forget what line it's on

sleek moss
#

i c its normal toh right and ok ty

fathom pendant
#

yeah it's not broken

#

it's just a weird config thing

sleek moss
#

ok ty

topaz holly
#

'We droppin shellcode

fathom pendant
topaz holly
#

Hahaha

#

Hey man you gotta make sure it works somehow

sleek moss
#

what is better parrotos with htb editiion or just kali linux

fathom pendant
#

whatever you prefer

#

it's honestly mostly a preference thing

severe arrow
#

Hey in the module File Upload Attacks on the assessment I got very stuck and read a walk through. I was kinda doing too much, but thats okay. Question, where in the world is the location of the file that is uploaded

wraith seal
#

hi anyone would please tell me im using linux tails but it is showing no wifi driver can anyone help me ?

#

@everyone

chilly cosmos
#

@wraith seal I believe there is another channel on this server for this question I'm not sure.

sleek moss
#

smb: > get Backup.vhd
parallel_read returned NT_STATUS_IO_TIMEOUT
smb: > getting file \Backup.vhd of size 136315392 as Backup.vhd SMBecho failed (NT_STATUS_CONNECTION_DISCONNECTED). The connection is disconnected now
why doesmblicnet say this

fathom pendant
fathom pendant
sleek moss
#

why wont hashcat crack this /spoiler $bitlocker$0$16$asd$1048576$12$80b20a04341fd80103000000$60$asd

languid wharf
sleek moss
#

hashcat -m 22100 backup.hash mut -o backup.cracked

languid wharf
#

should crack, also wrap the hash with double pipes like: ||hash||: ||spoiler||

sleek moss
#

wdym

fathom pendant
#

/spoiler needs to go at the beginning of the message but also: it's likely there's not a hashcat mode for it: try with john (as you likely used bitlocker2john)

paper gust
#

mode should be fine, probably just doesnt have the intended password in mut or something of that sort

sleek moss
#

i c danke

#

and also is password attacks the heardest module

thorn urchin
#

no

#

but it is the most tedious

sleek moss
#

why

#

what is most difficult

fathom pendant
#

probably the more technical modules like AD enum

sleek moss
#

why

fathom pendant
#

because it requires you to use more of your brain

#

password attacks is just a waiting game

#

nothing technically complex about it

rustic sage
#

Well most of these modules aren't hard, the password one made me curse a lot though, not because it was hard, but because of the amount of gotcha's it has.

#

the assessment at the end is very cool and nice though i still remember it

sleek moss
#

i c that hard lab where u us the bitlocker and mount it wont be on cpts right

#

or oscp

rustic sage
#

you bet your sweet bums it's prolly gonna be on the test.

sleek moss
#

:dead:

rustic sage
#

dont worry it's a breeze just keep calm and read

fathom pendant
sleek moss
#

what about OSCP

#

will that mounting virutal harddrive be there

fathom pendant
#

don't know about OSCP; the CPTS prep materials are for CPTS - you'd have to look at the OSCP domains to know what's on it

rustic sage
#

OSCP from what I've heard is mostly a CVE test, ensuring your ability to understand how to use them to pentest. they use metasploit for pretty much everything, they don't do most of the stuff we do on HTB.

fathom pendant
#

you can't use metasploit on OSCP

#

*well you can, but only for one lab - and that's it

rustic sage
#

You can't? oh bummer, at least their metasploit unleashed course is free.

fathom pendant
#

metasploit would literally trivialize the OSCP exam if it's mostly CVEs

rustic sage
#

you can still use searchsploit :> and just pass commands manually build payloads with msfvenom

thorn urchin
rustic sage
#

lol though i'd rather go with HTB personally.

#

@sleek moss just a tip, i wish someone told me this when doing the first assessment for the password attacks module, you gotta know how to read/write files using (i think it was) mysql statements. Apparently it's something you can do. Also the mysterious password database thing they have in one of the assessments is a file that can be cracked by one of the tools you learn about.

pale cliff
#

Hello

thorn urchin
#

the course modules assume you have knowledge from prior modules

fathom pendant
short trellis
#

htb

thorn urchin
#

yes this is htb

#

congratulations on being able to join a discord server. this is truly the height of your technical acumen

topaz holly
#

That was their version of a syn packet, and you hit them with the ack! I'm gonna grab the popcorn and wait in suspense for the beloved syn/ack!

cobalt trench
#

Nessus Skills Assessment lab - I cant get nessus to run

#

It says that the VM has nessus pre installed

fathom pendant
#

note it says "Authenticate to" not "ssh to"

placid edge
#

all i am going to say is thank god for questions like "Submit the NT hash of the administrator user"

#

if not i would have to redo all the steps from the first module in attacking enterprise networks

rustic sage
fathom pendant
#

writing to a file is covered in attacking common services i believe

molten prawn
#

target machines not spawning again ? kekhands

#

hmmm. no actually. holly shit its fast

dire abyss
#

is it a known issue that pwnbox seems to run out of memory using hashcat?

fathom pendant
#

?

#

i've not run into any memory issues with hashcat

dire abyss
#

Watchdog: Hardware monitoring interface not found on your system.
Watchdog: Temperature abort trigger disabled.

