#modules

1 messages · Page 201 of 1

drifting urchin
#

Stuck at the Footprint Hard Lab, got the credentials from snmp, logged into mail server through imap and trying to display the message from inbox, however it gives me no information which I can use. Can you give me any tips?

fathom pendant
fathom pendant
#

Switch all with body[]

#

I linked a blog for useful imap commands and stuff a while back

winter bough
#

hi

drifting urchin
fathom pendant
#

You can also get the email from pop3s

#

Just as an fyi

#

Imap is just nicer to navigate with

astral inlet
#

yes if available go for imap

fathom pendant
#

Especially if you have to look through hundreds of emails

#

Better sorting

sterile epoch
#

any hints how do I crack this hash. I used 2100 mode. Could not crack it with rockyou

astral inlet
#

link ?

sterile epoch
#

to the section?

astral inlet
#

yes please

sterile epoch
astral inlet
#

ah ok i am not yet there sorry

#

maybe try another wordlist

#

can you show the syntax ? dm is ok

#

or mask it

sterile epoch
#

||hashcat -m 2100 admin.hash /usr/share/seclists/Passwords/Leaked-Databases/rockyou.txt||

astral inlet
#

looks right to me

lusty hearth
#

v1

mint lodge
#

oh cool im doing v2 tomorrow

buoyant void
mint lodge
#

im nervous af i dont do well on tests

sterile epoch
#

the hash has $DCC2$10240# I check hashcat examples it was 2100

#

I guess if hashcat cannot do it there has to be another path

buoyant void
astral inlet
#

try this at the end ||--force --potfile-disable||

lusty hearth
astral inlet
#

restart target

mint lodge
dense pewter
mint lodge
#

i already started the modules for it

fathom pendant
#

Try with a regular scan, not syn

dense pewter
fathom pendant
#

Does it give you anything?

dense pewter
#

I can interact with other services on the VM, so it can't be a connection issue

fathom pendant
#

Weird, contact website support imo

dense pewter
#

Yeah, will do. Thanks for trying to help me

astral inlet
#

restart target and wait for 5-6 mins 🙂

fathom pendant
#

The support doesn't really look at the discord

acoustic owl
mint lodge
lusty hearth
mint lodge
tribal wadi
#

anyone studying introduction to Introduction to Digital Forensics ??

sterile epoch
#

I tried to use mimikatz and do a dcsync and it was not possible because klist was empty any help?

astral inlet
#

no klist no ticket

mint lodge
acoustic owl
sterile epoch
mint lodge
lusty hearth
acoustic owl
sterile epoch
#

dude I just switched and there was SRB cant miss a second here I guess

buoyant void
#

Damn that linked looked so tempting to click on too 😂

fathom pendant
#

I wouldn't doubt that vid is NSFW btw, given their name. People do dumb shit "cosplaying" characters

mint lodge
#

well good to know thanks for the input guys

ocean night
#

It was bloody roblox

surreal rain
#

oof

wild sinew
#

Hello Everyone. I am trying to complete the Footprint Lab - Hard but I am stuck. I am currently logged into the machine as tom but thats where I am stuck. I checked the bash history and I ran linPEAs. I feel like I am over thinking it

astral inlet
#

lol i went out for 5 secs and party is on

ocean night
fathom pendant
mint lodge
#

lmao

fathom pendant
lusty hearth
#

too lazy to change it now

fathom pendant
#

Perhaps seeing the services they interacted with is useful

wild sinew
fathom pendant
mint lodge
wild sinew
mint lodge
#

cool

lusty hearth
#

but work close to pen teams

mint lodge
#

i'm trying to find my first job as a junior but id really know how to search for it

lusty hearth
#

you can dm me if you about whatever, dont want to get too off topic for the channel

mint lodge
#

ohhh ok

#

i forgot this is the modules channel sorry guys

wild sinew
fathom pendant
astral inlet
#

if you donßt know it > crack it

fathom pendant
#

You retrieved it from your walk

fathom pendant
astral inlet
#

how can you renember all that 🙂 ?

wild sinew
fathom pendant
#

It should

wild sinew
#

ill try it again

fathom pendant
#

Make sure you copy/paste it

wild sinew
#

got damn it lmao thanks @fathom pendant

fathom pendant
sterile epoch
#

any help on how to crack lsa secrets?

#

or cached domain logon info?

astral inlet
#

did my "extension" not work ?

fathom pendant
astral inlet
#

for the syntax lol

fathom pendant
#

I think @next bronze has an lsa dump tool

astral inlet
#

you can dump lsa via cme nxc too

sterile epoch
#

I have dumped it i just wanna crack it

#

this is what i got from admin at ms01

#

I need admin/inlane to dcsync according to bh

#

I tried to use mimikatz but there is no klist

buoyant void
#

So I finished AD Skills Assessment 1 last night, and I was going over my notes to review my process. I had a couple of questions but I wasn't sure how I could ask them without spoiling anything but to try to keep it as vague as possible and put it in spoiler tags: ||I wasn't able to upload Chisel to the web-shell host as the web-shell kept crashing so I instead tunneled via netsh and RDP which was fine but for the last questions I was definitely a bit lost on how to authenticate to the DC as I had to do it from the RDP Session I was in. After some googling and remembering that mimikatz can do PTH I used mimikatz and psexec.exe. And I was wondering was there another way to PTH in this scenario? Some sort of Powershell PTH? Also could I have used netsh.exe in a similar way but instead of forwarding the traffic to the RDP port, forward it to another port so I can then run tools from my attack host like secretsdump.py?||

sterile epoch
#

this module is killing the little brain cells i have

sterile epoch
#

it low brain cell requirement makes it super easy to use and does not require admin
||shade|| : once I used it I was spoiled

buoyant void
sterile epoch
#

well we can try doing it again if you want my view. tho marcie and xre0us helped a bunch

tawdry vapor
#

hi, 'm in the Other Notable Applications, can anyone help me? i'm trying to catch rev shell

buoyant void
sterile epoch
#

I will complete (hopefully) the skill assessment 2 and put this module to rest until the exam

buoyant void
sterile epoch
#

assessment 2 is taking me a week to complete

astral inlet
#

i did many modules with pwnbox but now i use my vm

buoyant void
sterile epoch
astral inlet
#

rdp is pita 😉

#

even on my own vm

sterile epoch
#

I thought of using ngrok and tunnel my connection with pwnbox

buoyant void
sterile epoch
#

but too much trouble

astral inlet
#

i will have a look intoo ligolo tomorrow

sterile epoch
#

check john hammonds vid its detailed

astral inlet
#

as always 😄

buoyant void
#

oh cool I didn't know he a had a vid on ligolo I'm gonna go check that out right now

astral inlet
#

📣 #HTB has now launched its very first Penetration Testing certification!
In this AmA, we are hosting mrb3n and Dimitris Bougioukas, 2 accomplished and highly technical Cybersecurity professionals with r0adrunn3r, Community Manager and hacker, to discuss how to become a pentester through HTB CPTS, how to successfully pass the exam, tips & tric...

