#modules

1 messages Β· Page 203 of 1

fathom pendant
#

Resolvers.txt is purely for name server/resolving

#

It doesn't act as the hosts file

compact halo
#

I did some research, but as probably looking for the wrong thing. I didn't check for how the resolver should be configured on github

fathom pendant
#

It checks dns (public, /etc/hosts) if it knows what you're asking it but if it doesn't it'll just tell you "no:

#

It's basically a list of "hey check the dns for these specific resolvers"

karmic dagger
#

I'm on the Attacking Common Services - Easy module and am having trouble getting the flag. Is the goal to use the LOAD_FILE command to view the flag or to upload a shell through MySQL to make a reverse shell?

compact halo
fathom pendant
fathom pendant
compact halo
fathom pendant
#

yep using the ip tells it to directly query the IP instead of trying to look through other files for references

compact halo
#

🫑

steady matrix
#

Hey guys just a quick question. I don't have a subscription on Academy anymore, if I bought some cubes and unlocked a module, would I still get access to the VMs and all? In other word, I'm only interested in a couple of modules so paying for the subscription doesn't seem worth it

fathom pendant
#
  • the cubes from the subscription are yours forever
  • the modules unlocked via cubes are yours forever
#

the in-browser vm is accessible irregardless of a subscription, if you spent any money or previously had a subscription then you're not limited to the 1/day spawn of it. But it's in-general better to set up your own vm

steady matrix
#

are modules time-limited if unlocked with cubes? Say, a module i'm interested in costs 500 cubes ($50), i can't see how a subscription would be better

fathom pendant
#

no

#

look up the pricing and how much you get for a platinum sub vs the price of 1000 cubes

#

even gold monthly (500 cubes) is $38 while 500 cubes outright is $50

steady matrix
#

oh i see what you mean

fathom pendant
#

ye

steady matrix
#

so I could just do 1 month of sub to get the 500 cubes

fathom pendant
#

it's not so much a QOL thing you get from the sub, it's LITERALLY cheaper

#

yep

steady matrix
#

and once unlocked it stays yeah? Once the sub is cancelled I still get access to the module yes?

fathom pendant
#

yes

#

you can unlock a module with cubes, not touch it for months/years and it still be sitting there

steady matrix
#

awesome, thanks so much for confirming!

next bronze
#

what tier 3 modules are you looking to get?

steady matrix
#

the NTLM relay one

next bronze
#

good choice

steady matrix
#

That seems weird to have this many different subscriptions and cubes sold directly for more though

next bronze
#

it is, we just ignore the direct purchase lol

karmic dagger
fathom pendant
#

:)

#

windows uses the full word

fathom pendant
#

but aside from that monthly subs far outweigh the other options

#

(and the $8/m student sub is one of the best values if you have a student email)

next bronze
#

honestly even then it's not worth it, if you upgrade your monthly sub you get the difference in cubes right away

fathom pendant
#

if you're already on plat then it's gg

next bronze
#

that's the only situation kekw

karmic dagger
fathom pendant
#

but i'm just purely speaking hypothetically

steady matrix
shut quest
#

Almost done with the silver annual, 5 modules left to finish. Are there any two tier 3 or one tier 4 that anyone thinks is a must do?

steady matrix
#

actually one last question, can you cancel the subscription as soon as you got the cubes? (before unlocking any module)

dire abyss
#

stuck on password attacks - protected archives. I was able to crack the notes.zip but the question at the bottom doesnt accept the contents as the answer

#

unless what i cracked is a password to open the the zip file

#

yeah that was it..

rustic sage
#

Can someone tell me if it's possible to setup your very own VPN or Proxy on Linux destros.

fathom pendant
#

yes

lyric sigil
#

hello, i had a problem here, basically i had to start kali box with this comand ssh kali@10.129.204.151, but always i had that answer ssh: connect to host 10.129.204.151 port 22: Connection refused
, how i can fix it ?

fathom pendant
#

is 22 open on that device?

lyric sigil
#

i didn't know how too see it, i am very beginner also, this is the steps they said i have to follow

#

but, basically i just get refused

remote latch
fathom pendant
#

also sometimes you gotta wait a few minutes after starting the target

lyric sigil
#

yea, i had no problem for start for exemple the windows machine, with RDP command, just for got kali i had issue

lyric sigil
#

this is the question i have to answer, but without follow the steps i cant answer it

#

i have to acess kali for possible to use jack the ripper for broken hash criptografic for got my password

fathom pendant
#

also evidenced by the 3389 being open: you're being tasked to initially rdp as bob

lyric sigil
#

yes i am here, i already did the RDP

#

but, i cant start the kali with have the tool i need for find my answer

#

i close everthing, i start again, still have this answer

autumn pilot
#

the question tells you that you need to use RDP

#

if the port for SSH is not open (nor running) you cannot SSH into the target

buoyant void
lyric sigil
buoyant void
lyric sigil
#

really thanks

gaunt sluice
#

Hello,
the Connection is really is unstable here on my location. and the RDP is not works good.
i am thinking to run my c2 or just using Metasploit to connect over Powershell. is that allowed ? or there is some defender enabled will block my connection ?
did anyone try it before?
thanx

pearl warren
#
bash-3.2$ xfreerdp /v:10.129.110.241 /u:htb-student /p:HTB_@cademy_stdnt\!
[17:01:15:392] [1881:6d4c7000] [ERROR][com.freerdp.core] - transport_connect_tls:freerdp_set_last_error_ex ERRCONNECT_TLS_CONNECT_FAILED [0x00020008]
bash-3.2$ xfreerdp /v:10.129.110.241 /u:htb-student /p:HTB_@cademy_stdnt\!
[17:01:17:304] [1885:6d94b000] [ERROR][com.freerdp.core] - transport_connect_tls:freerdp_set_last_error_ex ERRCONNECT_TLS_CONNECT_FAILED [0x00020008]
bash-3.2$ xfreerdp /v:10.129.110.241 /u:htb-student /p:HTB_@cademy_stdnt\!
[17:01:19:047] [1888:6cecb000] [ERROR][com.freerdp.core] - transport_connect_tls:freerdp_set_last_error_ex ERRCONNECT_TLS_CONNECT_FAILED [0x00020008]
bash-3.2$ xfreerdp /v:10.129.110.241 /u:htb-student /p:HTB_@cademy_stdnt\!
[17:01:21:635] [1891:6f373000] [ERROR][com.freerdp.core] - transport_connect_tls:freerdp_set_last_error_ex ERRCONNECT_TLS_CONNECT_FAILED [0x00020008]
bash-3.2$ nmap -p3389 10.129.110.241
Starting Nmap 7.94 ( https://nmap.org ) at 2024-02-19 17:01 WIB
Nmap scan report for 10.129.110.241
Host is up (0.22s latency).

PORT     STATE SERVICE
3389/tcp open  ms-wbt-server

Nmap done: 1 IP address (1 host up) scanned in 11.52 seconds

I believe this error is expected right? Because the target server is very old (Server 2008). Is there any way to connect to this server using xfreerdp? (Im currently learning Windows PrivEsc module https://academy.hackthebox.com/module/67/section/912)

pulsar oyster
#

I'm having an issue with the last question of the Windows CMD line module. Question:
What user account on the Domain Controller has many Event ID (4625) logon failures generated in rapid succession, which is indicative of a password brute forcing attack? The flag is the name of the user account.

Output:


Message
-------
An account failed to log on....
An account failed to log on....
An account failed to log on....
An account failed to log on....
An account failed to log on....
An account failed to log on....
#

How do I expand the message?

#

nvm solved

solar pecan
#

Hello guys... Do you experience disconnection issues?

solar pecan
#

I see

rustic sage
#

Hello

minor stag
#

Just out of curiosity, on the linux OS fundamentals, when I did "locate **.log | wc -l" * I got 24 as the result, but when I used "find / -name *.log 2>/dev/null | wc -l" I got 32. What caused this discrepancy?

patent niche
#

Hi guys I'm on the [Code Analysis] part of INTRODUCTION TO MALWARE ANALYSIS

I've got the second question right, but not the first one, where could I start ? Looking for every function?

