#modules

1 messages Β· Page 204 of 1

simple socket
#

Between the 2 node the write is "GenericWrite"

fathom pendant
#

try using the powershell command

#

it'll take a few minutes

simple socket
#

But I tried with this command :

#

Just to know I used the SID of the group 'GPO Management" or Forend

fathom pendant
#

forend

#

The Object Ace is tied to the user SID over the object it has rights over

simple socket
#

Ahh Thanks

#

Not on the goroup.

#

group ?

#

I tried to understand (search on internet) but "GenericWrite" is ACE ?

#

or ACL ? Thanks

fathom pendant
#

it's the AceType

#

yes

simple socket
#

I got this :

fathom pendant
#

that's the rights over Dagmar Payne

#

this query takes a while to do/finish

simple socket
#

Oh thanks

#

πŸ™‚

fathom pendant
#

see: ObjectDN

simple socket
#

Yes I saw (it's the user "Dagmar Pay,e" ) ?

fathom pendant
#

well it's the User who's given name is Dagmar Payne

#

as you've seen in this module the usernames follow {firstinitial}{lastname}

simple socket
fathom pendant
#

so; with the Object Ace Queries - the Ace right is tied to the SID of the user that has the rights

#

It's how it's tracked in the ACL

simple socket
#

yes but I think the powershell query is lock

fathom pendant
#

it's not

#

hit enter; sometimes it can seem like it's frozen

#

but i can assure you it's doing things

#

as said previously: the query can take a WHILE

simple socket
#

Yes Thanks

#

But ACE/ACL is not easy to understand

fathom pendant
#

it's not inherently intuitive unless you mess with it a bit

soft cedar
# simple socket

by default, the GetDomainObjectACL finds all domain objects that our user(forend) has rights over. You can replace the * with the group name.

simple socket
#

Thanks

fathom pendant
#

that also speed things up

fathom pendant
soft cedar
fathom pendant
#

but it's definitely a good way to better understand how they work at least

#

and that each right is a separate object

simple socket
#

Thanks for the feedback In one another prompt I used this command with the group in parameter but no result

fathom pendant
#

not just a group of rights under an object

fathom pendant
simple socket
#

I said nothing

fathom pendant
#

i'll give you a second to realize

#

(hint, SID)

simple socket
#

Yes sorry in my country it's the morning :p

simple socket
#

Thanks It's worked πŸ™‚

simple socket
#

Really thanks for the help

fathom pendant
#

but in general: The Ace query shows what right the SID has over the "Identity"

simple socket
#

Ok But when you talk about ACE query are you talking about the the Raw Query present in bloodhound ?

#

or Powershell ?

soft cedar
#

Hence, we used Get-DomainObjectACL function to enumerate the ACL rights, and by adding ResolveGUIDs flag, it showed the human-readable format of theΒ ObjectAceType

fathom pendant
#

^

#

otherwise (as also shown in the module/section) you get a string that you'd then have to query in powershell again

soft cedar
austere osprey
#

Hi guys! After cpts and cbbh I would like to dive into tier 3 modules πŸ™‚
Since it's a bit costly to me I wanted to hear your opinion which were your top 10 tier 3 modules?
I would be happy to take them all but don't think can afford it as a student, will be happy hearing your opinion!

fathom pendant
austere osprey
austere osprey
tranquil axle
#

For web you can look into the whole new senor web path I guess

autumn pilot
#

don't unnecessarily overcomplicate things

austere osprey
orchid tiger
#

Hello, I am working on the Linux privesc course > Information Gathering > Environment enumeration (full link : https://academy.hackthebox.com/module/51/section/1592)
The question at the end of this section is asking me to enumerate the machine and discover a flag. I used a little trick to discover the file looking for it's content instead of its name or location but this is rather unintended.

What would be the correct way / enumeration steps and commands to discover the expected flag location ?
Even linpeas didn't get it 😦

twin nacelle
#

INTRO TO NETWORK TRAFFIC ANALYSIS - Guided Lab: Traffic Analysis Workflow :
Apparently the lab asks us to capture traffic from within the provided machine and analyze an incident related to host 172.16.10.90 for bob. But after going through the walkthrough provided in the lab it seems to be a completely different incident with different hosts too ....

dreamy solar
#

Hello !

#

How to connect to do this exercice ! with user Kira but ssh ? rdp ? it is not okay

shadow field
green smelt
#

WINDOWS ATTACKS & DEFENSE
PKI - ESC1

#

did anyone have issue when run certify

dreamy solar
shadow field
ruby whale
#

Module Linux Privilege Escalation
Section Skill Assessment
Anyone tried optional way to gain shell on the system using web ?

dreamy solar
dreamy solar
#

help me it's super long ^^"

cedar void
#

For those using a virtual box instead of one of the lab instances on HTB academy, what virtual box are you using? I am using the virtualbox on Kali linux(Linux kali 5.9.0-kali1-amd64 #1 SMP Debian 5.9.1-1kali2 (2020-10-29) x86_64 GNU/Linux) and I have been having trouble installing the crackmapexec tool on there...as well as instal;ing the suggestions to alternatives with the same syntax(nxc, netexec)

nova nest
#

Hey everyone, I'm exploring options for SMB brute-force attacks and noticed that Hydra only supports SMBv1. Does anyone know of alternative tools or methods that work with SMBv2 or SMB3? Any suggestions would be greatly appreciated!

next bronze
nova nest
#

thx bro! i did it with crackmapexec, but i will try the hydra solution too !

next bronze
next bronze
soft cedar
dreamy solar
#

I find finally thanks

dusky cloud
#

yo

molten prawn
#

i need a little help with windows privilege escalation module - 3rd section, situational awareness. either im extremely stupid or the question is disastrously inappropriately asked.

#

nobody even talks about it in the htb forum kekhands

shut wraith
#

#Session Security
XSS & CSRF Chaining

Both of the scripts in this section don't work properly. They only effect the profile that the payload is stored in and not the profile with the new session

Anyone please free for DM?

hearty zinc
#

Hello, i am doing footprinting medium challenge - when i xfreerdp i get: Failed to open display: :1
[Please check that the $DISPLAY environment variable is properly set. , did not find any helpful solution for this issue, how do i fix this? Kind regard!

rotund steppe
#

Is there something wrong with the box or is it me? Also tried ```SQL (ILF-SQL-01\backdoor dbo@master)> SELECT name FROM master.dbo.sysdatabases
[%] SELECT name FROM master.dbo.sysdatabases

vale tusk
#

#Linux privilege escalation
Python library hijacking

Give a hint please.
I cant find the directory with write permissions or something else.
User doesn't have permission to setenv and permission to write in python directories

lusty thicket
short hare
short hare
shut wraith
lean aspen
#

I'm using that script and the list of usernames the same for the other questions but the thing is that there's not much a difference on response timings

vale tusk
#

@short hare @lusty thicket thnx, solved

olive depot
#

Hmm.. Where i am suppose to find the /etc/host file? If i try cat it it just says "multi on"

acoustic owl
#

The computer file hosts is an operating system file that maps hostnames to IP addresses. It is a plain text file. Originally a file named HOSTS.TXT was manually maintained and made available via file sharing by Stanford Research Institute for the ARPANET membership, containing the hostnames and address of hosts as contributed for inclusion by me...

olive depot
#

Oh my.. Sorry, my bad missed the last "s" :3

icy hazel
#

Hi guys, I was just doing an academy question on DLL Hijacking and had to find the process responsible for it. I really didn't know what to be looking for and any extra research I did said look for unusual looking executables, I eventually got it but don't understand how I'd have done it in a real scenario.
Any tips on what to be looking for when using the event viewer?

fleet moth
#

Module - Password Attacks
Section - Password Mutations

can anyone who did this part tell me how long should i wait before knowing that the password list is not right?

