#modules

1 messages · Page 196 of 1

fathom pendant
#

read #welcome and #rules to learn about the server: if this server isn't what you're looking for you can freely leave

heavy marsh
#

Where do I go for the windows version?

soft cedar
fathom pendant
heavy marsh
#

All they showed was the ubuntu version in the module.

fathom pendant
#

literally took me like 5 seconds to find using google

#

this is actually where you'll find the latest release for chisel

stoic crescent
#

Hello everyone, I'm currently stuck on the FootPrinting hard lab and would like a push in the right direction.

fathom pendant
#

or alternatively: udp

#

both my hints relate to the same thing

stoic crescent
fathom pendant
fathom pendant
heavy marsh
#

Cool, I'll check the github releases. Thanks.

stoic crescent
heavy marsh
#

Is there a htb section on ligolo?

glossy wasp
#

Im on the beginning of metasploit and ive followed every step so far, but where im supposed to get control of the system the service times out. "Service start timed out" instead of whats supposed to happen, it doesnt even use ms17_010 as check, it just goes to target os

fathom pendant
stoic crescent
fathom pendant
heavy marsh
fathom pendant
fathom pendant
fathom pendant
#

if needed reread the section related to the service

stoic crescent
#

I'm not 100% sure if I need to use a command from there or if I used the wrong command to begin with

soft cedar
# heavy marsh If not I found this https://arth0s.medium.com/ligolo-ng-pivoting-reverse-shells...

https://jh.live/vanta || Prove your security compliance with Vanta! Get $1,000 off with my link: https://jh.live/vanta
The Pivoting Lab SnapLabs template: https://jh.live/pivoting

Free Cybersecurity Education and Ethical Hacking
🔥YOUTUBE ALGORITHM ➡ Like, Comment, & Subscribe!
🙏SUPPORT THE CHANNEL ➡ https://jh.live/patreon
🤝 SPONSOR THE CHANNE...

▶ Play video
fathom pendant
#

i believe that's the one from the section

stoic crescent
fathom pendant
#

it'll give you a bunch of info including the community string in brackets

#

it'll start with b

#

so it's completely easy to overlook

stoic crescent
fathom pendant
#

no problem!

#

fun fact: I spent an hour on this because I didn't realize the obvious

#

(I didn't read the brief which would have been more revelatory)

heavy marsh
#

Tried tunneling to MS01 on the AD Skills Assessment with

proxychains xfreerdp /v:172.16.6.100 /u:<user> /p:<pass>

and got some strange errors.

#

I used the following command on the windows box:

./chisel server -v -p 1234 --socks5

#

And this is my attack machine:

#

My proxychains is set up properly too

#

Why is this not working?

stoic crescent
#

Just wanted to let you all know I got passed the FootPrinting hard lab!

heavy marsh
#

I also attempted with the reverse tunnel.

fathom pendant
#

so you don't gotta worry about any sorta proxy conf

heavy marsh
fathom pendant
#

i haven't messed with chisel before ¯_(ツ)_/¯

#

ligolo is really simple to set up and get running tbh

heavy marsh
#

Is RDP the correct method in for this box? Just want to make sure I'm not wasting time. I see the tun0 in my ifconfig, but I can't even nmap the MS01 IP (172.xxx.xx.....)

fathom pendant
#

idk haven't done it yet

#

proxychains and nmap don't play well together usually you'd have to add -Pn

heavy marsh
#

It just keeps spamming this

#

I even got a fresh linux version to make sure the versions matched at v1.9.1

sterile epoch
#

I used the NoPac exploit and received the tgt from both ACADEMY-EA-DC01.ccache administrator_ACADEMY-EA-DC01.inlanefreight.local.ccache. I then updated the KRB5CCNAME with the ACADEMY-EA-DC01.ccache ticket. I then tried to use secretsdump.py -just-dc-user INLANEFREIGHT/administrator -k -no-pass "ACADEMY-EA-DC01$"@ACADEMY-EA-DC01.INLANEFREIGHT.LOCAL. this is not working can someone explain to me what I can achieve with the ccache files?

spiral spoke
#

Hello! I'm in the module "shells and payloads" at "The Live Engagement", I already have the shell... but not the flag pepehands look

#

And the question is: Exploit and gain a shell session with Host-3. Then submit the contents of C:\Users\Administrator\Desktop\Skills-flag.txt

||But there is nothing at C:\Users\Administrator||

#

Someone could help me pls? prayge brain_expand

soft cedar
spiral spoke
spiral spoke
soft cedar
#

Review your Nmap scan results for relevant details.

spiral spoke
#

I did again and get the same thing

Yeah, it seems that there is only one way FeelsWeirdMan

spiral spoke
#

Yeah, actually I did it before but there are like 4 or 5 exploits and it's kind of confusse which one is the correct to use, anyway I'm still trying

soft cedar
spiral spoke
#

Ready! it's done! RPOGGERS Thank you so much dude!

#

But it should have worked before with the web shell I think

soft cedar
soft cedar
spiral spoke
#

I thought that smb was a kind of rabbit hole lol

#

Because I tried to enumerate with smbclient, smbmap, rpclient and see if I could upload a file or something like that but there was nothing, but well, it's all about trying harder

soft cedar
plucky latch
#

The AD Enumeration and Attacks Skills Assessment is no joke

quick crane
#

hey bro do you solved this,if you solved it,can I dm you?

#

bro do you solved this,if you solved this,can I dm you

sleek moss
#

any tips for + 1 What is the FQDN of the IP address 10.10.34.136?
Information Gathering - Web Edition

Page 7
Active Subdomain Enumeration

Active Subdomain Enumeration

rustic sage
#

I NEED HELP WITH SOME PEOPLE

sleek moss
#

why

#

@rustic sage

safe dock
#

can anybody tell me why my responder is not catching the hash

sinful olive
#

In Documentation & Reporting Practice Lab We can send the report to mrb3n for him to check it out.. How can I get to him?

plucky latch
safe dock
#

Responder

sleek moss
#

can someone tell me why this wont work ffuf -w /usr/share/wordlists/seclists/Discovery/DNS/namelist.txt -u http://10.129.234.14 -H "HOST: FUZZ.inlanefreight.htb"

#

do i have edit /etc/hosts

mild jetty
#

Stuck on ntlm relay attack skills assesment last question i am not able to find any relay to compromise dc.. can someone Give me a hint

quick crane
#

In the Password Spraying section of the Crackmapexec module, I found the user, but I don't know the answer format, so I am basically wrong now. I would be grateful if someone would give a hint. This is the problem description: "Is there any other local MSSQL account created with the same username and password as the corresponding Active Directory account?"

placid edge
#

probably

user:password

#

@quick crane

quick crane
#

lol,thanks,but this is error,but I solved it

rustic sage
#

In the module for AD enums and attacks I had an issue getting the stuff for attacking domain trusts using linux from child ->parent, the forced ticket I had created wasn't getting me NTLM hash of the user bross, and in order to get it I had to end up using a mix of raiseChild.py and then use my access with raisechild and magically transfer mimikatz into the DC for the parent domain domain and use mimikatz to get the hash for bross.

the thing is as arduous as this was to do, I found it odd that despite following the structure in the section I wasn't able to get in with the forged ticket. I made sure to use the right SIDs for the forgery, namely the ones for the child domain and the one for the user bross in the parent domain. It was super frustrating and it gave out this odd error when i ran secretsdump to get the hash for bross [-] ERROR_DS_NAME_ERROR_NOT_FOUND: Name translation: Could not find the name or insufficient right to see name.

#

practically had me cursin as i lost a ton of sleep to make this work, as something that should work just didnt, im literally going to bed angry lol ;c

placid edge
#

I made sure to use the right SIDs for the forgery, namely the ones for the child domain and the one for the user bross in the parent domain - This isnt nessasary. The parent SSID user doesnt actually need to exist btw.

I cant really help you on the secretsdump because i ended up doing it the exact same way lol. Transfer mimikatz over and dumping the NTLM hash for the user bross.

dreamy solar
#

Hello I search this do you have a idea why?

#

Hello do you have a idea why I don't find this :

cursive vine
analog dock
rough tree
#

Hello to you all, anyone willing to discuss about foothold on SKill assestment 2 in "Intro NOSQL Injection" module?

NVM got it to work!

novel finch
#

Hello lovely people! Your local village idiot here again with another stupid question!

#

I managed to upoad LinEnum.sh to a machine with the path /var/www/html/theme.