"IDA to analyze orange.exe. Enter the registry key that it modifies for persistence as your answer. Answer format: SOFTWARE____"

limpid dirge
#

Hi, i am in "introduction to network analysis" and there is so many errors for the response... According to their solutions document, good response is 43 804 and 80 but at this question "What are the client and server port numbers used in first full TCP three-way handshake? (low number first then high number)" my response is "80 43804" and it is not good, please can you help me ?

#

Is there any support to report these inconsistencies ?

tranquil axle
plain coral
#

Just completed the AD attacks and enumeration module, finally! Hardest module I’ve done so far

tranquil axle
#

nice, thats a big hurdle

patent niche
simple loom
#

If you could not find it in the strings, maybe it is generated elsewhere πŸ‘€

short hare
#

Need a little help in file transfer
want to transfer a file from rdp seesion to pwn box but scp always say time out

#

Getting really really frustrated

limber river
short hare
#

i think so

#

For this simple thing stuck here for long can 't even complete the section

rapid sparrow
#

have anyone done Introduction to C#

#

Declare a byte variable aByte and assign it the maximum value that a byte can hold. (from Understanding Variables, Constants, and Data Types in C#)

shut quest
rapid sparrow
#

did you solve it?

frozen mesa
# rapid sparrow did you solve it?

No, didn't find any help so i went on to another module. I understand what the lesson is about but not what i have to do for the questions, maybe just my bad English.

rapid sparrow
frozen mesa
sour ether
#

Hello guys, I'm solving the module about windows event logs, have anyone got any idea about the first question?

rapid sparrow
frozen mesa
tranquil axle
#

Is it β€žbyte.MaxValueβ€œ?

#

Is that the full question even? Sounds like something is missing

rapid sparrow
tranquil axle
#

Oh I guess the answer is the line of code?

old kayak
#

Hey, is HTB having server issues? I'm trying to complete boxes on the CPTS Job role path and the lag is horrible. I'm in UK and tried every VPN server with the same lag issues

tranquil axle
#

byte aByte = byte.MaxValue;

rapid sparrow
rapid sparrow
frozen mesa
#

Thanks! Still wondering why the question is asked like this.

shut wraith
#

Hello can I DM anyone about Skills Assessment - File Inclusion

mossy nest
#

Hey guys, I'm struggling a bit about the xss Phishing section

rustic sage
#

any1 else get really slow VPN connection? (Have tried changing VPN+protocol and reseting target).

mossy nest
#

It looks normal for me perper

rustic sage
mossy nest
#

Did you try to resetting you openvpn file ?

#

Sometimes it worked for me

patent niche
rustic sage
jolly lily
#

hey guys

#

need help i wanted to try the HTB CTFs i see an event running but its asking for an invite code !!

limpid dirge
#

and event their response doesn't work...

tranquil axle
jolly lily
fathom pendant
#

Otherwise: if it requires a key, its private

cedar void
#

To connect to the internal network on the machine, I type the following command: (just like what was in this ligolo instruction link):

https://4pfsec.com/ligolo#heading-adding-a-new-route-on-proxy-server

listener_add --addr 0.0.0.0:11601 --to 172.16.6.100:11601 --tcp
listener_list

I then typed './agent.exe -connect 172.16.6.100:11601 -ignore-cert'

But it doesn't give me the option to choose that internal address.

Why is that?
https://academy.hackthebox.com/module/143/section/1278

4pfsec

Using Ligolo-ng to pivot through networks with ease!

fathom pendant
#

Meaning invite only

tranquil axle
jolly lily
#

yep thankyou for helping me with my questions

fathom pendant
cedar void
compact halo
#

@fathom pendant Good morning, Checking in on the Attack DNS Seems like one sub domain popped up on the "subbrute" command. Been about an hour. That one doesn't work for the axfr. Is this supposed to take hours?

shut quest
tranquil axle
limpid dirge
#

So my answer is 80 43804

#

but it is wrong and i don't know why

fathom pendant
#

Also make sure your target didn't die

tranquil axle
compact halo
fathom pendant
#

because that's the incorrect syntax

#

the @ is calling the nameserver in dig

#

if your system doesn't know what h*.inlanefreight.htb it doesn't resolve it

#

it would be dig axfr h* @ip

compact halo
fathom pendant
#

that's not so much dns, as it is you not using a tool properly

#

think of dig this way: you are digging for records OF a domain @ the nameserver

minor stag
#

Can someone help break down the command "curl https://www.inlanefreight.com | tr " " "\n" | cut -d"'" -f2 | cut -d'"' -f2 | grep www.inlanefreight.com | sort -u | wc -l" and help me understand how exactly this counts unique paths? I don't fully understand the delimiters in particular.

fathom pendant
#

look up what each command does

minor stag
#

I know what they all do individually

#

But not how this combination achieves the desired outcome

potent ermine
#

I'm no command line wizard, but I would ask chatgpt and it can give you a step by step breakdown

fathom pendant
#

it takes the curl result: cuts out everything that isn't in the specified area that's being filtered for then looks for a specific string, it then sorts by unique and counts them

minor stag
#

That's a good call. I forgot about chat gpt

fathom pendant
#

do it one part at a time if you're really having issues

limpid dirge
fathom pendant
#

Β―_(ツ)_/Β―

limpid dirge
#

you think ?

#

I thought they didn't see the connection has been rejecyted

compact halo
cedar void
# shut quest Your listener_add is incorrect

I changed the listener command too "listener_add --addr 0.0.0.0:11601 --to 127.0.0.1:11601 --tcp
listener_list
" but its still not showing three options:

(the option that includes 172.16.6.100).

fathom pendant
#

does that include the related subnet you're trying to access

#

2FA doesn't mean anything if they have your token

#

best option: reset all passwords, 2FA, everything

sour ginkgo
fathom pendant
#

we don't help with account recovery or anything of that nature

sour ginkgo
#

Oh okay

#

I'm sorry

fathom pendant
#

this channel is also for help with htb academy modules

#

not for rando "I got hacked" stuff

#

reading a server's #welcome channel is a good way to see what it's about

fathom pendant
#

did you also create a route on your system?

#

ip route

limber river
#

then start the session from ligolo

cedar void
fathom pendant
#

^

limber river
#

you should route the whole subnet

#

maybe this 172.16.0.0/16

fathom pendant
#

the .100/32 is an incredibly more limited network (in fact one could say that it is fully limited)

limber river
cedar void
fathom pendant
limber river
fathom pendant
#

/32 means the subnet mask is filled

fathom pendant
#

that would technically be the right thing

limber river
fathom pendant
#

it will

limber river
limber river
fathom pendant
#

try /24

limber river
fathom pendant
#

or i did it right when i was doing it and didn't realize lol

#

but that may have been subconsciously knowing how CIDR addressing works

cedar void
# limber river try this ?

So I typed IP route and I got only two results back I think for the 172.x.x.x subnet: I got three results back when I use the subnet /24

limber river
shell ore
#

hey quick question, are the labs and vpn connection on the academy soooo slow for everyone? or just me?

#

like REALLY SLOW

cedar void
shell ore
limber river
shell ore
#

my problem even when i ssh into a box, it is sooo laggy and slow when using the terminal

#

can anyone confirm me on that? i wanna know if its my problem and if i should do smth or what πŸ˜…

limber river
shell ore
#

appearntly my side it is πŸ™‚ πŸ’”

cedar void
rapid sparrow
#

btw new ligolo-ng syntax is different compare to old version, I forgot what is it but you need to add a tun something command

rustic sage
cedar void
limber river
#

name of the movie lol

cedar void
#

Hackers is so great. The Net with Sandra Bullock is underrated too

limber river
#

what you see has nothing to do with hacking

cedar void
#

I did nmap nmap 176.16.6.100 and nmap 176.16.0.0 and could not get any connection

limber river
#

you did something wrong just try again

cedar void
cedar void
#

IT still do not work so I will just try again

severe arrow
#

Hello, on the Broken Auth Skills assessment I have having issues privilege escalating. I keep getting "User cannot have requested role". Ive been trying to drop the cookie after authentication and then refreshing. Have also tried setting the cookie before I authenticate.