Host memory required for this attack: 65 MB

#

happened to me yesterday too

fathom pendant
#

hashcat -m mode file.hash password.list

#

you always do the hashfile first before the password list

#

what's your hashcat command?

dire abyss
#

sudo hashcat -m 1000 2b391dfc6690cc38547d74b8bd8a5b49 /usr/share/wordlists/rockyou.txt

fathom pendant
#

but the hash into a file first and see if that makes a difference

dire abyss
#

alright let me try that

fathom pendant
#

but i don't think i've had an issue like that

placid edge
#

anyone else have issues with impacket-getuserspns with Kerberos SessionError: KRB_AP_ERR_SKEW(Clock skew too great)

#

im guessing the timestamp difference is to great, but how can i fix this to make it work?

thorn urchin
fathom pendant
#

also: are you sure that's the right wordlist

#

what module are you working on?

placid edge
dire abyss
thorn urchin
fathom pendant
#

yeah Module is password attacks: section name is Attacking Active Directory & ntds.dit

dire abyss
#

thanks thought it was a memory issue, error was misleading

placid edge
#

i dont have the password to get into the dc tho

#

so im kind off stuck here

fathom pendant
dire abyss
#

noted

fathom pendant
#

always start with the list(s) provided by the module, then check others

#

usually it's either in the provided list OR in rockyou if it's password related

mystic light
placid edge
#

i ended up doing it locally on the host i have access to with rubeus

rustic sage
thorn urchin
#

you just need a route and your preferred time application

#

DCs have built in ntp functionality

#

you can sync without creds because devices need to match DC time to auth in the first place

#

Imagine getting KRB_AP_ERR_SKEW because you couldn't sync time to fix KRB_AP_ERR_SKEW πŸ˜‚

lofty wave
#

Dunno if you got this since your question is old. Either way for others there are multiple binaries in the list. You just have to get the right one for the flag. πŸ™ƒ

dull plover
#

Peace everyone, I’m doing the β€œNetwork enumeration with NMAP” and I’m on the question about host discovery. It’s asking me based on the last result find out which operating system it belongs to. It’s gives the hint to look at TTL, I’ve tried both TTLs but to no avail. Any suggestions?

fathom pendant
fathom pendant
#

most OS have a standard TTL they'll send back with pings

lofty wave
#

Can't remember if HTB was case sensitive. Might be as I've been Reeeee on quite a few lol

molten prawn
#

attacking common applications module - exploiting web vulnerabilities in thick client application section . so the very first step is capturing and analyzing the netowrk traffic of the .jar file in wireshark but it just wont show no matter how much i interact with the .jar client.

lofty wave
placid edge
#

finally

#

now i have a new apprication to ligolo-ng πŸ˜„

short hare
#

@placid edge awesome

ruby whale
#

how much time it took you to complete the whole path ?

placid edge
#

Im not done yet πŸ˜†

#

I just needed a little break from ad module

#

So i hopped on the smaller ones

#

But currently at 97%

rustic sage
# placid edge I just needed a little break from ad module

It has been a major headache I only have 3 topics left in the module before the assessment. Then I can rest in peace. I wish AD wasn't so complex. Kinda makes you wonder about the design thought process asking "what was going on in their heads when they made this?"

ruby whale
#

For me I skipped AD module to hop on web attacks due to spawning issue, going to resume it today.

rustic sage
#

yeah that was a thing last week

placid edge
placid edge
#

Taking some time off and learning each thing more indepth has helped me. Like with kerberos and ACL

#

Watching a lot of youtube videos. ippsec.rocks and you can search for like DCSync and ect

molten prawn
#

Today I was almost crying in front of the screen because of connectivity lol

ruby whale
heavy marsh
#

Active Directory Skills Assessment 1, I have the kerberoasted account name and password. Stuck on the fourth question: Submit the contents of the flag.txt file on the Administrator desktop on MS01. How am I supposed to access MS01?

heavy marsh
# thorn urchin wdym, what have you tried

I tried getting the Administrator desktop flag, but I was still on the first machine, because it was the same as the first question. I don't know how to log in to MS01.

thorn urchin
#

wdym you dont know how to log into ms01, what have you tried to access it with

heavy marsh
thorn urchin
#

okay, try the other access methods used throughout the module

heavy marsh
#

ssh failed

thorn urchin
#

what about psexec or winrm

heavy marsh
autumn pilot
#

SSH server (service) is not something that is enabled by default on windows

thorn urchin
#

if Im just blind guessing to log into a windows machine I usually go psexec->winrm->rdp

#

though relevant to remember that psexec and winrm usually require some form of privileged credentials by default

heavy marsh
#

and tried python3 psexec.py SQL01.inlanefreight.local/<user>:'<password>'@<ip>

#

what's the difference between SQL01 and MS01?

#

Is my syntax correct?

thorn urchin
#

the first one would be the syntax for trying a domain accouny

heavy marsh
#

First command gave this

#

Second command gave this

heavy marsh
thorn urchin
#

technically? yes

#

but Im pretty sure the challenge has nothing to do with that

#

in this case MS01 is just a machine name

heavy marsh
#

So is my command syntax correct?

thorn urchin
heavy marsh
#

win-rm failed as well

#

I don't know what else to try.

autumn pilot
#

Understand if there are multiple network adapters on the machines, if that's the case then you must do dynamic port forwarding

heavy marsh
#

I used the command: Enter-PSSession -ComputerName MS01 -Credential $cred

#

after setting up the cred and password variables

#

I feel like this shouldn't be so complicated. I have the creds, it's just that none of the methods are working.

heavy marsh
#

Are there any other methods to authenticate? I have the user and password, not sure why nothing is working.