I cannot execute the file even though the permissions look like this:
---x--x--x 1 www-data www-data 46631 Feb 7 10:01 LinEnum.sh

placid edge
#

make sure you chmod +x the file first

#
chmod +x LinEnum.sh
./LinEnum.sh
novel finch
#

I did, but the permissions didn't change

#

Would it make a difference if I uploaded it to /usr/local/bin where I have some permissions?

quick crane
#

can I dm you

zinc dust
#

help me change my ip address pls

quick crane
zinc dust
#

dms?

quick crane
icy hazel
#

Hi guys I've been stuck on this question for so long and keep getting left with a blank line ($ ... ) after I run the shellcode, I have no idea if I'm getting closer or further away, any help would be amazing. -- Disassemble 'loaded_shellcode' and modify its assembly code to decode the shellcode, by adding a loop to 'xor' each 8-bytes on the stack with the key in 'rbx'. --

next bronze
barren salmon
#

im getting a connection timed out on firefox in the parrot box. anybody had same problem

wheat laurel
#

hello , does anyone have finished injection attacks skills assessment ?

icy hazel
#

Cheers bud, my bad

tender niche
wheat laurel
languid wharf
#

sure

digital junco
#

https://academy.hackthebox.com/module/109/section/1038

who$@ami
w\ho\am\i

Exercise: Try the above two examples in your payload, and see if they work in bypassing the command filter. If they do not, this may indicate that you may have used a filtered character. Would you be able to bypass that as well, using the techniques we learned in the previous section?

Could anyone figure out how to bypass the \ character in this exercise?

past compass
languid wharf
digital junco
#

bypass tha \

#

that's the question...

placid edge
#

who$@ami

#

would prop work

digital junco
#

Exercise: Try the above two examples in your payload, and see if they work in bypassing the command filter. If they do not, this may indicate that you may have used a filtered character. Would you be able to bypass that as well, using the techniques we learned in the previous section?

placid edge
#

w'h'o'am'i

digital junco
#

the point is how to bypass the \...

placid edge
#

idk. Try the ones in the module.

w"h"o"am"i
w'h'o'am'i
%0aw'h'o'am'i
who$@ami
w\ho\am\i
who^ami
digital junco
placid edge
#

well, what do i know. Ive only gotten the flag

#
PING 127.0.0.1 (127.0.0.1) 56(84) bytes of data.
64 bytes from 127.0.0.1: icmp_seq=1 ttl=64 time=0.014 ms

--- 127.0.0.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.014/0.014/0.014/0.000 ms
www-data
#

weird huh

digital junco
sinful olive
#

IN **AD Enumeration & Attacks - Skills Assessment Part II

  • Submit the contents of the flag.txt file on the Administrator Desktop on the SQL01 host**
    I want to upload a file to SQL01, I can enter to mssql as netdb, but can't upload files, so I don't know how to escalate privileges... (also found ||SeImpersonatePrivilege|| but I need to upload files for this too)
digital junco
#

for example with:

echo $(tr '!-}' '"-~'<<<[)

\
or

echo ${PATH:0:1}

/
placid edge
#

yeah ok. use the path

#

But i dont see the problem? You have a RCE that works. And you know how to bypass the / character using the PATH

digital junco
#

that's the problem, the is no ENV for the \ character

#

and the only payload tha may work is

echo $(tr '!-}' '"-~'<<<[)
#

but don't

next bronze
placid edge
placid edge
#

what you could try is wordlist attack on ENV and see if you can find anything lol

#

idk lol

wind gust
#

Attacking Thick Client Applications module is very bad...

short hare
#

Stuck on Attacking Common Applications: Attacking Common Applications - Skills Assessment II
Question:
Obtain reverse shell access on the target and submit the contents of the flag.txt file.

I have found the password for the nagXXX application. Trying to get reverse shell using msfconsle, set every parameters correctly but still keeps failing like this

Can anyone give a little nudge to solve this last question..!!!

short hare
placid edge
#

I think you are using the wrong exploit

#

take it with a grain of salt tho since its been a while since this module

short hare
placid edge
#

dm me the password you are trying

languid wharf
#

Try looking at the version and find a matching exploit

placid edge
#

i want to make sure its correct

short hare
short hare
fathom pendant
#

no

#

<@&861185840277487616>

solid python
#

damn, too quick

novel matrix
#

sorted

#

heehe

solid python
#

pwning you bastard

#

❤️

novel matrix
#

🤍

topaz holly
#

Lol you can ping that?

#

Hilarious. Imagine being the person who said something like that and it just guys replied to and called out lmao

fathom pendant
topaz holly
#

I'll prob get banned if I try it out so I won't even lol

fathom pendant
#

i mean i ping it to notify those with the roles that someone is being a grade A dumbass with blatant rules violations

topaz holly
#

That happens a lot here

#

People trying to learn how to hack but can't read a small list of rules lmao

fathom pendant
#

sometimes it can be benefit of the doubt and redirected: but it's not always the case

#

90% people just want to hack their ex; 10% people actually wanna learn

topaz holly
#

Stg. It's very cringe to see. In high school I've been asked many times to either hack something or teach somebody to hack. Some mf offered me $1000 before to teach him how to build a botnet 😂 mf hit me up on Facebook and I don't even ever talk to him. This was after Hugh school was done with too. So random.

#

I bet he's in jail now lmao

#

Anyways I'll move over to general I just woke up and modules happened to be opened

#

(and shit I've realized people still ask after school)

quick flax
#

A bit confused in the intro active directory module.. if anyone can help me that would be great.

novel finch
#

I might be the worst hacker in the world

#

Just bashing my head into the table, watching people solve things that I seem incapable of doing

storm stratus
#

Hi all, can someone help me with the below question?

There is a file named log4shell.pcap in the /home/htb-student/pcaps directory, which contains network traffic related to log4shell exploitation attempts, where the payload is embedded within the user agent. Enter the keyword that should be specified right before the content keyword of the rule with sid 10000098 within the local.rules file so that an alert is triggered as your answer. Answer format: [keyword];

This is Snort Rule development in the SOC Analyst path.

quick flax
# quick flax A bit confused in the intro active directory module.. if anyone can help me that...

why does it say "The Disabled Forced Restarts GPO will have precedence over the Logon Banner GPO since it would be processed last"
isn't the "disabled forced restarts GPO" under the "local security policy"?

Google says that "GPOs are processed in what's known as an LSDOU order: local, site, domain, organization unit (OU). That means first, the policy on the local computer gets processed. This is followed by Active Directory policies from the site level to the domain"

so wouldn't the "disabled forced restarts GPO" be overwritten by logon banner and thus the logon banner have precedence over the disabled forced restarts?

static ledge
#

Hello everyone, I'm currently working on the CBBH certification and I just finished the section "Abusing Intermediary Applications" of the "Server-side attacks" module. On the practical side, I had no issues but when it comes to the usage of what I learned, I'm a bit confused. I don't see what's the practical usage of this. For other vulnerabilities, there were explanations and exercises on how to abuse the weakness. On this one, I just set up nginx and connect to a tomcat sever but what's the following, how do we levarage that ? Note that I'm a beginner in web penetration testing (I've only followed htb academy courses) and have close to zero knowledge of back-end server management. I would be very thankful if someone could explain to me what's the utility of accessing the target's tomcat panel.

dreamy moss
#

I am very new to the platform and wanted to ask if I'll get unlimited instance spawns per day even if I purchase the minimum number of cubes? If yes, for how long will I get these unlimited spawns per day?
Thanks.

cobalt trench
#

Windows File Transfer, am I using the Parrot OS web browser VM to perform the PS commands?

tranquil axle
tranquil axle
#

and getting access to tomcat is juicy because if you manage to get credentials for tomcat (and they might be set to the default credentials because the administrator of the server thinks that tomcat is not exposed to the internet) you can get a shell very quickly

heavy lily
#

Thank you 😉

cedar yew
#

hi guys i need help

Module: File Transfer
Section : Linux File transfer methods
Task: 2 ( + 3 Upload the attached file named upload_nix.zip to the target using the method of your choice. Once uploaded, SSH to the box, extract the file, and run "hasher <extracted file>" from the command line. Submit the generated hash as your answer. )

#

does not accept my answer

#

my command on server : hasher upload_nix.zip

tranquil axle
#

you need to unzip the file first

novel finch
#

So I'm on the GetSimple part of "getting started" module and I got access to box fairly easy, but I'm having trouble with escalation. The LinEnum.sh file says that /usr/bin/php can be used without root so that means I need to make a PHP shell, right? But that's where I'm getting stuck.

I've tried this and I'm getting nowhere:

export CMD="/bin/sh" php -r 'system(getenv("CMD"));'

tranquil axle
#

you are just allowed to run it as sudo without providing a pw

novel finch
#

The whole command?

#

OR two parts seperately? I know that's a stupid question but I don't know the answer

cedar yew
novel finch
tranquil axle
languid wharf
#

Hi, can someone help me with double-pivoting with ligolo? I tried some guides but none worked for me

languid wharf
#

Yes

#

I've been using it consistently and want to keep using it for double pivot as well

novel finch
tranquil axle
# languid wharf I've been using it consistently and want to keep using it for double pivot as we...

I'm not sure if I ever used it for double pivot, but my notes say listener_add --addr 0.0.0.0:11601 --to 127.0.0.1:11601 --tcp on your attack host (in ligolo proxy), then ./agent.exe -connect 172.16.8.120:11601 -ignore-cert on the machine that can connect to the second internal network to connect it to the machine in the first internal network (172.16.8.120 here) and then add the new network on your attack host sudo ip route add 172.16.9.0/24 dev ligolo

tranquil axle
#

php -r 'system("/bin/sh");'

novel finch
#

OMG it worked thank you 😭

languid wharf
# tranquil axle I'm not sure if I ever used it for double pivot, but my notes say `listener_add ...