I do not have 17hr+

cyan maple
#

On web requests, POST, the website given to find the flag isn't functioning correctly for me. First picture is my side, second is the explanation.

ruby whale
#

Any idea how I can solve this ? While using TCP I can't connect to RDP , with UDP I can connect but it is laggy.

stark vortex
#

you can also up the thread count

stark vortex
fleet moth
stark vortex
#

that's why I said bruteforce a different service

#

|| ftp ||

compact patrolBOT
placid edge
#

anyone here that could give me a hand. I want to download SAM,Security and System files off the machine im on, but my shell is really bad. How do i download things off a machine instead of uploading to it?

#

i would need some kind of http webserver no?

#

i have a metasploit shell but the download command doest seem to work

soft cedar
placid edge
#

the command in msfconsole

#

when i have a shell i can use the download option but it doesnt work. The output is like

download c:\windows\system32\config\SAM

placid edge
#

Usage: download [src] [dst]

#

i have tried to set the dst but still issues

soft cedar
#

Just try download [file] and see if it works?

#

It should save in your current working dir.

placid edge
#
PS C:\users\public> download c:\windows\system32\config\SAM

Usage: download [src] [dst]

Downloads remote files to the local machine.
Only files are supported.
hollow lake
#

the SAM file should be locked while the OS is running, isn't it?

green smelt
#

anyone have the issue with running Rubes on module : Windows Attack and defense , PKI-ESC1 :

soft cedar
placid edge
#

nah its just a basic shell

hollow lake
#

if you have meterpreter you could try with hashdump

soft cedar
#

Try

download \\server\share\file.txt C:\local\path\file.txt

This is from ChatGPT.

placid edge
#

Essentially i am stuck on getting this question.

Submit the contents of the flag.txt file on the Administrator Desktop on the MS01 host.

On Active Directory Enumeration And Attacks - Skills assesment 2

hollow lake
#

I didn't do that module yet, usually most of what you need is covered in the modules..I remember there is even a module specifically for learning how to download stuff, I didn't start the path yet, cuz I'm doing cbbh. Anyway SAM is a special file, it can't be copied like any other file, you need to use some other ways

placid edge
#

i am system user tho so

#

it should be fine

compact valve
#

Hi, I am stuck on the Password-Attacks module question where it asks me to use sam's credentials to find the credentials for MySQL and after doing some OSINT, I found that it is in the my.cnf file. However, when I attempted to open the file it did not have the credentials for mysql. I tried root root as the login and it also was not accepted by HTB. Can anyone help me find the login credentials for mysql?

fathom pendant
compact patrolBOT
green smelt
#

did the support is on maintance

compact valve
#

😦

ruby whale
#

I am stuck on Attacking Common Application Modules, Attacking thick client application , I got monta.ps1 , but could not run it run getting error to open powershell tried resetting the target but failed to start powershell any help?

fathom pendant
#

There's more to look for on the provided cheatsheet from this section

compact valve
fathom pendant
#

It's not gonna be in a file on the system

#

There's literally a "default credential cheatsheet" provided by the section

#

That you can look for MySQL in and find a handful of username/password combos

cyan maple
#

I also do not get the same packet in the network tab as the explanation shows

#

when i try to search a city

stark vortex
#

that's weird, I would try just resetting the machine, but if you've done that already you might wanna contact support about it, I haven't done that module so I really can't help you any further

cyan maple
#

Alright, I already tried resetting the machine but I'll contact support

#

thanks anyway

stark vortex
#

np dude, hope you find a solution

autumn palm
#

Anyone who completed the Skills Assessment on Kerberus Attacks that can help me figure out the last task?
What's the content of the file: \\DC01\Secret Share\flag.txt?

rustic sage
#

Has anyone made light mode?

ruby whale
# ruby whale I am stuck on Attacking Common Application Modules, Attacking thick client appli...

I did solve the Attacking thick client application section.
What I got from the section, that application runs a process -> it writes some files as its flow ( we change temp permission to keep files even after process ends) . The flow is such that it delete the files, we modify bat to not delete files, run ps script to get the exe, use x64dbg to check assembly level code, than see that at memory level something is loaded .
Is the original exe script being loaded here?
And after dumping from memory we decompile using dnspy?

Can someone elaborate on this?

placid edge
#

i have system shell

river birch
#

Hi! I'm currently debugging in GDB and would like "print $rax" to be executed and displayed when a breakpoint is reached. But unfortunately I don't get the output when I append the commands to the breakpoint using "commands". Example:

$commands 1

print $rax
end
$

I don't get any output after I continue with "continue". What could be the reason? Thanks in advance!

placid edge
astral inlet
#

dm

maiden field
#

In the assembly module each time I try to compile my assembly and run it I get this error anyone know why ? Even with the base program they gave me I still have this error

river birch
maiden field
#

Ok thanks !

#

I knew it worked with gdb but I was asking myself why I was never able to run it like that

river birch
rustic sage
#

Can you delete items from a table using a PUT request?

#

shouldn't curl -X PATCH http://94.237.56.248:35386/api.php/city/Evans_City -d '{"city_name":"flag"}' | jq this work

amber cypress
#

hello I'm doing the AD enumeration and attacks module and I'm getting different results from the same command, I've also noticed that in Wireshark:

#

I wasn't able to find these hosts with tcpdump or wireshark

#

is this a known issue?

fathom pendant
amber cypress
#

ah... it's literally right there x) i didn't read it

lusty thicket
rustic sage
#

maybe they meant DELETE is a post request πŸ€”

fathom pendant
#

Delete is a type of request

autumn palm
#

@thorn urchin Sorry for the ping. Got time for a question on the Kerberos Attacks skills assessment?

rustic sage
#

do request names like POST or GET have to be all caps

rustic sage
#

I got a huge problem.

First, try to update any city's name to be 'flag'. Then, delete any city. Once done, search for a city named 'flag' to get the flag.
when I run curl http://94.237.56.248:35386/api.php/city/flag
i get []

pulsar oyster
#

you updated a city to flag and deleted another city? the response is JSON so you need to pipe to jq

rustic sage
#

[] is the responce

lusty thicket
rustic sage
#

it returns all cities though

rustic sage
#

let me try what you said

rustic sage
#

what if I accidently deleted the flag

lusty thicket
#

idk

thorn urchin
rustic sage
#

now it won't connect to my target

#

it pings just fine though

#

its probably because it wants me to use the built in terminal. thats dumb. and it worked on previous ip which makes 0 sense to me

autumn palm
#

@thorn urchin
C:\Tools>Rubeus.exe monitor /interval:5 /nowrap

C:\Tools>Rubeus.exe renew /ptt /ticket:<TICKET>
[+] Ticket successfully imported!

C:\Tools\klist
#4> Client: j***.k*** @ INLANEFREIGHT.LOCAL
Server: krbtgt/dc01.inlanefreight.local @ INLANEFREIGHT.LOCAL
KerbTicket Encryption Type: AES-256-CTS-HMAC-SHA1-96
Ticket Flags 0x60a50000 -> forwardable forwarded renewable pre_authent ok_as_delegate name_canonicalize
Start Time: 2/21/2024 12:53:47 (local)
End Time: 2/21/2024 22:51:34 (local)
Renew Time: 2/28/2024 12:49:13 (local)
Session Key Type: AES-256-CTS-HMAC-SHA1-96
Cache Flags: 0
Kdc Called: DC01.INLANEFREIGHT.LOCAL

C:\Tools>more \dc01.inlanefreight.local\c$
Access Denied

So as the a*.j* user has administrative rights we've compromised server01 and are able to intercept the TGT ticket passed by j*.k*. However I cannot seem to figure out to use this to perform priviilege escalation to acess the "Secret Share" on the Domain Controller

thorn urchin
#

Well youre trying to access the C$ not the secret share there for starters

#

@autumn palm

autumn palm
#
Access Denied```

Edit. 