▶ Play video
sterile epoch
#

I put it in my watchlist

astral inlet
#

😉

#

john hammond missed this exam btw

sterile epoch
#

I think he did a vid on this

patent oak
#

I don't suppose anyone wants to DM me Kira's mutated password? Pretty please. I could have sworn I saved it somewhere. Hard lessons have been learned. Always save creds. Don't name files "hashyhash.hash2" and other variations of awful kek

sterile epoch
#

he was sponsored if I remember

fathom pendant
astral inlet
#

at least save it for the whole module .. i learned it today too

sterile epoch
#

any hints for me plis

#

anything

patent oak
astral inlet
#

5585 open ?

sterile epoch
#

evil winrm?

astral inlet
#

maybe

patent oak
#

Wait, what's a pot file...

sterile epoch
#

I am using that to connect to admin but I want its domain acct

fathom pendant
#

Oh wait you got kira's pw through bruteforcing a service

sterile epoch
#

I have access to A and B. need to access C but only admin has dc rights. I tried to crack sql_svc hash it did not work

astral inlet
#

dm @sterile epoch

fathom pendant
#

Just bruteforce ftp or something with the mutated list and wait

patent oak
#

Yeah and I can almost see it in my head 🤣

fathom pendant
#

¯_(ツ)_/¯

buoyant void
fathom pendant
#

Shouldn't take more than 10 minutes

patent oak
#

Guess I gotta go back. Lesson learned

fathom pendant
#

You don't learn lessons if someone just holds your hand and gives you something you should have saved

#

I always save credentials even before the module

#

Just a habit

patent oak
#

Just during this module I started saving the results of everything too. So I'm extra sickened that one slipped through.

#

Fun module though!

fathom pendant
#

I have a full creds.txt that gets updated per module with creds I find

#

I narrow standard/local users from /home/ and C:\Users

#

If I have a foothold*

patent oak
#

I could with seeing a pros workflow cause things got confusing fast on the PTT.

ocean night
#

Check out videos by ippsec 🙂

#

He does a good job of explaining his thought process

fathom pendant
#

PTT was interesting because it deals with domain joined hosts/accounts

#

Not just local

patent oak
#

Good news guys. I found a file called......

#

kira

#

On my desktop

fathom pendant
patent oak
#

Gonna be an awesome hacker obvs

fathom pendant
#

This is why I keep all my files separated

#

I have directories and such dedicated to the modules/sections

patent oak
#

Yeah I think that was my first time jumping about different machines in this module and I realised I was wasting a lot of time trying to remember who was who and such. Those little inefficiencies bug me

tacit bay
#

trying to do a double pivot with ligolo-ng, getting this error:
error: a tunnel is already using this interface name. Please use a different name using the --tun option

Anyone got any advice?

ocean night
#

The VM assosciated with the Attacking FTP section has the expected answers, did you try resetting the instance? Others have solved it very recently also. If you continue to face issues please raise it with our support department.

compact patrolBOT
ocean night
#

Also, that's a T2 module, so please avoid posting any spoilers @dense pewter 🙂

#

T0 is open season, but anything over that, please use discretion

vague eagle
#

Hi is there a channel I can ask a general question about a box?

ocean night
#

If it's an active box mind, do not post information that spoils the experience for others.

vague eagle
#

It says 🔒No Access for the provided link

#

It is an active box, I won't mention the name or any spoliers just a very generic question

ocean night
vague eagle
#

sweet thanks

fathom pendant
tacit bay
#

new interface worked - cheers

astral inlet
fathom pendant
#

Mr. Almond our hero?

astral inlet
#

be nice 🙂

#

if there is any cert .... john has it 🙂

dense pewter
fathom pendant
fathom pendant
astral inlet
#

masking is ok ?

fathom pendant
#

"masking" do you mean doing stuff like u*:p* for username:password and such?

#

as long as both parties understand what's being referred to

ocean night
#

Yeah.. if it's not a direct spoiler, I think it's fine. That goes for things like usernames, passwords, tools etc, along with techniques

fathom pendant
#

half the time it's just "read the section about x again"

#

or "you spelled it wrong, L + ratio"

vague eagle
ocean night
#

Sorry, I can't give any guidance on content, HTB staff

vague eagle
#

Ook

fathom pendant
gleaming raft
#

Module INFORMATION GATHERING - WEB EDITION
section Active Subdomain Enumeration
after starting the instance my Target: 10.129.79.219
question is Submit the FQDN of the nameserver for the "inlanefreight.htb" domain as the answer.
the solution i am trying is nslookup -type=NS inlanefreight.htb
but not getting required output
please guide me to follow proper approach to solve this task

fathom pendant
#

nslookup -type=NS inlanefreight.htb ip

azure fog
#

Hi everyone,
I'm doing Misc CSRF Exploitation in the ADVANCED XSS AND CSRF EXPLOITATION module and when I log in into the vulnerable app, I immediately got logged out and there is no ||Promote button||, does anybody know should it work like that?

rough tree
#

Someone who did the Skill Assessment lab from Blind Sql injection module?
I would like to know how you scripted the first part 😄
(I don't need a nudge, already finished the lab)

ember coral
#

Im currious. how am i 41% done with the course but only 18% on offensive and 7% on general

sudden sundial
#

hello everyone im new here

fathom pendant
sudden sundial
#

Do I introduce myself?

fathom pendant
#

no this isn't a gen-chat

ember coral
gleaming raft
fathom pendant
sudden sundial
#

I have

#

your welcome

#

so what do u do in hack the box

fathom pendant
#

there's instructions in #welcome to access more of the server

#

if you're talking about myself, personally, i just exist as another user in the framework

#

but that conversation isn't for this channel

sudden sundial
#

ok

#

thank u

patent oak
#

I haven't looked at the code

gleaming raft
#

Module INFORMATION GATHERING - WEB EDITION
section Active Subdomain Enumeration
after starting the instance my Target: 10.129.79.219
question is Identify how many zones exist on the target nameserver. Submit the number of found zones as the answer
the solution i am trying is nslookup -type=any -query=AXFR inlanefreight.htb 10.129.79.219
but not getting required output
please guide me to follow proper approach to solve this task

gleaming raft
fathom pendant
#

what is the localhost/loopback ip

#

:)

gleaming raft
#

but in question its asking about total number of zones on name server

fathom pendant
#

yes

#

count

#

:)

gleaming raft
#

you mean in answer how many 127.0.0.1?

chrome lotus
#

@mystic loom So, there is a tool in PowerSploit, which is indeed the answer

#

How to get to the answer? No idea. I think I discussed this with five other people, and everyone so far has brute-forced it

#

There might've been someone who actually knew the answer

mystic loom
#

Well.. Guess im part of the club now haha

tight mesa
#

hello there, happy Friday , did anyone have this issue, when was doing Citrix Breakout?

azure fog
#

Can anybody help with the ADVANCED XSS AND CSRF EXPLOITATION module?

next bronze
#

oh you dump lsa, not lsass

sterile epoch
next bronze
#

you don't have to get a shell to dcsync, read the dcsync section again

#

if that's what you want to do

sterile epoch
#

but only administrator.inlane has dc permissions

#

I cannot get to admin.inlane

#

I dumped lsass and got a hash for inlane.admin

#

now I am stuck

#

I could not crack the hash and its not nt hash

sleek moss
#

do I meed -t48 when attacking ftp or can i use it without the -t option

sterile epoch
sleek moss
#

yea ik but will it crash the system

#

with hydra

sterile epoch
#

no default is 8 iirc

sleek moss
#

its not 8

sterile epoch
sleek moss
#

how do ikno if it crashes tho will it tell me

#

hydra?

tranquil axle
gleaming raft
#

Module INFORMATION GATHERING - WEB EDITION
section Active Subdomain Enumeration
after starting the instance my Target: 10.129.79.219
question is Submit the number of all "A" records from all zones as the answer.
please guide me to follow proper approach to solve this task

sterile epoch
fathom pendant
#

you need to figure out this on your own; so far all you've done is ask questions on how to complete each task and doesn't feel like you've tried to do anything on your own

astral inlet
#

anyone got the same problem in ACL part ?