LOL that's the same task I'm on and I need the double pivot for
So I've done that, and I get a connection back to ligolo, but then this happens:

Agent : root@dmz01] » INFO[4166] Agent joined.                                 name="INLANEFREIGHT\\Administrator@DC01" remote="127.0.0.1:37764"
[Agent : root@dmz01] » 
[Agent : root@dmz01] » session
? Specify a session : 4 - #4 - INLANEFREIGHT\Administrator@DC01 - 127.0.0.1:37764
[Agent : INLANEFREIGHT\Administrator@DC01] » start
error: a tunnel is already using this interface name. Please use a different name using the --tun option
tranquil axle
#

I'm not sure if you even need to do the "session" and "start" part for the second pivot?

languid wharf
#

It doesn't make sense that we wouldn't need them, as a session established doesn't start active tunneling to another network

#

In @hallow kiln blog it get's the following error message: Tunnel already running, switch from <first agent> to <second agent>? Y/N, but for me it just fails for some reason

exotic pilot
#

How did you get on? I am having similar problems.

tranquil axle
#

I guess you have to set up another tun interface and do "start --tun newinterface" ?

languid wharf
#

yap, I tried it before and it failed for a stupid reason, but now it works. Thanks!

hallow kiln
languid wharf
#

Yeah, thank! I really appreciate all the help

tranquil axle
#

well he can't fuzz for the password because LDAP would be dumb to let you search for a users pw. They had to guess (or maybe there was a hint in the machine) that a administrator set up the account like that and put the password as description string to remember it easier, thinking that noone has access to the description

next bronze
#

isn't analysis still an active box, why is there a writeup and why are you sharing it

fathom pendant
#

<@&861185840277487616>

tight mesa
#

Hello there, I'm doing the step-by-step of User Account Control section under WinPrivEsc, but when I fired up the command to receive a reverse shell based on the dll {under user path} the reverse shell is not received, any idea why or what can I be missing?

languid wharf
fathom pendant
#

It's not

#

Once you have the second session you can stop and start the second one

#

Source: I did it

languid wharf
fathom pendant
#

Select session 1: stop
Select session 2: start

wintry ravine
fathom pendant
#

The older versions would do that swap seemlessly

languid wharf
#

then I got session2 lost connection.., because it's dependent on the tunnel of session1

languid wharf
wintry ravine
# fathom pendant <@&861185840277487616>

It is active but expired. Will not gain anything if pawned.
Was sure this would trigger miscomprehension, this is why I added context info and carefully shadow informations, apprently, not everyone is responsible of reading what tthey read, i let moderator do their moderation, and apologize for the situation

fathom pendant
wintry ravine
fathom pendant
#

This channel is specifically for academy modules

fathom pendant
wintry ravine
#

it says i have no access

fathom pendant
#

Man if only there was a way to gain access

#

Some sort of instructions or something

wintry ravine
#

wonderful "community"

fathom pendant
#

This wasn't to be cheeky

next bronze
fathom pendant
#

Seasonal boxes are still in active rotation

fathom pendant
#

👍

#

But anyway; instructions on accessing more of the server is found in #welcome

wintry ravine
#

well, i thought it was a place to learn and share apparently its a placewhere to lose time wondering if i ask a question when everyone is willing to hear that, lsorry, my eperience is bad, i quit thanks bye

next bronze
#

lol

fathom pendant
#

Bruh

#

Imagine being told "hey this is where you get info"

hallow remnant
#

Module: HTTPS/TLS ATTACKS
Section: Bleichenbacher & DROWN
Question: Performing this section's questions is proving painful. Working with TLS-Breaker had all kinds of errors being thrown which prevented the premaster secret from being dropped. I tried working with alternative tools to nab it, but the output doesn't appear compatible with the expected formatting. Is someone available to DM for aid?

wind gust
#

im getting unable to write to file. Any ideas why?

fathom pendant
#

Have you tried asking nicely?

languid wharf
#

What module? Maybe you're not supposed to write to this file

fathom pendant
#

Or there is a file in that portion that can be written to

wind gust
#

im doing the entripse attack

wind gust
wind gust
cobalt osprey
#

i am doing the btute force module on the ssh page, i am pasting the exact command i have to send but it is giving me this error

fathom pendant
languid wharf
fathom pendant
#

Most people treat AEN as a mock cpts exam

languid wharf
#

Yo marice, I just finished the CPTS path, how do you recommend to prepare for the exam?

fathom pendant
#

Just jump into it

#

the more you try and prepare, the more likely you are to overthink ¯_(ツ)_/¯

wind gust
languid wharf
quick flax
#

guys am I tripping? or is this paragraph self contradictory ?

"The GPO with the lowest Link Order is processed last"
"the Disallow LM Hash GPO will be processed first"

fathom pendant
#

It's like firewall rules

#

It goes in-order

quick flax
#

oh

quick flax
fathom pendant
#

Ye, its silly like that

quick flax
#

even in their own questionnaire they contradict themselves

fathom pendant
#

Domain overwrites site.

#

No matter what's done locally, if domain says "you can't do that" then you can't do that

quick flax
#

that's my understanding as well.. but read this, it contradicts that

jagged ferry
#

How do i use a reverse connection without open port in router?

quick flax
fathom pendant
#

OU = organizational unit

#

Generally that's a group

jagged ferry
#

What should i do to use a reverse connection without open a port in router?

fathom pendant
#

Repeating your question doesn't add clarity

#

If you're trying to get a reverse connection on a public site you will need to do port forwarding. But it sounds like you're trying to do something illegal, more context is needed

jagged ferry
#

Trying to exploit my own Phone with a payloader created on Msfconsole

#

But the connection does not stablish because of The port i am not find opened

#

I tried tô config in The router configs, no success

#

My network is lan i think

fathom pendant
#

Well if they're on the same network you don't need to do any router configs

jagged ferry
#

But even with The Lan ip i am not being able

fathom pendant
#

This has nothing to do with htb academy however

jagged ferry
#

I fill my ip but i need a port and i dont know which one

fathom pendant
jagged ferry
#

Ok

#

Thanks

fathom pendant
#

Then use that port

jagged ferry
#

Alright will try it

tight mesa
#

WinPrivEsc | UAC section, the reverse shell by SystemPropertiesAdvanced.exe is not working..!!!, I'm doing what is explained in the content, any hint would be appreciated...

cursive vine
#

AD Enumeration & Attacks - Skills Assessment Part I, Question 6, "Submit this user's cleartext password. ", any tips how to get it ? I've spent many hours already in just one question...

#

?

deep bay
#

For example, apply Harding configuration to a windows machine before domain join <- this should be consider as "local security policy".

reef birch
#

A little bit late in the party but if you still have problem with this send me a DM.

hallow remnant
# tight mesa can I copy ur style?

Whatever you'd like to do, friend.

I list all of that other information to help others help me. If they know the section/module upfront, its easier to contextualize the problem

static ledge
#

Module : Server Side Attacks, Section: SSRF Exploitation Exemple. Hi, I have a problem of understanding with this section. Indeed, after we find the the first SSRF, we fuzz the ports of the localhost and find this "http://<TARGET IP>/load?q=http://127.0.0.1:5000" and it says it's an app but then when we want to look at the "index.php" of this app and we go look at "http://<TARGET IP>/load?q=http://internal.app.local/load?q=index.html" why ? I tested to curl "http://<TARGET IP>/load?q=http://127.0.0.1:5000/load?q=index.html" instead but it didn't work. In my understanding, we fuzz the ports to discover the internal app but my first question is : How do we know that 127.0.0.1:5000 maps to internal.app.local (except the fact that it is an exercise and there is only one port and only one internal app)? In this exercice, it looks like we don't really care that there is an application listening on 127.0.0.1:5000 as we know (from the page source of the very first ip) that an "internal.app.local" exists, furthermore I don't even understand why we care fuzzing the ports. As you can see I'm a bit lost and would appreciate a little help. Thank you in advance.

cobalt trench
#

Linux file transfer, curl and wget are both not working. Says unable to connect. The question says to use python but I dont see any download tools with python. Anybody available to assist?

fathom pendant
fathom pendant
#

Second part of my question: public-ip:port?

cobalt trench
#

not sure what you mean by that

fathom pendant
#

How is the target given to you

#

Is it 10.129.x.x or something like 94.124.24.223:12345

cobalt trench
#

10.129.202.54

fathom pendant
#

Ah OK then. Are you connected to the vpn?

cobalt trench
#

yea

fathom pendant
#

Last question: what's your command?

cobalt trench
#

wget https://<target-ip>/flag.txt -O flag.txt

fathom pendant
#

Https

#

That's your problem

#

smileW change it to http 👍

cobalt trench
#

The amount of times I slap my forehead going through this course

fathom pendant
#

Most of the times the targets aren't running https

cobalt trench
#

I should have known to atleast try http

shell nexus
#

i've been stuck at the sme part for a bit now, linux introduction, system information, i am tasked with giving the directory in which the htb-student mail is found, yet after search through what feels like every directory i have found absolutly nothing