#

Everytime I try something new I get the same administrator flag

heavy marsh
#

So I think I figured it out. I have to use the Enter-PSSession module, however every time I attempt it, it does not work. The output is blank.

#

I have set up the password and cred variables correctly.

#

Anyone have similar issues?

mild jetty
#

Ok

heavy marsh
#

Has anyone used Enter-PSSession to get MS01?!

#

I feel like it should work, is just not giving me a session.

#

I used the command:

Enter-PSSession -ComputerName MS01 -Credential $cred

after I had set up the cred and password variables.

#

I saw something in the forum about using chisel, but if I remember correctly that's a port forwarding tool, not an AD tool.

sharp bluff
#

Guys i'm trying to run a python payload for achat buffer overflow (chatterbox machine) but keep getting errors with the script when trying to run python [payload].py

#

I read all the walkthroughs and videos on this box and at some point they use the python command to run the payload, any ideas? or is the payload just off with the new python3 ?

quick crane
#

who can help me this question:"Find what attack the Enterprise Admins group can execute over the Domain object.",that in "ACTIVE DIRECTORY BLOODHOUND-Analyzing BloodHound Data",I don't know what I did wrong. I can't find the so-called domain object and I don't know what the correct answer format is. If anyone would like to help I would be grateful,This is the direct link:https://academy.hackthebox.com/module/69/section/2080

tranquil axle
vale ruin
#

Im new and what does "Submit root flags" mean on the first course?

bright quiver
#

I wanted to ask the community or those who maybe have taken the cpts…or know more of it than myself…other than maybe Dante what other pro lab or labs are good to prepare for it? Like zephyr and Rasta ? Or offshore and zephyr or just offshore. Can anyone help me during my learning path?

daring island
#

hello, I'm new here and don't know where to start in terms of labs to build my skillset in hackthebox. can I get some advice please?

quick crane
tranquil axle
# bright quiver I wanted to ask the community or those who maybe have taken the cpts…or know mor...

Some say it is not a good idea to do the prolabs, as they require things that are not covered in the CPTS path, so when you do the exam you might overthink solutions. Others say all practice is good. Dante and Zephyr are usually what people recommend, Dante gives some easy wins and allows you to practice pivoting but had little AD, zephyr is full of AD. Offshore has AV evasion and stuff, that’s way out of scope for CPTS, so probably not good for practicing

bright quiver
cerulean barn
#

hi im new

#

where to go first

#

does this server teach something?

real sigil
cerulean barn
#

oh i see thats a website

real sigil
cerulean barn
real sigil
#

You can go to the shooting range, it’s on the hackthebox website, it’s very friendly to novices

cerulean barn
#

does modules mean chapters?

rustic sage
#

modules are the specific topics, they are combined to make the paths

dapper birch
#

Hello Folks,

#

I see that the password attacks module, Attacking Active Directory & NTDS.dit section does not tell us what to do with the extracted ntds.dit file rather than using CME to extract the domain user hashes from the ntds.dit file existing in the remote target. Am i missing something?

#

Kindly help

next bronze
#

cme is dcsync, you can also save ntds locally and extract hashes from it, two different methods

dapper birch
#

Yes, I want to know how to extract the hashes from the fetched ntds.dit file, i dont see it covered in the section in question.

next bronze
#

secretsdump

dapper birch
#

I get this error.

next bronze
#

yeah you need to save the system reg hive too, the key to decrypt is in there

dapper birch
#

Okay, Thank you

placid edge
#

Would OSCP be the same kind of network that cpts has? Or is it more "attack these hosts" rather then enumerating internal networks and such

next bronze
#

the oscp layout is known, you have 3 standalone hosts and 3 networked hosts in the AD set

onyx dust
placid edge
#

Should probably go watch some hard ranked ones to knock my confidence level down to normal again lol

onyx dust
#

me too lol

dark star
#

im finishing binary exploitation

onyx dust
#

did you do the 1st one?

dark star
#

going to bug bounty

#

then maybe im doing it

#

pm me @onyx dust

onyx dust
#

ok

next bronze
placid edge
#

Ye idk lol

onyx dust
#

oscp is easy

#

dont worry. if u can do htb u can do oscp but u have to be good at understanding tunnels in case they break something on purpose to make u try harder πŸ˜‰

#

i think this year they replaced pwnkit with dirtypipe for the linux boxes πŸ˜‰ wow right?

placid edge
#

I remember in my job interview they asked me if i wanted to take the oscp and was shocked when i said yes. Because only one of them had passed it @next bronze . They looked at me like i was insane lol. Didnt care anout the cpts plans tho, so idk how much they really know

next bronze
#

it's not difficult but the materials are bad

placid edge
#

Idk. They also liked to specify how much younger i was than the youngest guys that worked there( 15years). So i guess they didnt take me seriously at all either way so

fickle thicket
#

hihi guys, i am currently at "Dynamic Port Forwarding with SSH and SOCKS Tunneling". can anyone help me check if my understanding of proxychains and socks is correct?

placid edge
#

It is. Proxychains defaults to socks4 on port 9050

next bronze
fickle thicket
placid edge
#

So if its setup correct in the /etc/procychains4.conf file you can ssh in with the -D option and use proxychains before your tools

#

Or the cli

fickle thicket
rough trail
#

hello guys i am in attacking common applications skill assessment 2 and trying to get the shell , any hint on finding admin password will help

next bronze
fickle thicket
#

the proxy will make things look like any command used with proxychain come from the ssh server itself.