Get-ADObject -SearchBase "CN=Extended-Rights,$((Get-ADRootDSE).ConfigurationNamingContext)" -Filter {ObjectClass -like 'ControlAccessRight'} -Properties * |Select Name,DisplayName,DistinguishedName,rightsGuid| ?{$_.rightsGuid -eq $guid} | fl
An error occurred while enumerating through a collection: The (&ObjectClass -like 'ControlAccessRight') search filter is invalid..
At C:\Tools\PowerView.ps1:6664 char:13

  •         $Results | Where-Object {$_} | ForEach-Object {
    
  •         ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    
    • CategoryInfo : InvalidOperation: (System.Director...sultsEnumerator:ResultsEnumerator) [], RuntimeException
    • FullyQualifiedErrorId : BadEnumeration
deep trail
#

I found an exploit for the target at exploitdb but i dont find it in msfconsole to exploit the target

astral inlet
#

is it a .rb file ?

deep trail
#

its a .py payload

astral inlet
#

metasploit is .rb

next bronze
deep trail
#

so how do i payload the target

astral inlet
sterile epoch
sterile epoch
#

I was wondering if there is another way to get the hash. only dc came to mind

#

and inlane/admin has dc rights whose hash i have

deep trail
#

I'm new to pentesting and usually all the necessary resources were always explained in the module

next bronze
sterile epoch
astral inlet
gleaming raft
fathom pendant
deep trail
next bronze
astral inlet
next bronze
deep trail
astral inlet
astral inlet
tawdry vapor
#

anyone can help me with Attacking Common Applications - Skills Assessment I? I found the flag, but i can't read

sterile epoch
#

I wanna increase my attack vectors

deep trail
#

gn

astral inlet
#

gn 🙂

next bronze
sterile epoch
#

till now i have 3 users and one local machine admin still I cannot do dcsync. I guess I gotta wait till I have domain compromise

astral inlet
#

ok restartet the target ..... same error

buoyant void
#

so just started AD sills assessment II and I was just wondering is it possible to use Responder in tandem with Ligolo-ng?

next bronze
#

from my testing ligolo can't forward smb traffic so no

#

it could work with chisel though

buoyant void
#

Fantastic, of course this isthe one time I decided to try Ligolo-ng sadglas

next bronze
#

I mean responder you just run and forget, it's not like you need to do much else with it

buoyant void
#

As a hypothetical though, say Ligolo-ng could forward SMB traffic, what would the syntax be for Responder. Would the interface just be the name of the tun you created for ligolo?

next bronze
#

should be localhost/127.0.0.1, ligolo forward those traffic to local ports

sterile epoch
next bronze
#

oh does it

sterile epoch
#

yea I use it with smbclient

buoyant void
#

Okay good to know.

next bronze
sterile epoch
next bronze
#

oh like smbclient to a remote host

astral inlet
#

ok chatgpt fixed it 😉

next bronze
#

yea that works but not the reverse, so you can't receive traffic to your side through smb

sterile epoch
#

yea if you wanna reverse it then you gotta port forward it

buoyant void
#

I don't even know why I asked my question, my dumb ass forgot that there is a literal Linux attack host that I can run Responder on. Boy this assessment is off to a good start lol

sterile epoch
#

or another port

next bronze
sterile epoch
#

I dunno then i gotta try reverse

#

it always works for other tasks

#

oh yea I remember I used responder

#

on it I got a hash let me try doing it again give me a min

#

ok my bad responder does not work

#

I am back to my assessment

astral inlet
#

ligolo ?

#

damn sometimes i do not know if the lag is so bad or the machine hangs 😄

#

is this :

Get-DomainObjectACL -ResolveGUIDs -Identity * | ? {$_.SecurityIdentifier -eq $sid2} -Verbose

supposed to run for over 10 mins ?

next bronze
#

for big domains it can take a while

#

you can use bloodhound

astral inlet
#

i know but i want to at least do everything once

fathom pendant
#

i watched some YT vids to fill the void

astral inlet
#

yes family guy running 🙂

fathom pendant
#

this can be seen as spoiler

#

:P

astral inlet
#

mask it 🙂

sterile epoch
#

sorry

fathom pendant
#

"bloodhound shows I need C* to get to admin"

next bronze
#

that's the point of the lab, if you can get admin then the genericall edge is pointless

astral inlet
#

ok, i use sharphound

sterile epoch
#

done finally

#

I am free

astral inlet
#

i am here : ACL Abuse Tactics

buoyant void
#

okay is crackmapexec supposed to take an eternity to enumerate domain users, this thing has been running for like 25 minutes at this point I'm starting to wonder if it's even accurately enumerating real usernames

next bronze
buoyant void
#

Now it feels like wasted time if I don't just let it finish lol

next bronze
#

just open another terminal to run cme with ldap, whichever completes first

buoyant void
#

alright cme smb has a pretty good head start if ldap finishes before it that's crazy I'll give it a shot

severe eagle
#

Hey I am on lab Medium on footprinting and i have the sa:password for mssql and alex:pass for rdp but the studio doesnt have access i can guess it must be admin and looking on here others saying its admin so how do i obtain the admin password cause i have tried both passwords and will not work

fathom pendant
severe eagle
#

thank you just got in it doesnt work copying and pasting have to rdp as admin

fathom pendant
#

UAC doesn't like copy/paste

severe eagle
#

Thank you completed medium now i never used GUI of SQL hard to work out whats going. thanks again

fathom pendant
#

I think SQLCMD is installed for CLI stuff

#

but also the GUI does have a button for query

topaz cave
#

Hey guys

#

Do I have to buy Minecraft to do the crafty ctf

fathom pendant
#

2 things: Spoiler and no

topaz cave
#

Tnx

buoyant void
#

Can someone give me a hint in the right direction for AD skills assessment 2. I've logged into SQL01 using mssqlclient.py, and now have to get to the Administrator desktop for SQL01 and MS01, probably gonna take a break right now because I'm starting to get frustrated but any hint would be appreciated

twin kelp
#

Has anyone else target ip been deploying for 15 mins now?

soft cedar
#

switch the vpn server and download a new vpn and respawn the target.

twin kelp
twin kelp
#

I ended my browser session and its still deploying @soft cedar

onyx dust
#

how come there are no cheat sheets for the soc analyst path?

rustic sage
#

bruh

soft cedar
opal dirge
#

i don't know what i should do i set my account i try ed to verify my email and nothing would happen so i completed Meow than i had to go afk when i got back i was longed out and i cant log back in so do i mack a new account or am i missing something

compact patrolBOT
opal dirge
#

thanks

short hare
#

Stuck on
WINDOWS PRIVILEGE ESCALATION: Citrix Breakout

Some body please help me with this syntax, googled it found nothing relevant

gray hull
#

hi
im currently doing surveillance machine
and a found the CVE but idk what i have to change in the POC
in this line
" response = requests.post(url, headers=headers, data=data, proxies={"http": "http://10.10.14.31:8000"}) "

opal storm
#

Hey gamers, anyone alive can help me with the XSS phishing module?

