#modules

1 messages · Page 211 of 1

acoustic owl
#

?

modest girder
gloomy nebula
#

Stopped terminal on link remote

#

@oblique summit

next bronze
#

yes, it's supposed to do that. open another terminal

sterile epoch
#

is it truly out?

errant swift
heavy edge
#

getting the same issue too

#

slow af load times

jaunty basin
#

heyy

hard horizon
jaunty basin
#

is anyone here , i want ask something

sterile epoch
#

looks like there is a outage

sterile epoch
heavy edge
hard horizon
heavy edge
#

yeah even the ips are taking forever to load

errant swift
warm saddle
#

Hello
Did anyone finish the Appsanity box?

onyx sonnet
#

Anyone able to nudge me with the Nmap module: Scripting Engine, having some trouble finding this flag.

heavy edge
#

is that the easy nmap one

#

im in but like its janky man sloooowwww load times

proven panther
#

Just in case you were wondering i installed intel open cl and then it worked. From what i've seen its a problem with hashcat in a vm coupled with me using amd processor

onyx sonnet
onyx sonnet
heavy edge
#

im trying to go to the course one sec

onyx sonnet
#

Dopamine.

heavy edge
#

im on footprint hard box and nothing will load pepehands

bleak horizon
#

Are the academy servers down? I cant log in :c

heavy edge
#

yes and now

#

no*

misty saddle
#

is hack the box academy also really slow for u guys?

proven panther
#

I cant even load the website so

onyx sonnet
misty saddle
#

yeeeah, I think they have some server issues again..

heavy edge
heavy edge
#

WELL imma go distribute freedom on helldivers 2

tropic relic
onyx sonnet
#

@heavy edge no nudge :/?

heavy edge
#

i cant get to the dashboard it times out kek

#

imliterally stuck on the footprinting box screen

#

it may work!!!! is it the network enum with nmap module?

faint blaze
#

hello everyone i need ur help

#

i forgot how to start anyone help me please

heavy edge
#

wot

heavy edge
onyx sonnet
#

The NSE page of Nmap Module.

#

Module 19 section 108

heavy edge
#

yes okay so im guessing one of the ports is 80/443 for a webserver

onyx sonnet
heavy edge
#

so you need to look at the http scripts so fuzz it. you can either do --script http* or vuln iirc

onyx sonnet
#

I’ve ran it through like every category. But the flag that is showing to ME is the previous page’s flag

#

Http-*?

heavy edge
#

have you tried going to some oe the webpages it lists

#

ahhhh okkaaaay

#

i see what i did

#

just talk to the robots and curl an idea in your head to get the flag @onyx sonnet

#

also try and enum http via nmap to find the directory

jaunty estuary
#

We all agree that acad website is full of 504 ?

heavy edge
#

dont you mean 502

jaunty estuary
#

I've both xd

heavy edge
#

oh damn

onyx sonnet
#

They’re speaking to me

heavy edge
heavy edge
#

so you found it

onyx sonnet
#

The robots have spoken and I’ve listened

heavy edge
#

gud

onyx sonnet
#

They told me 01010100 01101000 01100001 01101110 01101011 00100000 01111001 01101111 01110101 00100000 01000101 01111000 01100101 01100011 01110000 01100001 01101110 01100100 01100001

heavy edge
#

yeah one of the places you always check is robots. this disallows for the subdir to show up on search engines and such

#

you can find alot of neat stuff

#

wait you found it or nah

#

i cant tell if you are srs

onyx sonnet
#

Convert binary to text nerd

heavy edge
#

oh i hate binary. network+ tiltled me in the binary section

#

so i just avoid botspeak

proper hornet
#

academy is dead.

onyx sonnet
#

Tis’ the language of the machines you must become fluent. I did find it.

heavy edge
#

no u

#

good lol glad i could help

onyx sonnet
heavy edge
#

youll love footprinting module. hacking imap is interesting

#

same with oracle

half lily
heavy edge
#

and smtp

heavy edge
vague valve
#

Hey guys. I have a question regarding SOC path in HTB. i am confused about the target IP. Any help?

heavy edge
#

time to dispense freedom

half lily
lofty wave
onyx sonnet
#

Check my profile links, I also indulge in freedom dispensing

heavy edge
#

yes it is down

lofty wave
#

Great, the one day I actually plan on doing work lol

heavy edge
#

please sight tight hack your VMs and eat a burger

rustic sage
#

502 issues Ray I’d: 85fafb74193c869b

lofty wave
#

Wonder if someone unplugged something in the data center to make space for their space heater. New person, intern, etc... fingerguns

heavy edge
lofty wave
#

Oh man!! And if they cook fish. Off with their heads!!

acoustic owl
empty imp
#

Academy is down....once again.

heavy edge
empty imp
#

Maybe it's a blessing in disguise. I've spending all my days in front of the screen.

Time to touch some grass.

half lily
lofty wave
#

Oo wait, wonder if it's a cloudflare issue. Just saw a random error popup and then disappear to the HTB we are working on it issue.

half lily
#

yes same with me

formal nimbus
#

It s me or Academy is down rn ?

heavy edge
#

its you

empty imp
half lily
astral inlet
empty imp
formal nimbus
heavy edge
half lily
#

😭 😭

formal nimbus
#

Working again for me

soft cedar
#

Y’all should touch grass at this point

empty imp
#

Kid named 'grass': 😳

formal nimbus
#

Valheim give me enough contact with nature don t worry

soft cedar
rustic sage
heavy edge
#

WANNA BET

rotund steppe
rustic sage
#

It’s an active war zone lol

empty imp
rustic sage
#

lol

urban wadi
#

ITS UP

rustic sage
#

That’s what she said

urban wadi
#

ACADEMY IS UP

empty imp
urban wadi
empty imp
#

Ah, I thought you meant the power plant

urban wadi
#

just got up, its been down

rustic sage
#

The city is taken over by Russia

urban wadi
#

but now its up

empty imp
rustic sage
#

It’s an active war zone

oblique spoke
#

hi! is cadamey website down?