#

i guess this is how it works?

next bronze
#

but roughly knowing how it works will be good enough for most situations

fickle thicket
#

thanks, i will read about it

torpid zinc
#

Hello everyone, i am in the lateral movement section of the attacking enterprise networks module. I am following the exact steps that are mentioned for the Priv Esc but the exploit does not work. If anyone cna help i would be really glad because i am trying it for 3 hours now and i am going crazy

rustic sage
#

Having an issue in the SMTP section of the HTTP Attacks module - can't seem to access the vHost after adding it to the /etc/hosts

fathom magnet
#

@rustic sage

rustic sage
fathom magnet
#

I really need a favor

#

Can you help me find a great server for my wz3

fathom pendant
#

This server has nothing to with w/e wz3 is

rustic sage
fathom pendant
#

I haven't dont the http attacks module

#

Congrats but this channel os for academy

quaint cloud
#

oh mb

dreamy solar
#

Hello I have a problem with this exercice can you help me please :
Attacking Common Applications osTicket

quaint cloud
#

im sorry

languid wharf
#

But this python tool is not needed for this section

dull plover
# fathom pendant most OS have a standard TTL they'll send back with pings

This cleared up how to find the information. However I’m still having trouble with getting the correct answer. Based on the question it gave me a 2 TTLS (a sent and received one) one was 255 and the other was 128 I tried brute-forcing it and trying both ||Solaris|| and ||Windows XP|| but to no avail. Am I missing something?

fathom pendant
#

Don't say xp

#

;) just windows

golden basin
#

Does anyone know about google dorks?

dull plover
#

Thank you

drifting vortex
topaz holly
#

HTB took my $8 today. That marks my first month. Taking it slow and steady with the modules. Even with lots of previous experience, I have to say it's been worth it so far. I have learned new things still and I greatly appreciate the perspective HTB teaches us from.

#

(first month in academy) I've used HTB far before academy every existed!

naive timber
#

I'm using VM instead of workstation instance..
And I have some problems when connecting VPN...
Is that ok to do some module exercise without using vpn

peak rover
#

Hello everyone, I want to start studying cybersecurity, can you recommend useful sources?

#

you can offer even basic things, I will be grateful

potent ermine
dreamy solar
languid wharf
#

You don't need this tool to complete the os Ticket section

placid edge
#

question. When you have a lot of shares. What are your goto tools to download all the files?

#

smbget?

long basin
#

smbmap is good option

next bronze
#

smbmap (which never works for me), netexec has the --spider and -M spider_plus, but usually just look through them manually with smbclient.py

placid edge
#

i have the following access rn

        Department Shares                                       READ ONLY
        IPC$                                                    READ ONLY       Remote IPC
        NETLOGON                                                READ ONLY       Logon server share 
        SYSVOL                                                  READ ONLY       Logon server share 
        User Shares                                             READ ONLY
        ZZZ_archive                                             READ, WRITE

And i am trying to download all the files in each share to have locally

#

tho, i want to use responder in the ZZZ_archive

#

but still dont want to miss anything

faint rampart
tight mesa
#

Hi there, 1 silly question for y'all related to Print Operators | Windows PrivEsc, did u download 'n compiled the EnableSeLoadDriverPrivilege code or directly used the files left into C:\Tools?

icy hazel
dreamy solar
placid edge
#
#

woo

frosty spade
#

hi folks can anyone drop a hint on the last question for the ad enum and attack skill assessment 1

tiny wadi
#

Hey everyone πŸ‘‹

frosty spade
#

@next bronze tried with the admin hash didnt work belive it was a null hash gonna go over the learning for said attack see if that gets me anywhere been on this module for a couple weeks so might have forgotten somethings

next bronze
#

admin hash? use the credentials of the user in the 5th question to perfrom the attack in the 7th question

#

unless you've already done that

frosty spade
#

i got ts pass but it wont connect with evil winrm

next bronze
#

there's more than one way of doing that attack, you don't need to get a local shell, read the section again

frosty spade
#

im lookin for the flag on admins desktop should i target smb or try for a shell

next bronze
#

have you done that attack or do you already have DA creds?

#

that user is not a DA

frosty spade
#

ok ill try with the others creds from previous question or try and crack one of the others from the massive hash dump i did

next bronze
#

use the credentials of the user in the 5th and 6th question to perfrom the attack in the 7th question

rustic sage
#

I've a problem in this exercise i tried many times and I couldn't find the solution
Exercise 2: Try adding a rule that automatically adds ;ls; when we click on Ping, by matching and replace the request body of the Ping request.