#

The payload doesnt work when I try sending my ip in the request but it works when I try sending anything else

opal storm
#

It even works with a random post server when I try locally but whenever I send it in the /phishing/send.php form i always get Issue in sending URL!

thorn urchin
#

@next bronze man this kerberos attacks assessment is weird. Finally had time to resume it. Tried netexec, no dice. Decided to try impacket on a whim, now impacket works lmao

#

oh well still a fun module all around

next bronze
#

that is indeed weird, is it a problem with the lab? I did the SA again the other day and even ptt through impacket didn't work

next bronze
thorn urchin
#

just the local shell since I was already there

next bronze
#

huh maybe they did change something, I think that didn't work for me the last time

thorn urchin
#

whats super weird is I was proxychains so I can see that it hits port 389 successfully when it gets the machine information, but then the next request for 389 gets connection refused

#
┌──(kali㉿kali)-[~]
└─$ sudo proxychains /home/kali/.local/bin/nxc ldap 172.16.8.3 -k -u XXXXXXXXXX -p XXXXXXXXXXXXX --kerberoasting output.txt 
[proxychains] config file found: /etc/proxychains4.conf
[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4
[proxychains] DLL init: proxychains-ng 4.17
[proxychains] Strict chain  ...  127.0.0.1:1080  ...  172.16.8.3:445  ...  OK
[proxychains] Strict chain  ...  127.0.0.1:1080  ...  172.16.8.3:445  ...  OK
[proxychains] Strict chain  ...  127.0.0.1:1080  ...  172.16.8.3:389  ...  OK
[proxychains] Strict chain  ...  127.0.0.1:1080  ...  172.16.8.3:135  ...  OK
[proxychains] Strict chain  ...  127.0.0.1:1080  ...  172.16.8.3:445  ...  OK
[proxychains] Strict chain  ...  127.0.0.1:1080  ...  172.16.8.3:445  ...  OK
SMB         172.16.8.3      445    DC01             [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:INLANEFREIGHT.LOCAL) (signing:True) (SMBv1:False)                                                                                                                                                  
[proxychains] Strict chain  ...  127.0.0.1:1080  ...  DC01.INLANEFREIGHT.LOCAL:389 <--socket error or timeout!
LDAP        172.16.8.3      445    DC01             [-] INLANEFREIGHT.LOCAL\XXXXXXXXXXXXXXXXX [Errno 111] Connection refused
#

same output if I dont request kerberos auth -k too

next bronze
#

monkaHmm that is weird

thorn urchin
#

So when using ssh -D with proxychains, some tools like netexec uses the remote pivot's dns for resolving hosts it seems.

I added the DC to the pivot /etc/hosts and it works

next bronze
#

tbh it's been a while since I used ssh pivoting, can't say I've ran into that problem. but nice I'll keep it in mind thanks

thorn urchin
#

I normally dont use it either lmao

next bronze
#

I'm pretty sure fox knows that, he used ssh for other reasons here

soft cedar
#

He already knows that I am sure xd

swift stream
#

Hello, I have a small problem with the section. The first part in the interactive section, I don't know what the answer is. I tried everything

thorn urchin
#

Damn I missed what it was I knew

next bronze
#

ligolo

swift stream
swift stream
#

the introduction to academy

#

I'm sorry I just want to complete it, I'm a bit of a perfectionist

soft cedar
swift stream
#

what is the name of the first section of this module?

swift stream
#

okey you´re right

#

sorry

lusty thicket
#

😉

soft cedar
swift stream
#

thanks

#

sorry for wasting your time

soft cedar
swift stream
surreal heron
#

Intro to Network Traffic Analysis module, Tcpdump fundementals. "Given the capture file at /tmp/capture.pcap, what tcpdump command will enable you to read from the capture and show the output contents in Hex and ASCII? (Please use best practices when using switches)".Like I know what switch i need to read .pcap files AND to read them with ASCII. And if i use them both to read a .pcap file it works but when i enter them in as the answer it doesn't. stuck for a long time kindly help

tranquil axle
surreal heron
rain zodiac
#

Gulibó

#

@jolly cradle give me admin rank

next bronze
astral inlet
#

hi 🙂 any recommendation for a vpn `? udp or tcp ?

next bronze
astral inlet
#

sorry for academy, ok i´ll switch then 🙂

rapid sparrow
#

Just my preference, you could use icmp too

astral inlet
#

pings are way from good

#

sadly

next bronze
#

choose a server closest to you

astral inlet
#

i use my own vm , i am from europe, i testet EU 1 and EU 2

#

tcp and udp

next bronze
#

that should be pretty fast

astral inlet
#

tbh it was never fast 🙂 but ok ... rdp is total pita

#

and i am on 100 mbit+

#

ok i changed the mtu size to 1492 seems a bit better now

raven lagoon
#

Hello everyone

Im doing Shells & Payloads module and im doing that question

Use what you learned from the module to gain a web shell. What is the file name of the gif in the /images/vendor directory on the target? (Format: xxxx.gif)

Once i request devices.php the service is hanging too much

wooden dust
#

Is there any roadmap for HTB what are their plans of courses etc?

next bronze
#

afaik cwee is very soon, and they do have the advanced versions of cpts and cdsa planned

#

but no roadmap or forcast time

rapid sparrow
#

I could also write some intermediate level of forensics and malware module if they want

fluid estuary
raven lagoon
merry kiln
#

can anybody tell me that how to start hacking, I'm a newbie.

compact patrolBOT
astral inlet
#

ok seems like a eu vpn issue, us works ok

acoustic owl
rapid sparrow
astral inlet
#

12 , now i am curious 🙂

rapid sparrow
#

I have already done 4 right now

livid ether
#

anyone knows in "introduction to windows command line" "Skill Assestment part 3" what kind of flag should i find, it says only || "If you search and find the name of this host, you will find the flag for user2."|| But ive tried || "hostname" "systeminfo" "Get-ComputerInfo" || and i dont see anytging related with a flag. Even the hint just say || systeminfo ||

rapid sparrow
#

CRTL, CESC-AS, CWI-RTO…

#

OSED, OSEP, OSWE, OSWA, OSWP

astral inlet
#

i ma going for cpts, oscp and maybe BSCP

rapid sparrow
#

I think I will do oscp after osce3

astral inlet
#

sadly you can´t do oscp without the 90 days

rapid sparrow
astral inlet
#

ok ping works, rdp doesnot

#

with udp vpn it does

autumn crest
#

Hi everyone, I'm doing the "password attack" module in the ptt section "from Linux", I became "root" but then I crashed, can you give me some tips?? Thank you 🙏

astral inlet
#

"Perform a DCSync attack and look for another user with the option "Store password using reversible encryption" set. Submit the username as your answer."

can i get a nudge how to find the user please ?

fickle cipher
#

Might be the wrong chanel but is it possible to use ssh intead of pwnbox?