#

does anyone have a push in the right direction?

cobalt trench
#

have you tried locate or find commands?

fathom pendant
shell nexus
#

i have yea

fathom pendant
#

However
env
Or
echo $MAIL

shell nexus
#

i am so dumb.

i tried that and forgot to add the $sadglas

fathom pendant
#

In bash all variables are called with $

gusty kiln
#

are there no channels discussing machines??

fathom pendant
#

#boxes but you need to have reading comprehension to access it, #welcome <--

west spindle
#

@reef birch thank you mate I did it 🙂

hallow remnant
#

Bumping for visibility:

Module: HTTPS/TLS ATTACKS
Section: Bleichenbacher & DROWN

Question: Performing this section's questions is proving painful. Working with TLS-Breaker had all kinds of errors being thrown which prevented the premaster secret from being dropped. I tried working with alternative tools to nab it, but the output doesn't appear compatible with the expected formatting. Is someone available to DM for aid?

gusty kiln
#

thanks! @fathom pendant

woven copper
tight mesa
#

Module: WinProvEsc
Section: User Account Control
Question: I'm doing what it's explained in the section to escalate privileges thru SystemPropertiesAdvanced.exe attack and it's not working {DLL with reverse shell Payload is placed into the user Path}

pearl pendant
#

I'm working my way through "SIEM & SOC Fundamentals" and just read the "What Is A SIEM Use Case?" section under "SIEM Use Case Development".

I'm having a hard time grasping what this section is trying to tell me. I took a stab at trying to summarize it for my notes:

It feels like what they are trying to communicate is you design a use case for the data/logs/events you record in a SIEM
- Example: We collect logs for login attempts, we can configure events for failed login attempts, the use case for these events is we can detect malicious actors attempting to brute force an account

Does that seem about right?

Link to the specific page: https://academy.hackthebox.com/module/211/section/2253

hallow remnant
tranquil axle
# static ledge Module : Server Side Attacks, Section: SSRF Exploitation Exemple. Hi, I have a p...

I think its just two exercises in one. On one hand it shows you that you can scan for internal services by port fuzzing, on the other hand it shows you that you can also fuzz for internal vhosts by putting the full url. I guess the exercise wants you to know that you have those options and should be open to them when you find a ssrf. The port 5000 and internal.app.local have nothing to do with each other

#

Technically you can’t even be sure that internal.app.local is even on the same host. It could be on a completely different host that is accessible from the host you are attacking

astral inlet
#

finally 🙂

tranquil axle
#

Nice, good job! That was a annoying one

astral inlet
#

hehe yes

#

hard lab was quite hard tbh 🙂

#

but i learned a lot

#

and those labs are quite realistic to real world pentesting

fathom pendant
#

Honestly my favorite lab as it ties a bunch of knowledge together

mint lodge
#

someone help i found a valid password to login to ssh and i know for a fact im suppose to use a password and im getting this when trying to login:
ssh harry.potter@94.237.54.48 -p 22
harry.potter@94.237.54.48: Permission denied (publickey).
from what i understand that mean the server only accept public key auth but the exercise says im suppose to find a password

#

help🥲

next bronze
#

the port should be given as a part of target ip

mint lodge
#

OMG

#

thank youuuuu

fathom pendant
#

Biggest skill issue right there, Identifying public ips

mint lodge
#

😅

fathom pendant
#

It's honestly troubling how deep some people get into the respective paths and don't know

astral inlet
#

the deeper the path go the more they let you fly , but yes

#

i so sucked @ easy lab because i was way overthinking 😄

fathom pendant
#

That's generally how the easy labs are

#

You're thrown at a combination of taught subjects and don't know where to start

#

Then by the time you're in the headspace for hard it's gg ez

astral inlet
#

yes

#

never forget the basics

fathom pendant
#

The only one that tripped me up was footprinting hard, but that's bc I can't read 4HEad

languid wharf
#

Hey, I'm working on a report for the Attacking Enterprise Networks module (I've already finished the labs) and I am a bit lost If anyone has an example report he wrote with sysreptor for this module/other module/other network and can send it to me (free to dms) to use as a reference guide I would be very grateful

astral inlet
#

sorry can´t help on that ... and i need to sleep 🙂

#

cu

severe eagle
#

hey has anyone done intro to assemble language

#

I am bit stuck on assessment 1 I have completed everything else

#

any help please pm me I am struggling been on this for couple days now

ruby whale
#

Can't we buy another monthly subscription before month ends?

fathom pendant
#

It's generally on an autorenew

ruby whale
#

Hey Marcie, I want to cancel PayPal as payment method and add credit card as payment method. I am able to cances it from PayPal any insight?

fathom pendant
#

Message support

#

I'm not staff so I wouldn't know how their payment processing works

ruby whale
#

Doing that right now as we chat

ruby whale
#

I have searched server, it's persistent issues with many, HTB resets the payment method from backend.

short hare
#

And wooo...!!!

marble raft
#

Just finished the Attacking Thick Client Applications and Exploiting Web Vulnerabilities in Thick Client Applications.

It's not as bad people are making it out to be, the content is really good in the sense that you might stumble across a jar application and then the teachings of that section become invaluable. Could it be re-written for a clearer explanation? Sure, but one can make a case that all the content in Academy could be re-written for clearer explanations, and banging your head against the wall sometimes is good.

Being that, in the Attacking Thick Client Applications all you have to do is follow the examples. For some reason powershell only runs if you run it as an admin. Other than that it all boils down to following the example. Exactly as is shown.

In the Exploiting Web Vulnerabilities in Thick Client Applications the IP address of server.fatty.htb is already on the hosts file. You don't need to add it. You just need to check the file for the IP, then you'll know which interface you should use to listen with Wireshark.

The main takeaway in this module is that, you have the original Jar file, and then you mod this jar file so that it connects to the server. Further modifications need to be compiled. When you save the source code as shown on the module, you're saving the code that it's not compiled. Remember that .java files are not compiled, the compiled ones are .class.

All the module asks of you is to have two folders, one for the source code you'll need to modify , and the other one for the compiled files that will be built resulting in the .jar file. All you need to do is modify and compile the files you need, and swap them on their respective folder on the folder you'll be using to generate the .jar file. Everytime you swap files you'll need to generate a new jar file. And that's it. Really

fathom pendant
#

It would be better if there was some other thing or if the pre-requisite Fundamentals covered some basics

#

But it was literally a late addition to the module

#

The other complaint being that it revolves around a retired insane machine

#

Where most stuff in the path is easy-medium modules comparatively

rustic sage
#

alright guys we finally did it! we finally after 7 days of agony, we have finally made it to the AD enumeration and attacks assessment!

marble raft
#

I mean, the module pretty much chews all the content and it gives all the code you need and specifically tells you where and how to put it.

I really don't mind the challenge, what I do mind is answering questions where i have the right answer but have to try 10 different variations because no format was given, this is something that needs to be addressed ASAP.

fathom pendant
#

It took a boatload of complaints for it to be what it is now

short hare
fathom pendant
#

Like a lot of the original complaints is that it

  1. Came out of nowhere
  2. Was nowhere near the same quality
#

But the people who were originally complaining about it are valid to complain, especially considering that portion isn't on the exam (yet) as there hasn't been word about the exam changing yet

heavy marsh
#

So I finally figured out chisel on the Active Directory Skills Assessment 1 and was able to nmap the MS01 computer, however, port 3389 is closed and psexec is not working.

#

Is there a way to proxychains port 80, as in get access to the web interface if there is one open on port 80?

#

I see most people in the forum that got stuck were finally able to get to MS01 with xfreerdp, but that port is closed.

#

What other options do I have with ports 80, 139, 135, and 445?

#

I've done crackmapexec but that doesn't do a whole lot.

#

What can I do with this, anything?

#

I did crackmapexec with the --shares option

#

I have creds and now my chisel and proxychain configuration is working, what other options do I have to get this?

#

Tried evil-winrm, that didn't work either

#

I have no idea.

dire abyss
#

for hydra, "-t" whats a common task number to add to improve speed or performance?

fathom pendant
#

48 is common

#

It mostly depends on your network bandwidth

dire abyss
#

gotcha, ima try that

fathom pendant
#

Some people can do 64 with no problems, I tend to get dropped connections with it

heavy marsh
#

I can tell my proxychain is talking though.

heavy marsh
#

I got smbclient to work, but there's really nothing useful in the files that I can find

#

Tried port 80, but the website just hangs

#

Should any of this be working? What am I missing?

tranquil axle
# heavy marsh Tried port 80, but the website just hangs

if you route the whole http traffic through the victim host and the victim host has a website that tries to load external data (like a js file or a font from google), but the host itself has no internet then you will try to load these external ressources through the no-internet host and it will load a long time and not work properly

heavy marsh
#

I got rpcclient rockin, but no good information

#

There is just no way for me to get a shell it feels like.

tranquil axle
#

try curling the website so you at least know whats on there

#

it shouldn't hang with curl

sour flicker
quick crane
mossy nest
#

Hey guys, I'm currently working on FUFF skill assesment, and I'm pretty sure I got a good response which doesn't fit in HTB input

#

Can anyone tell me where I'm wrong ?