#

i am not able to log in

rustic sage
#

Join the club

gloomy nebula
#

Error 504

half lily
#

haha

empty imp
oblique spoke
#

yeah okay thanks

urban wadi
#

just got up

oblique spoke
#

that was my question

urban wadi
#

lets goooo

half lily
#

its up now

oblique spoke
#

what could happened? 😄

rustic sage
#

It’s up!

oblique spoke
#

yeah its up for me as well

soft cedar
#

Yeah it’s back

rustic sage
#

:hero by nickel back plays in the background :

lofty wave
#

Yep same here. Back up. Took a minute with the loading screen. Akin to the hot busy bartender yelling get to you in a second 😂

misty saddle
#

I'm in the Live Engagement for Shells & Payloads and the machine i RDP to don't have a browser. Can anyone nudge me in the right direction?

empty imp
empty imp
misty saddle
misty saddle
empty imp
misty saddle
#

That's a module im looking forward to!

next bronze
empty imp
next bronze
#

I can't remember any modules that needs a browers but the target doesn't have one installed thonk

misty saddle
#

This might be a stupid question. But what does it exactly want from me? I can see that it want's me to list a protocol. Is that normal? It kinda feels a bit out of scope from the content I've been doing this module :p

misty saddle
#

Yeah, I'm a bit tired xd

#

Thanks!

empty imp
#

I got a question

How do y'all have these Discord roles in your profiles? (Like "HackTheBox - VIP" and stuff?

lofty wave
#

On the Linux Priv Escalation module. Has anyone ever figured out how to get into the target without using the HTB provided creds? I've already got all the flags it's just bugging me. DM if needed as to not provide spoilers.

molten prawn
#

Hi

#

Why I can’t see anything like general chat ?

empty imp
molten prawn
#

Funny guy

#

Shut the fuck up.

empty imp
heavy edge
#

twas a joke jfc

molten prawn
#

Hey bunny

acoustic owl
#

Hi Bread

molten prawn
#

Thank you

misty saddle
next bronze
misty saddle
#

same as before

molten prawn
misty saddle
#

It gives me the exact same error as the first screenshot i sent

heavy edge
#

oops

next bronze
misty saddle
molten prawn
molten prawn
#

Head over to general

empty imp
misty saddle
#

I terminated ip and spawned it again and now it works

empty imp
#

Ah

misty saddle
#

Just spent an hour on this issue. Thank god it works now xd

empty imp
misty saddle
#

Thanks for the support @next bronze and @empty imp ❤️

empty imp
misty saddle
#

yeah so weird sadglas

half lily
#

hey how do you guys take notes

misty saddle
#

I use OneNote for Windows 10. I know a lot of people use Obisidian. But the nice thing about OneNote it syncs to all ur devices and is free and veeeery easy to use.

half lily
#

if i will leave something then i think that i will forget it

#

how do i manage this

lofty wave
#

Cherrytree here

misty saddle
#

Well, I usually read one section and then take a few bullet notes of what i think was the most important points and then the commands I use for the test. But it really depends on you. I would recommend not taking too many notes, since it can get cluttered really easily.

half lily
#

Thank you very much

heavy edge
#

is it unstable for anyone else xfree is closng out and i have to keep resetting thr IPs

onyx robin
next bronze
#

use tcp vpn

heavy edge
#

yeah even just pinging and using onesixtyone im having issues

onyx robin
#

i'm trying to download again the file to connect to the vpn but i don't think will change the situation

modest girder
# half lily how do i manage this

Your notes will evolve over time. I use Obsidian and essentially paste the whole lesson into there and go back and take an abundance of notes and screenshots during the exercises, then go back and take the highlights from my notes on a new tool or methodology or useful command and add it to my own cheat sheet. Take more notes rather than less, then go back and clean it up to show your methodology and highlight your own mistakes to learn from them

onyx robin
rustic sage
#

yo

half lily
modest girder
rustic sage
#

somonme teach me how to ahsck

onyx robin
next bronze
#

are your creds correct? my rdp worked fine

onyx robin
#

i was talking about the vpn, in terminal is blocked to establish connection

compact patrolBOT
onyx robin
#

in the web site they talk about an incident in the EU Academy Lab Controllers, but the state is resolved

next bronze
#

contact support

mint lodge
#

am i even on the right track?

runic plover
half lily
#

notion is nice but I think one note is better

runic plover
#

Yea its notes so personal preference is key.

onyx robin
runic plover
heavy edge
#

i reallly tend to over think dude

#

medium and HARD module really makes me mad at myself

runic plover
# next bronze yes?

Is "are belong to us" in your bio a misspell or just something my brain is to smooth to understand?

dim wolf
#

heh

#

all your base..

runic plover
#

Haha that makes since, I was thinking it was just something that proves my Autodidactic insufficiency.

next bronze
#

nah just an old meme

sharp panther
#

Hey there, has anyone done the Hard footprinting lab? I'm really at a standstill on it.

heavy edge
#

just finished it

sharp panther
#

no, it is a part of the footprinting module

heavy edge
#

wait the lab or the module

#

the lab is different from doing the modules

sharp panther
#

I've only gotten as far as scanning and seeing it is a pop3 imap server with ssh. I can establish connection with both imap or pop3 but no commands work, i'm not sure if I need to authenticate or if I need to look at some more specifics of the dovecot version or what.

heavy edge
#

try scanning the udp ports

#

-sU -F

#

see what comes up

sharp panther
#

alrighty, I'll give it a go.

#

thanks @heavy edge

heavy edge
#

yw

naive imp
#

i'm on the File Upload Attacks module and been banging my head to find out the upload path of the image in the SKILL ASSESSMENT... plz help me with this one... urgent,...... 😭

heavy edge
#

ideally this takes info directly from nmap stuff. you wanna make sure you are scanning every corney you can so you can check it off

sharp panther
#

this was what I used for transparency : -sV -sC -v -p

heavy edge
#

also it may be -f lol i cant remember the "fast" scan setting

heavy edge
#

id just do -sV -sC -sU/sS and -f if you are doing udp. only -p if you are tegeting specific ports with nmap scripts

#

-sU/sS depending on tcp/udp

amber cypress
#

hello, is it possible to connect (RDP) to a windows host via windows?

#

the VM xfreerdp works but really slowly for me, I downloaded openvpn on my windows host machine and tried connecting to my target machine via remote desktop connection but it says logon attempt failed:

#

this is how it looks

#

I can ping the machine -

#

(in theory) there should be in difference right?

rapid sparrow
next bronze
#

is it a domain cred? you might need to specify that

amber cypress
#

yeah its a user on a domain

next bronze
#

domain\user

amber cypress
#

oh, one sec lemme try that aswell

amber cypress
# next bronze `domain\user`

oh it works! thank god I was going to skip all the windows RDP stuff because it was just killing me how slow it is, thanks so much

next bronze
#

is windows rdp faster than xfreerdp? thonk

amber cypress
#

not 100% sure, but since I'm running a VM into xfreerdp it might be eating my resources, I'll have to check though admittedly right now I'm getting a black screen

next bronze
#

hit enter

amber cypress
#

hmm nope it's just stuck now, tried to log into it again and same thing

#

wish there was a way to do this via terminal so i can see some logs

sharp panther
amber cypress
#

im gonna restart one more time and try it again and if it doesnt work i'll just do it via my vm

amber cypress
next bronze
#

no idea about that one, never used win rdp for academy targets

#

freerdp exists for windows, maybe you can try that one

minor stag
#

This password mutations lab is annoying. Hydra has been trying to crack this password for 45 mins

elder moon
#

Hello ?
Any hints for Footprinting HARD ?
i'm into tom user ( ssh)

analog dock
elder moon
heavy edge
#

ls -al

elder moon
#

yes i checked that and also logged in into mysql but didn't get anything from mysql

heavy edge
#

you are joking

elder moon
#

do i have to dig more into mysql ?

minor stag
elder moon
heavy edge
#

you are actually logged into mysql?