#

I don't know what should I set in the match and replace rules

frosty spade
#

im confused if i have 5s creds why would i need to get more creds with said attack

tight mesa
#

anyone to willing to give me a hand with UACMe/Akagi64.exe into Print Operator | WinPrivEsc section/module....

next bronze
astral inlet
#

πŸ‘€

frosty spade
#

my attempts at connecting to dco1 with 5s creds didnt work i dont think he had permissions ill try again see if itll work i remember i could list shares with cme but smbclient wouldnt connect mybe i did it wrong i was thinking winrm to get shell but that wouldnt connect

#

mabe cause im tunneling

astral inlet
#

maybe show some syntax ?

safe owl
#

who may help me with module (session security) im about: there is error in the (incognito mode) but (without incognito it's work)

shell nexus
#

currently in the Linux introduction.

i got everything done in the "system information" part, yet can't seem to find the answer to "What is the path to the htb-student's mail?"

i tried both using ls and dir yet neither showed any directories, how do i find a list of all the directories available on the user?

astral inlet
#

if you found the mail do pwd

#

"print" "working" "directoy"

#

and "ls" has some perimeters , do "man ls"

keen compass
harsh path
#

Hi i need help assembly language working on the unconditional module using jmp (unconditionals). I literally place the jmp between every line and its either exiting normally or its giving me the hex rbx value of 0x1000000 which is not correct.

#

global _start

section .text
_start:
mov rbx, 2
mov rcx, 5
loop:
imul rbx, rbx
jmp func
loop loop
func:
mov rax, 60
mov rdi, 0
syscall

#

this is what i have. Now my question is am i over thinking this or am i missing a step? also i need the hex of rbx

next bronze
#

what's the question

harsh path
next bronze
#

just do what the question asked, jump to func before the line loop loop and get the value of rbx

#

your code looks correct, just ge tthe right value from the right register

frosty spade
#

smbclient \\172.16.6.3\SYSVOL -U tpetty dont know how to get to admin desktop havent permissons to view C or ADMIN share

next bronze
#

because the user is not an admin, do the attack

frosty spade
#

by attack you mean dcsync i thought that was for dumping hashes or should i make a golden ticket

thorn urchin
#

golden ticket is just for persistence

#

you rarely get a golden ticket before youve already compromised the domain

frosty spade
#

im not sure how to proceed

next bronze
#

what do you mean? dcsync as I've hinted many times, you don't need to get a local shell to dcsync

frosty spade
#

DCSync is a technique for stealing the Active Directory password database

next bronze
#

correct

frosty spade
#

im so confused

astral inlet
#

do oyu have a BH dump ?

next bronze
#

you don't need bh for this, the question already hinted at this, it's the answer for the second last question

frosty spade
#

i need the flag on dco1 admin desktop so i have to use a different account to get it?

#

runas?

next bronze
#

problem: you don't have access to a domain admin
solution: get access to domain admin credentials

#

what kind of attack get you that?

placid edge
#

its getting dangerous here: 96.88%

thorn urchin
#

have you tried it?

harsh path
rustic sage
#

Hi everyone, I am doing the module Privilege Escalation and have it all figured out up to the point where you have to ssh into the root using the id_rsa, I created a vim called id_rsa and pasted the whole key into in and now I am running "shh root@ip -p port -i id_rsa" but it just throws a error: Warning: Identity file id_rsa not accessible: No such file or directory.

astral inlet
#

"No such file or directory."

thorn urchin
#

make sure id_rsa is in the local directory and has the correct permissions

placid edge
#

or am i trippin

rustic sage
#

I did run it through the chmod 600 but I dont know if it worked since it doesnt have a callback (I hope :D)

rustic sage
placid edge
#

did you accidently move it in a different directory?

#

do ls. see if you can see the file

thorn urchin
rustic sage
#

I am running it from root

thorn urchin
#

we didnt ask about the user

lapis pelican
#

I wish I had enough cubes for PowerView module 😩

placid edge
#

did you remember to actually save the file you wrote?

frosty spade
#

[] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash)
[
] Using the DRSUAPI method to get NTDS.DIT secrets
Administrator:500:aad3b435b5

#

now i pth with evilwinrm and it doesnt work

placid edge
#

dont use evil-winrm

thorn urchin
#

did you use the right hash, and is winrm even enabled

placid edge
#

use rdp

#

check what is actually open on the server

#

idk if rdp is open. i havent gotten that far

rustic sage
placid edge
#

ok so. nano might be easier then

astral inlet
#

":w"

thorn urchin
#

idk I use nano not vim kek

astral inlet
#

better ":wq!"

placid edge
#

@thorn urchin FINALLY I MEET SOMEONE WHO USES NANO

#

ops caps

astral inlet
#

there is no nano πŸ˜„

thorn urchin
#

its simple, quick, and installed on everything

placid edge
#

haha right

astral inlet
#

nano is a myth

low crescent
#

"True random value does not exist" - give someone new access to Vim console and ask them to quit it

thorn urchin
#

Ive never seen a linux machine that didnt have nano

#

Ive been on embedded Linux systems that still had nano

low crescent
rustic sage
#

E212: Can't open file for writing: permission denied

placid edge
#

can you do this in the /tmp directory

drifting urchin
#

I am doing the Module: Getting Started, Section: Privillege Escalation. The 2nd task is to "Once you gain access to 'user2', try to find a way to escalate your privileges to root, to get the flag in '/root/flag.txt'. " I have access to user2, which has read privlieges in /root/.ssh/id_rsa. I tried to copy paste the content of the the id_rsa on my local machine, and then trying to login as root, but asks for password. Any idea what im doing wrong?

placid edge
#

just restart everything

astral inlet
#

question : why do priv esc if there are no linux basics ?