#

and if yes, how?

fickle cipher
#

I remember it was an option before but now I can't find the ssh connect config anywhere

next bronze
distant wagon
#

I dont know anything about computers ngl

astral inlet
wild oriole
#

Hey guys,
Regarding the broken authentication module for timing attack exercise,
it does not make sense, everytime I'm getting different response time for different users, so how would be able to determine the correct guess?

next bronze
minor dome
#

where is the general channel

#

wat is this beta name xd change my name back wtf

autumn crest
urban wadi
#

unless you dont do so

astral inlet
next bronze
#

lasagna is for windows only garfieldapproves

#

last I checked they don't have support for linux anymore, you can try the python script though

autumn crest
urban wadi
autumn crest
urban wadi
astral inlet
#

hm what could be wrong : ||secretsdump.py -outputfile inlanefreight_hashes -just-dc INLANEFREIGHT/adunn@172.16.5.5|| PW : ||-ync-aster7-7||

next bronze
#

what's wrong with it

astral inlet
#

Password:
[-] RemoteOperations failed: [Errno Connection error (172.16.5.5:445)] [Errno 111] Connection refused
[*] Cleaning up...

next bronze
#

that should be a part of your initial messaege
did you pivot

astral inlet
#

ah lol

#

dumb

#

sorry

astral inlet
#

if you do it right it works 😉

next bronze
#

could probably use pyinstaller to convert it to a binary

tranquil dawn
#

s

fluid estuary
astral inlet
#

up?

tranquil dawn
astral inlet
#

<@&861185840277487616>

tranquil dawn
#

check dms

astral inlet
#

no

tranquil dawn
#

@spring tundra

#

dam i got warend

#

warned

astral inlet
#

leave

urban wadi
#

did he just got banned?

astral inlet
#

i hope so

urban wadi
#

sad*

#

what did he do?

acoustic owl
astral inlet
#

he probably come back later

#

i was askes some times in dm of this

#

hacking a roblox account lol

urban wadi
#

aint no way

#

honestly not suprised at all

astral inlet
#

i hacked a mincraft server the last days 😉

acoustic owl
#

@astral inlet You can block him in your settings. Then he can no longer send you messages

short hare
#

Somebody please correct me..!!
Why this smbserver.py is not working..!!!

astral inlet
#

i set him on ignore 🙂

#

tbh i do a share with remmina

urban wadi
#

are easy machines easy for you, like....can you just go and after 20 minutes be like "alr i got the root flag as well"

#

cuz its so fucking hard for me

astral inlet
#

on htb ? no

urban wadi
#

they are so hard even for beginner

#

i gotta constantly follow write ups to just even progress

astral inlet
#

as a beginner i would take other resources

next bronze
urban wadi
#

i dont get your point

astral inlet
#

thm is easier, yes

urban wadi
next bronze
#

htb has starting point and academy, both are more beginner friendly

urban wadi
#

i got 1 more machine in starting point

#

and im doing with 2nd tier

astral inlet
#

hacking is getting experience and then use it to modify what you learned , it takes time

#

i am on it since 8 month now

urban wadi
astral inlet
#

i try everthing for lets say 30-60 mins if i can´t get anwhere i look into walkthroughs

latent flame
#

Hello folks. Can you help me with the info regarding cron jobs. If I have cronjob that runs on the beginning of every month, then computer got shutdown and turned on 3 or 4th day of the month will the script that was scheduled on 1st day of the month run?

short hare
next bronze
astral inlet
#

and don´t watch "first blood" on new machines 😄

urban wadi
next bronze
#

isn't devvortex still an active machine.. you should do retired machines if you want to follow writeups, and learn from the boxes, don't just blindly follow them

latent flame
astral inlet
#

the older ones are easier

urban wadi
urban wadi
short hare
#

Little help in WINDOWS PRIVILEGE ESCALATION: Citrix Breakout

Trying to run PowerUp.ps1 by as per the section but have no permissions

trying to escalate priv by using powerup.ps1 as mentioned in the section

short hare
#

@rustic sage any idea regarding this?

next bronze
#

read the error, what can you do about that?

#

advice: try to figure out things on your own instead on relying here all the time

short hare
#

It's ok..!

next bronze
#

I'm not offended, I'm saying you won't learn if you keep asking for help instead of trying other things

#

use the module, google and brain

#

"execution of scripts is disabled" what can you do about that?

short hare
#

I need to enable them through registry by show how..!

tight bane
#

i took wireshark, looked matched proto. answer on hand in on first lines, but enabling http-log gave me empty files.

#

Did you found answer? i m do not get: i need paste content value from detection string or it is in packet. C___e is format only , not what you should find?

supple gorge
#

Yes I did. I included the hint on my message

astral inlet
#

question : are those questions in cpts exam quite the same "level" as in the path ? i find some questions missleading tbh

shut quest
astral inlet
#

ok i wanted to solve dante before entering cpts

wild oriole
#

Anyone can support in this question

Create a token on the web application exposed at subdirectory /question1/ using the Create a reset token for htbuser button. Within an interval of +-1 second a token for the htbadmin user will also be created. The algorithm used to generate both tokens is the same as the one shown when talking about the Apache OpenMeeting bug. Forge a valid token for htbadmin and login by pressing the "Check" button. What is the flag?

I tried to convert the printed date to timestamp then run the script with an internal +-5 seconds then convert it to ms
then md5(htbadmin{timestamp})
and send it, it's not working

Did I miss anything?

next bronze
#

it's actually +-1 second, and you'll need to convert the epoch time to the server time in utc

acoustic owl
wild oriole
acoustic owl
wild oriole
#

I used this JS code to convert it from UTC/GMT to localtimezone

var utcDateString = "2024-02-17 15:24:58";
var utcDate = new Date(utcDateString);

console.log(utcDate.getTime() / 1000)

#

but still wrong token

astral inlet
#

ok solved .... i love troubleshooting 🙂

woven sequoia
#

hey guys i have a question,
im currently doing the" network enumeration with nmap" module and at "Host and port Scaning" i got to the question " Find all TCP ports on your target. Submit the total number of found TCP ports as the answer."

I know that i have to use nmap and the flag -Pn to get to the answer, but somehow doing it on the pwnbox the ports to find are shown open, but on my own vm it takes forever to scan and when i search for a specific port , eg. 80 it shows as unfiltered, allthough in pwnbox it is shown as open.

Anyone know what the issue is here`?

fathom pendant
#

"unfiltered" just means there's no firewall

#

¯_(ツ)_/¯

#

but also: don't run your tests with Pwnbox and vm at the same time

#

if you're testing with your vm make sure the Pwnbox is powered off

woven sequoia
#

yes i am doing that, i run both seperately

fathom pendant
#

if you do ip a do you only have 1 vpn connection?

woven sequoia
#

i m sorry im not sure how to identify if theres only one

mint lodge
#

qlmap -u "192.168.0.20:8081/index.php?option=com_fields&view=fields&layout=modal&list[fullordering]=updatexml" --risk=3 --level=5 --random-agent -D nexust_joomla -T #__users -p list[fullordering]

im having a problen because the table starts with # im getting this sql error:
sqlmap: error: -T option requires 1 argument

help

fathom pendant
fathom pendant
mint lodge
#

single quotes did not help how can i escape the # ?

fathom pendant
#

\

mint lodge
#

didnt work

woven sequoia
fathom pendant
#

you can also likely put it into a file and have it call from a file maybe? ¯_(ツ)_/¯

nocturne flint
#

Can anyone help with module "Pass the Ticket (PtT) from Linux".
The Optional Exercises "Transfer Julio's ccache file from LINUX01 to your attack host. Follow the example to use chisel and proxychains to connect via evil-winrm from your attack host to MS01 and DC01. Mark DONE when finished."