#

Im attempting to password spray the admin users I found

shut wraith
#

Hey @molten prawn do u want to see what I tried

molten prawn
#

sure

#

show me what you tried and imma tell you if you are on the right path

#

@shut wraith

shut wraith
molten prawn
#

how are you sending these messages then

#

No spoiling the labs please . Just dm me

twilit ruin
#

i think i found a broken module in Web Attacks > IDOR in Insecure APIs. the server has a index.php page that is using jquery, but doesnt have jquery loaded. i have tried resetting to a new server but the same issue. the issue occurs when trying to click the 'Update profile' button, its supposed to call updateProfile function in script.js but script.js is full of 'ReferenceError' errors since it doesnt know what the $ symbol is without jquery.

frozen mesa
twilit ruin
shell ore
olive depot
#

How do avoid "to many request" while using gobuster?

shell ore
#

ayoooo whats happening pepehandspepehandspepehands

mint lodge
#

i dont really understand what im suppose to do in the WEB SERVICE & API ATTACKS module what is that vpn connection file shit?

molten prawn
#

try restarting the the target

molten prawn
#

whats the problem ?

urban wadi
shell ore
#

nth nth bro πŸ˜‚

#

im just still suffering here w connection for some reason chillkitty

patent oak
shell ore
remote latch
#

what could possibly cause this

shell ore
#

wait huh, you too have the same profile πŸ˜‚

remote latch
shell ore
#

you and lolz

remote latch
#

lmao

shell ore
#

litterlaly same profile πŸ˜‚

remote latch
#

bro got bamboozled

shell ore
remote latch
shell ore
#

omg πŸ˜‚

remote latch
shell ore
remote latch
shell ore
#

cicada

remote latch
#

LETS GO

#

CICADA 3301πŸ”›πŸ”

shell ore
#

yep

rustic sage
#

lets solve it

remote latch
#

test

#

omg thats not forbidden

shell ore
remote latch
remote latch
#

thats nice

shell ore
#

typical, thats MD (mark down)

#

different symbols represent different ways to showcase the text

remote latch
zenith gazelle
#

Hi guys, im doing a soc analyzing a phishing email and I need help with something, if I can send a message with more details let me know.

slow zealot
#

For those who have finished "Introduction to Digital Forensics" , what's the proper way of using Velociraptor to get the IP of the C2? I ended up getting it using other tool because I couldn't figure how to do it with velociraptor

dire abyss
#

stuck on password attacks lab - medium, found a docx file thats protected, ran office2john on it and grabed the password to the file. However is there a way to open the file w the pw? nano, cat and vi dont prompt me to enter the pw. is there a missing flag to either of those commands?

buoyant void
dire abyss
dim wolf
#

you could try opening it in libreoffice

buoyant void
#

Huh weird I had no issue with using Google docs

dire abyss
#

i dont think libreoffice is loaded onto the pwnbox

buoyant void
#

Yeah LibreOffice or O365 should have no issues opening it either

#

Yeah I just checked I even still have that document on my Google drive so I definitely used Google docs for it

dire abyss
#

weird okay let me try that again

buoyant void
#

So just to confirm you got the hash from office2john and then cracked it? If you have the clear text password I can't imagine why any word processor application wouldn't open the document

dire abyss
#

yeah exactly

#

still trying to open it on google docs, file just gets stuck on the upload at 9kb

buoyant void
#

Yeah then just try different applications that can open that format eventually you'll get it to open

upbeat dragon
#

Hey guys, how can i move to a folder after performing a ExtraSids attack, need the flag located under "c:\ExtraSids". Using the following command "ls \academy-ea-dc01.inlanefreight.local\c$" returns he content of C drive, but when i attempt something like "ls \academy-ea-dc01.inlanefreight.local\c:\ExtraSids$" it return an error saying it doesnt exist SOLVED

oblique spoke
#

hi! How do i connect a compromised windows to a payload windows meterpeter reverse tcp session?

patent oak
dire abyss
#

ditched pwnbox and loaded up my personal VM with libre.. got into the docx file, thanks

patent oak
#

Does subbrute always look like it's hanging? Or is it actually hanging? It didn't do anything after I hit enter. The strong silent type perhaps?

tranquil axle
twilit ruin
molten prawn
#

ur welcome

oblique spoke
#

assessment 1. I was able to foothold woth reverse shell

#

now i want to escalate it to meterpreter session wwith msfconsole

#

is there any suggestion how to do it?

fathom pendant
dim wolf
next bronze
#

I think metasploit has the upgrade option, but it doesn't always work

#

do you already have a shell in msf?

oblique spoke
next bronze
#

then yeah to get a meterpreter shell you need to use the msf handler

oblique spoke
#

Thank you fpr your help im gonna try it

patent oak
dire abyss
#

can anyone tell me why I get this error when trying to run ssh2john?

python3 /usr/share/john/ssh2john.py id_rsa > rsa.hash
Traceback (most recent call last):
File "/usr/share/john/ssh2john.py", line 193, in <module>
read_private_key(filename)
File "/usr/share/john/ssh2john.py", line 103, in read_private_key
data = base64.decodestring(data)
AttributeError: module 'base64' has no attribute 'decodestring'

next bronze
#

try with python2/2.7

fathom pendant
#

^

#

A lot of the 2john tools were written in python2

dire abyss
#

that worked, had to install python2 on my vm

olive depot
#

Hmm.. How can i avoid "out of 12 dropped probes since last increase."? while using nmap. Scanning an text file with ips~

dire abyss
#

would -Pn help there?

olive depot
#

Used in flags :3

#

proxychains -sS -Pn -v -A -sC -iL πŸ˜’

tidal kelp
#

On Windows Priv Esc > Windows Server - trying to get the reverse shell running Metasploit.

#

But get the the following error on target

#

any ideas?

crystal steeple
#

hello im stuck on passwords attakcs module in Network services section

#

not stuck but i found the rdp username and password

#

but i get error back when i try to xfreerdp

fathom pendant
#

Each answer in this section is unique

crystal steeple
#

but lemme double check

olive depot
#

@fathom pendant None tbh.. Just went with gobuster gobuster dns -d "" -w ~/wordlists/subdomains.txt -i on a friends homepage ;p then tryes proxychains nmap etc :3.. Forgot might not ask here ^_^ I Apolgize.

fathom pendant
crystal steeple
fathom pendant
#

I've never seen that tbh

olive depot
#

@fathom pendant Ayeh i forgot! Thas why i said sorry mate πŸ™‚

next bronze
tawdry vapor
#

anyone can help me with skills assessments 2 - attacking common applications

crystal steeple
fathom pendant
next bronze
#

yeah ik, there are some modules where you're not supposed to rdp into the linux jump host

next bronze
crystal steeple
#

nvm i got it

#

i was putting right creds but wrong IP omg

#

lmao

next bronze
#

<@&861185840277487616>

solid python
#

GONZO

#

BOOYAAAAA

fathom pendant
#

Domain expansion: proper use of power

solid python
#

Ryoiki Tenkai!

fathom pendant
next bronze
crystal steeple
fathom pendant
#

I didn't get to ping >:[ shakes fist at cloud

molten prawn
#

what happened ?

fathom pendant
#

Someone being a dumbass

molten prawn
#

not unusual Kappa

cedar void
mint lodge
#

well I'm doing the web services and api module and i got no clue what is the VPN connection file or how to use it

lusty thicket
mint lodge
#

are there other modules that explain that before?

lusty thicket
mint lodge
#

because there is no particular order from what i see

fathom pendant
#

If you want a structured path, there's the skill paths and job role paths

mint lodge
#

thanks

fathom pendant
#

It will give you a list of modules in order

mint lodge
#

yeah i saw that thanks

raven lagoon
#

You just need to send me feet pics, afterwards you should see the path on the academy

raven lagoon
#

wdym

fathom pendant
#

Asking for feet pics

raven lagoon
#

I mean its the requisite to achieve the path

#

i dont decide yk

fathom pendant
#

It isn't, and you're just being weird

next bronze
#

kekw where's the ban

mint lodge
#

lmao

fathom pendant
#

Pspsps @solid python

dire abyss
#

why would CME work against SMB on a target while failing with hydra?