thorn urchin
#

Ive considered learning vim but I just have so many other things of higher priority on my learn list

astral inlet
#

vimtutor

drifting vortex
#

or chmod 777 id_rsa

astral inlet
#

just fire it up πŸ™‚

placid edge
#

vim is usable for me, but i prefeer nano. Also i use a basic terminal and not tmux.

low crescent
#

Fair. Vim to me is like regex - it doesn't take a while to learn it, but once you do, it's actually useful πŸ˜„

placid edge
#

tmux is weird on my keyboard because i live in a different country lol

astral inlet
#

you should see our seniors use vim πŸ˜‰

drifting urchin
#

both don't work 😦 "ermissions 0777 for 'id_rsa' are too open.
It is required that your private key files are NOT accessible by others.
"

lapis pelican
#

Hah, kids. I use DOS for pentesting fingerguns

astral inlet
#

if not do sudo chmod 600 id_rsa

low crescent
#

^ in that case, also change the ownership of the file

lapis pelican
drifting vortex
lapis pelican
astral inlet
#

and please learn how to crawl before learning how to run πŸ™‚

lapis pelican
#

Crawl what?

astral inlet
#

linux basics

thorn urchin
#

google op

placid edge
thorn urchin
#

Im literally googling a problem right now

lapis pelican
#

Google bad

astral inlet
#

it will probably end up to stackoverflow :>

thorn urchin
#

no need, I googled and clicked on the first link and it had the exact solution to my issue with examples

drifting urchin
astral inlet
stable cloak
#

Linux is very important

#

Ls -la

placid edge
thorn urchin
drifting urchin
dusty fiber
#

i not able to connecting the SMB1 Please help me

low crescent
placid edge
#

you failed to copy it over

low crescent
#

Incomplete/corrupted private key, repeat the process

thorn urchin
#

invalid format means its a bad copy yeah

rustic sage
#

@astral inlet ty for the help, I figured it out and when I finish the module ill be sure to check out linux basics

astral inlet
#

maybe missed some "---" or so ?

low crescent
astral inlet
#

and you can ask chat gpt , it does google for you πŸ™‚

lapis pelican
#

I remember my old days of struggling to connect with openvpn.

astral inlet
#

yes me too

#

it took me quite a while, but i solved it myself

low crescent
#

Everybody did, it's the process of learning

placid edge
#

same. i struggled for 2 hours with /etc/host cause i didnt know what it was

lapis pelican
#

How far we've all come.

astral inlet
#

the key point is how to learn to help yourself ...

faint rampart
lapis pelican
placid edge
#

02hero

astral inlet
#

i am on my way to cpts too

lapis pelican
astral inlet
#

just eJPT / JPT yet πŸ˜‰

#

started around 7-8 months ago

lapis pelican
#

I have CRTP next month.

faint rampart
astral inlet
#

working as a junior PT since december 2023

placid edge
#

lets prey for all to pass cpts

lapis pelican
astral inlet
#

yes and after it oscp is on the menu

faint rampart
lapis pelican
astral inlet
#

sure πŸ™‚

#

but i am @ around 40% of the PT path atm , will take a bit m

lapis pelican
astral inlet
#

AD ?

lapis pelican
#

Yes, CRTP bootcamp.

astral inlet
#

with nikhil

lapis pelican
#

Yes. Started 2 days ago .

faint rampart
lapis pelican
#

I read as much as I could about AD. Academy modules, Microsoft Learn docs, PowerView docs, labs etc.

#

And I have a pretty fine amount of knowledge considering the time I started.

astral inlet
#

if you need some resources dm me @lapis pelican

lapis pelican
#

Resources!! Why not??

frosty spade
#

got it guys thanks for the help

astral inlet
solar zodiac
#

hi everyone! could anyone possibly advise me on the NTLM Relay skills assesment?

#

im pretty sure I've found a the correct path... Im getting access denied for some reason though when using impacket

frosty spade
#

the previous hash i got for admin was wrong redid the dump and was able to execute type C:\Users\Administrator\Desktop\flag.txt

astral inlet
#

you may check it with nxc or cme before

next bronze
frosty spade
#

i originally dumped it with katz on ms01 this time used secretdumps with the dc01 ip and creds gathered

astral inlet
#

πŸ™‚

frosty spade
#

not gonna lie that was a tough module to get through

junior widget
#

new fortinet breach, anyways what are some challenging modules? any genre.

astral inlet
#

yes HTB does not take you fully through it you have to think much

drifting urchin
#

finally it worked, it was a bad copy, thought everything was fine but some additional "~" were at the bottom, that was the issue.. silly me xD.. ty all for help @astral inlet @low crescent @placid edge @thorn urchin

placid edge
#

np. Good job!

frosty spade
#

there was alot of rabbit holes i had to dive headfirst into

solar zodiac
astral inlet
#

your welcome and tbh the most you will do is troubleshoot

solar zodiac
astral inlet
#

and learn to fix things

fathom pendant
astral inlet
#

no offence

next bronze
junior widget
fathom pendant
#

Rabbit holes by colloquial definition lead nowhere

junior widget
#

something that leads somewhere and can or will lead to another place repeatedly is technically a rabbit hole

frosty spade
#

they lead me to the rabbit who had the carrot

junior widget
#

a rabbit hole being what seems like an infinite cycle of repetition between discovery is quite literally it

junior widget
#

like some SOG or Mamamax videos where they cover disturbing sites (usually darknet) that all interconnect to each other and seem to have no end to redirections

#

thats a rabbit hole

frosty spade
#

this module shouldve been put lower on the list imo

junior widget
#

an end to no end

#

no end to an end

ornate olive
#

I need help with login brute forcing skills assessment, can someone help me with the parameters?

placid edge
#

sure

astral inlet
#

tell us your syntax πŸ™‚

ornate olive
#

hydra -l user -P /home/kali/Downloads/rockyou.txt -f 83.136.249.57 -s 35205 http-post-form β€œ/admin_login.php: user=^USER^&pass=^PASS^:F=<form name='log-in’”

astral inlet
#

-1 ?