elder moon
elder moon
heavy edge
minor stag
heavy edge
#

DID YOU READ THE QUESTION

sharp panther
elder moon
minor stag
#

||Reminder that you can get to mysql from inside the SSH session.||

heavy edge
elder moon
heavy edge
analog dock
raven lagoon
#

is it normal that if i try to spawn a session with PSSession using Villain.py everything crashes?

minor stag
heavy edge
#

||S H O W D A T A B A S E S ;||

elder moon
heavy edge
#

but like

next bronze
heavy edge
#

why wouldnt you initially do that

#

if you have a msql server its juicy

analog dock
#

I’m gonna start with cwee path

heavy edge
#

tell me how it is

analog dock
#

I should probably revise web attacks first

#

But whatever

next bronze
heavy edge
#

i was considering doing the pntp but theyre raising the price 100 bucks

next bronze
#

I might need to revise on my web stuff soon evilclown

analog dock
heavy edge
#

😢

analog dock
#

I’m gonna start oswe soon

next bronze
#

I have some stuff coming that might need me to do web

#

sometimes

heavy edge
#

i need to get better at xss/sql/xsrf attacks

#

i have never ever understood them or how they work or why they work

analog dock
#

I already am

#

Also need to do crte in the upcoming months

#

Blegh

heavy edge
#

mr htb god i see

analog dock
#

Well partly am, I’m not doing any HTB certs any time soon

heavy edge
#

do peopel actually hire those with htb certs?

#

i know offsec and comptia are big and sometimes gsec, cometimes i see cppt/ejpt etc but curious about htb certs

analog dock
#

Not well known, so pretty much no

limpid hemlock
#

Hey does anyone knw how to solve this question

#

In linux pass the hash

#

Check the /tmp directory and find Julio's Kerberos ticket (ccache file). Import the ticket and read the contents of julio.txt from the domain share folder \DC01\julio.

#

I check the tem directory to copy cache file but not working

winter shard
#

Is there student pricing for hackthebox or only for academy?

dim wolf
winter shard
mint lodge
#

i think im getting it right and still nothing im so confused

midnight hornet
#

I think they tried to patch something and broke another thing

urban wadi
analog dock
#

That makes 1 of us

dim wolf
#

what?

quick charm
#

I downloaded the top1million-5000 wordlist, but somehow when I open it in Linux it loads in halfway? When im searching the file I cant find certain words.

thorn urchin
#

what are you opening it with

somber salmon
#

Hi guys! If you unlock a module using the cubes from a monthly subscription, Do you still keep access to it after the subscription ends?

somber salmon
#

That's awesome! Thanks a bunch 💪

modest girder
#

I've been going through the pw attacks hard lab and I'm stuck on

#

||decrypting and mounting the backup.vhd file inside pwnbox. I tried dislocker but don't really know what I'm doing. I cracked the hashes with bitlocker2john. Can someone point me in the right direction?||

ember coral
#

Anyone else had issues grabbing Rev shells in File Upload Attacks module /upload exploitation? i'm using php pentesting shell trying with port 80, 1234, 4444, and the random port machine is hosted on. when i access the page the page hangs like its connecting but get a time out error after about 30 seconds. Getting similar results with msfvenom shell as well. however page resolves to */ after hanging instead of the time out page.

turbid lily
livid knoll
#

HOW CAN I HACK?

ember coral
turbid lily
#

where %26 is & urlencoded

astral inlet
#

do it with burp as a get req and urlencode it

modest girder
astral inlet
#

do not spoil too much please i want to do this exercise in a "few" mins too 😉

junior oxide
#

in the pass the ticket from linux section under password attacks i've obtained a hash for linux01 user do i crack the hash using rockyou.txt or the password.list or the mut_password.list that is made with hashcat ?

turbid lily
compact patrolBOT
dim wolf
#

@livid knoll

modest girder
runic plover
#

Can anyone point me in the direction of making a ticket?

turbid lily
livid knoll
next bronze
next bronze
runic plover
#

lmao support ticket***** please no kerberos for the time being

compact patrolBOT
runic plover
#

Legend, Thanks.

livid pier
#

anyone around that can help a poor soul with the last question on the final assessment of ADCS?

livid knoll
#

very hard to learn

runic plover
next bronze
#

unbased and banned

runic plover
next bronze
#

you

ember coral
runic plover
#

This is wild....

raven lagoon
#

nano>>>>>>>>>>>>>>>

runic plover
next bronze
#

skill issue

runic plover
livid pier
# next bronze what are you stuck on?

getting to the DC. found jimmies password, I think i found the DC password(doesnt work). given it is a cert mod, i re ran certpy with jimmy and see anoter esc vuln, but idk who that user is

next bronze
#

"username and password is incorrect"

runic plover
next bronze
junior oxide
#

can anyone help me with the password attacks (pass the ticket in linux) section ? i found the linux01 hash but couldn't do anything with it

astral inlet
#

is nano really real ?

next bronze
#

waitwhat how does that change what I meant

livid knoll
#

idk anything

dim wolf
#

because and is not or but i think you should show us the values of $damundsenPassword and $Cred instead

next bronze
#

I'm saying that the credentials given is wrong, hence the error

next bronze
#

doesn't matter if it's and or if or else or whatever, the error suggests than the creds are wrong

rustic sage
livid knoll
rustic sage
dim wolf
#

Is not FindByIdentity a credential verification

fathom pendant
#

^

livid knoll
rustic sage
livid knoll
#

nvm i know it

dim wolf
#

it boils down to you have incorrect creds

fathom pendant
#

otherwise it wouldn't spit out the a or b response

fathom pendant
# livid knoll nvm i know it

if your initial question was regarding mounting the b*.vhd from a skill assessment: there's a guide if you use discord's search feature

next bronze
dreamy solar
#

Hello can you help me please ?

next bronze
#

you're trying set a password isn't it? to set a password you'll need a user with sufficient rights, so valid creds will need to be applied

fathom pendant
#

^

#

the section goes over it actually fairly well

#

you likely misread a step; or skipped one and didn't realize

#

however if you're using the ForceChangeUserPassword you don't need the OG password; just your password

#

as in the password of the account you're leveraging the account with

dreamy solar
#

Where is my message???

cursive oriole
#

Hey I'm currently working with medusa. I have multiple user name and a password list.

I want to run a thread per user example first thread takes a user1 and the password list and the second thread takes user2 and password list etc...

cursive oriole
floral cedar
#

Somebody have the same issue with the connection? I cannot ping the academy box in the Windows Privilege Escalation Skills Assessment - Part I from the pwnbox or from my own machine with the VPN.

wheat breach
#

hi, i have a problem with the SIEM & SOC fundamentals : SIEM Visualization Example 4: Users Added Or Removed From A Local Group (Within A Specific Timeframe).

Here is the question : "Navigate to http://[Target IP]:5601, click on the side navigation toggle, and click on "Dashboard". Extend the visualization we created or the "User added or removed from a local group" visualization, if it is available, and enter the common date on which all returned events took place as your answer. Answer format: 20XX-0X-0X".