fathom pendant
#

Because hydra silly sometimes

#

they likely do something slightly different behind the scenes Β―_(ツ)_/Β―

next bronze
#

what's with the spam today lol

raven lagoon
next bronze
fathom pendant
#

There it is

#

<@&861185840277487616>

#

Bruh

raven lagoon
#

chill bro

raven lagoon
dire abyss
fathom pendant
dire abyss
#

that was.. unexpected lol

fathom pendant
next bronze
#

big yikes

next bronze
next bronze
fathom pendant
#

For hydra*

next bronze
#

it still works I think

fathom pendant
#

Yeah I just mean it's not "reliable"

#

Allegedly

patent oak
#

I thought I'd copy the results so far from subbrute before the Pwnbox or target inevitably dropped. Pressed CTRL + C by accident and closed it. Light a candle for me sumE

#

I waited so long

next bronze
#

why not use something much faster like ffuf or gobustr

patent oak
#

If you were my teacher rather than this vague page then maybe I would

#

πŸ˜„

fathom pendant
next bronze
#

ah, unlucky

patent oak
#

Indeed

fathom pendant
#

it should only take a few minutes Β―_(ツ)_/Β―

patent oak
#

At least I know what a resolver is now...I think

#

I know what it's not

crystal steeple
#

should i really wait for eternity to get ssh password in Password mutations section of the Passwords Attacks module 😦

crystal steeple
#

but its still taking a long time lol

fathom pendant
#

Increasing threads can help too

crystal steeple
#

nvm i just got the password

fathom pendant
#

Just start complaining and it works

dire abyss
#

anywho, whats the best -t argument to use with CME

crystal steeple
next bronze
#

netexec simply isn't designed to be a bruteforce tool

dire abyss
#

damn i was hoping there was a way to speed this up lol

fathom pendant
#

If it's taking too long: it's likely the wrong list

#

Most stuff should happen within 10-20 minutes

raven lagoon
dire abyss
#

it shouldnt be the wrong list, its a mutated pw list from the resources

#

password attacks module

fathom pendant
#

Size of list?

dire abyss
#

how do i get that?

raven lagoon
#

we are all doing password cracking wtf

fathom pendant
#

wc -l

fathom pendant
dire abyss
#

94044

fathom pendant
#

Also bruteforcing is not password cracking

dire abyss
fathom pendant
#

So at this point: patience

raven lagoon
dire abyss
#

yeah looks that way @fathom pendant im curious how often ill have to bruteforce on the actual exam

fathom pendant
#

Personally with cme I'll pipe to grep and do grep -v [-]

fathom pendant
dire abyss
raven lagoon
fathom pendant
raven lagoon
dire abyss
dire abyss
#

so how does everyone like to pass time while you wait for a successful bruteforce attempt?

patent oak
#

Just button mashed my way to the attacking DNS flag LUL

storm stratus
#

HELP!

I am stuck in the Intrusion Detection With Splunk (Real-world Scenario) section. This question has been bugging me for days:

Navigate to http://[Target IP]:8000, open the "Search & Reporting" application, and find through an SPL search against all data any suspicious loads of clr.dll that could indicate a C# injection/execute-assembly attack. Then, again through SPL searches, find if any of the suspicious processes that were returned in the first place were used to temporarily execute code. Enter its name as your answer. Answer format: _.exe

I tried to filter for EventCode 4688 and clr.dll but got no results. I tried to filter with Update.exe but it was of no use. I am literally stuck here and would like to know what are the steps to be taken in order to find the process.

crystal steeple
#

you can get more hints to speed up the process by checking forums HTB, its actually helps

crystal steeple
dire abyss
#

trying the marcielee suggestion with CME '| grep -v [-]' , worked pretty nicely just not used to not having all the feedback constently

raven lagoon
fathom pendant
dire abyss
#

this last lab is killing me.. pw attacks lab - hard.. i found a .kdbx file that im trying to download to my attack host using evil-winrm.Evil-WinRM PS C:\Users\johanna\Documents> download <file>.kdbx /home/<file>.kdbx

download failed

buoyant void
#

I don't remember off the top of my head but I feel like download should be at the hitting of the command maybe

dire abyss
#

what do you mean?

buoyant void
#

Oh nvm I misread the command my bad. In any case, try to specify the absolute path of the file you want to download and the absolute path of the destination, it's probably just a syntax issue

#

For example,

download C:\Users\johanna\Documents\file_name.kdbx /home/file_name.kdbx

dire abyss
#

dude... ugh .. i was missing an 's' in the file name

buoyant void
#

πŸ˜‚ happens to me all the time

dire abyss
#

maybe its time for a break

crystal steeple
#

so i have this question , why not just extract the sam & lsa secrets remotely with crackmapexec instead of copying the 5 hives to our attack machine..

#

remotely seems a lot faster and easier?

dire abyss
#

i think htb just shows you different methods

crystal steeple
#

i see, but i believe there must be some advantage in that method over the remote one idk

#

or maybe just an alternative

fathom pendant
#

Just different ways of doing a similar thing

tight mesa
#

hello there, to Moderator, the lab Windows Server from WPE is not working, looks is something related with the certificate

crystal steeple
fathom pendant
tight mesa
#

ok., I will

grizzled atlas
#

i need extra practive with Bash Scripting does anyone have any refereences ?

short hare
#

Stuck on WINDOWS PRIVILEGE ESCALATION:Pillaging
Question: Log in as Grace and find the cookies for the slacktestapp.com website. Use the cookie to log in into slacktestapp.com from a browser within the RDP session and submit the flag.

Need to transfer the file from rdp to pwnbox but ohh... this is just not happaning..
Can anyone help..?

fathom pendant
#

the question tells you to use a browser in the rdp session

#

(also xfreerdp has the /drive: option)

ember coral
#

Trying to answer the following but having no luck, anyone able to provide some insight?

fathom pendant
#

they're part of multiple groups

ember coral
#

so im better off looking outside of rpcclient?

fathom pendant
#

yes

#

i believe you should be able to rdp into that device

ember coral
fathom pendant
#

What module is it?

ember coral
fathom pendant
#

I don't quite recall but there's stuff on that section that should tell you how to get more info

#

rpc is very basic

ember coral
#

ight i'll keep looking thanks, having to use thes shells vs normal machine is frustrating lol

short hare
frosty spade
#

hey folks running through the attacking enterprise network module and am hittling [-] CCache file is not found. Skipping...
[-] Kerberos SessionError: KRB_AP_ERR_SKEW(Clock skew too great)
anyone have an idea on how to get passed this i tried rdate but theres no time port on the dc cant procedde here

next bronze
#

try ntpdate, make sure you're targeting the right ip

frosty spade
#

proxychains sudo ntpdate -u 172.16.8.0 && date
[proxychains] config file found: /etc/proxychains4.conf
[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4
ntpdig: no eligible servers

#

tried with the target ip and all ips that are up and get this error

#

not able to grab the hash i need for questions complete sol

placid edge
#

anyone have any tips to transfer from a internal network out to the attacker machine?

#

i guess the priciple is the same its just i dont remember what powershell command to use

frosty spade
#

get a meterpreter shell or use nc im not there yet with pivoting and tunneling

next bronze
next bronze
frosty spade
#

yes

placid edge
#

but i cant remember how to send files from windows machine with basic shell to that http server

next bronze
#

the sever supports upload yeah? you need the psupload script if you want to do it through powershell

placid edge
#

what way would you do it?

frosty spade
#

i dont know if not being on the same network is preventing it from working or if theres no port open for time

next bronze
#

no, I sycn clocks through pivot all the time, never been an issue

next bronze
frosty spade
#

i disabled auto sync for vm ran the said command with the dcs ip and its still erroring out

#

date: Not enough valid responses received in time
rdate: Unable to get a reasonable time estimate

next bronze
#

172.16.8.0 is not dc's ip

frosty spade
#

im tunneling through ssh

#

yeah im doing .3

#

not 0

next bronze
#

use faketime to manually change it then

frosty spade
#

i dont know the time to fake

next bronze
#

use nmap --script smb2-time

frosty spade
#

i got a password last changed 2022-06-01 14:32:18.194423 but i dont know dcs current time or date only have 16 mins left on box maybe itll work tomorrow or support will have something differnt to say other then change location on vpn