#

-l

fathom pendant
#

-1

ornate olive
#

Yeha no it’s -l , I had to take a picture of my script and copy paste it from the picture

fathom pendant
#

You can't copy/paste to discord? Or are you running baremetal and don't have discord installed

ornate olive
#

I don’t have discord installed, company computer

fathom pendant
#

Ah

#

Install discord in the vm

ornate olive
#

I’m really not sure where I’m missing something, I’ve re read the module multiple times and I can’t seem to figure out what is wrong with my parameters

astral inlet
#

did you check with burp ?

ornate olive
#

Burp outputs user=test&pass=test

#

When using test:test

astral inlet
#

thats correct

tranquil axle
ornate olive
#

Yes, it’s giving me user:12345 as the username password

tranquil axle
#

Then the β€žfailure detectionβ€œ part is wrong, that’s the part after F=

astral inlet
#

is user meant to be a name or a text file ?

tranquil axle
#

Basically it tells hydra to look for a part in the result html and if it finds what’s after F= it didn’t log in correctly

#

I assume your page does not contain <form name='log-in' on a failed login

#

Maybe the form is named differently or you can find another unique string

astral inlet
#

better use the correct error message

ornate olive
#

Might be a dumb question but, is it case sensitive?

astral inlet
#

yes

#

probably

ornate olive
#

Ahhh I needed to use β€œLogin” not β€œlogin”

astral inlet
#

and die perimeters of hydra are too

#

l = name
L = wordlist

ornate olive
#

It’s a name

#

I got it, thank you peoples

astral inlet
#

nice

stable cloak
#

Bro hi am new to start my journey

#

Of hacking

astral inlet
#

great πŸ™‚

frosty spade
#

Greetings and salutations bb10

ornate olive
#

So uh guys I did not get it, I thought I did and I did not

#

Im looking at the curl rn and it says form name=β€˜log-in’

stable cloak
#

Where to start how to start give me some tips guys

astral inlet
#

do you have linux skills ?

stable cloak
#

Yeah some

compact patrolBOT
ornate olive
#

Is that not what your F= is?

#

My fail string is wrong but I’m not sure why

astral inlet
#

-f exit after the first found login/password pair (per host if -M)

   -F     exit after the first found login/password pair for any host (for usage with -M)
#

man hydra

frosty spade
#

you sure its rockyou maybe a custom wordlist been awhile since Ive done it

tranquil axle
ornate olive
#

No, it just brings you right back to the login page

#

This is the html on the page <form class=β€œform” name=β€œlog-in”

tranquil axle
#

Maybe make sure you are using the right quotation marks? Single vs double etc

astral inlet
#

example :

sudo hydra -l atlas -P ~/rockyou.txt 10.10.11.218 http-post-form "/login:username=^USER^&password=^PASS^:F=Invalid credentials"

frosty spade
#

which assessment and which question

astral inlet
#

just an example

fluid basin
#

Module: AD Attacks and Enumeration, Section: Living Off the Land -> I believe I found the user I need via the ldap querys and UAC bit values but when I query info on the user themself it responds with user does not exist. Plz point in right direction

tranquil axle
meager otter
#

I am on Exploiting XSS Via WebSockets. I am sooo stuck for close to three hours now. I have tried xss payloads that will call out to a script I am hosting but cant seem to make any progress. If anyone has completed this please feel free to ping or DM me for more details on what I have tried. I would be grateful for a push in the right direction. Thank you!

glad citrus
#

Ok I’m in footprinting medium and have admin privs… I see the NSUSER.Dat in file explorer. How can I view its contents?

fathom pendant
#

why do you need that file?

glad citrus
#

I thought maybe the user creds im looking for could be in it

fathom pendant
#

nope; you can find the creds in 2 ways; either exploring what shares your user has access to - or enumerating other services

#

oh waut

#

you have admin

#

why not ||SQL||

glad citrus
#

Rgr I’ll dive in

fathom pendant
#

it's literally like the one thing on the desktop when you RDP

glad citrus
#

I’m not familiar with the software lol. Digging for my creds

fathom pendant
#

i mean you have the admin creds no? so you just launch it as admin

glad citrus
#

Found it! I was scrolling the DB

fathom pendant
#

then you can just click around and found it

#

gz

fathom pendant
#

there's some commands that they teach you in Attacking Common Services that would speed it up 1000%

glad citrus
#

I’ll go back in the lesson next time, good call. Had to do quite a bit of note checking to do this box. Learned a lot in that one.

