#modules

1 messages · Page 213 of 1

limpid field
#

am i supposed to figure out which exploit lets me mess around in the http server by description alone or am i supposed to look at it on a search engine

autumn pilot
#

narrow down the exploit to the one that will help you gain what you want flag or a reverse shell etc

limpid field
#

jsut add reverse shell to keywords in the search

autumn pilot
#

Think about file reading exploits

limpid field
#

the only exploit for the plugin that specified reading files doesnt work, check returns target is not exploitable. plus i have 7 mins left on pwn for the day so im probably going to have to come back later

autumn pilot
#

You can extend the lifetime of the workstation if i'm not mistaken

sly grotto
#

module: ABUSING HTTP MISCONFIGURATIONS
content: Advanced Cache Poisoning Techniques
any hint?

limpid field
#

i couldnt extend the lifetime, im a free user so thats it for the day

brittle arch
#

Has anybody done the Pivot, Tunneling etc Skills Assesment using ligolo-ng? I've used it many times before (did the whole of Zephyr with it), but it isn't working on this box and I'm a bit confused. Not sure if it is because I have a new VM or I'm just stupid today

rustic sage
#

I have not, although the tools inside the module I would assume work best for it

brittle arch
tranquil axle
# brittle arch I can’t get a connection from 172.16.5 back to kali

In zephyr all machines could connect to your attack machine directly, here this may not be the case and you may have to create a listener on the first machine you compromised to forward the traffic to your attackmaxhine and have the other machines connect to the internal, compromised machine if you need to double pivot

short hare
#

Solved

stuck pier
#

Pls guys who would help me with this ? I can sort myself but my pwnbox time has exhausted How many partitions exist in our Pwnbox ? That’s page 22 of Linux fundamentals 🙏🏻

quick crane
#

I dm you

#

can I dm you

#

do you solved this

#

can I dm you

fallow depot
#

Hey guys, can someone explain me in short : when do u use gobuster dir and when do u use FFUF? Like.. they both search for directories, so?

tranquil axle
#

They both do the same stuff just in a different way, look at what options they have and which output you like more and pick one

#

I personally use ffuf for everything, others swear on gobuster

remote latch
#

its kinda chaotic but it gets most pages

fallow depot
#

Ty alot 🙇‍♂️

minor stag
#

When I dump something like "Administrator:500:aad3b435b51404eeaad3b435b51404ee:e53d4d912d96874e83429886c7bf22a1:::" Which part of this is the crackable hash? Is it the second hash after the colon or the entire thing after "500:"?

next bronze
#

whole thing is crackable, hashcat can parse it

#

but the format is username:group:LM:NT

minor stag
#

Ahh okay. LMNT hashes are slightly more legible than the ones I get from /etc/shadow

next bronze
#

difference hash types, shadow hashes are usually salted

minor stag
#

And they're, what, SHA512Crypt?

next bronze
#

depends on the distro, could be bcrypt, yescrypt, sha256/512

limpid field
#

is there a reason why i can upload a php file with the reverse ssh script in it to the server, try and load it with the url that the instructions told me to load it with and be met with "the requested URL was not found on this server"? i dont know what would casue it at all but after following the guide included in the section it keeps saying that the file was not found on the server

#

<p>The requested URL /nibbleblog/content/private/plugins/my_image/image.php was not found on this server.</p>

minor stag
#

You're sure it actually uploaded and wasn't rejected because of the file type?

snow ridge
#

Module using crackmap exec: Use --screenshot to take a picture using Julio / Password1 creds, then submit DONE as the answer when finished. Any idea why I get this? crackmapexec rdp 10.129.146.226 -u julio -p Password1 --screenshot --screentime 10 --res 1280x720 Nmap shows that rdp is open and I get pings back. Error: socket.gaierror: [Errno -2] Name or service not known

next bronze
#

add the ip and hostname to your /etc/hosts

next bronze
snow ridge
next bronze
#

also add the hostname

snow ridge
limpid field
#

Ill figure it out later

next bronze
#

if it's empty then your file wasn't uploaded, but you should ss the title index of /nibbleblog/... and db.xml

minor stag
#

After three days I finally finished the password attacks module. That was the most frustrating one so far lol

next bronze
#

it's the direction of the traffic, when you use wmiexec, you're initiating the connection to the target, but what if you need a reverse shell? in the case where the target initiate the connection, you'll need remote/reverse port forward

worldly pagoda
#

I have a shell with wmiexec

next bronze
#

yeah?

noble harbor
#

Hello, in module ACTIVE DIRECTORY ENUMERATION & ATTACKS, I've to connect to BloodHound but the credential for neo4j doesn't work ? Do you have an idea of the id:pass ? I've found neo4j:HTB_@cademy_stndnt! but it doesn't work

EDIT : It's neo4j:neo4j

next bronze
#

is that your own vm or provided vm?

noble harbor
#

pwnbox

#

Oh, I see my error now...