#

/module/54/section/511

mossy nest
subtle pine
#

I'm stuck on Academy Footprinting lab Hard

#

I've done Nmap with ports open, but don't know how to enumerate further

indigo crane
#

are you using the correct port? use the port they give you with the target instead.

autumn pilot
#

You need to use the port that comes with the target

mint lodge
#

how can i see only modules that are relevant for the path im taking cbbh?

autumn pilot
#

Enroll in the path and you will able to see them

mint lodge
#

i can see everything not only the modules that are relevant for my path

#

i have the annual sub

#

found it

languid wharf
wind gust
#

why are targets not spawning ?

unreal granite
#

Hi everyone i am sitting with the DCSync section in Active Directory Enumeration & Attacks and have a question in the module it says For the portion of this section that requires interaction from a Linux host (secretsdump.py) you can open a PowerShell console on MS01 and SSH to 172.16.5.225 with the credentials htb-student:HTB_@cademy_stdnt!. but when iam ping the ip adress 172.16.5.225 i get a request timeout and when i try to log on to the machine via ssh it says that the password is wrong ... what should i do ?

tranquil axle
#

are you trying to ssh from your attack machine or MS01? only MS01 can access 172.16.5.225

wind gust
#

ligolo showing connection failed any thoughts how to troubleshoot that?

thorny ridge
#

I want technical support

novel matrix
thorny ridge
novel matrix
novel matrix
severe eagle
#

Hey just checking if anyone has done the intro into assembly language assessment 1

#

I have modified and changed and recreated the code multiple times but I am unsure what to put in for answer

#

Please someone on here must be able to guide me in right direction I have done the second assessment

tranquil axle
#

If you decrypt and run the code it will print a flag in the HTB{} format

severe eagle
#

ok thank you what am I decrypting though what part?

#

just python decoder isnt part of the gdb and I am running that with modified code I have even resulted to check with ai to see if im missing something and my code I know xor turning it into 8bytes does that decrypt it?

tranquil axle
#

well the task comes with a loaded_shellcode.zip

#

and you have to decode it by xoring everything like it says

#

and the result is shellcode that you can run that prints the flag

severe eagle
#

ok maybe i am way off track so do decode it in the gdb or seperate with the python program

#

damm im so lost with this one it has been like +50 houurs on it any chance I could personally message you my code u could have look for me?

#

sorry to be pain mate just out of options I have even tried the ai

tranquil axle
#

sure, I can try to remember how its done lol

manic onyx
#

I did that recently and just remember you need to loop thru the stack 8 bytes at a time

severe eagle
#

have you would be ok to send you my code so you can see if my codes right then tell me what to actually get for the decoding I really am lost on it thank you for replying people

#

I am lost if it will come up as finish product the HTB{} or 0xnwand39 code that i use python to decrypt

#

pwn

manic onyx
#

Send to me I can check later

tepid pier
#

Hello Hekers!
I am planing to purchase CDSA using Student Subscription.After research I came to know that “SOC Analyst Prerequisites” is a prerequisite to start this course. My question is that will I get free access to “SOC Analyst Prerequisites” skill set module?

fathom pendant
#

Also you don't get the cdsa voucher with student sub

zenith mango
#

Just got the admin flag for AD Enumeration & Attacks - Skills Assessment Part I. It seems to me like there are multiple ways to skin this cat, ||I used crackmapexec and proxychains to more out the flag on the admins desktop|| Been seeing a lot of folks recommend ligolo, so I think I'm going to redo this scenario using it instead of proxychains. Am I off base with the multiple ways to do this one, or am I on the right track?

soft cedar
harsh swan
#

hi guys, I'm getting an error on the module JAVASCRIPT DEOBFUSCATION / Section Decoding, when solving the exercise, I know I cannot say the flags obtained here but following all the instructions I get the error that the flag is wrong when I'm pretty sure it's right, how can I show here without revealing the flag itself just to get some help?...

#

I know the answer is right since the excercise is very very easy to complete, and the response I'm getting is obviously a string that looks like a flag, I need a hand

manic onyx
#

What is the exact question

harsh swan
#

Using what you learned in this section, determine the type of encoding used in the string you got at previous exercise, and decode it. To get the flag, you can send a 'POST' request to 'serial.php', and set the data as "serial=YOUR_DECODED_OUTPUT". @manic onyx

#

I could send the screens here but it would reveal the flag for others so

manic onyx
#

Use cURL

harsh swan
#

yes I used, can I send you a DM?

manic onyx
#

Sure

open hollow
#

Anyone who has completed the intro to deserialization skill assessment II, task 2?

late moth
#

in the "Intro to threat hunting with the elastic stack" this statement is made: If we inspect network connections leveraging Sysmon Event ID 3 (Network connection) around the time this file was downloaded, we'll find that Sysmon has no entries. This is a common configuration to avoid capturing network connections created by browsers, which could lead to an overwhelming volume of logs, particularly those related to our email provider. This is where Zeek logs prove invaluable

#

since zeek is still analyzing the traffic over the network, how would zeek capture less traffic since its still capturing all traffic over the network?

#

just trying to wrap my head around it

fathom pendant
marble raft
#

Sysmon and Zeek serve different purposes and operate in different levels on the TCP/IP stack as so, they do different stuff.

Sysmon is primarily for endpoint monitoring, and zeek is used for network security monitoring.

Sysmon can't capture traffic coming and going from a router for example, it only captures traffic that reaches or departs an endpoint. Zeek can capture traffic across the whole network.

In the section is stated that is not practical to use event ID 3 because the sheer amount of junk you'll be capturing. As so, is more useful to use the zeek logs, and filter only for DNS queries.

round sable
#

Hi, about "ADVANCED XSS AND CSRF EXPLOITATION - XSS Filter Bypasses", I am trying to use ||<object data="data:text/html;base64,etc ||, to as usual ||use xhr to download a page and exfiltrate it||. This code bypasses the xss protection and runs the javascript but with errors.
If running in the console I get : "Uncaught DOMException: A network error occurred.", and in the exfiltrate.htb I get "SyntaxError: The URI is malformed.", even though my javascript is the same as usual and the URI is /home.php here.
Any hint ?

round sable
fathom pendant
#

Gotcha

#

Just wanted to be sure

icy hazel
#

Anyone who's used elastic got any tips for viewing the results of a search, I'm using the Pwnbox but there is a tiny bar which i have to scroll through to see the results, it shows one line at a time and is really fiddly

mint lodge
#

Target: 94.237.55.163:37053
Life Left: 87 minute(s)

  • 1 Run a sub-domain/vhost fuzzing scan on '*.academy.htb' for the IP shown above. What are all the sub-domains you can identify? (Only write the sub-domain name)

ffuf -w /opt/useful/SecLists/Discovery/DNS/subdomains-top1million-5000.txt:FUZZ -u http://FUZZ.94.237.55.163:37053/

can someone help me understand why am i only getting errors?

placid edge
#

I need some help understanding something. I often see the different usage off the domains and domains trust in the AD Lab. Such as FREIGHTLOGISTICS.LOCAL and INLANEFREIGHT.LOCAL. I understand that there is some kind of domain trusts going between these two domains. But what i dont really understand is that is this two different domain controllers? Do they have different ip adresses? Or is it strickly inherited and only used by the main domain controller?

#

Cause when i look at the /etc/hosts file in the linux attacker machine it seems like each subdomain under the domain has their own ip adresses

wheat laurel
#

hello , is there anyone finished introduction to nosql injection skill assessment || ?

molten prawn
#

any mods i can talk to in regards of a target machine in the academy ?

rustic sage
#

Hi I'm on the introduction to Windows and when I try to connect in RDP with the target, that's don't works

#

I use the correct command because I can connect myself to the target but the connection is always fall.

molten prawn
#

okay. how do i get in touch with staff ?

compact patrolBOT
fathom pendant
#

Green bubble on the academy site

molten prawn
#

thanks marcie

cerulean crow
#

Firewall and IDS/IPS Evasion - Easy Lab

I can't even see the IDS status page. Just get a timeout. Have reset the box multiple times. Is there a known issue with the box or am I doing something wrong?

#

NVM, my Kali box was broken somehow

wanton estuary
#

Anyone completed advanced xss and csrf skill assessment? I can redirect myself but I never get promoted

round sable
wanton estuary
vestal oasis
#

Where should I go if I'm new here?

median kestrel
#

What was the issue? I'm stuck on this last one and finished the rest of the course

potent ermine
fathom pendant
wanton estuary
#

Does the admin user open all file types in the advances xss and csrf skill assessment?

median kestrel
round sable
mystic light
#

I'm working on the noSQL injection module skills assessment II and could use a hand crafting the injection.|| I can get the login page to 500 out, but thats as deep as i can get. ||

wanton estuary
#

is the admin user broken for the advanced xss and csrf? I'm using the exfiltrate server to test if the xss ever pops and it does when I visit the uploaded file but I never get any requests from the admin.

round sable
wanton estuary
open hollow
#

Anyone who completed the intro to deserialization attacks?