I have modified /etc/hosts file and also /etc/proxychains4.conf file.

I am unclear what chisel does. Is chisel to help transfer the ccache file to my box?

When I try to run proxychains4, I get an error.

What am I doing wrong?

fathom pendant
#

if you have burp intruder running: it's stopping the request until you forward it

raven lagoon
#

do you think am i stupid MarcieLee

fathom pendant
#

no, just a suggestion based off others experiences

raven lagoon
#

;/

#

not not the case thx too

fathom pendant
#

don't jump straight to an assumption

#

many issues are dumb user error, that i've done too

rapid sparrow
# nocturne flint Can anyone help with module "Pass the Ticket (PtT) from Linux". The Optional Ex...
astral inlet
#

chisel saved my a$$ many times 😄

raven lagoon
astral inlet
#

EU vpn ?

raven lagoon
#

y

astral inlet
#

change to us and try

#

udp

raven lagoon
#

ok

astral inlet
#

solved my problems for today

raven lagoon
#

it works

#

i had to wait for like 1 minute to let the page show but it works ahahha

astral inlet
#

please report this issue

raven lagoon
#

@fathom pendant fix that

fathom pendant
#

?

#

i'm not staff lol

#

shit just happens

raven lagoon
#

wtf

compact patrolBOT
mint lodge
raven lagoon
mint lodge
#

bruh

raven lagoon
#

dont be a pussy

mint lodge
#

lmao im trying

fathom pendant
raven lagoon
narrow nacelle
#

Hey guys, a quick question. I'm at "Information Gathering - Active Subdomain Enumeration" and at the end of that module you can see the explanation of how to use gobuster. What I don't get is that if you don't have permission of using that tool on a specific domain, you shouldn't do it. Then why the examples of gobuster are with facebook.com?

astral inlet
narrow nacelle
raven lagoon
#

if its subdomain enum i think anyone can do it

indigo valley
#

Hello
So i was doing the LFI module on HTB academy and i am stuck in a question which expects a flag as an answer. It tells me the location of the flag, i try to transverse and i get a flag with the format HTB{} but when i submit the flag its showing incorrect answer

#

any help is appreciated pls do ping me while replying

fathom pendant
#

make sure no weird extra spaces

indigo valley
#

nvrmind i worked space was the issue

#

thx

astral inlet
#

damn AD module is huge 🙂

calm mesa
#

Repent of your sins and turn to God, for the kingdom of heaven is near. For God so loved the world that he gave his one and only Son, that whoever believes in him shall not perish but have eternal life.

astral inlet
#

great

mint lodge
#

i am still stuck 😦

pastel lava
#

where do i go for help on openvpn i am trying to connect to hack the box vip machines i am using a vip vpn but it says destination host unreachable when i ping

fathom pendant
#

nmap as the -Pn flag

pastel lava
fathom pendant
#

¯_(ツ)_/¯

#

make sure you're on the right vpn if you're doing the labs platform

#

also read #welcome to find out how to acess more of the server

stark vortex
pastel lava
stark vortex
#

real

#

It's never the skill assessments that I waste time on either it's always some random sections exercise that gets me lol

pastel lava
stark vortex
#

I'm currently doing pivoting and I haven't had that happen to me, I'll keep a lookout for something like that

dim wolf
#

For module Understanding Log Sources & Investigating With Splunk, section Introduction to Splunk & SPL, third question
Why is the answer ||not waldo||? The query I used shows them as the one with the most login attempts within 10 minutes

rustic sage
rare grotto
#

Hey all, I'm doing the Intro to AD module and having trouble connecting with xfreerdp. Everytime I try to connect with the pwnbox, I get this return:
[18:29:26:557] [3091:3092] [ERROR][com.freerdp.core.connection] - Timeout waiting for activation
[18:29:26:559] [3091:3091] [ERROR][com.freerdp.core] - freerdp_abort_connect:freerdp_set_last_error_ex ERRCONNECT_CONNECT_CANCELLED [0x0002000B]

Anyone know what this is about?

vital zephyr
#

Is there anyone who could help me with the ftp attack module? please, I'm going crazy

rustic sage
#

It seems like there might be an issue with the connection timing out. Check your network connectivity, and ensure that the server you're trying to connect to is reachable. You may also want to verify the correctness of the connection parameters such as the server address and credentials. If the issue persists, consult the documentation for xfreerdp or seek assistance from your course instructor or technical support.

vital zephyr
#

please help me..

rustic sage
#

did you mean Files Transfer Protocol

vital zephyr
#

yes,

azure fog
#

Hi everyone,
I'm doing Misc CSRF Exploitation in the ADVANCED XSS AND CSRF EXPLOITATION module and when I log in into the vulnerable app, I immediately got logged out and there is no ||Promote button||, does anybody know should it work like that?

urban wadi
vital zephyr
#

i cant resolve the 2* answear

urban wadi
vital zephyr
#

I used:

hydra -l robin -P /home/kali/Desktop/wordlists/rockyou.txt ftp://10.129.203.6

medusa -u robin -P /home/kali/Desktop/pws/pws.list -h 10.129.203.6 -M ftp -n 2121 -t 30 -f

crackmapexec ftp $10.129.233.82 -u robin -p ./home/kali/Desktop/pws/pws.txt --port 2121

but none produce any results

pastel lava
vital zephyr
#

yes, discors prevents me from sending the link, anyway yes, I am referring to the ''attack on common services'' module, in particular ftp attack

vital zephyr
#

the question tells me: Use the discovered username with its password to login via SSH and obtain the flag.txt file. Submit the contents as your answer.
but using medusa, hydra and crackmapexec I can't find any password

fathom pendant
vital zephyr
pastel lava
fathom pendant
#

are you using the mutated password list

vital zephyr
#

nothing, it is so frustrating

fathom pendant
#

this is the acs one

#

hydra should work tbh

tight mesa
#

hello there, anyone willing help with the Slack cookie part of Pillaging section of Windows PrivEsc?, cuz the process described into the section is not working for me on my PC as Lab either...

rustic sage
fathom pendant
#

the error is that the connections are getting dropped btw

vital zephyr
#

how i can resolve?

fathom pendant
fathom pendant
fathom pendant
vital zephyr
#

via this forum: https://forum.hackthebox.com/t/academy-attacking-common-services-attacking-ftp/257166
I have noticed that many have had some problems of this type, that is, they have to reset the target several times

#

however if I scan with nmap, nmap gives me some results

#

and

fathom pendant
#

i think you may need to specify port with -s for hydra instead of ftp://ip:port

vital zephyr
half wolf
#

Im working on the password mutations section of the password attacks module and trying to solve this question. Ive generated a custom wordlist using the resources provided but trying to use crackmapexec like I have for the other sections is going incredibly slow. I'm lead to believe I should get the ssh hash and put it into john but I dont know how to do so

fathom pendant
#

look for other running services

half wolf
#

I was running crackmapexec on the ftp server as well but it was also going slow, do I need to just let it run for a long time?

cedar void
#

Doesn't this command "sudo smbserver.py -smb2support CompData /usr/share/mimikatz/Win32
" create a share called 'CompData'?