#

BloodHound was on MS01 but I didn't notice that... My bad :/

quick crane
#

me too,if you solved,can I dm you

tough lava
#

Hii

quick crane
#

hello

tough lava
#

I am beginner I want to learn about networking any budy help me

compact patrolBOT
minor stag
#

Why do most of the people I ask prefer NXC to CME? Aside from the CME installation difficulties, I haven't seen a huge difference between the two

autumn pilot
#

CME is discontinued

minor stag
#

I have to run it via poetry but it seems to still work just fine, though I'm only using it because the modules use it

stark sandal
#

Did you find a better method to answer number 2 ?

supple gorge
empty imp
#

What are y'all using to write your pentest reports for the exam?

Every single reporting software I'm testing out is full of issues.

All I need is an automated workflow to store my findings and quickly generate reports.

ocean night
#

There's a template I think?

#

But for generating the report.. don't over think it, you'll spend all the time perfecting a report generator instead of writing the report yourself 😉

#

(I made this mistake when taking OSCP, and just ended up writing it myself using my notes and findings)

next bronze
#

I've heard sysraptor is good

minor stag
#

I couldn't get sysraptor to work because for some reason I can't get docker installation to work

next bronze
#

you can use the online version

#

I think a lot of people did for their cpts report

minor stag
#

Is it just built for pentesting reports?

empty imp
#

Maybe I'm overthinking

marble raft
#

Hi! Yes! You can DM and i'll help ya

small sage
woven copper
#

hey did you manage to get this ?

pine dagger
woven copper
ocean night
pine dagger
woven copper
pine dagger
woven copper
pine dagger
#

Yup

lucid mountain
#

Does anyone have any idea what I'm doing wrong in the Sysmon & Event logs section? I'm on the Replicate the Unmanaged PowerShell attack described in this section and provide the SHA256 hash of clrjit.dll that spoolsv.exe will load as your answer. question.
I changed the sysmong config, set it, ran the commands and when I search by event ID 7 nothing comes up

#

I was able to get answer by using get-filehash {path} but I'm curious to why its not showing up in sysmon

acoustic owl
fathom pendant
#

What module/section

dim wolf
pine dagger
#

How goes with you?

acoustic owl
pine dagger
#

Making? Noooo. Doing... not currently, although I want to go back to it. New job + handover from old job is keeping me busy (- -)

acoustic owl
#

But you have understood what I mean. That's the most important thing

pine dagger
#

I think I've got 9 modules to do now, booo 🙂

analog dock
#

I have unlocked the first module of cwee but been postponing it lol

#

Too scared of it

next bronze
#

I might be doing cwee soon

#

maybe

analog dock
#

Web nerd

next bronze
#

gonna become half a web monkey

acoustic owl
narrow umbra
#

@acoustic owl

sly grotto
fossil wing
#

Hi, anyone may help me understand this?

The module: Network Enumeration with nmap.
Section: Firewall and IDS/IPS evasion - Medium lab.

I tried solved this labs of many forms, but I can't do it, so I research in this channel for hints o help and I saw anyone said "pwnbox", so I try use the pwnbox and the same command that I use in my kali that this didn't work but, it works in the pwnbox.

I don't understand, why?

Sorry for my english, I'm improve this skill

pine dagger
#

That lab isn't an easy one. Lots of people have problems with it. And your English is fine. 😉

#

Sadly I dont have notes for that one (- -)

acoustic owl
fringe urchin
fossil wing
fossil wing
fringe urchin
fossil wing
fringe urchin
fossil wing
#

Okk, It could be. Thanks a lot @acoustic owl and @fringe urchin for explain me this, I grateful :3

flat niche
#

Hi, can someone please give me some hint on the skill assessment of the file upload attacks?

#

I have read the source code and uploaded a ||.jpg|| payload, but I cannot get the code executed

zinc verge
#

Heya, anyone able to give me pointers on the logrotate privex module assessment? I can't seem get the ||reverse shell to start. I've found the access logs that get rotated and i can run logrotten to monitor them and it does pick up when it rotates. But my payload doesn't seem to get executed at all. I tried putting a payload of touch /tmp/hello and that doesn't work. Am i missing something?||

zinc verge
#

just to check, the way i'm forcing a rotation is by ||editing the access.log file and that means logrotate when ran by cron will see it needs to rotate|| is that in the right area for how to do that?

hallow remnant
# quick crane me too,if you solved,can I dm you

MODULE: HTTP ATTACKS
SECTION: HTTP Response Splitting

Hey, so as to avoid getting spammed with DM requests in the future, is it possible to ask whatever questions you have here in the open channel? This way others with similar questions who use the search function can benefit from witnessing the correspondence.

fringe urchin
#

htb down?

zinc verge
#

hmmm ok, similar mechanism as i'm adding to the file. Still no luck, but i'll keep at it

ocean night
rustic sage
#

'Something went wrong
Error Code: 502

Our engineers have been notified and are working to resolve the issue.'

fluid basin
#

^^same issue over here as well

fringe urchin
ocean night
#

What's the URL you're trying to access?

ocean night
#

oof ok, checking

fringe urchin
#

ill just wait it out duckthumbsup

cloud urchin
#

i'm having the same issue

ocean night
#

We're working on it, give us a sec, apologies for the inconvenience.

cloud urchin
#

no worries just wanted to confirm

snow ridge
cloud urchin
#

@snow ridge there appears to be issues going on right now with the servers

ember coral
cloud urchin
#

no time to read guys

snow ridge
#

Guess its movie time then

next bronze
#

oof

ocean night
#

It'll be back up shortly

loud anvil
ocean night
#

You should be able to get back in now 🙂 It's recovering

fringe urchin
#

Works ty KermitShout4

zinc verge
#

done

ember coral
loud anvil
#

Anyone else still having issues with the integrated terminal? or is that apart of the recovery process?

ocean night
#

We're still working on it, please stick with us.

loud anvil
runic depot
#

real quick question. doing ELK and it says to Navigate to http://[Target IP]:5601. would that mean i take this IP and put into mozilla with :5601 after?