#

Stuck on Skill Assessment Task 2

broken lichen
#

i need tool brute force netcat server

azure fog
unique palm
#

Hey guys,
for weeks now i am stuck on the ad module Skill Assesment 1... I pwned the WIN-01 Machine and got the tpe*** user on MS01. I also got the Hash for Administrator using DCSync. But i just cant pass the hash to the DC01. Can anyone help ?

round sable
# wanton estuary I could only get it to pop an alert, ended up using a payload from a cheat sheet...

Indeed it seems the ||<object>|| didn't have access to origin, but there is another payload in the link that does. I can now exfiltrate correctly from the user, but not yet from admin, at least not consistently from admin : hard to know if it is a real issue, since there are always weird unpredictible latencies in the "deliver to victim" feature.
EDIT : it worked, just had to wait around 15 minutes for the admin request to reach exfiltrate.htb.... weird...

unique palm
#

im using this command from the MS01 machine to Pivot to the DC01 machine but it only opens a shell on the MS01 machine again @next bronze

||mimikatz # sekurlsa::pth /user:Administrator /domain:INLANEFREIGHT /ntlm:admin-hash /target:172.16.6.3||

next bronze
#

mimikatz will open a shell as the user you pth as but on the same host, so if you want to use mimikatz you'll need to psremote or connect read the flag over smb

unique palm
#

so you mean chisel tunnnel Kali VM -> MS01 and the psexec to DC01?

next bronze
#

pth directly

lapis whale
#

I've just started HTB a few days ago and on a section about basic service exploiting. There's only 1 open service running, openssh v8.4p1. There are no metasploit exploits for it thoguh so I'm fully lost on what to do...

unique palm
languid wharf
#

I guess psexec.py should work from your attacker machine

#

you can also use evil-winrm

unique palm
languid wharf
#

yes

sterile epoch
#

can someone explain this to me?

glad citrus
wanton estuary
lapis whale
#

How long does a usualy full nmap enumaration go with sC and sV enabled?

glad citrus
#

For top ports it’s quick. For all ports it can be 5ish mins

dire abyss
#

whenever i'm bruteforcing an ssh enabled acct, am I always able to use hydra against FTP instead?

thorn urchin
#
  1. ftp has to be enabled
  2. they have to be using the same authentication source
#

when those two factors are true then sure

dire abyss
#

how can I be sure about 2?

thorn urchin
#

You dont

#

its usually true though

dire abyss
#

damn i thought there was a clue in NMAP or something

fathom pendant
#

sometimes ssh uses an RSA key pair

thorn urchin
#

that too in which you couldnt brute ssh anyways

fathom pendant
#

usually hydra or cme will tell you that it can't because password auth isn't enabled

dire abyss
#

alright i think im officially stuck in password attacks module, credential hunting in linux section. I cant find Kiras pw. the hint suggest i use the password.list from resources against it. nothing found.. the hint also gives the users pw but that pw doesnt work to SSH into the machine. made a mutated pw list (love.list) based off that pw in the hint using hashcat, "hashcat love.list -r custom.list --stdout | sort -u > mut_love.list". from here i tried a few things with hydra, "hydra -l Kira -P mut_love.list ssh://<target> -V -t 48" used password.list in there from resouces provided as well, no hits.. am I missing something?

native turtle
#

Hi guys module skills assessment for sqlmap, I found two entry point a**.php and ac***n.php trying to fuzz some parameters because the response show me SQL error, I'm on the right way? because I can't find any parameters to try injection

fathom pendant
dire abyss
fathom pendant
#

and make a judgement off that

#

step 0: enumerate/scan

#

even if you're given a bunch of leading info: sometime the info assumes a few things

dire abyss
#

during my scan i did see port 21 and 22 open

fathom pendant
#

ssh is a generally slow service

#

and in some cases; it can be restricted to only 4 threads at a time

#

while it's not always the case; always observe best practices when attacking practice environments

astral inlet
#

and probably some services uses the same creds

sleek moss
#

i had to reset my system and lost all my notes :dead: is there anywhere online filled wwith notes for the CPTS

fathom pendant
#

nope

#

there's no online repository of notes for a closed/paid service

#

take this as a lesson to always have a backup

#

heck my stuff is on an external drive

sleek moss
fathom pendant
#

just gonna have to go back through and rewrite some stuff

#

and likely better because you should know most of it by now

unique palm
next bronze
#

chisel has to be running to keep the tunnel up, so the web shell will become unresponsive, as long as the chisel in your attack host is able to connect, you're good

sleek moss
#

the payload is the malicious code after u gained access right while exploit is the thing that gets u access like the shell so then why does this say Exploitation & Security: A payload is code crafted with the intent to exploit a vulnerability on a computer system. The term payload can describe various types of malware, including but not limited to ransomware.

#

Payloads Deliver us Shells

fathom pendant
#

it's not necessarily after you gained access

sleek moss
#

oh i c

fathom pendant
#

in fact it says it right there

#

" Exploitation & Security: A payload is code crafted with the intent to exploit a vulnerability on a computer system."

#

somtimes it's internal but you gotta exploit something externally first usually to gain access internally

open mica
#

I am looking for some guidance on thelab Brute Forcing Weak Access Tokens in the Attacking Authentication Mechanisms module. I have tried several approaches and found multiple valid tokens. However, I keep getting redirected to the "Not Authorized" page, when I try to use any of the found tokens or cookies. I feel like I am missing something (silly), or that something seems to be broken.

#

Has anyone successfully completed this lab?

quasi wave
#

anyone got a hint for finding the admin email address?

wet kite
#

I'm trying to do shells & payloads, but can't RDP in the "Reverseshell" section. anybody else has similar problems?

#

problem persists since yesterday

quasi wave
#

this is for IMAP and POP3 sections of footprinting module?

#

can someone hint me like what to google to figure it out? Please don't give me answer tho I wanna be able to figure it out and learn

fathom pendant
quasi wave
#

ok thanks

fathom pendant
#

If you read the email you can generally get all the info from it

quasi wave
#

ok thanks

wet kite
#

ok, pawnbox actually worked, but kali with remmnia / xfreerdp didn't work and also a windows workstation with rdp didn't work at all... very confusing...

fathom pendant
#

Well in your own vm you need to be connected to the vpn

wet kite
#

really, i didn"t know that..

fathom pendant
#

...how are you expected to connect to an internal resource if you aren't physically plugged in.

#

The vpn facilitates a connection to htb resources

wet kite
#

i was joking 😄 of course i was connected to the VPN not my first module

fathom pendant
#

Listen there's too many people that are dumb for me to not think thats the case

wet kite
#

not gonna lie sometimes i forget to connect / switch vpn to the right one, but as soon as i get my first "can't reach host" i normally remember 😄

rustic sage
#

I feel like although I learned about Rubeus, I still don't know what it's doing.

sleek moss
#

does anyone htb-student@ubuntu:~$ rm -f /tmp/f; mkfifo /tmp/f; cat /tmp/f | /bin/bash -i 2>&1 | nc -l 10.129.41.200 1234 > /tmp/f
nc: Cannot assign requested address
why wont this work

rustic sage
#

the address youre listening on isn't correct

sleek moss
#

oh right hat coreect danke

azure fog
rustic sage
#

though I have to admit, the assessment for the AD enums and attacks module is super cool I feel like all of the things i learned up to that point are being applied, from pivoting to everything else. Only downside is one thing didn't work correctly and was supposed to on the first assessment still trying to figure out what went wrong.

#

pretty exciting stuff.

cobalt trench
#

PHP web shells - Use what you learned from the module to gain a web shell. What is the file name of the gif in the /images/vendor directory on the target? (Format: xxxx.gif)

I am following what was taught in the module but I am having whenever I upload the webshell.php file it fails

astral inlet
#

use burp

cobalt trench
#

I used burp to modify the content type but it still wont upload

astral inlet
#

then something was wrong

molten owl
#

Mhh

cobalt trench
#

There was an extra step that needed to be taken that was not mentioned in the module

placid edge
#

Can i get some help for Exploiting Web Vulnerabilities in Thick-Client Applications.

I cant seem to compile it again.