half wolf
#

additionally is there any way to speed it up? I modified the threads to 1000 but that didn't seem to help anything

cedar void
vital zephyr
#

is it working correctly?

fathom pendant
#

yes it's running

#

though i would have suggested using the smaller pws.txt file

#

because uhhhh rockyou is gonna take a minute

#

generally rockyou isn't gonna be used for Bruteforce as it's a HUGE list

vital zephyr
#

i dont knwo what to do

#

the pws list with both medusa and hydra doesn't give me any kind of result

fathom pendant
#

weird

vital zephyr
#

I know that I find out the password via either medusa or hydra, with the ''pws'' wordlist that they gave me from the module, but neither of the two tools works, or rather, neither of the two gives me the password

vital zephyr
fathom pendant
vital zephyr
fathom pendant
#

you forgot to specify port

vital zephyr
#

ftp -ip:2121?

fathom pendant
#

ftp ip 2121

#

no colon

vital zephyr
#

it asks me for the password

fathom pendant
vital zephyr
#

can you be more clear?

fathom pendant
#

user ...

#

you didn't wait for it to prompt you to enter a username

pastel lava
#

u need to login as anonymous

#

then list for files

#

u will find a wordlist

fathom pendant
#

so ftp took the error code of trying to ls as the username

#

which is actually funny

pastel lava
# vital zephyr

where it says name u need to put anonymous u typed ls as the username

fathom pendant
#

literally he typed ls before ftp sent the login response

pastel lava
#

u have to wait for the name thing to appear

fathom pendant
#

so the error code that came up 331 Password required for ls was taken as the login username

vital zephyr
#

so now I have to write anonymous?

fathom pendant
#

yes

pastel lava
#

yup

fathom pendant
#

why are you suspending processes btw

#

just close or quit them

vital zephyr
fathom pendant
#

just hit enter

#

"Anonymous login ok" > this part means you can literally log in as anon

#

and use anything as your password, it doesn't do any kinda email verification check

vital zephyr
#

ok now I'm logged in, can you please tell me the wget command to download everything?

fathom pendant
#

wget isn't an ftp command

astral inlet
#

help can be the answer

vital zephyr
#

thank youi marciel

fathom pendant
#

it's covered in the Footprinting Module btw

#

if you're doing the CPTS path; please do them in order lol

astral inlet
#

PLEASE 🙂

fathom pendant
#

and even then Footprinting is a pre-req for Attacking Common Service

#

as it covers basic recon for these services

vital zephyr
#

Now I'll go ahead on my own to understand how to download the files, you've been a great help Marciel, thank you very much

fathom pendant
#

np

#

it should take ~ 1 minute with your newfound list to get the answer

#

:)

half wolf
maiden field
#

Intro to Assembly Language
Debugging with GDB

Download the attached file, and find the hex value in 'rax' when we reach the instruction at <_start+16>?

I'm running the code then doing this
|| gef➤ x/wx 0x401010
0x401010 <_start+16>: 0x00bf0000 ||

But it doesn't seem to be the answer

#

I'm not sure to understand

astral inlet
#

on or against ?

vital zephyr
#

unfortunately here we are, why does it say permission denied?

fathom pendant
#

do you have permission to write to where you're downloading to?

#

i.e. are you in a root-protected directory

#

also: passowrd.list

#

you typoed

vital zephyr
#

I can not do anything? what should I do now?

#

should I use hydra from here?

fathom pendant
#

i meant: from the directory you launched ftp from

#

i.e. / or /root/ i cannot recall if /home/ is

vital zephyr
#

/home

fathom pendant
#

just type cd or cd ~ to get to your user's home directory

#

then try downloading again

#

/home/ is where the users are and is (in-fact) a root protected directory

vital zephyr
#

I don't know if I didn't understand anything, or I'm not able to download these files

dim wolf
#

you need to exit ftp before changing your working directory

vital zephyr
#

I don't understand what changing the folder on my Kali has to do with the fact that ftp prevents me from downloading the files

#

why can't I download the files?

cedar void
dim wolf
#

generally in linux you will have a root directory containing every file on the system. this directory is owned by root and every user must abide by its permissions placed on this folder. from where you did your ftp command is this folder.

root can read, write, and execute all files within the root dir. all other users can only read files. you, the kali user, can only read files. you are attempting to download (write) a file to that directory, which is not possible because of the permissions.

vital zephyr
#

probailly it works

dim wolf
#

perhaps, but you can just move to a directory where you do have the permissions to write files to it, e.g., your user's home directory

vital zephyr
#

this is a really strange thing, I discovered the world, that is, I didn't know that based on how you log in, whether as root or as a normal user, ftp recognized this thing

whole grotto
#

does someone has used metasploit for the "Other Notable Applications" in the "attacking common application" and can help me to configure it because i got "Exploit completed, but no session was created" and i think its because of the payload ! but there is more than 200 payloads for the exploit

vital zephyr
#

he downloaded it for me, it worked

whole grotto
#

do someone can help me on that

dim wolf
#

you shouldn't need to use root unless you have to

#

marcie was trying to tell you to change your working directory as the kali user, not to use root

compact patrolBOT
finite tulip
#

anyone faced an issue that when rebooting splunk, it never goes up again!

upper ruin
#

Hello, kind fellows of HTB.
I come yet with another issue:

Pivoting, Tunneling and Port Forwarding Module.
SOCKS5 Tunneling with chisel.
Can someone tell me what am I supposed to do? Do I have to install the library on the target host? (worst case scenario, if I can't fix it on my kali I will just use pwnbox).

stark vortex
#

but I would recommend ligolo, it is way easier in my opinion

upper ruin
#

See, the task is to use chisel.

#

I downloaded it, built a binary and transferred it via scp to the target host.

stark vortex
#

sorry I was wrong it is server on pivot & client on host my bad

astral inlet
#

better dl the binary

upper ruin
#

and retry?

astral inlet
#

download

upper ruin
#

Oh..

#

So, you want me to start an http for example in the chisel directory and wget from the target.

#

For example.

#

Wget the binary**

astral inlet
#

and scp it to the host for example

upper ruin
#

I will try that.

#

I will redownload chisel and "go build"

astral inlet
#

yes

#

AD Enumeration & Attacks - Skills Assessment Part I <--- i am scared 😉

upper ruin
#

Gl, ser.

astral inlet
#

I´ll be back 😉

stark vortex
#

nice

upbeat dragon
#

Hey Guys, stuck at ACL's in AD Module with the following question:

What is the ObjectAceType of the first right that the forend user has over the GPO Management group? (two words in the format Word-Word)

Any idea what command to use?

half wolf
dreamy solar
woven copper
half wolf
tight bane
#

Thanks, i found with google mighty help....

Thank you very much for the tip @supple gorge10

next hint for others, who struggling with this question: idea is improve detection! Copy answer Template to another text editor, IlO0 problem :), you do not see hint with human eye , your regex will be more focused then my.