fathom pendant
#

nah the footprinting module doesn't give you any sql navigation commands

#

to do from a command line/query

delicate swan
#

how ;-;

sleek moss
#

why doesnt 10.129.89.51 inlanefreight.htb
i put that in my hosts but when i go visit http://inlanefreight.htb dont work why

#

i did and then used dig NS inlanefreight.htb but it dont work

#

im on
Information Gathering - Web Edition

Page 7
Active Subdomain Enumeration

Active Subdomain Enumeration and i cant find the ns

fathom pendant
sleek moss
#

oh i c danke

#

i got the nameserver do i have to add it to my /etc/hosts? 1└──╼ $nslookup -type=any -query=AXFR 10.129.65.204 ns.inlanefreight.htb
nslookup -type=any -query=AXFR inlanefreight.htb 10.129.65.204 ns.inlanefreight.htb

#

no work

fathom pendant
sleek moss
#

i didnt add the nameserver yet

fathom pendant
#

also it's likely breaking because you're trying to specify multiple things

sleek moss
#

shud i add nameserver to the hosts

fathom pendant
#

if you want to, it's not necessary: the ip is just as good

soft cedar
fathom pendant
#

(if the nameserver said something like 127.0.0.1 don't use that)

sleek moss
#

└──╼ $nslookup -type=NS inlanefreight.htb 10.129.65.204
Server: 10.129.65.204
Address: 10.129.65.204#53

inlanefreight.htb nameserver = ns.inlanefreight.htb.
the nameserver is just the ip addres?

#

nslookup -type=any -query=AXFR 10.129.65.20 10.129.65.204#53

fathom pendant
#

no

#

you're misunderstanding the information presented

#

the #53 is just a representation of the port that's relaying information (port 53 is known as the DNS port btw)

#

nslookup -type=any -query=axfr inlanefreight.htb target_ip

#

i'm gonna be honest dude, you need to read the sections more carefully

sleek moss
#

oh i c danke

solar zodiac
#

hi everyone! just wondering if anyone had done the first set of exercises in the NTLM relay module. They're keeping me from completing the module and I don't know what is going wrong. The first question asks for information about a 172.16.117.50 on responder, but after waiting an hour I still dont have any traffic from 172.16.117.50. I'm not sure if something is wrong with the lab or I'm doing something incredibly dumb lol

fathom pendant
#

i take it you're connected to a jump host on the 10.129.x.x network?

#

also responder doesn't do anything, it listens for things

solar zodiac
#

im running responder in analyze mode

#

so its not poisoning anything

fathom pendant
#

are you connected to a host that has access to that internal network?

solar zodiac
#

with sudo python3 responder.py -I ens192 -A from the host on the internal network

#

it is capturing alot of traffic from the dc, 172.16.117.3

#

but nothing from 172.16.117.50 like the question asks

fathom pendant
#

what is the question asking for specifically

solar zodiac
#

it asks for the hostname that 172.16.117.50 requests via nbt-ns or llmnr

fathom pendant
#

hmm idk then

solar zodiac
#

yeah its weird lol

fathom pendant
#

make sure you didn't skip a step from the section

#

sometimes it's dumb like that, you miss one step

solar zodiac
#

whoa found it

#

it wasa needle in a haystack lol

#

also had to leave responder running for ~ 15mins

heavy marsh
#

Are the AD labs down again? I can't seem to get connected to the AD skills assessment 1

#

Switched VPNs, UDP, TCP, all of that.

#

Been staring at this for way too long.

#

When this finally does work I will have a question. Is there a way to run chisel on Windows AD?

#

I didn't think about that option yesterday since it only showed linux as an option in the section that covered it.

fathom pendant
#

doesn't the pivoting module literally show you how to?

#

there is a chisel.exe Β―_(ツ)_/Β―

#

but i mean ligolo-ng is better

sleek moss
#

if a subdomain has a subdomain that subdomain is a zone?

#

or + 1 Identify how many zones exist on the target nameserver. Submit the number of found zones as the answer. i would do this by checking if the nameserver is the same right

fathom pendant
#

it's a shockingly low number

sleek moss
#

i c

#

or + 1 Identify how many zones exist on the target nameserver. Submit the number of found zones as the answer. i would do this by checking if the nameserver is the same right

#

that a right way to do it?

heavy marsh
#

Doesn't mention windows in the module at all.

fathom pendant
heavy marsh
sleek moss
#

i c any other way to check if they are zone?

soft cedar
heavy marsh
#

What would be a good alternative. Someone told me I need to tunnel to the MS01 machine in the AD Assessment 1.

#

Saw someone in the forums that used chisel, but there was no clarification as to how that worked.

amber pelican
#

Are there cyber security sims

heavy marsh
#

Okay, apparently there is, it's just not mentioned on the github repo for some reason

#

πŸ€¦β€β™‚οΈ

fathom pendant
amber pelican
#

Are there cyber security sims

fathom pendant
amber pelican
#

Are there cyber security sims

soft cedar
fathom pendant
#

what do you mean by cyber security sims?

amber pelican
#

I play flight sim

fathom pendant
#

ah

#

this channel isn't for that kinda conversation. Closest i've seen uses some typescript/javascript stuff - Bitburner

#

but there's not really a "cyber security sim"

#

besides you can likely google or search steam and find the answer

amber pelican
#

fuck

zenith mango
#

Very smooth

heavy marsh