Just figured it out. The shared drive is obviously not found under C$...
thorn urchin
autumn palm
#

Thanks anyway. πŸ™‚

thorn urchin
#

ye lol

rustic sage
#

can someone give example of using PATCH

acoustic owl
#

Hopefully never

rustic sage
#

its always been a .txt

#

whats Ffluf

buoyant void
rustic sage
buoyant void
#

Not exactly a spider will just crawl a web application usually, but fuzzing can help you find hidden directories for example among other things

dreamy solar
#

Hello I do the indeed the course but it is not okay why?

astral inlet
#

chmod +x @dreamy solar

gleaming bluff
#

yo

#

im new to hacking can someone help me out

#

just tell me where to get started

rustic sage
compact patrolBOT
thorn urchin
#

ping uses ICMP. most pivoting tools can only transport tcp and fewer can transport tcp/udp. Ones that can transport ICMP are even rarer

#

sshuttle creates a simulated VPN but it is not in fact a real VPN

buoyant void
low crescent
#

Module: Abusing HTTP Misconfigurations
Section: Advanced Cache Poisoning Techniques

I'm having issues submitting a payload to fatget.wcp.htb webapp because the unkeyed parameters are getting URL encoded on the view, so there is no reflected XSS. The only parameter that actually yields XSS is the language, which is the keyed parameter so it's of no use. Tried working with both ref and content, but no success.

thorn urchin
buoyant void
thorn urchin
#

there are some situations where its not ideal

#

but its my goto for sure

astral inlet
#

hi skill assesment brute force login :

||hydra -l user -P /usr/share/wordlists/rockyou.txt -f 94.237.62.195 -s 55399 http-post-form β€œ/admin_login.php:user=^USER^&pass=^PASS^:F=<form name='log-in'” -I -v||

i get this error :

[ERROR] optional parameter must start with a '/' slash!

any idea why ?

hollow lake
astral inlet
#

now i get false positives πŸ˜„

#

i h8 hydra for this

astral inlet
#

done

astral inlet
#

zap solved it

polar wagon
#

Hello everyone - I am looking for little help with Command Injection Skills Assessment. I am able to find the vulnerable method but I am unable to exploit it. Your help is greatly appreciated. The command I am using /index.php?to=tmp&from=2380029473.txt&finish=1&move=1%7c%7cbash<<<$(base64%09-d<<<bXYgJHtQQVRIOjA6MX1mbGFnLnR4dCAke1BBVEg6MDoxfXZhciR7UEFUSDowOjF9d3d3JHtQQVRI%09OjA6MX1odG1sJHtQQVRIOjA6MX1maWxlcyR7UEFUSDowOjF9dG1w)

astral inlet
final kite
#

hey

#

anyone no why nikto is giving me 0 hosts scanned when running it

broken zephyr
#

@polar wagon injection skill assesment in wich module?

runic plover
#

Anyone willing to give a nudge in the right direction for the last module in footprinting?

fathom pendant
#

You mean the hard lab?

#

Start walking.

ember coral
#

For Bleeding Edge Vulnerabilities in the AD enum and attack course is there a easier way to practice these attacks? ATtack01 machine doesn't have any of tools installed on it, cant install via git hub becuase DNS cant resolve on it, and even if you transfer them over from main box the dependencies arent installed. Best case just to deal wit setting up a pivot every time and just using my machine?

next bronze
#

you can set up a pivot but getting relay to work over a pivot would be tricky

#

if you want to play with relaying more there's the ntlm relay module

runic plover
fathom pendant
fathom pendant
#

πŸ‘

#

Don't forget, you can always refer back to sections if you need to make sure your notes aren't missing something important

runic plover
# fathom pendant πŸ‘

I got the walk done found a nice community and also tried some sshing (to no avail) still not making much progress. I have the info from such walk but not sure what to do with it. Also the id_rsa keys not workig even after chmod ....

fathom pendant
runic plover
#

Yea

#

So thats why im confused

fathom pendant
#

Make sure you're also using the right user (same username of how you got the rsa key)

runic plover
#

Yea im using the right one

#

I think..

#

I didnt have to use a name to get the key... Maybe thats where im wrong

fathom pendant
#

Well the walk should have revealed a name and a password if I'm recalling

#

The steps and services involved are mostly outlined in the engagement brief for the lab

short hare
#

On to Windows Privilege Escalation Skills Assessment - Part I

Question: Which two KBs are installed on the target system? (Answer format: 3210000&3210060)

After nmap and visiting this and pinging provide nothing of interest
It's been a while at this point -_-
Any clue how to move forward from here..!!

heavy marsh
#

Why is the ZAP HUD so inconsistent?

#

Just this, no HUD

fathom pendant
heavy marsh
#

Module shows I should be getting something like this:

fathom pendant
heavy marsh
#

And then at one point i got a message saying "cannot /GET ping" or something to that effect.

fathom pendant
#

Read the section

heavy marsh
#

I might just stick to burp. Any feedback on ZAP?

fathom pendant
#

Apparently zap just sucks idk

fossil birch
#

Hello Sir, How can I solve this question? Determine the registry key used for persistence and enter it as your answer.
this question on "Introduction to Digital Forensics" module.

tropic relic
#

For Attacking Enterprise Networks, there is a certain machine that wil allow one to get a shell two ways. Both shells are service accounts and both have SeImpersonatePrivilege enabled. However, only one will allow you to priv esc via PrintSpoofer or JuicyPotatoNG. The one that fails to priv esc, will run the exploit and show a success message, but the account isn't elevated to nt authority/system. Is there a good explanation for this? Something I can read? Not knowing why one worked and the other didn't is bothering me.

ruby whale
#

I did solve the Attacking thick client application section.
What I got from the section, that application runs a process -> it writes some files as its flow ( we change temp permission to keep files even after process ends) . The flow is such that it delete the files, we modify bat to not delete files, run ps script to get the exe, use x64dbg to check assembly level code, than see that at memory level something is loaded .
Is the original exe script being loaded here?
And after dumping from memory we decompile using dnspy?

Can someone elaborate on this?

fathom pendant
short hare
# ruby whale I did solve the Attacking thick client application section. What I got from the ...

First question : Yes you just modify the script not to delete the file after execution. Here you get those before execution. These tools simulates the entire process and shows you output for debugging/other stuffs

Second Question: After dumping memory file, we de4dot.exe to to make it readable for dnSpy.exe. Then opening this cleaned memeory dump in dnSpy.exe reveals the application running behind this. As it stored the password locally and fetching, we just used dnSpy.exe to reveal those and hence the password

runic plover
fathom pendant
#

Np

short hare
ruby whale
sleek moss
#

β”Œβ”€[sam@parrot]─[~]
└──╼ $smbclient -L 10.129.44.223
Password for [WORKGROUP\sam]:

Sharename       Type      Comment
---------       ----      -------
ADMIN$          Disk      Remote Admin
C$              Disk      Default share
Home            Disk      
IPC$            IPC       Remote IPC

Reconnecting with SMB1 for workgroup listing.
do_connect: Connection to 10.129.44.223 failed (Error NT_STATUS_IO_TIMEOUT)
Unable to connect with SMB1 -- no workgroup available

#

can sum1 help

fathom pendant
#

When you do -L btw it quits out after listing

#

Looks like it's a connection issue

#

Β―_(ツ)_/Β―

sleek moss
#

i reset like a billion t imes

#

dis is cray cray

fathom pendant
#

Try changing vpn region, also waiting a few minutes after spawning

rustic sage
#

Can someone please help me

fathom pendant
#

With?