#

tried fake time with output of nmap script and changing my time zone to england neither worked tried disabling the autosync of vm but it didnt work ill have to redo the module for the 6th time good practice i guess

sleek moss
#

hydra -l marlin@inlanefreight.htb -p pws.list -f 10.129.203.12 pop3 why doesnt this work attacking common services mail

placid edge
#

@next bronze im trying something like copy SAM //172.16.x.x:30007/share with ligolo-ng

next bronze
#

smb always use port 445 on windows, and ligolo can't reverse forward smb traffic

buoyant void
#

Man the Web Proxies module feels like such a come down after the AD module, I've been on this same section for 2 days now just because I can't get in the groove for this

sleek moss
#

w

#

why]\

sick frost
#

hey guys, I got stuck in the Active Directory Skill assessment 1. I'm trying to solve question 4 where I need to connect to MS01 and obtain a flag from it. but I don't seem to get into the system. I tried to use Enter-psssession using the credentials found for the previous question, I get the shell but I'm not able to run any commands on them, only a few commands like systeminfo, whoami works. Even cd and ls doesn't work. I don't understand what the problem is. I thought of using evilwinrm using chisel but commution through chisel is not happening at all. The question is "Submit the contents of the flag.txt file on the Administrator desktop on MS01". It would be great if someone can give me nudge on this one. Thanks

sleek moss
#

Why wont my target spawn in htb

buoyant void
short hare
sleek moss
#

why doesnt my taget spawn i switched vpn but it n owork why

#

how do i connect to port with imap/pop3 and login?

#

β”Œβ”€[βœ—]─[sam@parrot]─[~]
└──╼ $openssl s_client -connect 10.129.21.20:993 -debug -starttls imap

is just empty no prompt

cedar void
soft cedar
next bronze
#

172.16.0.0/16 is huge, that's 172.16.0.0 - 172.16.255.255

#

usually for academy /24 is enough

short hare
#

Just going through an optional exercise

(In windows environment)
I have access to jeff user which have permissions to open cmd and powershell as Administrator
I have the hash of the Administrator.
Question: Get into Administrator RDP session
Condition: Cracking Administrator hash FAILED from all aspects

What fails:-
Trying : reg add HKLM\System\CurrentControlSet\Control\Lsa /t REG_DWORD /v DisableRestrictedAdmin /d 0x0 /f FAILED
Trying: xfreerdp /v:IP /u:Administrator /pth: HASH_OF_ADMINISTRATOR cert:ignore FAILED

Just want to know the approach of you guyz..!!!! how you are gonna deal with this
I have very limited idea regarding this so want to broaden up..!!!!

next bronze
#

wdym by DisableRestrictedAdmin failed

#

just putting failed doesn't really help if you don't include the error

ruby whale
#

Any idea why I cant connect to RDP using TCP vpn , but connect through UPD but its laggy

short hare
next bronze
#

that shouldn't be possible, if you have admin rights, you can edit the registry

novel oxide
#

Hi everyone, I need help with the academy's Windows privilege escalation part.
The question asked is: "What service is listening on 0.0.0.0:21? (two words)"
I used

netstat -ano

to find the service running on port 21, and noted its PID, then used ```bash
tasklist /fi "PID eq <pid-no>"