#

breaks everything

#

hard to share without giving out info so

placid edge
#

when i recompile for the download of the jar file it breaks the application. I tried to follow the cource but i cant seem to get it. Been stuck now for a while

molten owl
placid edge
#

javac

molten owl
#

I see

#

What is the error prompt?

placid edge
#

i dont get an error. It just wont download the file at all

#

The thing is that it looks weird when editing the file as well. since all the lines starts with

/*  223   */

Or something

#

but not the code thats been edited

#

which makes me think thats what breaks it, but as its a comment that doesnt make sense really

next bronze
#

you might have messed up the formatting while editing it, I would suggest transferring the files out and edit them in vscode or something, also you can follow a walkthrough of fatty

fathom pendant
next bronze
#

oh did they update it? that's good

fathom pendant
#

Apparently it's now more "follow the section" than "here's something that you likely will rarely ever see"

placid edge
#

nice to have a insane challenge on a "attacking common applications" lol

astral inlet
#

which one , this is my next module

placid edge
#

Exploiting Web Vulnerabilities in Thick-Client Applications.

astral inlet
#

pheew

#

Attacking Common Services , is my next 🙂

placid edge
#

this one

#

for user.txt

#
placid edge
astral inlet
#

good night, good fight 🙂

placid edge
#

yeah thats it for me

glad citrus
#

Working the footprinting hard box. I have access to “the user” and am looking through his files. Not sure what I’m trying to find now. See his logs, and see some docs that have unreadable characters

languid wharf
#

Hi, I'm not even in the exam, and I see the error message of Exam entrypoint ips have been moved to a new location at the top of my page on academy. Does it happen for someone else?

rustic sage
#

Hey @placid edge did you have issues with the first assesment of the AD attacks/enums module?

#

I had a bit of trouble with getting the 2nd account js

ebon sapphire
#

Is anybody else having issues with OpenVAS installation on the vulnerability assessment modules? It is not installing at all

onyx dust
#

more time wasted on disconnecting machines and unreliable service

#

i can rdp through packet radio better than this, a premium service.

#

just terminated both instances

#

i really dont have any time for this lame shit.

glad citrus
#

Nope, took a break

cobalt trench
cobalt trench
onyx dust
#

the discord users carry everyone for that course since the forums are long dead.

#

johnCkirk the legend

#

💐

short hare
#

Stuck on WINDOWS PRIVILEGE ESCALATION: Communication with Processes
Question: Which account has WRITE_DAC privileges over the \pipe\SQLLocal\SQLEXPRESS01 named pipe?

I got the thing as in pic but why the answer is not been accept as ||NT SERVICE||

onyx dust
#

did you put the \ in your answer?

#

the answer is in your screen shot

#

copy and paste it starting from NT and ending at the number

short hare
pulsar portal
#

Hi currently working on User Enumeration via Response Timing from white-box attacks, is there a way to get a shorter wordlist, the one suggested by the module is to big and I'm currently getting a lot of usernames enumerated, thanks for any help

cobalt trench
#

Shells & payloads Live Engagement - I made a payload with msfvenom, I uploaded a webshell and navigated to the directory, I checked for exploits and attempted metasploit. None have worked so far. Any tips or hints on this?

#

Are you kidding me lol

cursive cradle
heavy marsh
#

Can anyone give me a nudge on the AD Skills Assessment? I'm in an RDP session on MS01 trying to find the cleartext password for the user in question. Using mimikatz with "sekurlsa::logonpasswords" shows the user and the NTLM hash, but I am unable to crack it. The other mimikatz commands do not show that user.

#

There doesn't seem to be a rhyme or reason as to what users show up for what commands.

#

kerberos::list /export did not give the username

#

Also, running "Get-DomainUser * -spn | select samaccountname" does not show this username.

#

The only way I found the username was on C:\Users, and it seemed to be a pretty obvious account

#

username is tp***y so that those that have done this know if I'm on the right track

#

How do I go about getting a plaintext password?!

#

The output for the tp***y user looks like this, this is just a different user as an example so that there are no spoilers

onyx dust
#

did u u try checking comments?

heavy marsh
#

I cracked the NTLM for svc_sql just to make sure it wasn't the hashcat mode. svc_sql worked.

onyx dust
#

i know the password it wont be in a list

heavy marsh
onyx dust
#

i was thinking it might be in a comment or something

#

since the question asks for plaintext

thorn urchin
#

the module mentions a bunch of different enumeration methods for credentials, what have you tried besides just mimikatz

onyx dust
#

i dont remember how i answered it. it was a while ago

#

i was thinking maybe try the ldap filter

heavy marsh
#

Get-DomainUser -Identity t****y | Get-DomainSPNTicket -Format Hashcat

#

That didn't work

thorn urchin
#

before messing with other networked stuff that you would have already had access to, what other post compromise enumeration can you do on the box

rustic sage
heavy marsh
#

Rubeus did not work either

thorn urchin
#

what else

heavy marsh
#

I'm guessing the NTLM hash should crack with hashcat?

rustic sage
#

it's not like that; there is no way to get the answer as of right now without some serious help from the forums.

thorn urchin
#

Incorrect

heavy marsh
#

hmmmm

rustic sage
#

the tools and stuff don't give the cleartext.

thorn urchin
#

yes they do

#

you literally just listed one

rustic sage
#

that's not the right tool for the approach; even if you used it, it would point to the wrong account.

thorn urchin
#

doesnt to my memory

#

sure you interpreted it right?

onyx dust
#

what is the dpapi section of the module

rustic sage
#

if I show the pic with the error it will spoil the intended approach

thorn urchin
#

to me it was the intended approach

#

I didnt use the forums

rustic sage
#

you think so? interesting.

thorn urchin
#

it was a taught method that works

rustic sage
#

I wouldn't have thought of using Lazagne as it wasn't mentioned anywhere in the module

onyx dust
#

the active directory and the attacking common applications modules are the most brutal

thorn urchin
#

lazagne was covered in password attacks

#

the course modules presume you have done the prior ones

rustic sage
#

I'll admit the assessment really has been a fun experience putting everything you learned in the other modules to use ^^

onyx dust
heavy marsh
thorn urchin
#

why are you skipping modules

#

dont do that

#

making shit harder for yourself for no reason

rustic sage
#

yeah i tried everything from stealing the SAM database and trying to crack the hash too @heavy marsh

#

good mindset but wont give you the answer

thorn urchin
#

iirc secretsdump can work too but idr for sure

heavy marsh
#

lol

#

LaZagne didn't work, 0 passwords found

onyx dust
#

u can skip modules if you want to

thorn urchin
#

ah k it sounded like you hadnt done it

heavy marsh
#

no, I knew they are intended to be done in order, so I've stuck with that

thorn urchin
#

thats all

#

proverbial you ftr

heavy marsh
#

I have each module in markdown so that I can find stuff from previous ones easily if I can't see it in my notes

#

so without LaZagne I'm not sure, I'll keep looking at the password attacks options

#

As long as someone can confirm that the NTLM hash is not crackable that makes me feel better

onyx dust
#

try secretsdump

#

run lazagne as admin btw

heavy marsh
#

Isn't secretsdump a python program?

onyx dust
#

yeah but it gets dpapi i think

thorn urchin
#

secretsdump is rad

heavy marsh
#

I'm running powershell from the rdp session

thorn urchin
#

sometimes ill dump admin ntlm hash just so I can run secretsdump instead of mimilatz lul

onyx dust
#

u gotta run powershell as admin and then run lazagne thru it

thorn urchin
#

whole point of secretsdump is you use it remotely

onyx dust
#

mimkatz is good 🙂

#

its detected irl tho, like everywhere

thorn urchin
#

yeah which is why I prefer to lower my reliance on it as much as reasonable to do so

onyx dust
#

still good and easy to make undetected

thorn urchin
#

secretsdump not dropping files to disk(iirc) is rad

onyx dust
thorn urchin
#

yeah I ain't pretending it's perfectly stealthy or anything

heavy marsh
#

lazagne just runs and disappears when I run it from powershell

#

I saw it said shahash found, but no cleartext

thorn urchin
#

sure lazagne copied properly? sounds like an error if it found nothing

heavy marsh
#

It showed output in realtime but then the cmd window closed

thorn urchin
#

what? how did you run it?

#

that sounds like you just double clicked it or something

heavy marsh
#

No, it was strange. I'm going to make it an early night. I'll try again tomorrow.

#

Thank you all for the help!

onyx dust
#

run powershell as admin then run it thru that

#

u gotta right click -> run as admin

heavy marsh
#

I did. I saw some weird output on the defaultpassword section to the effect of "supersecretdomainpassword" or something like that.