When I enter 2023-03-06 I get the wrong answer and I don't know what the right answer is other than that...

can anyone help me please ?

minor stag
#

Man, how am I supposed to do any of the RDP labs when the entire spawned server crashes just from me trying to open cmd.exe on the remote desktop

livid pier
next bronze
#

I'm not sure what you're doing exactly but keep in mind that the CA is not on DC

cloud urchin
#

is that from the ADCS module? i remember that error, it was because i was doing something wrong

thorn urchin
minor stag
thorn urchin
#

did you make sure to kill all your vpn instances first?

minor stag
#

I only have the one running

thorn urchin
#

This sounds exactly what symptoms you get if you have another instance accidentally running

fathom pendant
#

sometimes they don't all die properly;
sudo killall openvpn is a good way to make sure they all are stopped

thorn urchin
#

Not to be rude but I didnt ask if you only have one instance, I asked if you checked. Subtle difference

#

I believe you think you only have one instance, but did you confirm it

fathom pendant
#

^

thorn urchin
#

Happened to me on my Oscp exam even

fathom pendant
#

sometimes it literally can be dumb and somehow run 2; or it can silently fail and initialize twice

minor stag
#

What's the command to see all open vpn instances? I'm not seeing it on the --help

next bronze
#

ps -aux | grep 'openvpn'

fathom pendant
next bronze
#

or just reboot 4Head

#

ah right

fathom pendant
#

get skill issued Kapp (meanwhile hasn't completed the AD module after months and doing it like every other week)

minor stag
#

Yeah just the one instance, but crossing my fingers because this one is persisting longer than before after a modem reboot. Probably disconnected any other instances if there were any.

next bronze
#

extra dash, sent to the shadow realm nooo

fathom pendant
next bronze
fathom pendant
#

tbh though it's genuinely funny (i've done it too) where the reason something failed is because a single spelling mistake

minor dome
#

@loud prawn

thorn urchin
minor dome
#

comon

thorn urchin
#

the openvpn process resumed in the bg even though I couldnt see it in my term. So I started a new one and it fucked things

minor dome
#

i lov you marcielee

thorn urchin
#

Nah once I manually killed I was all good

minor dome
#

always good opinion

next bronze
thorn urchin
#

I professionally work in repair and can tell you that's a lie kek

fathom pendant
minor dome
#

we talked other day about cpts and i will tell my friend at htb to mod you

#

for great service and contribute to community

thorn urchin
#

Customer had factory reset their mac, the voice was the setup assistant

fathom pendant
minor dome
#

this is me rn when i see you macie

fathom pendant
#

dont be weird

minor dome
#

its not

thorn urchin
#

can you fucking not?

fathom pendant
#

also embed fail

minor dome
#

open it

#

its not weird lol

fathom pendant
#

nah i'm good

minor dome
#

ur loss .-.

thorn urchin
#

<@&861185840277487616> person is being fucking weird

fathom pendant
#

i'm sure i'll recover

minor dome
#

xd

solid python
#

Don't be gross.

minor dome
#

LMAOOOOOO

#

macie i garrenty u they setting me up

#

if i may, i can dm it to you to counter their vain attempt

#

they just jalous

solid python
#

Keep this channel clear of nonsense that isn't related to module content

minor dome
#

great wich channel do i go

#

make new one for general chat

#

brb

solid python
thorn urchin
#

Youve been in the server for 5 years and never figured out how to verify your account

solid python
#

Then you'll be able to see general chat

minor dome
#

T-T

ember coral
#

Working on File upload Attacks (blacklist Filters), i found a some extensions that bypass the filter, and when navigate to them i can see it was successful in the source code but any commands result in blank white page. Any idea what im doing incorrectly?

buoyant void
#

That just means that despite bypassing the blacklist filter this extension isn't able to execute the PHP code, as you can see by the output all you see is the raw PHP web shell code. So keep trying different extensions until you find the one that can bypass the blacklist and also execute PHP code

wise badger
#

Yes, of course 🙂 There is only one tool mentioned in the module. I have discovered already subdomains including subdomain of subdomain of inlanefreight.htb but still no luck in finding the one ending with 'x.x.x.203'. Any hints? There are many files in the SecLists, I already tried a few.

rustic sage
#

hey i am new here where can i find the section related to people working on zephyr right now :<

#

(or just talking about it)

wise badger
wise badger
#

Thanks very much, I figured out with a hint from someone. I did not know that a subdomain can be further bruteforced with the tool. I really appreciate it. TIL!

fathom pendant
sick frost
fathom pendant
#

I don't see where it's showing shell is already there

#

I see you're mounting tmp to the device

#

Then moving shell directly to the mnt location

sick frost
#

you see in the NIX02's tmp directory is where we compiled the shell binary and then mounted it onto pwnbox

fathom pendant
#

Yes

#

You're literally mounting the shell from the target to your device

cloud chasm
#

Module:NTLM Relay Attacks
Question Skills Assessment:Compromise BACKUP01 and then submit the flag located at 'C:\Users\Administrator\Desktop\flag.txt'
Hi can anyone give a hint im stuck here (edited)

sick frost
#

yes. then why are they trying to move the shell from my device to target machine. It doesn't make any sense because I don't have shell in my device it's already on the target

fathom pendant
#

I.e. making it always run as root

#

So when you go back to the target and run it: you become root

next bronze
sick frost
# fathom pendant You're setting the sticky bit

I get that part. But my question is when we mounted the /tmp to /mnt all the files in the tmp supposed to show up in /mnt. Then what is the purpose of copying to /mnt again. It's like copying the file again into same directory

fathom pendant
#

It's so you can have write permissions, likely

hallow remnant
#

MODULE: HTTP ATTACKS
SECTION: HTTP Response Splitting

Could I get a nudge on payload formatting for interacting with the Admin user? I'm a little confused as to what page the notional admin is checking for triggering the payload.

sick frost
mossy blade
#

hello, if I pay gold annual, how that works? can I access Modern Web attack module?

next bronze
mossy blade
next bronze
#

yeah but only a few

fathom pendant
#

you also do still earn the cubes from completing modules

#

20% for all tiers except 0; which is 100%

ember cove
#

I know I have it right, but I'm told it's wrong, there must be something about the format of the answer I'm giving it, is there anyone that can help on that?