#

[IP]─[htb-ac-1206217@

old vector
#

I’m stuck on footrprintin medium lab. I’ve mounted nfs share but cannot see in it and cannot travers it. I get permission denied. And I going the wrong direction here

old vector
#

Ok

ocean night
#

Things should be better now

#

We'll be monitoring closely

old vector
#

Thank you very do t know why I was stuck on that I kept trying Sudo cd which don’t work yes Ty

runic depot
#

Navigate to http://[Target IP]:5601, click on the side navigation toggle, and click on "Discover". with this question what is my target IP exactly

dim wolf
runic depot
dim wolf
#

i'm not sure. i'm working on something else rn

runic depot
#

nvm its up

#

thank you i had to restart the page a few times

fringe urchin
#

but it should be better now

mystic furnace
#

Hi team! I'm sitting on ZAP Scanner excersize for ages already and can't get it through. I've read through all the related messages in disc and on the forum - there is still no solution. First of all I was never able to get high level alert on any version/type of scan/infra (aka Parrot web instance or my own remote Kali) on ZAP. Multiple attempts, resetting the target - nothing. I wonder how it works on the side of those who see directly the URL and vuln description in High alert section straight in Zap scanner. wpscan also gives nothing. This is also a question to HTB, asking why this ex is operating so unstable. I was able to find the base URL manually, but checking the related vuln description on exploit-db.com does not progress so far. Whatever options I'm trying to contruct into url I'm getting the blank page back from the server, so no RCE at this moment. I'd appreciate if anybody could DM me to give a nudge.

minor stag
#

I haven't done the module yet but I've used ZAP pretty extensively so lemme see what happens when I try it

flint laurel
#

Hi I need help with the Module DACL ATTACKS I
https://academy.hackthebox.com/module/219/section/2332

Follow along the section and use Pedro's account to connect to DC01 using the Administrator's account hash. Submit the contents of the flag located at C:\Users\Administrator\Desktop\flag.txt as the answer.

I have added the user to the Backup Operators group but i cannot login with the admin hash.

shell ore
#

Am i the only one facing spawning issues rn?🥲

minor stag
flint laurel
next bronze
#

permissions to read the flag?

shell ore
#

Nuh uh wont work 🥲💔

flint laurel
turbid walrus
#

Ahm HTB student version is worth it?

next bronze
shell ore
#

+100000

next bronze
#

I'm not clicking that link, sorry

turbid walrus
#

Ahm yeah But I can access only upto tier 2 nah!?

minor stag
shell ore
minor stag
#

When does tier 2 end?

shell ore
#

Like lets say at least u can get the 3 certs full path

minor stag
#

I didn't even realize there were tiers

shell ore
#

Yeah some advanced modules are not covered in the students plan

#

Like the new Certs

#

And advanced AD stuff

minor stag
#

Gives me something to save my cubes for I guess

shell ore
#

Yep

#

Im thinking either ADCS or OSINT

turbid walrus
faint rampart
shell ore
#

Tbh, its really really worth it

#

Like giving that price, man it’s really worth it

minor stag
cloud urchin
#

I'm working on the Thick Client Apps part of Attacking Common Applications, i successfully obtained restart-service.exe, but when opening it in x64dbg and using memory map i can't find the read/write mapped location to dump the bin. can someone tell me what i'm doing wrong?

shell ore
#

Still no VPN is working for me, can i study please 🥲💔💔💔

flint laurel
turbid walrus
cloud urchin
#

i'm not seeing any MAP RW privs here from the user

shell ore
#

Finallyyyyy

#

It worked

faint rampart
signal laurel
#

skill

faint rampart
flint laurel
next bronze
shell ore
#

ehm, in AD attacks module, im the userenumeration section

#

i spawnede the attcking host, but nothing is there, no other machine is there to attack ._.