to know which service was running on that port. The output I got is: 
```bash
Image Name                     PID Session Name        Session#    Mem Usage
========================= ======== ================ =========== ============
FileZilla Server.exe          2096 Services                   0     11,004 K

but this answer is incorrect ?? Can anyone help in this ?

oblique coyote
#

Hallos

tidal kelp
#

On Windows Priv Esc > Windows Server - When trying to set up the meterpreter session I get the following error on target when running the dll

#

Could it we the port in metasploit? Couldn't use the default one (445) since it gives Permission denied

novel oxide
tidal kelp
#

been there

oblique spoke
#

Hi! i am a bit stucket with windows privilege escalation assessment 1. The target appears to be vulnerable but session is not created with the exploit. Can someone please help? msf](Jobs:1 Agents:1) post(multi/recon/local_exploit_suggester) >> exploit

[] 10.129.225.46 - Collecting local exploits for x64/windows...
[
] 10.129.225.46 - 181 exploit checks are being tried...
[+] 10.129.225.46 - exploit/windows/local/bypassuac_sdclt: The target appears to be vulnerable.
[+] 10.129.225.46 - exploit/windows/local/cve_2020_1048_printerdemon: The target appears to be vulnerable.
[+] 10.129.225.46 - exploit/windows/local/cve_2020_1337_printerdemon: The target appears to be vulnerable.
[+] 10.129.225.46 - exploit/windows/local/cve_2022_21999_spoolfool_privesc: The target appears to be vulnerable.
[+] 10.129.225.46 - exploit/windows/local/ms16_032_secondary_logon_handle_privesc: The service is running, but could not be validated.
[+] 10.129.225.46 - exploit/windows/local/ms16_075_reflection: The target appears to be vulnerable.
[+] 10.129.225.46 - exploit/windows/local/ms16_075_reflection_juicy: The target appears to be vulnerable.
[] Running check method for exploit 42 / 42
[
] 10.129.225.46 - Valid modules for session 1:

frozen mesa
#

Password attacks --> Create a mutated wordlist using the files in the ZIP file under "Resources" in the top right corner of this section. Use this wordlist to brute force the password for the user "sam". Once successful, log in with SSH and submit the contents of the flag.txt file as your answer.

Password Mutations; I've used the provided lists to create a mutated list with the next cmd: hashcat password.list -r custom.rule --stdout | sort -u > mut_password.list

lusty thicket
frozen mesa
lusty thicket
#

i might be wrong tho

frozen mesa
#

Yes, that is what i tried.

#

with hashcat

#

hydra -l sam -P password.list ssh://10.129.74.79

lusty thicket
frozen mesa
lusty thicket
#

ssh can be quite slow to attack

frozen mesa
#

will try ftp

lusty thicket
#

great idea!

frozen mesa
#

Thanks for the help!

oblique spoke
#

hi is there a good way to enumerate CLSID?

oblique spoke
#

windows priv skill assessment is a bit frustrating πŸ˜„

glossy timber
#

Can some1 help me with a question in Intro to AD

tranquil axle
frozen mesa
hardy gorge
#

Module : modern web exploitation ,, second order LFI ,, changed the names multiple time using different bypassing techniques but did't work anyone might help

oblique spoke
#

but im gonna just try random clsid-s i think

midnight coyote
#

Bro leaked where he lives

oblique spoke
crisp nacelle
#

how to get burpsuite professional for free?

oblique spoke
#

you crack it

frozen mesa
crisp nacelle
minor stag
#

I'm on the MacOS fundamentals. It's asking me questions about an instance of MacOS and I can't find any way to launch a MacOS instance anywhere on the page. What am I missing?

next bronze
#

you're supposed to use your own mac machine

minor stag
#

Well that was never communicated

#

HTB has used the word "machine" to mean HTB hosted VM in pretty much every other use of the term

next bronze
#

it's in the info page before you start the module

minor stag
#

Where is that blurb located?

next bronze
cedar void
#

Once again, I don't know why this nmap scan is take so long to scan the network with my ligolo-ng tool...even though I am using the correct subnet for the IPV4 address I want the nmap tool to scan.
sudo ip route add 172.16.0.0/16 dev ligolo

nmap 172.16.0.0/16 -sn

I followed the tutorial on the main ligolo-ng github page and followed some tutorials online. I still don't get any ping response back when I ping nor does the nmap tool scan the subnet

minor stag
#

Which started MacOS without the main screen explaining it

next bronze
#

you can still do the questions, just need to google the right thing whatcanisay

minor stag
#

I'll just dust off the macbook. Hopefully the answers are still compatible with newer macOS versions

cedar void
violet spoke
#

Got an issue with skill assessment in the module login brute forcing someone who finish it avaible for dm?

soft cedar
cedar void
# soft cedar Is this a first / second pivot?

I ran the agent.exe with the target machine ... and then it returned a list that contain three Interface...one of them including the 172.16.x.x...the address I am initially trying to pivot

soft cedar
#

so add 172.16.6.0/24 to your IP route list and start the tunnel.

cedar void
soft cedar
soft cedar
cedar void
soft cedar
#

Yeah, remember to start the tunnel before you ping.

soft cedar
cedar void
lean aspen
#

Hey guys,
Regarding the broken authentication module for timing attack exercise, question 3, using timing.py.
I'm getting times completely different everytime that I run the script. Any suggestion or tip? Thanks in advance πŸ™‚

rustic sage
#

Anyone got a hint for the 4th flag at Linux Local Privilege Escalation - Skills Assessment? I've found the creds for t*******m user and logged in to the service manager. Am able to upload stuff but the shells won't work 😦

potent ermine
# frozen mesa Yes, that is what i tried.

a time saving tip is to get rid of|| passwords under 10 characters long||. doing so, Hydra ran the process in 12 min, while I've heard some folks it took close an hour

unreal granite
#

Hi guys i need some help with AD Enumeration & Attacks - Skills Assessment Part I iam at the question 4 iam trying to pivot with chise ,netsh l and the creds i got from the questions before to ms01 via xfreerdp but i just cant get in . I dont understand what iam doing wrong... could someone give me a tip maybe

cedar void
tulip bobcat
#

hey so i'm stuck on a very basic question ....
question: Use cURL from your Pwnbox (not the target machine) to obtain the source code of the "https://www.inlanefreight.com" website and filter all unique paths of that domain. Submit the number of these paths as the answer.
i came up with this regex syntax which gives me all the paths but that's not the answer soo anyone has any suggestions ?
['\"]([^'\"]*inlanefreight.com[^'\"]*)['\"]

#

would inlanefright.com/wp-includes/whatever and inlanefright.com/wp-includes/whatever2 not actually be unique ?

#

it's more of an understanding problem i guess for me πŸ€”

frozen mesa
#

password attacks --> rundll32 C:\windows\system32\comsvcs.dll, MiniDump 672 C:\lsass.dmp full should give me a dump in PS but it does not do anything. The alternative i know via procdump does not work. What did i do wrong?

frozen mesa
soft cedar
next bronze
limber river
#

some1 having issues with rdp ?

#

it's to slow and laggy

lusty thicket
frozen mesa
exotic seal
#

Am stuck with footprint medium lab right now i have been login to adminstrator via rdp but i can not find user HTB's password

#

Any body have some tip where can i find it ?

limber river
limber river
exotic seal
#

Any body can help Am stuck with footprint medium lab right now i have been login to adminstrator via rdp but i can not find user HTB's password

frozen mesa
limber river
soft cedar
soft cedar
cedar void
soft cedar
cedar void
#

Yep, this time for the 172.16.x.x address

soft cedar
cedar void
fathom pendant
#

don't you already have access to that device?

#

isn't that the device that's hooked into your ligolo proxy

soft cedar
soft cedar
shut wraith
#

Session Security

Section: XSS

Hello I'm trying to repeat the methods in the section but I can't make connections through my payload to my php server. It worked once and then it stopped working. Can I DM anyone?

frozen mesa
#

command injections --> advanced obfuscation --> ip=127.0.0.1%0a${IFS}ZmluZCAvdXNyL3NoYXJlLyB8IGdyZXAgcm9vdCB8IGdyZXAgbXlzcWwgfCB0YWlsIC1uIDE=
This payload does not give me an error, just the ping results. What did i do wrong ? I want the output of the cmd

cedar void
soft cedar
cedar void
#

I mean I am not in that network. The network just lists that address when I type 'ifconfig'

soft cedar
cedar void
#

nmap results showed port 80 as a port

soft cedar
soft cedar
limber river
urban wadi
#

i wanna ask you smth

lusty hearth
#

I messaged you about this

urban wadi
#

i got told i must write notes in order to progress, but...maybe my notes can be a lot and unneccessary, or too few, i was doing AD and wrote for every termin in the terminology section

urban wadi
#

like what should i note

soft cedar
urban wadi
#

guess the more i do it, the more i will know what to note

soft cedar
cedar void
# soft cedar run this command on your attack machine ```crackmapexec smb 172.16.6.0/24``` and...

$ crackmapexec smb 172.16.6.0/24
<frozen importlib._bootstrap>:219: RuntimeWarning: greenlet.greenlet size changed, may indicate binary incompatibility. Expected 144 from C header, got 152 from PyObject
<frozen importlib._bootstrap>:219: RuntimeWarning: greenlet.greenlet size changed, may indicate binary incompatibility. Expected 144 from C header, got 152 from PyObject
<frozen importlib._bootstrap>:219: RuntimeWarning: greenlet.greenlet size changed, may indicate binary incompatibility. Expected 144 from C header, got 152 from PyObject
<frozen importlib._bootstrap>:219: RuntimeWarning: greenlet.greenlet size changed, may indicate binary incompatibility. Expected 144 from C header, got 152 from PyObject
<frozen importlib._bootstrap>:219: RuntimeWarning: greenlet.greenlet size changed, may indicate binary incompatibility. Expected 144 from C header, got 152 from PyObject