#

For example, I've tried 192.168.0.255 for a network

#

and 192.168.0.1 for broadcast

#

Sorry, I meant it the other way around

minor stag
#

What am I supposed to be putting in the \?\GLOBALROOT\ part of this command? "cmd.exe /c copy \?\GLOBALROOT\Device\HarddiskVolumeShadowCopy2\Windows\NTDS\NTDS.dit c:\NTDS\NTDS.dit"

fathom pendant
#

for example in a 10.x.x.x network, a 192.168.x.x address wouldn't be apllicable for it's addresses

minor stag
#

So it wants the IP of the box I've compromised?

fathom pendant
minor stag
#

Oh, whoops

fathom pendant
#

also: use backticks

#

because if you have any \\ discord formats them

gray merlin
minor stag
#

Yeah, I realize that now

fathom pendant
#

I believe the section explains it

minor stag
#

This is all it says. Then it starts talking about using CME as an alternative

fathom pendant
#

you can literally use that exact syntax

astral inlet
fathom pendant
#

you don't need to replace \\?\GLOBALROOT\ with anything; it's a filepath itself

buoyant void
# astral inlet

Right behind you bro starting the skill assessment soon damn thought I was finally about to catch up too 🤣

fathom pendant
#

\\?\GLOBALROOT refers to the disk itself's file root, not the windows C:\ root

astral inlet
#

i was stuck a few dys on the last 2 modules

buoyant void
#

File Inclusion skill assessment definitely had me stumped for longer than I expected

astral inlet
#

hehe me too

buoyant void
#

I'm hoping File Upload assessment won't take too long

astral inlet
#

we will see 😉

#

tomorrow i can play in a hardened AD

minor stag
astral inlet
#

at work 🙂

minor stag
#

I assumed I had to change the path somehow

gray merlin
fathom pendant
astral inlet
#

btw use NXC instead of CME 😉

minor stag
minor stag
# astral inlet btw use NXC instead of CME 😉

It took me like 20 mins of trying various methods before I could finally get CME working and I had to use poetry to do it. Least I can do is use it for a bit before switching to netexec lol

astral inlet
#

lol yes but netexec is way more stable and has more functions 🙂

minor stag
#

Yeah, I'll have to give it a try

astral inlet
#

@buoyant void i did have a layer 8 problem the last 2 days 😄

ember cove
astral inlet
minor stag
#

What's the point of pipx? Is it just an advanced version of pip/pip3?

astral inlet
#

it works

gray merlin
astral inlet
#

and they recommend it , so i use it

ember cove
#

That's the first subnet?

astral inlet
#

just use a subnet calc 🙂

ember cove
#

the Second one would be 192.168.1.32 for the network and 192.168.1.63 for the broadcast

#

and yes, I did use a subnet calc

gray merlin
#

Looks right.

astral inlet
#

its 32-27 ** 3

#

if i am correct

ember cove
#

RIght

#

So I'm not sure why it's not taking the answer I"m giving.

next bronze
astral inlet
#

ok that soundws different

next bronze
#

without knowing the question we wouldn't know it needs to be split into 4

astral inlet
#

which module is that ?

fathom pendant
#

Intro to networking

next bronze
#

into to networking - subnetting

astral inlet
#

maybe i should take a look after hehe

buoyant void
#

I didn't even know there was a networking/subnetting module, I'm going to have to check that out

gray merlin
#

I could use a refresher also... lol

fathom pendant
#

I also said earlier: it depends on what the question is asking

buoyant void
ember cove
#

I get it.

#

And I agree I used to do this in my head, but haven't in years, anyway, I just figured it out.

astral inlet
#

did anyone take the bloodhound module ?

next bronze
#

yeah I did

astral inlet
#

can you recommend it ?

#

BEFORE cpts

next bronze
#

it's an alright module but compared to all the other tier 3 ad modules, it's probably the weakest imo

astral inlet
#

hm ok , later then 🙂

#

many did CBBH first,

#

nessescary ?

fathom pendant
#

Not strictly

#

As the web stuff is likely just barely a blip/covered by the modules in the path anyways

#

Too much prep can cause you to overthink

astral inlet
#

thats true

#

i hope cpts is not soooooooooooo much web stuff , more AD

lone canyon
#

in linux fundamentals module: Find Files and Directories this command won't work for me "find / -type f -name *.conf -user root -size +25k -newermt 2020-03-03 -exec ls -al {} ; 2>/dev/null"

astral inlet
#

what is the error msg ?

lone canyon
#

no error message it goes to the next line for new commands

astral inlet
#

then it did not find anything

lone canyon
#

interesting

astral inlet
#

2>/dev/null

minor stag
#

Try it without the 2>/dev/null and you'll see the errors

#

But it didn't find anything

lone canyon
#

shows: "find: paths must precede expression: Templates' find: possible unquoted pattern after predicate -name'?"

astral inlet
#

time for troubleshooting then 🙂

#

like 60% of a pentesters life 😄

next bronze
#

are you running the command in pwnbox or the target? did you ssh?

fathom pendant
#

it sounds like a common layer 8 issue with this module

astral inlet
#

ok 2 am .... good night 🙂

minor stag
#

This is a dumb question but I keep meaning to ask it and forgetting, when I get something like this ||root:$6$XePuRx/4eO0WuuPS$a0t5vIuIrBDFx1LyxAozOu.cVaww01u.6dSvct8AYVVI6ClJmY8ZZuPDP7IoXRJhYz4U8.DJUlilUw2EfqhXg.:19032:0:99999:7:::|| from a /etc/shadow, which part of that is the actual password hash?

#

I thought SHA-512 starts with $6$ but I just can't parse the sections

fathom pendant
#

you can throw the whole thing at hashcat i believe

#

it's built in a way to parse it so you don't have to

fathom pendant
#

also delete that as it's literally a hash of an account you gotta crack

cloud urchin
#

that explains it all

fathom pendant
#

even though you put it in "spoilers" it really doesn't do much

minor stag
#

I know, but it's the answer to one of the lab questions so I thought that would be the right way to do it

fathom pendant
#

Yes it can be cracked with the right password

#

The password attacks module has you create a mutated list: try that first

minor stag
#

hashcat just tells me that no hash-mode matches the structure of that lol

fathom pendant
#

then specify the hash mode

#

it's not that difficult to do that

minor stag
fathom pendant
#

you specify hashcat mode with -m

minor stag
#

Maybe I should do the hashcat module sooner rather than wait for it to pop up in queue

fathom pendant
#

literally the module gives you the syntax as well

#

if you don't use -m it assumes the first argument is the filename of the hash file

#

therefore it's trying to autodetect 1800 as a hash

minor stag
#

Gotcha

fathom pendant
#

instead of the mode you're trying to use

#

that's why it's giving you the error "No hash-mode..." because there is no hash mode that would output a 4 digit number

minor stag
#

I missed the unshadow step too so that would've helped.

fathom pendant
#

unshadow is how you normally would have gotten the hash

#

¯_(ツ)_/¯

balmy cradle
#

hi

cloud urchin
#

Web Service & API attacks, I still can't find this dumb parameter. Information Disclosure (with a twist of SQLi) is the specific part of the module, i'm using the wordlist mentioned in the module but it never shows the other parameter that can be exploited with sqli. i tried another wordlist that was about double the size of the one suggested, but that didn't find anything either. can someone tell me the wordlist to use or give me a hint if i'm just totally off here?

buoyant void
#

I spent over an hour troubleshooting a stupid question that turns out I was getting right the entire time and I just needed to reset the target sadglas I really need to start resetting the target sooner

cloud urchin
#

ahh it's not another param that's vulnerable, i see

#

still not sure why my payload didn't work, sqlmap worked but that's not the intended way. idk why they threw this random sqli thing in a module that has nothing to do with sql and doesn't teach it

#

i see why it didn't work, i was doing '1 or 1=1; --, instead of just 1 or 1=1; --

fathom pendant
#

simple syntax slip-ups screw you

misty current
#

@hallow remnant You can DM, if you're still stuck on the HTTP Response Splitting Section.

candid lily
#

eee how to do this? i checked the time and event id but process name was different

#

it would be better if they just give the event log file

lone canyon
#

thanks for the help so far! funny i'd thought this discord would be flooded and it'd be impossible to get help.

dim wolf
midnight hornet
#

Free platforms for bug hunting practice anybody please tell me ??

fathom pendant
#

Bug crowd, hackerone

mild cypress
#

Was having an issue with the Skills Assessment - File Upload Attacks module. I found the path to the files, and the format of the filenames via base64 decoding - but even totally normal pictures I uploaded were 404ing.