#

am i missing smth?

flint laurel
next bronze
#

didn't you say "user is not showing as part of the group"?

flint laurel
remote latch
#

like does this happen?

next bronze
flint laurel
next bronze
#

okay so there's no error, then just dump ntds and get the admin hash?

remote latch
#

how the hell do i do the service login on login brute force

#

its all fucked

#

even the question doesnt make sense at all

flint laurel
next bronze
#

read and follow #welcome and you can upload screenshots

next bronze
flint laurel
next bronze
#

just show the command and any errors

#

in fact you can just copy and paste them

remote latch
#

im desperate

#

this is fucked, never doing brute forcing again

next bronze
#

your diskshadow command is not correct, there's an extra command at the back

#

and again, you can dcsync with the machine account hash

ocean night
#

Please don't post information for modules over Tier 0.. take it to DM. This is covered in our Terms of Service.

shell ore
#

hiiiii g0blin :).

ocean night
#

👋

next bronze
ocean night
#

With respect, I disagree. I've nothing against people helping each other, but posting information pertaining to modules over T0 is not permitted.

cloud urchin
next bronze
#

and for me to be able to help, I'll need some information

ocean night
#

Then again, take it to DM 🙂 Appreciate you offering your assistance

next bronze
#

when I reply to DMs, people just use me as their personal tutor and DM whenever they want, so I don't do that anymore

ocean night
#

Ahhh @hexed spindle T2 module

#

I'm done, nn

hexed spindle
#

My bad, just saw your post.

flint laurel
#

Long week

ocean night
#

Just like a speeding driver saw my finger as he almost plowed in to me, but didn't see the 40 MPH sign 100ft down the road as he drove over 60 MPH

#

Speeding drivers NotLikeThis

#

Sorry 😄

shell ore
#

btw question, when submitting a walkthrough, how long does it usually take to get accepted/rejected?

hexed spindle
ocean night
#

🤷‍♂️ I should just stop trying I guess

#

Rock on 😴

hexed spindle
#

Keep on keeping on, just be kind.

vocal lagoon
shell ore
vocal lagoon
#

are some of the target machines not working either?

#

it's that or I could be dumb

#

Strong possibility

#

I can't even ping the target host :c

ember coral
vocal lagoon
#

even if im using the built in vm?

#

it hasn't been an issue before this

#

unless something looks very wrong here im not sure what im doing differently

#

currently doing the public exploits part

fringe urchin
vocal lagoon
#

that

#

would explain some things

#

thanks :)

noble harbor
#

Can't connect with RDP to the lab in Living off the lands

#

I've tried with :

rdesktop -u htb-student -p 'Academy_student_AD!' 10.129.22.65
rdesktop -d . -u htb-student -p 'Academy_student_AD!' 10.129.22.65
rdesktop -d INLANEFREIGHT.LOCAL -u htb-student -p 'Academy_student_AD!' 10.129.22.65
xfreerdp /v:10.129.22.65 /u:htb-student /p:'Academy_student_AD!'
ember coral
# noble harbor

all of those ssh and rdp sessions are an absolute nightmare with responding and laggyness but double check the password provided, a few labs switch up the user/password combo for some reason

noble harbor
#

🤡

#

Restarted lab again

#

and it work now

timid steeple
#

Hello!
I’m having some trouble on SOCKS5 Tunneling with Chisel module/158/section/1437
When I tried to upload chisel it couldn’t execute binary as it was sent from my machine that runs aarch64 while ubuntu @web01 is x86_64
So I then transferred and x86_64 binary of chisel to the pivot host which runs and connects to my attack host. All good.
The problem is when I then try to xfreerdp I get the following error:

$ proxychains xfreerdp /v:172.16.5.19 /u:victor /p:pass@123
[proxychains] config file found: /etc/proxychains4.conf
[proxychains] preloading /usr/lib/aarch64-linux-gnu/libproxychains.so.4
[proxychains] DLL init: proxychains-ng 4.16
[proxychains] Strict chain ... 127.0.0.1:9050 ... timeout
[17:51:46:831] [329929:329931] [ERROR][com.freerdp.core] - freerdp_tcp_connect:freerdp_set_last_error_ex ERRCONNECT_CONNECT_FAILED [0x00020006]
[17:51:46:831] [329929:329931] [ERROR][com.freerdp.core] - failed to connect to 172.16.5.19

I would really appreciate some help, is it still something to do with aarch64 into x86_64 ? HELP! I have also edited and confirmed the proxy chains like the module says to do.

elder flame
#

Module: "Linux Fundamentals", can't to connect with ssh to htb-student@94.237.45.59, wrong password or ip, I don't know

#

chapter "System information"

#

I got ip address using ifconfig in parrot Vmachine

#

I don't see it being specified in the task

#

help pls

#

ohhh

#

my bad

#

thanks

fathom pendant
#

You also need to use the specified port if there is one

#

Generally in most circumstances is as simple as adding -p

upbeat oak
#

I'm stuck trying to enumerate the ftp server to find the flag. I've so far tried to login anonymously but that requires a password still of course, is there another method for logging in I'm missing or do I need to find the credentials somehow maybe with nse?

fringe urchin
fathom pendant
#

4HEad sometimes you can just hit enter

#

It depends how it's set up

upbeat oak
#

I'll try that out and add to my notes

elder flame
#

now I'm waiting endlessly for ssh's reaction.