#

We can't help with a problem you don't ask

rustic sage
#

Someone keeps harassing my girlfriend

fathom pendant
#

Gonna stop you right there

#

Go to the police/platform they are being harassed on

sleek moss
#

ok danke

fathom pendant
#

There's nothing we can do for you

rustic sage
#

What do I do then they blocked me

#

I’m so lost

sleek moss
#

wdym

short hare
# ruby whale `Is the original exe script being loaded here? ` This was the question regarding...

Original Script : restart_oracle_service.exe and restart-service.exe both loaded in the memory actually

Explaination:
restart_oracle_service.exe runs to create monta.ps1, oracle.txt and restart-service.exe. Also during execution of restart_oracle_service.exe it spawns a powershell to run restart-service.exe hence the rest process goes.

that's how you run the restart_oracle_service.exe and restart_oracle_service.exe runs the restart-service.exe.
As far I know any program runs in windows at least for once it is loaded in the memory

For Proof:
look at the text 5435.bat generated by restart_oracle_service.exe

I think now it will be clear

It's indeed a tough one πŸ˜…

rustic sage
#

My girlfriend is being harassed

supple patio
twin kelp
#

Does htb do maintenance everyday at this time? My target ip never loads around this around

rustic sage
#

I don’t want to do that I just want to get his account banned

#

Or hacked

sleek moss
#

why dont u go beat him up

rustic sage
#

He lives somewhere else

#

Cyber bullying

supple patio
twin kelp
rustic sage
#

What do I do I thought y’all could hack him

sleek moss
#

bro stop asking

#

u already got ur answer.....

rustic sage
#

Sorry

#

My bad

supple patio
rustic sage
#

I didn’t mean any harm

ruby whale
limber river
steady bone
#

Just wondering why there is no public writeups for pro labs in the google?

fathom pendant
limber river
fathom pendant
#

Your only recourse is going to the authorities and platforms involved. We cannot help you as any action like that, justified or not, is illegal

fathom pendant
steady bone
fathom pendant
#

It's More that it's paid, active content

#

And having a writeup bypasses any actual skill

limber river
fathom pendant
#

They aren't traditional certs

#

Just "congrats you pwned it"

#

Which, in the grand scheme of things, doesn't really mean much as they aren't a timed activity

#

You can pwn it after a year, or after a few weeks

#

It's moreso just additional content to practice on

#

And it follows the overarching content policy that active content is barred from having writeups

#

The only writeups that exist for them are on Enterprise platforms available only to the lab admin

steady bone
#

@fathom pendant thanks for the clarification

fathom pendant
#

If you follow instructions in #welcome you can gain access to prolab channels where you can ask for nudges

zenith mango
#

CPTS path would probably be beneficial too.

limber river
zenith mango
#

Yes it is. Just wrapped up AD enumeration and attacks. That second scenario had me tripped up for about a week and a half. But, everything needed to solve it, was in the material. Just had to go back and read my notes a lot.

limber river
#

yeah the web shell in the first Skill assessment great scenario

sleek moss
#

\└──╼ $hydra -l simon -P random.txt mssql://10.129.85.162 -t1
Hydra v9.4 (c) 2022 by van Hauser/THC & David Maciejak - Please do not use in military or secret service organizations, or for illegal purposes (this is non-binding, these *** ignore laws and ethics anyway).

Hydra (https://github.com/vanhauser-thc/thc-hydra) starting at 2024-02-21 19:55:33
[WARNING] Restorefile (you have 10 seconds to abort... (use option -I to skip waiting)) from a previous session found, to prevent overwriting, ./hydra.restore
[DATA] max 1 task per 1 server, overall 1 task, 7 login tries (l:1/p:7), ~7 tries per task
[DATA] attacking mssql://10.129.85.162:1433/
[ERROR] Child with pid 2672 terminating, can not connect
[ERROR] Child with pid 2674 terminating, can not connect
[ERROR] Child with pid 2677 terminating, can not connect
[ERROR] all children were disabled due too many connection errors
0 of 1 target completed, 0 valid password found
Hydra (https://github.com/vanhauser-thc/thc-hydra) finished at 2024-02-21 19:56:11

GitHub

hydra. Contribute to vanhauser-thc/thc-hydra development by creating an account on GitHub.

#

can sum1 tell me why it dont work with hdyra?

next bronze
#

why are you burting mssql, it has different authentication modes, try other services

fathom pendant
#

^

fathom pendant
#

It failed bc it couldn't connect to the service

plucky latch
limber river
misty bough
#

anyone have a .txt of tier 0 notes to send 2 me?

rustic sage
#

could u all suggest best hacking book ??

autumn pilot
#

there is no such thing, every book has its benefits and drawbacks

ruby whale
fathom pendant
#

Do a Google dork: inlanefreight site:hacktricks.xyz

#

(Inlanefreight is a fictitious company that htb uses in its academy content)

ruby whale
fathom pendant
#

To be specific they site htb academy as the reference

#

But its like, barely altered

fathom pendant
#

Hacktricks is more of a reference guide than a "read this" book

#

You find a thing, and look it up

#

Like LoLBAS and gtfobins

limber river
lusty thicket
frozen mesa
#

Footprinting - DNS. Last question of the task : What is the FQDN of the host where the last octet ends with "x.x.x.203"?
I've tried 4 different wordlists but no results that end with 203. Anybody suggestion what i did do wrong?
||dnsenum --dnsserver 10.129.239.38 --enum -p 0 -s 0 -o subdomains.txt -f /opt/useful/SecLists/Discovery/DNS/subdomains-top1million-110000.txt inlanefreight.htb||
Found subdomains: ||app.inlanefreight.htb: 10.129.18.15
dev.inlanefreight.htb: 10.12.0.1
internal.inlanefreight.htb: 10.129.1.6
mail1.inlanefreight.htb: 10.129.18.201
ns.inlanefreight.htb: 127.0.0.1||

acoustic owl
#

Your List is much tooo big
Take the smallest

sudden sundial
#

idk man

frozen mesa
#

Footprinting --> IMAP --> Try to access the emails on the IMAP server and submit the flag as the answer. (Format: HTB{...})

I try to connect, get some info but dont know what todo next to get the answer(s). Still looking for the admin emailaddress too. Anyone a nudge?

neon dagger
digital junco
#

Hi guys

#

can someone help me with one question from the Broken Authentication module?

#

Log in to the target application and tamper the rememberme token to give yourself super user privileges. After escalating privileges, submit the flag as your answer.

#

I got the PHP cookie and try to decode it but nothing happen

#

I see that when I logout I got one HTBPERSISTENT cookie but

#

again, nothing

#

the cookie is also in plain text so I don't know what to do exactly...

#
printf("Please Help!\n")
frozen mesa
cedar void
#

when doing hackthebox academy modules....are you guys more likely to use the lab instance or your own VirtualBox lab?

frozen mesa
#

I prefer pwnbox, did use my own VM before but the pwnbox is comfy, few scripts so i get all my tools in an instant ready and personalized.

errant elbow
#

Can I DM someone for AD Enumeration & Attacks - Skills Assessment Part II ? Im stuck at Q11

neon dagger
snow ridge
#

Re doing Attacking enterprise networks and I get errors with this command proxychains enum4linux -U -P 172.16.8.3

ERROR: nmblookup is not in your path.  Check that samba package is installed
ERROR: net is not in your path.  Check that samba package is installed
ERROR: rpcclient is not in your path.  Check that samba package is installed
ERROR: smbclient is not in your path.  Check that samba package is installed
WARNING: polenum is not in your path.  Check that package is installed and your PATH is sane.
WARNING: ldapsearch is not in your path.  Check that package is installed and your PATH is sane.
For Gentoo, you need to install the "samba" package
For Debian, you need to install the "smbclient" package

I already checked and all of those tools are installed and located in $PATH variable. Any ideas? I don't remember having any issues when I first did this module

!! Found fix by using -q flag with proxychains

frozen mesa
placid edge
#

i realllllllly hope the exam isnt as slow as these modules man

snow ridge
soft cedar
placid edge
#

cbbh was smooth

#

but the modules where also smooth so

#

not really comparable when handling websites and ad

patent oak
#

Hi guys, I'm on Remote/Reverse Port Forwarding with SSH. I think I'm doing the right thing but am not sure if it's me or the machine NotLikeThis

#

I have everything set up to the point that I can port scan the target through the pivot

#

I presume it's a job for RDP from here but it won't connect

#

I need access to the Windows target to download the payload

#

Could someone please let me know if it's me stupid or machine stupid

patent oak
#

Nevermind πŸ™„

#

It was me stupid

short hare
#

Hey can anyone points out why certuitl is giving this error. Neither certutil or curl is working

Trying to upload juicypotato.exe to tragert for priv esc

#

I mad really getting mad with this..!