As I was typing this request for help, I tried to put in tomorrow's date instead of my own on a whim and surprise, it worked. Guess there's some timezone shenanigans going on Facepalm

Been struggling with this for a while.

fathom pendant
quick crane
#

Module: INTRO TO WHITEBOX PENTESTING, Section: Skills Assessment, Question: The attached archive contains a basic script that may be vulnerable. Try to identify as many vulnerabilities as you can and patch them. Then, visit /patch and paste the patched script to get the flag, or to know what you have missed.. After I patched the code correctly I got the prompt "code injection should not be possible, even without sanitization or validation". I understand that I should have blocked code injection, but I don't know why there is no flag feedback.

analog dock
#

Probably because you need to patch it more?

quick crane
analog dock
#

I haven’t done it yet

quick crane
#

lol

fathom pendant
#

why are you pinging random mods?

#

idk if that was one of them, or you being a pussy and not owning up to it

#

btw there's chat logs, they know

fathom pendant
#

in many cases with windows; Hashes are as good as passwords

cloud chasm
#

i know i have tried to pass the hash but no luck

sly grotto
#

hey
I think the module >
abusing http misconfiguration > identifying unkeyed parameters
have some problem
I tried both ways
first steal admin cookie
and second steal the response of the /admin.php?reveal_flag=1
but did not get the response to my server

next bronze
deep needle
#

I got a question regarding Attacking LSASS.

we can dump shares with CMD by making it powershell and giving administrator privilage. then what's the benefit of it? Is this thing i useful in AD pivoting?

fathom pendant
#

yes

#

some accounts might have mismanaged privileges across the domain

#

I.E. SEImpersonatePrivilege OR ForceChangeUserPassword or something along those lines

#

(or GenericWrite)

next bronze
#

any user that's currently logged in will have their credentials stored in lsass memory, for example a domain user. it also stores kerberos tickets

deep needle
#

so it uses only to gain DC admin creds, right?

next bronze
#

no, the technique works on any hosts and what you get depends on what's on the system

deep needle
#

okay get it. but basically to get different user creds, right? because we can dump lsass (at least when we don't hae GUI) only with Administrator privileges

i am sorry to give trouble about this but i am really confused with it. I tried GPT to understand concept but couldn't understand fully that's why jump over here

next bronze
#

yes correct

deep needle
#

okay great, thanks @next bronze & @fathom pendant

proper hornet
#

is hklm\system needed for hklm\security?
it was not explained in the module but also think that ntds.dit requires the hklm\system. thanks

deep needle
next bronze
#

yep, the bootkey in system is needed to decrypt the hives

fathom pendant
#

system and save are needed at the bare minimum i believe in order to get anything from the ntds.dit; secret is sometimes needed but not always

#

if you can get all 3, extract all 3

deep needle
#

👍

proper hornet
#

got it guys. thank you for clarifying

minor stag
#

These modules where I have to connect to the world's laggiest RDP server and do all my activites from that are brutal lol

astral inlet
#

they test your patience 😄

dreamy solar
molten cove
#

Hi, am currently doing the Skills Assessment for the module Kerberos Attacks.

Currently stuck at qn 3:Which user allows you to connect, as administrator, to the server with unconstrained delegation?

Will anyone be able to provide any nudges? Thanks!

icy hazel
#

Hi guys, on "Windows Attacks and Defense | Credentials in Shares", any ideas on how to import Powerview's "invoke sharefinder". The VM is not connected to the internet so I can't download straight from Git, might be being stupid I dont know.

next bronze
dim wolf
proven panther
#

Hiya, doing the skills assessment for cracking passwords with hashcat. On q4 crack the kerberos TGS ticket hash, when i run it in hashcat i just get no result and status 'exhausted' instantly. Looked up someones walkthrough and my command is exactly the same so not sure why mine isnt working. Anyone know?

clever topaz
#

im doing one of the sqlmap chall in academy and i keep getting connection error

#

what would be the issue ya

limpid hemlock
#

Check the /tmp directory and find Julio's Kerberos ticket (ccache file). Import the ticket and read the contents of julio.txt from the domain share folder \DC01\julio.

#

I'm stuck in this question any help

naive imp
#

I've been banging my head on this Skill assessment (FILE UPLOAD ATTACKS) for over a day now and still haven't got the source code which would probably be containing the upload path.

I've successfully uploaded the SVG containing XXE which would've given me the source code but all it returns is just my payload and noting from the source code... please help somebody...

wheat breach
#

can anyone help me with this answer? I don't see the problem

naive imp
#

how can i share image for doubts here.... plz help

#

??

dim wolf
#

i mean looking at the visualization

keen compass
#

hi, on Server-side Attacks> Blind SSRF Exploitation Example here I have troubles understanding how the reverse shell payload gets double url encoded. I have tried multiple times (using jq as shown in previous section) with different tools, I can't find a way to properly double encode my payload.
The provided payload in the example encode single quotes and parentheses and mine (with jq or other tools) don't.
Any suggestions please ?

wheat breach
#

I don't understand what I'm supposed to do here

#

except put 2023-06-03

cloud urchin
#

did you try 2023-03-06

dim wolf
cloud urchin
#

yeah but UK uses a weird format and isn't htb in the uk lol

wheat breach
#

yep i tried it too

cloud urchin
#

plus if it's not working it's worth a try

wheat breach
dim wolf
#

i wish i had access to my notes anywhere

cloud urchin
#

that's one reason i use onenote

dim wolf
#

so there is a date there yes

cloud urchin
#

there are other note taking apps that are online as well

dim wolf
#

that's not necessarily the date the action occurred

cloud urchin
#

i agree with @dim wolf , it looks like that's simply the date you started the filter, not the results from the search/filter

dim wolf
#

that's the only thing i can think of right now

wheat breach
#

ok i will check this later

#

thank you

shut quest
cloud urchin
#

what is everyone's favorite module? which one do you think is definitely worth getting?

dim wolf
#

honestly depends on what you wanna do

cloud urchin
#

i want to do it all lol

dim wolf
#

i found the investigating with splunk module to be awesome

limpid hemlock
#

Check the /tmp directory and find Julio's Kerberos ticket (ccache file). Import the ticket and read the contents of julio.txt from the domain share folder \DC01\julio.

sinful olive
#

Did anyone here pass the exam already?
Is it similar to Attacking Enterprise Networks module?

limpid hemlock
#

Any one knw how to solve this question

dim wolf
#

i did intro to assembly earlier and that was pretty worth

wheat breach
cloud urchin
#

@limpid hemlock that's a kerberos credential cache file.