#

nothing happens

fathom pendant
#

Well if it's not generally quickly: you're doing something wrong

#

Reminder as i said earlier: if it's a public ip: you'll need to also use the port

elder flame
fathom pendant
#

2 things:

  1. I'm assuming you're connected to the vpn
  2. can you ping the box
normal brook
#

can someone help me with the linux privilege escalation module? I'm stuck at the introduction where i need to "enumerate the linux environment and look for interesting files that might contain sensitive data. Submit the flag as the answer"

hallow remnant
#

MODULE: HTTP ATTACKS
SECTION: Software Vulnerabilities
Question:

I've gone ahead and solved this section's exercises, but I came across a behavior that I don't quite understand. In the section, they give an example of ordering the requests as the root page "/", then the 404 page "/404", and then root "/" again. The module explains that the descynchronization results in the /404 page response as returning back to the request to the 2nd root "/" request. To me, this suggested that third request could go to an arbitrary page (e.g. "/doesntmatter"), so long as the Host header was the same.

In practice however, I found that the third request does matter, and I don't know why. More to-the-point: if I request "/", then "/admin", and then "/admin" again, the exploit does not work. But if I do "/", "/admin", and then "/" it does. Why the discrepancy?

crystal steeple
#

hey im trynna replicate what shown in the creds enum in linux in the AD module using bloodhound

#

i launch bloodhound from my attack host but i have no idea what to put on the neo4j URL

#

its says database not found

next bronze
#

have you started it?

crystal steeple
#

the sudo neo4j start from the ssh connection?

next bronze
#

ssh? where are you running it?

#

bloodhound needs a gui, you won't be able to run it in ssh

next bronze
#

do it in pwnbox or vm

crystal steeple
#

its worked using xfreerdp

ember coral
#

anyone else having issues with labs crashing? they are spawning fine but stop responding after about 3-5 min

cloud urchin
#

Going through the Attacking Common Applications module, I'm at the Thick Client & Web Vulnerabilities section. I've built the new fatty-client-new-2.jar which works fine. i'm able to connect to the server without issue, however when i go to compile the traversal.jar it doesn't launch after building. Double clicking on it does nothing.

vital seal
normal brook
vital seal
thorn urchin
#

who said you couldnt put ascii inside png files :)?

#

as for whether or not a file gets executed as code that depends on the server settinga

#

but typically it works based on the file extension

#

review the section notes about bypasses

#

well its a .png so its not gunna be interpreted as anything else

#

the whole idea behind this kind of attack is to go after the ambiguous parsing between them

#

you want to convince the upload form its a png and convince the server its php

#

examine the bypasses for it. review the section notes

#

What I try to do if my initial guesses dont work is to script generating the different combinations and then use ffuf to brute em

#

is trying some doesnt work then try ALL of them 😛

#

¯_(ツ)_/¯

#

unless a function is changing the file name it really shouldnt be

#

and even then its usually a pattern

#

which module are you doing

cloud urchin
#

anyone complete the attacking common applications module that can help?

cloud urchin
#

i did ask

thorn urchin
#

Read the link

#

its about asking better questions to more likely get a response

cloud urchin
#

Going through the Attacking Common Applications module, I'm at the Thick Client & Web Vulnerabilities section. I've built the new fatty-client-new-2.jar which works fine. i'm able to connect to the server without issue, however when i go to compile the traversal.jar it doesn't launch after building. Double clicking on it does nothing. -- i asked that earlier

#

never got a response so i asked if anyone's done it

thorn urchin
#

Then shoulda referenced it lol

#

Id recommend watching ippsecs video on the box Fatty, this section is straight ripped from that box and you can follow it along to understand it better

cloud urchin
#

i rebuilt this all again following the steps correctly again (step has a mistake in it) but it still doesn't work

#

alright i'll check it out

#

he's using software that's not included in the virtual machine

thorn urchin
#

ah yeah you need to do some code reading for that one 🙂

thorn urchin
#

this is the hardest section in the module

cloud urchin
#

i understand the concept. recompiling it works fine, up until i recompile it again for the traversal.jar

thorn urchin
#

and one of the worst sections in the whole course

cloud urchin
#

hence why i'm reaching out for help

thorn urchin
#

Right, and my help is to follow along with that video

#

Youve definitely made an error with the second jar so you need to pay attention and see if you can discover what that error is

cloud urchin
#

there's only 1 step

thorn urchin
#

honestly decent chance you just have a typo in your code

limpid field
#

im able to see the php script i uploaded in the nibble section of etting started but visiting the url to run it is just displaying half the command and not establishing a reverse shell

limpid field
#

ping you where

limpid field
#

I must have a bad remote shell script because none of the ones in the chest sheet or in the instructions are working, I know for a fact netcat listen is on the right port because I copy and pasted the commands to try and make it work

next bronze
#

did you change the IP to your own tun0's IP?

limpid field
#

i tried both setting the ip in the command to tun0 like the guide says and using the one listed under tun0 in ifconfig

next bronze
#

both? those mean the same thing, there should only be one correct tun0 ip

limpid field
#

i tried "tun0" and the actual address neither work

next bronze
#

screenshot the reverse shell you're using and the output of ifconfig

limpid field
#

ok you aint gonna believe this but every time i copied the address from ifconfig the copy selection left out the first 1 in the address

old vector
#

On the footprinting lab hard I’m getting this. I thought v3 of snmp didn’t let you enumerate because of requiring authorization (snmpwalk)

fringe urchin
limpid field
#

now im on the http server file transfer for the linEnum script but i keep getting 404d

old vector
#

Well there’s no username they gave to authenticate

#

I tried logging in guessing some default usernames and passwords in imap and pop3s with no luck