Just for this little thing stuck for hours

#

Even if I want to create a text file it doesn't show but the command get executed
Look..

next bronze
#

save to another dir other than c root, it needs elevated privileges

river birch
#

Hi, I'm currently here -> https://academy.hackthebox.com/module/details/85 trying to complete the competency assessment. Unfortunately I haven't been able to get anywhere for 5 days. Has anyone already completed this and could you please help me? Thank you very much!

next bronze
river birch
#

Oh, I see you answered that once. I had already searched here, but unfortunately I missed this answer. Unfortunately, after copying from rax to xor, the shellcode is always unusable. And that's why I wonder if I'm missing something. Here is my current code:

#

prepair:
mov rbx,0x2144d2144d2144d2 ; In RBX ist der SchlΓΌssel gespeichert
mov rcx, 14 ; 14 DurchlΓ€ufe im Loop
mov rdx, [rsp] ; [inhalt] ohne [] die Adresse

decodeLoop:
mov rax, rdx
xor rax, rbx
add rdx, 8 ; Zeiger um 8 Bit Byte verschieben/erhΓΆhen
loop decodeLoop

end:
mov rax, 60
mov rdi, 0
syscall

#

If I then do a break on β€œloop decodeLoop” and see what $rax is. And then putting them all together one after the other always results in unusable shell code.

#

Hmm, should I delete the code here?

next bronze
#

mov rdx, [rsp] copies the value in the pointer to rdx, and not the pointer itself, so +8 would just simply add the value instead of moving the pointer

#

also why mov rax, rdx, this instruction is unnecessary

#

you should modify the given code and don't over complicate things

prisma spruce
#

Did they actually go over your exam again, or did they ignore your email?

river birch
next bronze
#

correct

river birch
next bronze
next flame
#

Hi everyone, y

dreamy solar
#

Hello why I don't do my scp request ? help me plz

vital adder
#

use scp -r for copying directory

fathom pendant
#

^

#

If you ls -la chisel I have a sneaking suspicion that it'll have d at the front of its perms

river birch
paper basalt
#

Anyone else not able to spawn targets?

#

"Target is spawning..." for 5 mins

inland shoal
#

just bought academy student monthly plan, the grind is on πŸ”₯

paper crag
#

Anyone available for a hint on the Whitebox Attacks Race Condition section....can't seem to be able to get anywhere with it at the moment...

patent oak
soft cedar
faint gulch
# paper basalt "Target is spawning..." for 5 mins

I am having issues with the targets the last 3 days. They are spawning but everything, e.g. ssh to them, is extremely slow (and I mean extremely extremely slow). I have tried switching udp/tcp files, eu 1 to eu 2, etc. but it still the same.

patent oak
#

I've had my soul taken so many times today because RDP won't connect or rev shells

faint gulch
#

You are not alone

patent oak
#

Just jumped back on the Pwnbox and it works first time. No doubt it's my fault

paper basalt
#

no it was not

#

its been like this the last week or so i want to say

#

and it becomes worse as you get near peak hours

#

its basically impossible to do anything around EU peak hours now, its really really sad

patent oak
#

I'm about 40% through CPTS and I've found that it really depends what you're doing and your connection too. I had days where RDP was making me wait ages for each keystroke

patent oak
paper basalt
#

nah its blatantly obvious that HTB's infrastructure cant handle the load

patent oak
#

It's annoying because the lessons are already vague enough without having to guess if it's your connection.

#

Vague in a good way

#

Ah well. I'm sure it'll work itself out πŸ˜„

paper basalt
#

yeah, the content is soooo good, and up untill fairly recently, the infrastructure was good too

#

but its infuriating recently. Having to RDP back into your target every 10 seconds because connection drops etc etc

#

and yes, ive tried every single VPN, every single pwnbox location etc etc

faint gulch
#

Well, I am sure that everything will be back to normal soon!

shrewd tangle
#

I could do with some explanation for a Getting Started: Privilege Escalation

I got stuck going in circles trying to get a reverse shell or run a script and ended up watching a kinda tutorial that nudged me in the right direction:

Although I was running sudo -l I didn't really understand or could research what I was meant to to with the output but I got through the task in the end.

Here's my notes output if anyone could explain / breakdown what the sudo -l output meant and what ||/bin/bash|| was doing?

faint gulch
high reef
#

has anyone done this room

#

my objective

#

i dont see a home dir

#

and when i do home i dont see a flag.txt

shrewd tangle
stark vortex
faint gulch
#

Here you just trying to type home as a command, you are not listing the directory as @stark vortex mentioned. ls /home would be worth trying.

high reef
#

i get invalid here

stark vortex
#

try a + or url encode the space character so that the entire string is together and highlighted in burp

faint gulch
# high reef i get invalid here

So remember what you are trying to do: bypass blacklisted characters. In this case you are trying to inject the command ls /home, but (as far as I remember) both spaces and / are blacklisted. So you need to use what you learnt from the previous sections and replace those somehow.

high reef
#

Which in this module is the bypass that works in every section

faint gulch
#

Take your time to understand what you are doing, don't just rush to complete the exercise.

mortal mural
#

guys

#

anyone familiar with nand to tetris ?

fathom pendant
mortal mural
#

dude

#

where is the channel for such topics then

fathom pendant
faint gulch
#

@high reef let me know if you need more help, I spawned the target myself to remember the exercise

hidden pecan
past tendon
#

Hey All, can anyone help me with lab setup on Advanced XSS and CSRF Exploitation Module from the Senior Web Academy. I cannot access the URLs and am trying to see if I missed a step. πŸ™

frosty spade
#

howdy folks on the server side attacks module theyre using tplmap unfortunatly kali comes preinstalled with python3 when tplmap requires python2 cant install with venv getting a bunch of errors anyone know if theres an alternative to tplmap that utilises python3

acoustic owl
past tendon
dreamy solar
#

Hello man can you help me plz on the skills assessment exercice PASSWORD ATTACKS Password Attacks Lab - Hard, I do a brute force but nothing...

frozen mesa
#

Footprinting: SNMP -> enumerate the custom script. What part of the module does explain how to do this?

fathom pendant
#

Literally perform the walk and you'll see what it's talking about

#

You're not executing the script

frozen mesa
#

I did the three things they learn, but i couldnt find what they are looking for. Could also be me not understanding correctly what they look for

fathom pendant
#

In the output: first look for something.sh

#

Until you reach the final output line of that bit: that's all under that OID

dreamy solar
# dreamy solar

I must to do bruteforce or not ? I don't find others solutions for moment

fathom pendant
#

Because it's actually addressed as 172.16.5.0/24 and 172.16.6.0/24

#

Kinda/sorta. The addressing for those subnets is different

#

They both fall under the main network as 172.16.0.0/16 however they were subnetted to be separated

#

So hosts on 172.16.5.0/24 can't communicate on 172.16.6.0/24

#

(Unless they share an interface)

#

If you have access to a purely segregated 172.16.5.x system and a 172.16.6.x system, try pinging them from each other

#

The /16 is purely to indicate the overarching class B network is /16

#

It's just one of those sorts of networking things you learn

dreamy solar
fathom pendant
#

It's also funny bc recently in my class I just did some networking where one of the labs was configuring a static class C IP on a windows vm lol

#

Fun fact as well: the networking on htb/vpn is Class A

frozen mesa
fathom pendant
fathom pendant
#

As there's times you won't just be able to grep for a flag format

#

I.e. one of the skill labs

frozen mesa
#

I've tried to do it manually first

#

but failed several times. Thats why i asked what did i miss.

fathom pendant
#

Nah you're good. The snmpwalk gives a LOT of visual noise

#

So if you don't know specifically what to look for then it's just like "woah dude, I just sat down"

nova nest
#

I'm attempting to log in to MS-SQL in the "ATTACKING COMMON SERVICES" module, but I'm not getting any response. Even with the -v option, there's no output. The service is pingable.