<frozen importlib._bootstrap>:219: RuntimeWarning: greenlet.greenlet size changed, may indicate binary incompatibility. Expected 144 from C header, got 152 from PyObject
<frozen importlib._bootstrap>:219: RuntimeWarning: greenlet.greenlet size changed, may indicate binary incompatibility. Expected 144 from C header, got 152 from PyObject
<frozen importlib._bootstrap>:219: RuntimeWarning: greenlet.greenlet size changed, may indicate binary incompatibility. Expected 144 from C header, got 152 from PyObject
<frozen importlib._bootstrap>:219: RuntimeWarning: greenlet.greenlet size changed, may indicate binary incompatibility. Expected 144 from C header, got 152 from PyObject
<frozen importlib._bootstrap>:219: RuntimeWarning: greenlet.greenlet size changed, may indicate binary incompatibility. Expected 144 from C header, got 152 from PyObject
[*] Generating SSL certificate
zsh: segmentation fault crackmapexec smb 172.16.6.0/24

soft cedar
cedar void
soft cedar
cedar void
limber river
limber river
cedar void
#

I guess not then since I am on the network

urban wadi
urban wadi
#

i can see your spotify

limber river
soft cedar
#

why?

limber river
whole grotto
#

Hi everyone ! someone can help me on Skill assessment 1 in Attacking common app module ? i found the cgi dir but couldnt find the executable 😦

cedar void
# urban wadi you can

Does this mean crackmapexec tool is not installed on my local machine?? crackmapexec --help 127 β¨―
<frozen importlib._bootstrap>:219: RuntimeWarning: greenlet.greenlet size changed, may indicate binary incompatibility. Expected 144 from C header, got 152 from PyObject
<frozen importlib._bootstrap>:219: RuntimeWarning: greenlet.greenlet size changed, may indicate binary incompatibility. Expected 144 from C header, got 152 from PyObject
<frozen importlib._bootstrap>:219: RuntimeWarning: greenlet.greenlet size changed, may indicate binary incompatibility. Expected 144 from C header, got 152 from PyObject

...

...
[*] Generating SSL certificate
zsh: segmentation fault crackmapexec --help

urban wadi
#

What AD object handles all authentication requests for a domain?
Domain Controllers

Domain Controllers are essentially the brains of an AD network. They handle authentication requests, verify users on the network, and control who can access the various resources in the domain. All access requests are validated via the domain controller and privileged access requests are based on predetermined roles assigned to users. It also enforces security policies and stores information about every other object in the domain.

NATE WHY ITS SAYING ITS WRONGelmofire

urban wadi
#

or if its giving error then just google how to check

urban wadi
#

WHAT it literally didnt accept Domain Controllers but Domain Controller is the right one

#

like...tf?

limber river
#

WHY TF THIS RDP IS TOO SLOW , CAN'T RUN CMD

cursive oriole
#

Hi guys i got stuck in Password Reuse / Default passwords section of Password Attacks module. I got the creds for Sam and logged in via ssh. I tried googling to find default creds and roaming around in all the dirs back and forth but couldnt find password for mysql what should i do. [But i did find something interesting in other two user directories but i am not sure whether its relevant to the task at hand]

urban wadi
#

OMG I ACTUALLY GOT IT RIGHT

urban wadi
cedar void
# urban wadi check with crackmapexec --version

When I first ran crackmapexec --version . It showed the same error. Tried google and chat gpt suggestions to fixing this error . IF anyone here has encountered a similar error on their local machine(in my case, ubuntu virtualbox) , I really like to here how you troubled shooted that error.

limber river
#

and then use nxc instead of crackmapexec

#

they had the same syntax

cursive oriole
# stark vortex you still stuck?

yeap I have a doubt Is it about mutating the previously found passwords or to guess which passwords were reused in the previously cracked services?

stark vortex
#

yeah no that would be a rabbit hole, I recommend double checking the resources they give you in that section for default credentials for services you may have enumerated on the box locally.

cursive oriole
stark vortex
#

yeah no when I was doing the password attacks section I can remember how much of a headache it was

cursive oriole
stark vortex
#

no problem

frozen mesa
frosty spade
#

am i using fake time correctly proxychains sudo faketime '2024-02-20T20:56:55' /bin/date | proxychains GetUserSPNs.py -dc-ip 172.16.8.3 INLANEFREIGHT.LOCAL/mssqladm -request-user ttimmons

#

fuck yeah i got it

cedar void
# limber river and then use nxc instead of crackmapexec

I initially had issues with running that command. Then followed steps suggested by chatgpt online to follow the pipx command. Verified that pipx was installed with 'pipx --version'. Ran the command again and got a new error. Followed the steps that chat gpt suggested and their suggestions did not work.

cedar void
# cedar void I initially had issues with running that command. Then followed steps suggested ...

Also do you think the command that I am running has to do with the version of linux that I am running on my local machine?

User
pipx install nxc
The virtual environment was not created successfully because ensurepip is not
available. On Debian/Ubuntu systems, you need to install the python3-venv
package using the following command.

apt-get install python3-venv

You may need to use sudo with that command. After installing the python3-venv
package, recreate your virtual environment.

Failing command: ['/home/noblegas/.local/share/pipx/shared/bin/python3', '-Im', 'ensurepip', '--upgrade', '--default-pip']

'/usr/bin/python3 -m venv --clear /home/noblegas/.local/share/pipx/shared' failed

uname -a 1 β¨―
Linux kali 5.9.0-kali1-amd64 #1 SMP Debian 5.9.1-1kali2 (2020-10-29) x86_64 GNU/Linux

languid juniper
#

I stopped working on the CPTS three weeks ago because of all the issues with their VPN's and still cannot access targets

#

Is there a channel that is providing an ETA when this will be fixed?

stark vortex
#

Have you contacted support?

languid juniper
#

so many times

#

they tell me to switch the vpn connections.

#

I litterally have them saved on my desktop and switched to each one, spawned a new box each time and attempted connection

#

EU1 UDP is working for the particular module I am on now, but the RDP connection to the target is lagging and keeps disconnecting

stark vortex
#

have you tried in xfreerdp using the flag /network:modem? this helps for me

fathom pendant
#

So saving a bunch of old ones doesn't help

kind turret
#

I can, DM me. And please remove the spoiler if you may.

crystal steeple
#

hello

#

how can u solve the creds hunting in linux section in the password attacks without the hint?

#

how can u find the kira creds?

fathom pendant
#

Enumerating likely

#

The targets are reused within that module

#

So you can go to any one of the linux ones and check /home/ for usernames

amber magnet
#

Hello i am having hard time with the Linux Fundamentals ( Submit the full path of the "xxd" binary.)
i have found it but i think i am writing wrong

craggy spoke
#

who is the author of Recollection sherlock challenge?

acoustic owl
crystal steeple
#

im in Passwd, Shadow & Opasswd
section , i can't crack the root hash with neither rockyou.txt or password.list from resources

fathom pendant
crystal steeple
#

orr wait

#

i tried the mutated list , and even created a mutated list with will's password, ran hashcat, still exhausted

dim wolf
#

anyone else having lab connection issues in the Windows Attacks & Defense module?

dim wolf
fathom pendant
languid fjord
compact patrolBOT
dim wolf
crystal steeple
#

or maybe im doing something wrong

fathom pendant
astral inlet
#

hi πŸ™‚ any idea what could be wrong with my syntax ?

||ffuf -w /opt/useful/SecLists/Discovery/Web-Content/directory-list-2.3-small.txt:FUZZ -u http://faculty.academy.htb:49492/FUZZ -recursion -recursion-depth 1 -e .php,.phps,.php7 -v||

FFuF skill assesment

lusty thicket
#

did you get any errors?

crystal steeple
#

idk what im doing wrong

#

1- i found the hidden folder

astral inlet
fathom pendant
crystal steeple
#

2- trasnfered the pass.bak and shadow bak and unshadowed them in my attack mahine

lusty thicket
crystal steeple
#

tried hashcat with mutated wordlist :v

#

and nothing 😦

limber river
lusty thicket
tight mesa
#

hello there, anyone willing to share a hint about how to find the ldapadmin & confidential.txt files from WPE Assessment I?

#

I'm trying with findstr /SIM /C:" as shown into the section with no success

crystal steeple
#

im done can anyone give me the answer or just the wordlist im hard stuck

fathom pendant
#

the mutated_wordlist should work fine. I'm not at my computer rn to double check and verify but i'm like 99% sure it's in mutated

#

i'm also sure you're using the right mode

#

||1800||

crystal steeple
#

yes im using the exact syntax given

#

||hashcat -m 1800 -a 0 /tmp/unshadowed.hashes /usr/share/wordlists/rockyou.txt -o /tmp/unshadowed.cracked||

#

but with the mutated wordlist

#

the mutated wordlist created by the custom.rule and password.list given

fathom pendant
#

hmm

crystal steeple
#

i also get this error at first before hashcat start running

limber river
raven haven
#

I don't have a solution but can I DM you for help on how you got there? I'm stuck at the transferring ccache stage and nothing seems to work.

tranquil axle
# crystal steeple

Do you know what it looks like when hashcat does crack the pw? Sometimes it doesn’t show that clearly even though it got a hit

crystal steeple
limber river
crystal steeple
crystal steeple
compact halo
#

Unfortunately, I'm back again for assistance from you great HTB peeps: My steps

Attacking Common Services - Easy Box

  1. added ip and domain to /etc/hosts
  2. got the creds <f*Ainlane...> <#>
  3. Extracted docs from webpage and even ftp # showed directory to put file
  4. Got on the database and did the "INTO OUTFILE" command to the correct directory