#

you'll need to perform a pass the ccache attack

limpid hemlock
#

I'm stuck I found the files

#

I try to pass it by copying it

cloud urchin
#

it doesn't work like that

limpid hemlock
#

Ah

cloud urchin
#

try googling "pass the ticket ccache"

#

then look up hacktrickz or something

shut quest
wheat breach
#

😢

shut quest
wheat breach
#

i don't understand

dim wolf
#

when you create the instance of the machine, you have to set the timezone in the settings

wheat breach
shut quest
wheat breach
#

I look and I tell you

limpid hemlock
cloud urchin
#

great job

limpid hemlock
#

Missing to put the command in between Those double quotes costed me a day

#

🤣

shut quest
#

Nah, just means you learned a valuable lession 😂

cloud urchin
#

i bet you will remember it next time 🙂

#

if your subscription isn't active are you still able to run the VM's for the modules you purchased?

shut quest
#

yes

shut quest
limpid hemlock
cloud urchin
next bronze
#

I like adcs, kerberos, relay, cme

#

those are very well written

cloud urchin
#

i thought about cme, but it's not being developed anymore instead of netexec. i wonder if they'll update it

#

i'm guessing the same commands apply to netexec though

next bronze
#

yes

#

netexec is a fork that's being updated, that's all

minor stag
#

I still need to try out nxc. I just try to use the tools the modules recommend so I got to spend like 45 mins trying to successfully install CME

cloud urchin
#

i thought cme was native in kali

minor stag
#

I'm using parrot security. I have to run it via poetry

shut quest
#

the netexec folks have an easy way to install it, at least it works for me for the time being

ember coral
#

For file upload module I am understanidng how to brute force the extensions to see which allow for upload, however as course says not all extensions will allow for code execution. Is there a better way to do it than just going through the list 1 by 1?

minor stag
#

This one just does not want to connect.

#

Hm, Pwnbox doesn't work either.

plucky latch
#

The Attacking Thick Clients Module Lab is absolute trash... On hour number 7, and my problem isnt the instruction, it's the slowness of the VM and the behavior of the machine that causes issues and making me reset 3 to 4 times an hour

next bronze
minor stag
#

Well that worked. I don't remember having to do that before

next bronze
#

because $$ is a special variable in bash

#

without escaping it won't get passed correctly in the terminal

plucky latch
minor stag
#

I'll keep that in mind. Wish they'd mentioned that lol

rustic sage
#

hi guys, im on the file filters section of the file upload module of htb academy: https://academy.hackthebox.com/module/136/section/1290

i am stuck on the flag: The above server employs Client-Side, Blacklist, Whitelist, Content-Type, and MIME-Type filters to ensure the uploaded file is an image. Try to combine all of the attacks you learned so far to bypass these filters and upload a PHP file and read the flag at "/flag.txt"

i've tried all the previously mentionned task: blacklist, whitelist, content type, mime type

after dumping the wanted data from intruder i was left with the working extensions not mentionned in the blacklist:

pht
phar
pgif
phtml
phtm

working content-type:

image/gif
image/jpeg
image/jpg
image/png

Character Injection:

%20
%0a
%00
%0d0a
\x00
/
.\
.
…
:

I fuzzed every valid output (extension,filter bypass, etc…) using ffuf and intruder and got the following urls in order to retrieve the working payload that would only give me the executed PHP hello,i was left with the following list of "working payloads" i used curl in order to see which uploaded payload worked, but they did not executed the command itself

─[eu-academy-1]─[10.10.15.88]─[htb-ac-559209@htb-30pzvfozfr]─[~]
└──╼ [★]$ cat final2 
 http://94.237.54.75:58290/profile_images/shell.gif.phps.gif.phps
 http://94.237.54.75:58290/profile_images/shell.gif.phps%0D0a.gif.phps
 http://94.237.54.75:58290/profile_images/shell.gif.phps%0A.gif.phps
 http://94.237.54.75:58290/profile_images/shell.gif.phps%20.gif.phps
 http://94.237.54.75:58290/profile_images/shell.gif.phps/.gif.phps
 http://94.237.54.75:58290/profile_images/shell.gif.phps.//.gif.phps
 http://94.237.54.75:58290/profile_images/shell.gif.phps..gif.phps
 http://94.237.54.75:58290/profile_images/shell.gif.phps….gif.phps
 http://94.237.54.75:58290/profile_images/shell.gif.phps:.gif.phps
 http://94.237.54.75:58290/profile_images/shell.pht.gif
<..SNIP..>
minor dome
#

?

solid python
#

@minor dome keep this channel relevant please

minor dome
#

well i'm adking about the modules

solid python
minor dome
#

but ok

#

will redact it better

solid python
dim wolf
#

```
you can wrap stuff in a giant code block like this
```

minor stag
#

So I did the first part of the pass the ticket attack and it successfully imported the ticket with Rubeus. Now I'm trying to do the powershell remoting and getting this error.

solid python
minor stag
#

It only gives me the one unfortunately. Am I just supposed to use mimikatz exclusively on this even though the module teaches Rubeus?

next bronze
#

did you transfer it yourself or it's alreayd there

#

also module and section?

minor stag
#

It was already there. Password Attacks > Pass the Ticket from Windows

rustic sage
rustic sage
candid lily
#

he says about your text, to format it

solid python
#

Yeh, it would just be easier to read if it had formatting

next bronze
minor stag
oblique spoke
#

Hi i finoshed the cpts path, do you guys have any tip, suggestion for preparing the exam?

#

Also just any suggestion to the exam.itself 😄

next bronze
rustic sage
solid python
tranquil axle
#

Add the domainnames to your hosts file maybe

sick frost
#

Is anyone else facing lag while using the labs in linux privesc module?

dusk crater
#

guys i need help

#

i'm doing DNS enumeration with python

#

i completed the entire module but I still can reach the first answer, I miss only this one

#

"Investigate all records for the domain “inlanefreight.com” with the help of dig or nslookup and submit the one unique record in double quotes as the answer"

#

pls help me

heavy edge
#

i must be stupid. because im looking at the vhost section of the info gather module and how they find the hosts does not make sense

#

im using the NAMELIST.TXT from seclists but i dont get how im supports to verify 150k urls when they all come back as a 200 response when pointing to the inlanefreight.htb and its ip via ffuf

#

even doing the fuzzing command and its looping thru the response codes and url but doesnt confirm that any were successfull