#

ah finally got a 115 (Cant connect to server)

#

what could i do here?

dreamy solar
#

Hello man can you help me plz on the skills assessment exercice PASSWORD ATTACKS Password Attacks Lab - Hard, I do a brute force but nothing...

fathom pendant
nova nest
#

better try hydra, crackmapexec is slow

soft cedar
dreamy solar
soft cedar
fathom pendant
nova nest
#

I do not trying to bruteforce. I got credentials, but still no connection can be established.

#

using mysql and sqsh

fathom pendant
#

Well you can't connect to mssql with mysql

#

Impacket has their own mssqlclient tool

soft cedar
#

^ plus it would just be easier to help you out if you shared a snippet of your code or the error

nova nest
fathom pendant
nova nest
#

i feel like an idiot, but failing makes us smarter hahaha!

fathom pendant
#

failing mistakes

#

Failing implies the lack of success at the end

prisma spruce
#

pinging doesn't really tell you anything, tbh

fathom pendant
#

Some hosts can be configured to not respond to icmp requests

prisma spruce
#

Classful networking has been dead for twice as long as it has been around by this point. I don't understand why people still teach it.

#

Well, I do know why they still teach it.

fathom pendant
dreamy solar
fathom pendant
#

AFAIK my home network isn't classfull but still uses /16

prisma spruce
fathom pendant
#

I was also just referring to the general ip as a/b/c because that's (in general) how most people learn it

prisma spruce
#

Sure, but even then it's not useful to call them as classes because a 128.0.0.0/8 address is not a class a address

soft cedar
fathom pendant
prisma spruce
#

Oh wait, yes, if I'm following you.

fathom pendant
#

Ye

#

Like it follows the address schema of private class not so much that it is (though usually its interchangeable

dreamy solar
#

I forget something?

soft cedar
prisma spruce
#

It's just that it's not useful to call something a class a address when what someone probably means is a /8 address. Saying that htb uses a class a address doesn't really mean too much. You can configure your own private network and give it any address. It's only when you have public + private stuff that you have to take into account addresses that you can't use. But by default, if you're going to host a server in the cloud, I'm pretty sure you're always going to have a 10.0.0.0/8 block of addresses that you can work with.

austere minnow
#

Guys, I need help here, please. SOC Analyst Introduction To The Elastic Stack: second question. Now, execute the KQL query that is mentioned in the "Wildcards and Regular Expressions" part of this section and enter the number of returned results (hits) as your answer.

I have found the username for question one but when I put in what I am seeing as the answer I keep getting that the answer is wrong.

fathom pendant
#

Because I think we're saying similar things just in a slightly different way

prisma spruce
fathom pendant
#

And academy I believe also adds 10.129.0.0/16 I'd have to spin up the pwnbox to see

crystal steeple
#

is htb academy site down ?

prisma spruce
crystal steeple
prisma spruce
#

Uh, nvm. The homepage is up, but I can't connect to any of the other pages.

austere minnow
prisma spruce
#

So it's up, but there's probably something happening with their web server.

fathom pendant
#

Yeah I was gonna say it looks like it just died at least isn't loading new requests

#

It's active as I can at least ping it

prisma spruce
#

I managed to visit another page. It's probably just high traffic.

crystal steeple
prisma spruce
fathom pendant
prisma spruce
#

It's probably not meant for it, but if it doesn't tell that sort of information, it's effectively useless for me.

fathom pendant
#

It's kinda hit-or-miss if it lands on status.

#

I think it needs to be a hyper prolonged issue. And it needs to be in-part at least verified/hookable to the api

#

It's likely that since the api could make valid callbacks it was like "all good, nothing to see here"

astral inlet
#

hi

fathom pendant
#

Is -P the port flag for mysql?

astral inlet
#

yes

fathom pendant
#

^

astral inlet
#

na, its the same, after password ( which i copied ) error comes up

rose swallow
#

Any hint for Injection Attacks module -> skill asessment ?

quick cloud
#

Greetings im on the "mini module" UNDERSTANDING LOG SOURCES & INVESTIGATING WITH SPLUNK and the section Introduction To Splunk & SPL I am having a hard time understanding what I need to do with the last question in this sectioon Navigate to http://[Target IP]:8000, open the "Search & Reporting" application, and find through an SPL search against all 4624 events the account name that made the most login attempts within a span of 10 minutes. Enter it as your answer. I know I can get the answer the unintended way but would love to do it the right way! I have a SPL query that I think solves the question even though its wrong any help will be appreciated.

astral inlet
#

its "-h" <---

#

now it works

prisma spruce
astral inlet
#

me neither lol

prisma spruce
#

I hope you don't run into issues where you need to specify -h localhost or -h 127.0.0.1

fathom pendant
#

Wasn't there one tool where it used to be one thing then switched to the other flag

remote latch
#

and the kali linux history as well

astral inlet
#

i use joplin πŸ˜‰

remote latch
#

is it like ancient spell or smth like that?

prisma spruce
remote latch
#

thats cool

#

brotha im doing the learning way or whatever its called module

#

im literally being taught wisdom

prisma spruce
fathom pendant
#

Huh... just looked on pwnbox and it's

10.10.10.0/23
10.10.14.0/23
10.129.0.0/16
remote latch
#

its great to hear some kind words

prisma spruce
#

I don't like some of the other tier 0 modules, but that is the only module I will call hot garbage.

prisma spruce
#

It actively teaches pseudoscientific nonsense as well as absolute falsehoods.

remote latch
remote latch
prisma spruce
#

Well, I instantly laughed at the part where it spouts the bs "Einstein was bad at math"

#

Maybe he was, compared to Hilbert, lol.

remote latch
#

but he was very creative

#

and he slowly became good at it

fathom pendant
#

It's moreso the framing of the statement

prisma spruce
remote latch
#

ehhh

#

alr, im not Einstein soo

remote latch
prisma spruce
#

I dunno. Go and do them to see what you like.

fathom pendant
#

It's all subjective

limber river
fathom pendant
#

What one person may say is different from another regarding a topic

remote latch
prisma spruce
#

The main issue for me is that the learning process module is similar to one of those garbage "motivational" speakers, except it's even worse because it spouts absolute bullshit.

remote latch
remote latch
prisma spruce
#

Some forms of bullshit are fine I guess, like Gladwell's 10000 hour thing, but I would not want to see it in any sort of serious publication.

#

Unless they're writing about how it doesn't really work that way, lol.

remote latch
#

a little more than a year

prisma spruce
#

Gladwell's 10000 hour rule is pretty similar to the "walk 10000 steps a day" rule

fathom pendant
#

it just depends on how you view it Β―_(ツ)_/Β―

fathom pendant
#

10,000 hours can also mean spending dedicated time on it

remote latch
#

and obsessed as well lol

fathom pendant
#

10k steps a day for a healthy heart or sth along those lines

remote latch
prisma spruce
#

This would not have happened if the Japanese did not decide to officially simplify their script after WWII.

remote latch
#

almost 180cm and 54kg, am i cooked?

fathom pendant
#

Everyone is different

remote latch
#

isnt this what all people are tryna find? soulmate?