#

Yeah I ran powershell as admin

onyx dust
#

¯_(ツ)_/¯

heavy marsh
#

I'll start with a fresh machine tomorrow.

onyx dust
#

that's the right password tho

thorn urchin
#

I cant see a reason why it would close the window

heavy marsh
#

I'm going to look for an output of what lazagne normally looks like so I know when I try it again.

thorn urchin
#

you can redirect the output to a text file if its closing the window

#

¯_(ツ)_/¯

heavy marsh
#

The password that showed was in no way connected to the username so I don't know how that all works

#

It just said defaultpassword

thorn urchin
#

yeah and?

heavy marsh
#

No file came out

thorn urchin
#

then you did it wrong

heavy marsh
#

Like I said, lots of weird things going on, going to try again tomorrow with a fresh machine.

terse igloo
#

where is a ticket dude i need assistance @_@

thorn urchin
#

defaultpassword is a normal field you can see creds stored in sometimes

onyx dust
heavy marsh
#

ptt

terse igloo
heavy marsh
#

pass the ticket

terse igloo
#

and the screen keeps jumping when i try to type

onyx dust
#

the subscription dont come with free private tutors @terse igloo the discord operates as a tax deductible charity

terse igloo
#

and no input comes out

heavy marsh
#

anyway I'm passing the ticket to ransomthehost, have a good night all!

terse igloo
#

i dont need a tutor

#

i need the rdp to work properly

terse igloo
#

anywho, outside of getting an answer i did ask about , i dont need a tutor 😄

onyx dust
#

what's a ticket person?

terse igloo
#

someone who answers the box in academy

#

: P

#

i put in ticket

thorn urchin
#

what?

onyx dust
#

just use that chat on the website

terse igloo
#

@_@

onyx dust
#

this is discord the charity

thorn urchin
#

ohhhhhh you a silver academy peep?

terse igloo
#

yes

#

i pay for both labs and academy

thorn urchin
#

ah Ive never seen someone actually get timely help from that

onyx dust
#

the charity is better

thorn urchin
#

I mean no shit you pay for academy lul

terse igloo
#

xD

thorn urchin
#

youre better off just clearly asking your question and explaining your problem

#

instead of just saying I need help and a box is bouncing

terse igloo
#

well, as i stated above 🙂 i cannot type in the rdp cmd prompt , the terminal jumps and no type

onyx dust
#

sir, have you tried turning it off and on again?

terse igloo
thorn urchin
#

what does terminal jump mean

terse igloo
#

meaning

#

it wil jump to the bottom

thorn urchin
#

and what are you using for rdp

#

screenshot?

terse igloo
#

and i am a mam is what i mean jinn 😄

onyx dust
#

excuse me ma'am

terse igloo
#

danke'

terse igloo
thorn urchin
#

? I dont see a problem

terse igloo
#

its a photo

#

not a vide o

thorn urchin
#

no shit

terse igloo
#

its not in motion

#

the problem accurs in motion

onyx dust
#

xfreerdp /v:<ip> /u:htb-student /p:"HTB_@cademy_stdnt!" /cert:ignore /workarea

#

try using /workarea at the end

terse igloo
#

ok thank you ^^

thorn urchin
#

do you mean like you cant see the start menu cause of the resolution?

terse igloo
#

no, i mean i go to type a letter to start my syntax

#

and the minute i hit a key

#

the screen jumps up and i gotta scroll up to it to see if it typed at all

#

but nope

thorn urchin
#

is it ANY letter that does this?

terse igloo
#

yes

thorn urchin
#

what kind of keyboard are you using

terse igloo
#

just my regular keyboard

#

@_@ why

#

the keys arent the issue trust 😄

onyx dust
#

did you try /workarea at teh end

thorn urchin
#

because I could see a scenario where youre using an atypical keyboard layout and its mismatched with the remote machine and interpreting keypresses as other keys. Thats why I ask.

#

also did you try jinns suggestion yet

onyx dust
#

for me it's mom coming into the basement to deliver me a pizza pocket that scolds my mouth as i eat it and falls into the [SHIFT] key lodging it stuck and enabling sticky keys on windows

#

what a nightmare omg

thorn urchin
#

so youre using an american US keyboard layout?

terse igloo
#

lmao

thorn urchin
#

yes no?

terse igloo
#

😂

#

ya

thorn urchin
#

its a pretty simple question

#

if you dont want to take your problem seriously why should I

#

good luck

terse igloo
#

i already did ^^

thorn urchin
#

idc I shouldnt need to ask three times for a basic answer and get lols in response

#

good luck figuring it out, Ive got other stuff Id rather do now

terse igloo
#

reported 🙂

thorn urchin
#

for not helping you for free lmao 😂

terse igloo
#

U didn't help me jinn did 😉 looks like he was the better man in this

thorn urchin
#

good, im glad his advice worked

#

GL on the rest of the course 👍

cobalt trench
#

shells & payloads live engagement - I tried env command but I cant find the shell

thorn urchin
#

but random reporting because you dont like that someone didnt want to help you anymore means you can go fuck yourself 🙂

terse igloo
#

no soliciting sales 😄 i dont buy

onyx dust
#

yeah why r u reporting

#

furries work at discord

#

dont feed the animals.

sterile epoch
#

Hi I was curious for which account does the get-domainsid generate the sid for? I tried to look for it using the command Get-ADDomain -Identity $DomainSID but it does not work

sterile epoch
#

any idea why this is happening I am in ad enumeration attacking domain trusts section

thorn urchin
#

youre not authenticating properly

terse igloo
#

sorry we got off on the wrong foot 🙂

limber parcel
#

howdy people

rustic sage
#

question, can you use a hash from a dcsync attack to perform a pth attack?

thorn urchin
#

absolutely

#

dcsync gives you the ntlm hashes hot and fresh from the AD database

rustic sage
thorn urchin
#

dcsync is ggnore youve compromised the domain

#

besides even the DA hashes. there's all the machine hashes. and also krbtgt's hash which can forge kerberos tickets.

open mica
#

I am looking for some guidance on thelab Brute Forcing Weak Access Tokens in the Attacking Authentication Mechanisms module. I have tried several approaches and found multiple valid tokens. However, I keep getting redirected to the "Not Authorized" page, when I try to use any of the found tokens or cookies. I feel like I am missing something (silly), or that something seems to be broken.

limber parcel
thorn urchin
limber parcel
#

oh nvm but thats fancy

#

i wanna get that, i am a Noooob

thorn urchin
#

well start doing the course then

limber parcel
#

i just finished the getting started knowledge check and got it solo, ive done two paths and started the information security path

#

im addicted lol this is super fun

thorn urchin
#

nice, good luck

limber parcel
#

ty

thorn urchin
#

if you want to access the rest of the server follow the directions in #welcome

limber parcel
#

oh thank you

#

the identify command doesnt work

severe eagle
#

Massive thank you to twopoint and olliz0r on here I spent days stuck on Intro to assembly code and they helped me understand it bit more cant thank them enough

patent oak
#

Is RDP always so laggy in general? NotLikeThis

patent oak
#

It really ups the stress level kek

thorn urchin
#

youre streaming video and input over a vpn tunnel over the internet to virtualized machines likely from a virtual machine. it gunna lag lol

patent oak
#

Deep joy

short hare
patent oak
rustic sage
#

I tried creating a golden ticket with the Administrator's account...then rdp didnt work properly...lol

#

it wont ptt with the administrator acc im going to assume maybe kbrtgt is more appropriate

placid edge
#

finally i got it

#

that Exploiting Web Vulnerabilities in Thick-Client Applications Was such a pain in my ass. With some sprinkles off lag

rustic sage
#

yep nothing working

#

im tired gonna continue this later

#

I keep getting this error

"ERROR kull_m_rpc_drsr_getDCBind ; RPC Exception 0x00000005 (5)"

#

really annoying i think it's the target machine having an issue or something made sure to use the runas /netonly with the appropriate acc

heavy lily
#

ADVANCED XSS AND CSRF EXPLOITATION - Skills Assessment. i manged to craft a xss payload and running it, but it seems that admin does not look at the payloads automatically. it also mentioned only that admins can access that files, but in the tasks section that admins automatically checks the files. so i guess that the admin does not check the uploaded files automatically. Stuck for now, anyone can guide me to the next step or give me a direction?

dreamy solar
#

Can you help me plz?

#

?

median patrol
heavy lily
upper haven
#

@heavy lily @median patrol The files are not automatically checked. Keep in mind that the module does not only cover XSS attacks but another class of attacks as well 🙂

#

Feel free to DM me in case you get stuck again

astral inlet
#

hi, still performance / spawning issues ?

patent oak
#

Hey guys. Metasploit pro. Do I need it?

#

As a noob

astral inlet
#

no

patent oak
#

Cool thanks

short hare
mortal nexus
#

Linux File Transfer Methods. I try to transfer a file with exec 3<>/dev/tcp/IP/port, when I enter cat >&3 I doesnt show anything. I can get this file with wget, but not with exec method.

wanton timber
#

Question, when you already finished the module and your subscription ended (silver annual for example), do we still have access to that module?

next bronze
#

yes

wanton timber
#

@next bronze thanks, how about those already started but not yet finished ? 🙂

soft spear
#

Does anyone know if enterprise accounts have access to all Academy content or only certain modules for the vouchers they cover?

next bronze
next bronze
onyx dust
#

it's not easy though

#

yaay you did it!

#

another day another terrible experience trying to get this box to spawn and stay online

#

/me sighs

wanton timber
onyx dust
#

it's vexing to have my productivity inhibited by the ineptitude of an organization that is happy to charge 100$ for tier 4 modules that tell you to use google images for grappling hooks but can't be bothered to provide a stable environment.

#

i find great disparity in the corporate osint module vs tradecraft used practically irl

#

why is it 100$

high zinc
placid edge
#

only 3 challenges left 🙂

#

then im 100% done. What a scary feeling lol

ruby whale
#

Keept it up.

placid edge
#

scary cause off the CPTS exam is coming lol

ruby whale
#

Insert : Click it gif*

onyx dust
astral inlet
#

i hope on exam the network is much better then the academy atm