    <?php system($_REQUEST['cmd']);?> tried shell_exec with ($_GET...([]) as well
  5. Went back to the webpage and tried to run the cmd that I uploaded and I get an error.
    when I try to do the command http://ip-addr/exploit.php?cmd=whoami

Any assistance wuld be appreciated

crystal steeple
sleek moss
#

β”Œβ”€[βœ—]─[sam@parrot]─[~]
└──╼ $smbclient -L //10.129.43.200
do_connect: Connection to 10.129.43.200 failed (Error NT_STATUS_IO_TIMEOUT)
attacking common services easy lab why

sleek moss
#

that doesnt make any diff

#

β”Œβ”€[βœ—]─[sam@parrot]─[~]
└──╼ $smbclient -L -N //10.129.43.200/
do_connect: Connection to 10.129.43.200 failed (Error NT_STATUS_IO_TIMEOUT)
β”Œβ”€[βœ—]─[sam@parrot]─[~]

tawdry escarp
#

I'm struggling with section ICMP Tunneling with SOCKS within the Pivoting module. I can successfully establish the ICMP tunnel, but attempting to RDP to DC results in time outs. The tunnel now states the following, not sure what happened. I'm using the Pwnbox.

[inf]: Packet discarded - outside receive window.
[inf]: Packet discarded - outside receive window.
[inf]: Packet discarded - outside receive window.
onyx sonnet
#

[msf](Jobs:0 Agents:0) exploit(windows/smb/ms17_010_eternalblue) >> options

Module options (exploit/windows/smb/ms17_010_eternalblue):

Name Current Setting Required Description


RHOSTS 10.10.10.40 yes The target host(s), see https://docs.metasploit.com/docs/using-metasploit/basics/using-metasploit.html
RPORT 445 yes The target port (TCP)
SMBDomain no (Optional) The Windows domain to use for authentication. Only affects Windows Server 2008 R2, Windows 7, Windows Embedded Standard 7 target machines.
SMBPass no (Optional) The password for the specified username
SMBUser no (Optional) The username to authenticate as
VERIFY_ARCH false yes Check if remote architecture matches exploit Target. Only affects Windows Server 2008 R2, Windows 7, Windows Embedded Standard 7 target machines.
VERIFY_TARGET false yes Check if remote OS matches exploit Target. Only affects Windows Server 2008 R2, Windows 7, Windows Embedded Standard 7 target machines.

Payload options (windows/x64/meterpreter/reverse_tcp):

Name Current Setting Required Description


EXITFUNC thread yes Exit technique (Accepted: '', seh, thread, process, none)
LHOST 192.168.1.19 yes The listen address (an interface may be specified)
LPORT 4444 yes The listen port

Exploit target:

Id Name


1 Windows 7

onyx sonnet
opal jewel
rustic sage
#

LE BREAD?!

opal jewel
onyx sonnet
opal jewel
#

So whats the actual issue

onyx sonnet
#

My issue is that I want to double check that I'm doing it correctly.

crystal steeple
limber river
#

actual trying to help actual , wtf is going on here ?

next bronze
next bronze
onyx sonnet
#

ah shit

#

Does the LHOST need to be my tun0

crystal steeple
limber river
onyx sonnet
lusty thicket
onyx sonnet
#

Calm down.

opal jewel
#

I guess the world will never know until you run the exploit

onyx sonnet
#

Already dumped hashes my boy

opal jewel
rustic sage
#

Jadin it's actually just basic networking, if you look at the ifconfig on your pwnbox it will show you the interfaces that connect to the SMB server

opal jewel
lusty thicket
fathom pendant
onyx sonnet
limber river
fathom pendant
#

I think for academy it's routed as 10.129.0.0/24 dev tun0

opal jewel
#

sudo ip route show cause we care about stuff

onyx sonnet
opal jewel
rustic sage
#

There's a weird issue in the AD enums and attacks assessment part 2 for some reason after getting the administrator's NTLM hash in the SQL01 machine, you can't evil-winrm or do any pth with any other service with the acquired hash after dumping the LSA with mimikatz. I made sure I wasn't crazy about my approach as I saw someone else do it on youtube for the same assessment. Left me utterly confused as to why it doesn't work on my end.

#

I've been at this for several days now, I'm just going to the next module I'm tired.

lusty thicket
limber river
next bronze
rustic sage
#

i tried psexec too

next bronze
#

afaik evil-winrm doesn't have a local auth option so that won't work for sure

rustic sage
#

I tried smbexec, WMIexec too, nothin, I think there is actually something wrong with the targets, more specifically for me but not others.

#

but it's alright i'll come back to it later.

rustic sage
#

I've seen a case like this before, someone had tried to crack a hash and I was able to do it on my end, but when he tried to do it using the exact same commands/approach it didn't work for him.

#

@limber river how did you end up breaking into MS01 as admin?

limber river
#

||then I dump the hashs uing lsa with mimikatz||

rustic sage
#

yes that's what i did lol it is the correct approach to take.

limber river
limber river
next bronze
#

what I'm gonna say lol

limber river
rustic sage
#

I was trying to pth from the attack box to MS01 directly instead of pth from SQL01 to MS01... is that the issue? I don't know it just wouldn't make any sense to me

next bronze
#

what are you trying to pth with? the local admin hash?

rustic sage
#

hmmm....i don't know :/

#

iight let me go back and try again

next bronze
idle jewel
#

hello everyone, question regarding subscriptions for the academy, is the silver subscription the same wether paid yearly or monthly? Semms montly is cube based right and yearly is access based, am i correct?

crystal steeple
#

still can't crack the root password , its been 4hours and im still stuck on that question sadglas

next bronze
idle jewel
#

Thanks

crystal steeple
opal jewel
#

Fun fact. Up until recently I never knew you can pth with smbclient🀣

#

Smb as protocol yes but not smbclient. Forgot what it is I was doing that prompted me to try it

next bronze
#

the impacket smbclient is much better than the samba smbclient imo

rustic sage
#

i mean were talking a dump of the LSASS service no?

next bronze
#

lsadump::lsa does not dump lsass

#

it dumps the security reg hive

#

lsa != lsass

rustic sage
#

okay

next bronze
#

look for a cleartext cred

fathom pendant
#

your tool is lsass stuff yeah?

next bronze
#

it does both now after an update

fathom pendant
#

ooh nice

limber river
next bronze
#

some of the techniques used yes, and a lot of independent research

nocturne flint
#

Trying MSSQL linked server, and I got an error "Linked servers cannot be used under impersonation without a mapping for the impersonated login." Does that mean that user doesn't have the permission to connect to the linked server?

rustic sage
#

it doesn't lead anywhere though

rustic sage
#

kek yes?

next bronze
#

try it on other hosts

rustic sage
#

OH wow

#

woooooooooooooooooow kek kermit_thnk .... I got it

onyx sonnet
#

@next bronze DM

rustic sage
#

thanks @next bronze

indigo locust
#

PASSWORD ATTACKS >>>
Password Attacks Lab - Medium>>>
Examine the second target and submit the contents of flag.txt in /root/ as the answer.

Hey all, in above question I tried using Hydra to get list of username with possible passwords but it didnt give any results. I also tried using msfconsole to exploit smb but no luck. I'm not sure how else to look for a user or get to root. Can someone help/hint?

shut quest
indigo locust
shut quest
#

Enumeration

fathom pendant
#

step 0) enumerate

indigo locust
#

I enumerated Target and saw 2 ports were open: SSH and SMB

#

knowing that I tried supplying username with password through hydra to ssh to target but no luck. And same for SMB

shut quest
indigo locust
#

ok so I did get a username and password by using crackmapexec through SMB port but the password isnt being accepted and throws """Permission denied, please try again."""

shut quest
shut wraith
#

Session Security

XSS & CSRF Chaining

Both of the scripts in this section don't work properly. They only effect the profile that the payload is stored in and not the profile with the new session

shut wraith
indigo locust
fathom pendant
#

You'll need a document reader like Libre office or whatever it's called

indigo locust
fathom pendant
#

Why are you trying to convert it?

#

I told you a tool that can be used

indigo locust
limber river
limber river
indigo locust
fathom pendant
#

it should be installed

limber river
fathom pendant
#

if not i think it's easily installed with sudo apt install libre-office

limber river
fathom pendant
#

yes

#

at this point in the course i'm assuming they have either a sub or bought cubes

#

which fully unlocks the pwnbox

#

it's sudo apt install libreoffice

#

oh yeah currently parrot repos are a bit borked

#

you'll need to uncomment out lines 71-74 in /etc/apt/sources.list.d/parrot.list

indigo locust
#

Im getting lots of error just to install libreoffice and its so stupid pwnbox doesnt come with one

fathom pendant
#

there's also the website i got Β―_(ツ)_/Β―

#

that literally links to how to install libreoffice on linux

fathom pendant
fathom pendant
#

spent 2 seconds on using google

#

"Install libreoffice"

tight mesa
#

hi there, I escalated privileges into a Windows 2016 server, added a user & assigned to Admin group, then connect to the server via RDP, but when try to chage to a Administrator folder I got a Access Denied message, what could I've done wrong?

harsh epoch
#

is this normal that my VM's uptime is 1-2 min? I cannot do my exercises because VM seems to reboot constantly..

soft cedar
harsh epoch
#

yes

soft cedar
#

What Vm are you using?

#

Did you recently update your Vm?

harsh epoch
#

it's an Academy VM

#

for basic enumeration exercises

#

it's a target system

soft cedar
#

Maybe try restarting the instance / switch vpn servers

harsh epoch
#

will try terminating and starting it again. thank you for your suggestion.

soft cedar
#

If the problem persists, you should contact support

simple socket
#

Hello, I am currently lock in the exercice "ACL Enumeration" in the section "ACTIVE DIRECTORY ENUMERATION & ATTACKS" in the question "What is the ObjectAceType of the first right that the forend user has over the GPO Management group? (two words in the format Word-Word)"

#

I used sharephound and bloodhound and got this graph :