#

never saying she/he should be the same

#

but like? close interests etc

prisma spruce
# fathom pendant Everyone is different

Yes, but we are more similar than not. Which makes it hilarious when researchers talk about how the "everyone learns in a different way" thing is again, mostly nonsense.

limber river
remote latch
#

heard these things make u smarter, basically tony start from wish

quick cloud
#

HTB has taught me so much about how slow I learn

prisma spruce
fathom pendant
prisma spruce
# fathom pendant It's just how people absorb it. Thus people get a crutch on only learning via vi...
fathom pendant
prisma spruce
#

I actually hate videos and will ragequit if I'm presented with one.

fathom pendant
#

I'm moreso stating people that were told "you're a visual learner, so reading is gonna be difficult" internalize it

prisma spruce
#

It's even worse with the non-educational stuff, where they try to talk as quickly as possible without saying anything useful at all.

fathom pendant
#

Oh you mean salespeak

prisma spruce
#

Nah, not even that.

#

Imagine someone talking about the canon of some random creative universe.

fathom pendant
#

Throwing in buzzwords that add 0 value

#

Ohhh

frozen mesa
#

Do i need to add the domain (which isnt mentioned) to etc/hosts for the skill assesment in Footprinting?

limber river
prisma spruce
#

@languid fjord ngl, I find it funny that you have to explain the difference between blackbox and whitebox pentesting for a senior level cert

junior oxide
#

guys

#

i need help

shut ivy
#

when i spawn a target and try to connect via ssh htb-student@ the ip adresss it keeps saying connection close by ip addess port 22

#

what am i doing wrong

prisma spruce
junior oxide
#

im stuck in Password Reuse / Default Passwords module in password attacks i loged as sam got a note.zip file from kira but don't know how to crack it ... also where do i find the default creds that i should try i found the defaultcreds on github tried to download it to the attackbox but got some python error and the port for sql in the machine isn't even open ... any hints pls ?

shut ivy
#

ill check my ports

prisma spruce
junior oxide
# shut ivy ill check my ports

try to download a differant vpn or you may have to fix something in the config file for ssh not really sure what you'll have to fix tbh

rustic sage
junior oxide
frozen mesa
#

DM? Did that part last week, maybe i can help you

paper basalt
fathom pendant
austere minnow
#

Has anyone else done the SOC Analyst training in here?

fathom pendant
#

Read the question: use the default cred cheatsheet

austere minnow
#

I need help here, please. SOC Analyst Introduction To The Elastic Stack: second question. "Now, execute the KQL query that is mentioned in the "Wildcards and Regular Expressions" part of this section and enter the number of returned results (hits) as your answer."

I have found the username for question one but when I put in what I am seeing as the answer I keep getting that the answer is wrong.

fathom pendant
#

Not for a specific name

austere minnow
#

I got the name for question 1.

fathom pendant
austere minnow
fathom pendant
#

But yes: hits is how many times you get results

#

Also it doesn't indicate that you should modify the query

crystal steeple
#

how do you read a docx file in linux

#

i asked chatgpt , gave me a few tools but doesnt work

fathom pendant
#

Use office libre

crystal steeple
fathom pendant
#

It will if you download the office Libre suite from the website

#

And follow their install

crystal steeple
#

okay thank you i will instal it now

fathom pendant
#

:) the install works just fine

crystal steeple
#

yes i followed chatgpt command to install it that why it didnt work probably

#

i will go to their official website and follow their instructions

fathom pendant
prisma spruce
#

I'm sure there's a cli tool somewhere that converts docx to pdf directly too

crystal steeple
#

its related to a lab im working on

#

trying to read a docx file

austere minnow
upbeat dragon
#

Hey guys, im trying to dump cached credentials with mimikatz, after executing "sekurlsa::logonpasswords" it returns (null) on the user i'm targeting, any idea why is that?

prisma spruce
prisma spruce
#

Yes.

tight mesa
#

hello there, any hint about WinPrivEsc onto WPE Assessment II would be good appreciate it....

#

cuz I guess the admin password found is a hanging fruit or big distraction...

#

cuz I tried to use that creds with Runas also with RDP unsuccessfully

crystal steeple
#

im stuck in the medium lab in Password attacks module, i got a user creds , did ssh and stuck cuz can't get to root

#

i tried multiple techniques in linux creds hunting section but nothing seems to work

#

a hint would be appreciated :3

crystal steeple
#

nvm i think i figured it out

prisma spruce
#

I know there are .xlsx viewers that crop out a lot of the content.

fathom pendant
astral inlet
prisma spruce
fathom pendant
#

Yeah. There's an extension I believe for better support

haughty girder
#

Hi guys, i have a quick question.. once i buy the cubes, will there be any expiration date for them?

astral inlet
#

afaik no

haughty girder
#

Im planning tk use them after an yearπŸ˜…

prisma spruce
haughty girder
#

Because company buying me some cubes and i bought silver already. So

prisma spruce
#

lol ouch

crystal steeple
astral inlet
#

after completing modules , you get some cubes back

rustic sage
#

Making my way down the Pen Tester pathway, learning so much

astral inlet
#

yes πŸ™‚

#

great path

rustic sage
#

Much better way of learning

astral inlet
#

where are you at ?

rustic sage
#

I used to just do CTFs but I noticed I wasn't really understanding why I was doing things

#

I only switched to HTB academy yesterday, so I'm only on the 2nd module "getting started"

astral inlet
#

i am @ 60% now, this will be fun πŸ™‚

rustic sage
#

60% overall?

astral inlet
#

yes

rustic sage
#

How long did that take? I'd imagine it takes a good amount of time

astral inlet
#

there is no time line here but i think less then 1 month

#

i do not know tbh

rustic sage
#

I mean for you

astral inlet
#

it was for me πŸ™‚

crystal steeple
#

im 30% in and it did take me 2 months or so

#

its actually related to how many hours you dedicate to htb academy in a day

crystal steeple
astral inlet
#

yes i take every weekend and 3-4 hrs after work

#

btw does the academy count for rank in htb too ?

fathom pendant
#

No

crystal steeple
astral inlet
#

ok

fathom pendant
#

Separate platforms

astral inlet
#

i wonder i get higher and higher lol

rustic sage
#

I'm just going to focus on Academy for now, until I got a big chunk of it done

astral inlet
#

good idea its worth it

rustic sage
#

I like how its a lot harder than some other sites I have tried

#

it doesn't help you as much

crystal steeple
rustic sage
#

that's good to hear

#

I'm just finishing off a cyber security degree and have learnt nothing so far

astral inlet
#

if you like frustration and pain you are 100% right on track πŸ˜„

rustic sage
#

I do I do. I'm not new to CTFs, I just switched from another site

#

I just want to get a better foundation to my skills

fathom pendant
#

Well academy is still a good place to realize how many gaps you may have

rustic sage
#

there are many gaps that's for sure

ember coral
#

having trouble connecting to some rdp sessions all of a sudden, was connecting fine about 20 minutes ago

languid fjord
compact patrolBOT
ember coral
rustic sage
thorn urchin
rustic sage
#

I thought a meme was coming

prisma spruce
#

I think it would be funny if htb created pointless modules like "how to use vim/tmux"

astral inlet
#

google it πŸ™‚

#

top 5 questions about vim i think

prisma spruce
fathom pendant
prisma spruce
astral inlet
#

priv esc for example

fathom pendant
#

Yea. Priv-esc with vim is neat

wild sinew
#

has anyone in here taken the cpts exam yet?

fathom pendant
#

No one has. You would be the very first

prisma spruce
#

Oh, I see what you mean.