#

i literally looked at a guide on how they got the flags and nothing tells me how they were able to find the subdirs

heavy edge
#

yes

#

ffuf comes back with every name as its valid

soft cedar
thorn urchin
soft cedar
thorn urchin
#

but iirc the info gathering module doesnt even cover ffuf yet. but maybe im misremembering or there was an update since I did it

thorn urchin
#

so it doesnt do that

#

filtering by response code doesnt work. but typically something like byte length would

soft cedar
heavy edge
#

it covers it

thorn urchin
heavy edge
#

sorting -fc 200 gives me no results

thorn urchin
#

why are you using fc

soft cedar
thorn urchin
#

use a different filter

ashen umbra
#

I am trying to connect to the MSSQL from the pwnbox. For some reason it is not working. Machine is able to be pinged, ran nmap confirming open ports. here is my syntax on the sqsh command:

sqsh -S 10.129.111.98 -U htbdbuser -P 'MSSQLAccess01!' -h

thorn urchin
#

their example is using size

#

99% of the time you use ffuf you want to filter by size

heavy edge
#

because when i do fs 612 it gives me every single result

thorn urchin
soft cedar
#

you dont just follow the module blindly

thorn urchin
#

thats what you want to filter by

soft cedar
#

^

heavy edge
thorn urchin
#

lol no

heavy edge
#

so i sort by 10918

soft cedar
thorn urchin
#

academy hates blind copying

ashen umbra
# ashen umbra I am trying to connect to the MSSQL from the pwnbox. For some reason it is not w...

and this is response

sqsh -S 10.129.203.12 -U htbdbuser -P 'MSSQLAccess01!' -h
sqsh-3.0 Copyright (C) 1995-2001 Scott C. Gray
Portions Copyright (C) 2004-2014 Michael Peppler and Martin Wesdorp
This is free software with ABSOLUTELY NO WARRANTY
For more information type '\warranty'
Open Client Message
Layer 6, Origin 8, Severity 5, Number 3
ct_connect(): directory service layer: internal directory control layer error:
Requested server name not found.

soft cedar
thorn urchin
#

some sections you can blind copy. but assessments never

dim wolf
heavy edge
#

okay so i have to sort by the false then to get them to not show up

dim wolf
#

granted he still is in high school

misty saddle
#

I'm in the Password Attacks in Network and Services on question 2.
Find the user for the SSH service and crack their password. Then, when you log in, you will find the flag in a file there. Submit the flag you found as the answer.
I found the flag. Copy pasted it into the answer box. But says it's wrong. Is it possible to encounter "fake" flags in Academy? Feels a bit misleading.

thorn urchin
#

you find the common denominator amongst the false positives and then filter by that value

#

sometimes thats status code. sometimes thats file size, sometimes is something crazy more esoteric that needs a custom processing module

misty saddle
thorn urchin
misty saddle
#

Yeah, I think that might be it. Got titled for a second xd

thorn urchin
#

I love academy but its a weird oddity. Every other platform strips extraneous whitespace before evaluating lol

misty saddle
#

Hahaha, yeah. I've encounterd some weird things the past few weeks

#

Part of the experience I guess

ashen umbra
#

you mean mssql and mysql?

soft cedar
cloud urchin
#

it's always important to get syntax right, whitespaces, etc. imagine high level/pressure pentests where one typo mistake could crash the app you're testing preventing you from accessing it again etc. i can only imagine how meticulous it has to be.

ashen umbra
#

let me try the other one I think I know what you are talking about

junior oxide
#

in the Password Attacks Lab - Hard
should i use rockyou.txt, mut_password.lis, password.list to brute force the user johanna via smb

ashen umbra
#

used impacket. It worked

paper basalt
#

I am doing the Pivot-module. I'm on the double pivot part.

I've made it onto the DC (172.16.5.19) from which I have to pivot onto "jason" (172.16.6.155). But I cant even reach 172.16.6.155 from the DC with ping or RDP there.

(Im using ligolo but thats besides the point). Any ideas?

junior oxide
soft cedar
junior oxide
#

im talking about brute forcing smb i'm currently doing it using crackmapexec with the mut_password.list

#

its been a while and still got nothing

soft cedar
astral inlet
#

those password sections can take about 1hr and more

junior oxide
#

yeah sometimes they even take days and you still get nothing

next bronze
#

hurry up and wait 4Head

astral inlet
#

get fast being slow :>

misty saddle
#

I'm doing question 3 in Password Attacks; Network and Services.
If I've been enumerating a username:password for over 15 min with a username list and password list from HTB. Does it usually take so long? I'm just starting to wonder if I'm doing something wrong.

astral inlet
#

serious ?

misty saddle
#

?

#

Yes, very serious.

astral inlet
#

this is no CTF 😉

misty saddle
astral inlet
#

hydra did not work ?

misty saddle
#

Nope, been going for a long time as well

soft cedar
astral inlet
#

and way faster then cme

junior oxide
#

finished brute forcing and got nothing i'll try hydra next

misty saddle
#

I'm a huge noobie at password attacks. So this might be a stupid question. Is it a issue to run Hydra and Crackmap the same time?

next bronze
#

yeah don't use cme for bruting in genral

soft cedar
#

^ Unless password spray.

astral inlet
#

you can in AD 😉

#

but then use NXC

next bronze
#

nah even then it's too slow, either use the ldap proto or kerbrute

astral inlet
#

ldap proto ?

misty saddle
#

hydra been going at it for approx. 20 min. Is this syntax ok?
hydra -L username.list -P password.list rdp://10.129.42.197

astral inlet
#

seems ok to me

next bronze
dense pollen
#

Anyone who finished the Command Injection Skill Assessment who I can ask a question to?

misty saddle
#

Hmm okay, pretty weird it haven't hit anything yet. Can it maybe be because I run crackmap and Hydra at the sam time?

astral inlet
#

proto = protocol 😄

junior oxide
#

yeah running two brute force attacks at the same time can result in false results at least for me i used to do in mutation password section and kept getting no results i learnt it the hard way after a week of brute forcing

astral inlet
misty saddle
rustic sage
#

Can anyone offer a little guidance on the web enumeration module. feel a little lost , I've tried getting some information by grabbing the website banner as well as listing potential directories but they both feel like deadends, aplogies if this is too generic of a question

rustic sage
junior oxide
dense pollen
astral inlet
#

anyone ?

rustic sage
# junior oxide check that path

doesnt curling the robot.txt just give you the file and not the path, I dont really see a path here but I think I'm missing something

rustic sage
misty saddle
astral inlet
#

n1

raven lagoon
#

guys is it normal that if i use mimikatz on evil-winrm session it glitches?

next bronze
#

run it in non interactive mode

#

like .\mimikatz.exe "privilege::debug" "token::elevate" "<command here>" "exit"

junior oxide
raven lagoon
next bronze
#

wdym? just run the command and get the info you need, if you want something else, run it again

raven lagoon
#

i cannot see suggestions

next bronze
#

what suggestions

signal laurel
#

Can I DM someone about the Advanced XSS and CSRF skill assessment?

raven lagoon
supple idol
#

Guys, have you ever faced this problem while solving Linux PrivEsc module, logrotate task?

#

looks like the problem with HTB's machine idk

next bronze
#

git clone in your own vm, the target doenes't have internet access