After that dig in attack, all info is packet capture, copy somewhere and work it. Read also link on top network detection part will help. Payload is "content: value;" that should be in local rules (value is answer)

"Working with IDS/IPS, ayone ever done the skills assessment Suricata" Assement module

half wolf
#

I ran with the pypykatz command in the cheatsheet and got an error aswell

fathom pendant
next bronze
next bronze
upbeat dragon
next bronze
cedar void
#

Can someone help me regarding why I am not able to transfer my mimikatz file to my windows machine? I have followed the instructions listed here:

https://0xdf.gitlab.io/2018/10/11/pwk-notes-post-exploitation-windows-file-transfers.html

sudo smbserver.py -smb2support CompData /usr/share/mimikatz/Win32
net use \10.10.15.20\CompData
PS C:> copy \10.10.15.20\CompData\ C:
PS C:> dir

soft cedar
next bronze
#

and the user probably doesn't have write perms to C root

fathom pendant
#

Also plausible

next bronze
#

I mean if you wanna follow the command at least do the same thing

upbeat dragon
soft cedar
fathom pendant
upbeat dragon
#

Yeah my bad, thanks for reply

cedar void
next bronze
#

that's also not what the example command is doing, you need to specify an outfile name and the file you're trying to copy

ocean grail
#

Hey guys , I have a question can any one help me ?

fathom pendant
#

We can't answer questions you don't ask

ocean grail
#

I recently downloaded GNS 3 on a Debian device, but I'm having a problem when opening the Wireshark, the window opens and you do the loading but suddenly it closes I tried hard to find a solution I didn't find I tried the Wireshark only and it worked without any problem but with the use of the gns3

#

Can anyone help me to fix this issue

fathom pendant
fathom pendant
cedar void
upbeat dragon
#

Another question, for "Set a fake SPN for the adunn account, Kerberoast the user, and crack the hash using Hashcat. Submit the account's cleartext password as your answer." i have to use Dagmar Payne?

#

Like, reset her account and from there create a fake SPN for adunn?

stark vortex
#

hey y'all I have a problem regarding the pivoting skills assessment I'm trying to transfer a file from a machine to my home machine but I'm getting an error and I'm not quite sure why
I'm running a smb server with:
" impacket-smbserver -smb2support data . -port 4444"
and I've set up a listener on my ligolo agent that listens on port 4444 on 0.0.0.0 of the pivot machine and sends it to 0.0.0.0:4444 of my attack host,
However when I run the command ''' cp ./file \<pivot-ip>:4444\data '''
I get the error:
''' cp : the network path was not found '''
any help would be appreciated

fathom pendant
#

Or copy to temp

#

C:\Windows\temp

next bronze
stark vortex
#

damn ok thanks I'll do something else then

upbeat dragon
fathom pendant
#

Don't just skim, read

maiden field
# next bronze step to the right instruciton, look at rax

That’s the part I don’t really understand when I enter debug mode I have Start+12 and start+17 I have nothing in between I’m not sure how can I go to the good one with step. Can we go in dm since I can’t upload picture there

next bronze
#

you can get verified and upload images, read #welcome

maiden field
#

I can't since I use htb entreprise

fathom pendant
#

You can just create an account

#

¯_(ツ)_/¯

maiden field
#

I don't see the point of having 2 accounts tbh

fathom pendant
maiden field
fathom pendant
#

it's a feature of SSO to sync progress with Enterprise and Lab accounts as well

maiden field
#

Ok but I still need to create another account

#

but if they are both link that's more interesting

fathom pendant
#

yep your progress will get linked so you don't have to redo boxes and stuff

maiden field
#

ok ty

fathom pendant
#

np

maiden field
twilit cipher
#

Is anyone working on the Advanced Web Exploitation course yet? I have a question about the "Injection Attacks" Skills Assessment.

maiden field
#

Do i still need to create a classic academy account

hot ledge
#

Guys I need help, i can't identify in #bot-commands it's throwing me an error, i did open a ticket on the website, but maybe someone here can give some insight if it happened to them. I know this is not the right channel but it's the few i have access to for right now.

cedar void
# fathom pendant C:\Windows\temp

I tried the Windows\temp method and don't see the mimikatz.exe file in that temp folder:

"copy \10.10.15.20\CompData\mimikatz.exe C:\Windows\temp
"
I did not see the mimikatz.exe executable file.

I also tried 'copy \10.10.15.20\CompData\mimikatz.exe C:\Windows\temp\a.exe(exactly like the example from the link I posted)
' and that did not work

maiden field
#

Ok I guess I'll use that for now

fathom pendant
maiden field
#

Yeah it didn't work I cant link my main lab account

fathom pendant
maiden field
#

with sso I contacted support

fathom pendant
#

weird it worked fine for me

#

might be some weird thing that's causing conflict ¯_(ツ)_/¯

maiden field
#

It says I'm already link with another sso account and I just created the account 10min ago lol

fathom pendant
#

weird LMAO

maiden field
fathom pendant
#

+16 would be +000a

#

i think

#

brain is tired

next bronze
#

yep, tour gdb is in b16 for some reason

fathom pendant
#

or wait wouldn't it be 0010? in b16

next bronze
#

wait right

#

did you even download the right file

fathom pendant
#

idk why my brain was thinking a was 16

maiden field
cedar void
maiden field
#

I'll try downloading it again starting from scratch just to see

maiden field
#

my computer put a (1) so I thought it was the same lol

fathom pendant
#

because it's called the same thing

maiden field
#

I know

#

I'm tired

fathom pendant
#

which imo is kinda dum of htb LMAO

#

nah not a you thing; HTB should def have them called diff things in the backend

#

or you can alternatively rename it <section_name>.zip after downloading

next bronze
#

the zip name is unique tho, the previous sections isn't named that

fathom pendant
#

is it? i honestly never looked at the asm module

next bronze
#

yeah, idk where they got the other file from

fathom pendant
#

weird ¯_(ツ)_/¯

maiden field
#

what

#

I juste downloaded it again and I still don't have the same thing

fathom pendant
#

weird

next bronze
#

the file inside should be called gdb

#

you were using disasm

#

are you at the right section

maiden field
#

thats what I have

next bronze
#

that's the correct file

#

your gdb is just in b16

maiden field
#

Ok so I was just not in the good file --'

fathom pendant
next bronze
#

yep

fathom pendant
#

the xor rax,rax instruction looks to be what will hold the answer then

maiden field
fathom pendant
#

it means it's giving you the instruction + in base 16 instead of base 10

#

16 in base 10 translates to 10 in base 16

#

{1,2,3,4,5,6,7,8,9,a,b,c,d,e,f}

next bronze
fathom pendant
#

i used to dabble in pixel art stuff and manually inputting the values

next bronze
#

yea it's correct, just looks funny

maiden field
#

ok but since I need the hex value I need to stay in base 16 no ?

fathom pendant
#

i think irregardless the value is stored in hex

next bronze
#

again step to the right instruction, look at the value in rax

fathom pendant
#

the debugger is just in b16 mode for stepping

hot ledge
#

Can someone help me with identifying on discord? It's throwing me an error when i do so.

fathom pendant
#

plenty are online atm

hot ledge
#

I did but nobody responding.

fathom pendant
#

just be patient

#

it's the weekend and they're likely having a life

#

:P except maybe @slender shoal he has no life

hot ledge
#

Yeah that's why I don't want to message multiple people, waiting on somebody to respond. But tought somebody maybe can help.

fathom pendant
#

no one here can help you tbh

maiden field
fathom pendant
#

it sounds like your account used to be linked with one that was deleted

#

and the only way to clear it is for a mod/admin to clear that link so you can verify