#

I thought you were talking about exiting the file still lol.

fathom pendant
astral inlet
#

vimtutor

prisma spruce
#

There's probably someone out there who doesn't know how to exit vim because they have a f-122 keyboard and they had long ago bound their f24 key to esc+:wq!

astral inlet
#

no one knows about

fathom pendant
#

Ye it's neat

prisma spruce
#

There's a thm room on how to use tmux, and you can pretend that you're learning when it's one of those things that you set up and never touch its configuration again.

astral inlet
#

tmux is great

prisma spruce
#

And there's a room on classful networking. It never ceases to make me rage because we still talk about it.

astral inlet
#

and netexec is too πŸ˜„

fathom pendant
prisma spruce
fathom pendant
#

Well yes, I'm more referring to the private ranges within the classes

#

Other than that

#

Everything is CIDR

prisma spruce
fathom pendant
#

I mean 172.16.0.0 -> 172.31.255.255 is a relatively small range comparatively

prisma spruce
#

And it makes it sound like it's some sort of static thing, when sane people would be dividing their 10.0.0.0/8 block

fathom pendant
#

Yup or use vlans to further subdivide

#

I'm right in thinking you can manually assign a range (on router/switch) to assign via dhcp yeah?

prisma spruce
#

Yeah.

prisma spruce
fathom pendant
#

Mhm

zinc tapir
#

I'm in the early modules for linux fundamentals! there's several questions I can't answer without using sudo, yet I don't know the htb-student's sudo password. Is there somehwere I might find that?

prisma spruce
fathom pendant
#

sudo password is generally the user's password

prisma spruce
#

You would have to really go out of your way to make it not the user's password.

thorn urchin
#

yeah I think thatd be some esoteric authentication module for sudo or some shit like that

prisma spruce
limber river
thorn urchin
prisma spruce
thorn urchin
#

if youre editing PAM configurations rethink your life

astral inlet
#

i like both

limber river
astral inlet
#

i am top 1% πŸ˜‰

#

no joke

limber river
thorn urchin
#

THM is nice because they have looser restrictions on types of uploads and private instances means you can have weirder challenges that would be rejected or hated on the HTB platform

#

sadly very few people actually take advantage of this

astral inlet
#

tbh i think htb boxes are more esoteric

#

but i do not wanna "be the guy"

prisma spruce
thorn urchin
#

absolutely

#

its a weird case where thm infra and setup is great, but the content sucks ass, and HTB is the opposite lmao

prisma spruce
#

And it's way too much effort to sort through all the trash.

limber river
prisma spruce
#

Their wreath network is amazing. It's a bit of a shame that they throw a bunch of the names of tools at you and you only touch them once for each question.

thorn urchin
#

the best usage of THM ive seen is that its an easy platform for individual content creators to upload and host their challenges.

astral inlet
#

the hard boxes are totally unreal

thorn urchin
#

And then people do em because its X persons challenge, not because its a THM challenge

astral inlet
#

jump fromhere to there to get this and then rev shell to another thing

#

bllah

#

i like the academy here but tbh not many of the boxes

#

i hope dante will prove me wrong

limber river
astral inlet
#

in real world you are after the DC

#

in a AD

#

to get 1-5 killchains

#

because a pentest is time limited

thorn urchin
astral inlet
#

which enumeration payload ?

#

1 OR 1=1 ?

prisma spruce
#

I remember one htb box where everyone was struggling because the published poc used mysql but the box itself used sqlite. That was a fun one.

thorn urchin
prisma spruce
#

from twitter

#

"OR 1=1 should not be the go-to example for SQL injection..."

astral inlet
#

thats right

#

you can del stuff

#

even portswigger changed it

limber river
#

the boxes in HTB might be hard or weird but really good

astral inlet
#

and if you f*** up a customers database ... pray

limber river
astral inlet
#

or be smart and donΒ΄t do this crap

limber river
astral inlet
#

thats right

#

but many ctfler wanmna get pentesters

#

and itΒ΄s smart to avoud certain things

limber river
astral inlet
#

like zerologon, eternal blue and stuff

limber river
astral inlet
#

same is 1 OR 1

limber river
#

also some BOF can ruined the client life

thorn urchin
# limber river including me

pro tip if you get an interview and mention doing HTB make sure you have notes to talk about a recent box youve done. Dont me that froze like a deer in the headlights and couldnt even think of a single box I did kek

limber river
prisma spruce
limber river
thorn urchin
#

Ive been cringing at myself every day since the interview over that

astral inlet
#

but you got the job ?

thorn urchin
#

when people say sometimes you can lie about stuff in interviews resume thats one of the situations you lie in lmao

thorn urchin
#

"While your background is technically impressive we feel it wouldnt be an appropriate fit for what were looking for"

#

aka they thought I was psycho and noped

astral inlet
#

less then 1% applying for jobs at the company i work can work there, the human part is the most important

limber river
#

question is the CPTS lvl enough to get a job , technically speaking ?

astral inlet
#

i got mine with eJPT and showing my passion

#

as a junior

limber river
astral inlet
#

no i worked my ass off

#

and a bit of luck, yes

limber river
astral inlet
#

did you pass ?

limber river
astral inlet
#

never talk about something you donΒ΄t know πŸ˜‰

languid fjord
limber river
astral inlet
#

tbh only HR cert is OSCP

languid fjord
#

Its really what companies are looking for in the end, CPTS gets you enough skills to be competent for sure though

limber river
astral inlet
#

at ther moment maybe CEH urgh and network plus

limber river
astral inlet
#

yes they are well known

#

but my company pais me if i get the cert 100% of the money back

#

and later then oscp BSCP maybe

astral inlet
#

yes

opaque geyser
#

Where do we discuss labs?

limber river
limber river
limber river
astral inlet
#

i would say if you wanna learn CPTS ( PATH ), HR = oscp

languid fjord
astral inlet
#

the problem is pentester is maybe 50% hacking

languid fjord
#

CPTS gives you the skills needed for the job though

limber river
astral inlet
#

meetings.etc

#

yes the path is great

#

but as i said pentester is not all about hacking skills

limber river
#

already 94% , i will finish it this week

astral inlet
#

the human part is very important, and please never do it for money only

limber river
astral inlet
#

no its fun

#

95% is remote

limber river
astral inlet
#

you have to prepare kickoff, do documentation etc ...

#

do tech workshops

#

to improve the security of your customer

#

they pay you for documentation not for hacking πŸ˜„

limber river
astral inlet
#

they do

prisma spruce
astral inlet
#

we do all kinds of stuff

#

external internal , SE, physical

#

sometimes you are DA in under 1, hrs

#

sometimes you fail

#

πŸ˜„

#

good night have to get up in 6 hrs

thorn urchin
# astral inlet sometimes you fail

imo unless its literally skill issue theres no such thing as failing, it just means you actually have a client that did shit right which is noteworthy in a report itself.

prisma spruce
cobalt trench
#

Password Attacks Lab - Hard: I extracted the S-- and S----- hashes but Im stuck on what to do next. The hashes are not crackable

thorn urchin
prisma spruce
#

btw I sent you a message. Hope you got a good laugh out of it

limber river
cobalt trench
zenith mango
#

winrm might work as well

cobalt trench
#

Even though CME doesnt authenticate?

limber river
cedar void
twilit cipher
#

Anyone around who has complete the NoSQL Injection Skills Assessment II? It's the one with the "MangoFile" application.

cedar void
cedar void
rotund steppe
#

The clipboard disablement on the vdi stopped working for pwnbox- anyone else experience this?

fossil birch
fathom pendant
#

I haven't done the module so I couldn't tell you more

crystal steeple
#

im stuck , i can't transfer the

#

||Logins.kdbx||

crystal steeple
#

to my attack machine

#

i literally tried smb impacket , ftp methods but doesn't seem to work :{

#

im in the hard lab on Password attacks module btw

jolly jackal
#

i wanna learn hacking