#

So looking back into snmp lesson they didn’t go thru v3 I tried using engine I’d but still wants username

fringe urchin
#

yea nwm dont listen to me. i read it as smb and not snmp... im too tired to stay awake

old vector
#

I’ll come back to this later pm me if you have a clue of what I may be doing wrong. So far nmap and tried all scripts snmp* . Tried snmpwalk but authentication issues. Maybe guessing can use braa haven’t done that yet

limpid field
#

running the file with my reverse shell as root for privelage escalation is starting then immediatelly stopping

rustic sage
thorn urchin
limpid field
#

idk if the guide and the machine are different versions cause i nknow nibbler exists seperate of 'getting started'

thorn urchin
#

shouldnt be enough to not work

#

might have a typo in your command

limpid field
#

the reverse shell as root is working its just immediatelly stopping after, and copying commands into the virtual machine has been messed up for me today

thorn urchin
#

though the easy way in this scenario would be to not use a revshell even if it tells you to because thats silly, you already have a shell to work with.

thorn urchin
limpid field
#

can i put something like sudo su - at the end of the file and just root myself then and there

thorn urchin
#

since you already have a shell and just need to escalate I would instead use a simpler payload like /bin/sh -p

thorn urchin
#

doesnt hurt to try and learn

limpid field
#

i am going to try the sudo su then the one you said

thorn urchin
#

go for it

#

experimentation is king

#

using a revshell when you already have a shell is more useful for cases where the priv esc is like an automated service or is spawning a sep process you cant interact with

limpid field
#

swag

thorn urchin
#

👍

dim wolf
#

after taking about 4 hours to set up the VMs i think i can finally finish malware analysis

sleek moss
#
  • 1 What is the IPv4 address of the hostname DC1? tips for footprinting dns
cloud urchin
#

nslookup

sleek moss
#

└──╼ $nslookup DC1 10.129.63.18
Server: 10.129.63.18
Address: 10.129.63.18#53

** server can't find DC1.lan: REFUSED

cloud urchin
#

are you logged into the dc itself?

dim wolf
#

ok so i'm confused on this
Intro to Malware Analysis -> Debugging
what exactly does it mean by "our VM/machine", because i've seen HTB refer to my own personal VM as "our VM", but i'm not entirely sure in this case

cloud urchin
#

i don't know about that module, but i believe in practice you detonate the malware on the same machine that has inetsim running since i think it simulates traffic to fool the malware into thinking it's successfully connecting to its c2 etc

dim wolf
#

the malware is on HTB's target machine, and i'm using my own VM to run inetsim

cloud urchin
#

i'm not sure though maybe it runs on your kali box and responds

#

i can see how that can be confusing

#

been a while looks like inetsim does run on the kali

dim wolf
#

so what IP address do i use

#

is it my VM's TUN IP or is it the target's IP

cloud urchin
#

it says in your screen shot

dim wolf
#

looks like i set it up correctly then

#

and now my target RDP connection is bugging out :(

cloud urchin
#

service_bind_address should be tun0, along with dns_default_ip

dim wolf
#

ok we're all good. thanks for clarifying

#

i don't think RDP likes me having two simultaneous VPN connections

#

because it's losing connection every minute or so

heavy hearth
#

Finally 🕺

upbeat oak
#

I'm trying to connect to the smbclient and rpcclient however I'm either getting an error nt status timeout or nt status host unreachable error. nmap scripts seem to not be working either is this something on my end?

minor stag
#

can you ping the IP?

upbeat oak
alpine umbra
#

i want to find cms of the vhost and i try each tool in the section no lock? help....

fathom pendant
#

Use the provided tools and Google

minor stag
#

Why does this not work for me

thorn urchin
minor stag
#

It is mssql, but the module only focuses on mysql commands and my google fu seems to be weak today

thorn urchin
#

which module

minor stag
#

I can't even get sqsh and sqlcmd to install properly so I have to use the mssqlclient.py

thorn urchin
#

the module discusses mssql

minor stag
#

Nvm, I found the command

rustic sage
#

Hello, i'm studying a specific course for cybersecurity, and i want to practice in hand in hack the box about the section that i was studying which is SSH, so i typed in the academy search bar SSH, but i'm lost and don't know how to practice for this specific thing.

thorn urchin
rustic sage
#

No i'm talking about the sections, because i don't see sections called SSH but i see it appears in the search bar.

thorn urchin
#

the search bar searches module contents

#

some modules have sections that reference or utilize ssh

#

but theres not a dedicated ssh module

#

academy isnt a good option for just learning ssh

alpine umbra
rustic sage
# thorn urchin there is no single module that covers just ssh

For each section of the course i want to practice in hand, so for example : i saw a section about reflected attacks and wanted to practice it, so i typed in the search bar reflected attack or xss, how can i practice after that if there is too many modules having this section?

upbeat oak
#

Trying to use netsharegetinfo <share> to get more info on the share to find out the customized version of the share but I'm unsure of what exactly it wants me to put or if i'm using the wrong command? figured everything else out

thorn urchin
#

if you wanna do the xss modules do the xss modules

rustic sage
#

Just pick anyone randomly?

#

Sry i'm new.

thorn urchin
#

if youre new Id recommend following the CPTS pathway

#

it covers a little bit of everything

rustic sage
#

what is the full term of CPTS?

upbeat oak
#

figured it out

thorn urchin
#

Certified Penetration Tester Specialist. its htb's cert

#

even if you dont go for the actual cert itself id recommend doing the course

rustic sage
#

I wish i can just focus in hack the box because it's all in hand experience, but i'm rolling in programs that i bought and i have to complete them but i prefer to practice in hand for each section the course covers.

thorn urchin
#

academy is extremely hands on

#

every module has practical labs

rustic sage
#

Yes, let's say you are in a course, you saw a section talking about Session hijacking, how you will practice for it in hackthebox?

thorn urchin
#

the module will have a section specifically for you to practice it

rustic sage
#

The names are different, how can i recognize and know that this section is covering what i need for the course?

thorn urchin
#

the CPTS course?

#

or your personal course?

#

ignore the search bar its confusing you for some reason

rustic sage
#

No, i'm in a harvard course, there is a section mentioning SSH secure shell to connect to a remote server to execute commands in computers remotly, so i typed in the search bar of hack the box academy : SSH.

But i saw too many results under them with a green typo : SSH. But after clicking , i don't see any section written as SSH.

thorn urchin
#

academy isnt a good resource for just ssh

#

some modules will have sections covering elements of ssh thats related to their topics but thats it

rustic sage
#

So if i clicked on any module / section mentioned in the search bar as ( SSH ) it means that there is a section for it in the module even if it's not written as SSH in the module or section?

thorn urchin
#

more or less yeah

#

for instance the password attacks module will discuss ssh in the context of bruteforcing ssh

#

while the pivoting module will discuss using ssh in terms of pivoting

rustic sage
# thorn urchin while the pivoting module will discuss using ssh in terms of pivoting

Thanks for explaining, i will paste this to you from harvard course : SSH is a secure protocol by which you can execute commands on a remote server.
If one wants to communicate with a remote computer and execute commands there, one may issue an ssh command. The following is an example of using the SSH command to connect to a server at Stanford University. You would still need appropriate credentials and permissions to successfully connect.

ssh stanford.edu
If one has the appropriate access rights, one can execute commands directly on a remote server.

#

So after this one, i can just hop into anything written as SSH in hackthebox, or i have to practice specifically for what mentioned in harvard course?

thorn urchin
#

Thats up to you lol

#

but I would not recommend just hoping into random modules for that lol

cloud urchin
#

i'm surprised ssh wouldn't be covered under the linux fundamentals module

thorn urchin
#

academy isnt a generic basic education platform

thorn urchin
rustic sage
#

The practice way that i prefer is to read and after that practice for it, then next section of the course read and practice for it in hand, but i don't want to practice something not related to what i read in the course 🙂

thorn urchin
#

ill be blunt Krozza you may be attempting htb stuff a little too early in your learning journey

rustic sage
#

I understand but all i need is to know how to practice for a specific thing that i'm studying, because you said that you don't recommend just choosing a random thing

thorn urchin
#

Yeah I dont think thats an effective usage of htb academy

cloud urchin
#

ssh is just one command, a very simple one at that, that securely connects you from one computer to another..

thorn urchin
#

not to the minutia youre looking for

rustic sage
#

So if you were me and you saw a topic in the course that you are enrolled in, how would you practice for it in hack the box?

thorn urchin
#

Depends on the topic

#

Im not doing your course so how would I know

rustic sage
#

Okay i will clarify

thorn urchin
#

htb might not be a good practice for some things in your course at all

cloud urchin
#

i would imagine the course itself is the best resource for the course you're going through

rustic sage
#

Stored Attack
A website could be vulnerable to an attack where it is tricked into storing malicious code.
Imagine where one could email malicious code. If an email provider blindly accepts any code sent to it, any person receiving the malicious code may become a victim of an attack.

So after you read this, how would you practice for it in hack the box?

thorn urchin
#

I wouldnt because that sentence is vague nonesense

rustic sage
cloud urchin
#

yeah that's a very broad statement and could be done in a myriad of different ways

thorn urchin
#

let me use an analogy

cloud urchin
#

you're not going to be able to study each way before moving on in the course without taking up a ton of time

thorn urchin
#

Youre basically doing the equivalent of "Learning what food is" course and then asking how to use a habachi training school to cook mexican food.

rustic sage
#

LOL

#

I'm just trying to practice man, i hated reading alot without in hand experience

thorn urchin
#

Oh I get it

rustic sage
#

i feel like i'm doing litterly nothing

thorn urchin
#

I didn't vibe with college education for the same reason

#

Honestly what I would do in your shoes?

cloud urchin
#

it may be Rei, i didn't do that one

vocal lagoon
#

I just started htb like 3 days ago I could've sworn it had ssh

#

lemme check

thorn urchin
#

Take your college course and focus on the course. and if you have extra time. do the htb penetration tester job role pathway course as well. But dont necessarily try too hard to match up the information in both to each other.

vocal lagoon
#

huh I guess not

#

I just went right into htb without any linux experience and it's been something for sure

rustic sage
thorn urchin
#

your course sounds like its in the babys conceptual explanation stage of security, htb is for the practical elements that come after

cloud urchin
#

krozza you'd be splitting your learning

#

htb has a lot of advanced concepts

thorn urchin
#

yeah so either dont. or make sure theyre kept split lol

rustic sage
vocal lagoon
#

krozza from my experience coming from almost nothing with htb, you gotta rely on google and your own study methods otherwise you'll suffer

cloud urchin
#

you're putting the cart before the horse

vocal lagoon
#

yeah

thorn urchin
#

its okay to take babys steps

vocal lagoon
#

as much as it sucks you gotta just stick it out in the harvard course for now until you get the ideas down

#

write everything down/take notes

rustic sage
#

True, thanks for the support guys, never thought i will find amazing people like you so open and willing to help.

#

❤️

vocal lagoon
#

<3

thorn urchin
#

this chat can be extremely toxic you just got lucky kek

vocal lagoon
#

htb is incredibly fun but difficult if you come from not knowing anything

#

so after your course you'll prob have a better time :)

rustic sage
thorn urchin
#

or even the middle if youre a fast learner!

vocal lagoon
#

that too

#

I'm coming from knowing nothing basically

#

I've been uhhh

#

skipping around modules to say the least

rustic sage
vocal lagoon
#

now that it's been a day or 2 I need to go back and redo all the ones I've done to reinforce what I know

#

yes :)

rustic sage
#

@cloud urchin Appreciate it ❤️

vocal lagoon
#

trust fox more then me though

#

he knows what he is talking about, I am just yapping

rustic sage
rustic sage
cloud urchin
#

man i'm at a loss on this module. teh attacking common applications one. i cannot get fatty-server.jar downloaded, it just keeps loading in the jar's text window instead of downloading

rustic sage
#

Third question credential hunting in windows. Uploaded lazange but it appears powershell doesn’t have python on it and work work

rustic sage
dim wolf
#

it was a doozy

rustic sage
#

How long did it take

#

Any hints on why lazange isn’t working on victim for the third question for credential hunting. I migrated the .py but it’s not running as it says Python doesn’t exist and the victim doesn’t have outside connection to the internet

dim wolf
#

minus personal VM setup because trying to work on the target is laggy

cloud urchin
#

the commands in this module do not work if you follow them exactly, and it doesn't explain what the command does, this should be updated imo

indigo locust
#

Need help for below question:

ATTACKING COMMON SERVICES

Attacking DNS

Find all available DNS records for the "inlanefreight.htb" domain on the target name server and submit the flag found as a DNS record as the answer.

I added " inlanefreight.com" and the Target IP into /etc/hosts. Then created and added "ns1.inlanefreight.com" to resolvers.txt . then ran subbrute but all of the subdomains it gives me ends with "inlanefreight.com" not ".htb" not sure if that makes a difference. Lastly I run dig for each subdomain but it times out. Can someone please help?

crimson moon
#

How to see the full path of CPTS? I find myself manually selecting modules is there a way it does automatically switch to next module after one completes a module/path without having to do that manually?

indigo locust
grand portal
#

need hints

#

i opened wireshark and started capturing, then ran malware and after a few seconds stopped capturing, still scrutizing. the answer format got me thinking, it should be only 3 values like 1.1.1?

cloud urchin
#

it says provide the domain, not the ip

vocal lagoon
#

on the introduction to nmap module could someone explain the suddon use of sudo in the example? from the first image to the 2nd

#

I know the first one is just reading commands

dim wolf
vocal lagoon
#

ahh I see

#

is their an indicator for it?

dim wolf
#

i would look at the man pages

#

it's probably there

dim wolf
# grand portal need hints

i didn't do this, but i believe theoretically you can capture the packets that detail the server it connects to

limber river
grand portal
vocal lagoon
#

I see

grand portal
dim wolf
#

if what you're looking for is a DNS query, i would investigate why you're not capturing any DNS queries

#

because from the way you worded it, it sounds like you couldn't capture any network activity

grand portal
#

I did capture the traffic, i was looking for ip, knowing what domain means. mind just off sometimes. well if you did not do the module, there is no more help i can get from you. Thanks for trying.

dim wolf
#

if the question is asking for a domain, i'd assume you would filter for a domain name and not an IP address

#

that being said, i did say theoretically, so if it doesn't work, then it doesn't work

#

there is a surefire way to get to the answer, and i would say scrutinize the disassembly in IDA if you want to figure this question out

dim wolf
grand portal
grand portal
#

may i dm you what i found?

dim wolf
#

sure

weak beacon
#

I'm working on the sqlmap attack tuning module and I got the table with the flag but its keeps outputting blank. I tried restarting the host a few times now with the same results.

soft cedar
weak beacon
#

I copied the get request with the param from burp to a file

soft cedar
weak beacon
#

I have

sqlmap -r req.txt --dump --batch --risk=3 --level=5 -T flag5 --no-cast
[23:39:27] [INFO] resumed: 1
Database: testdb
Table: flag5
[1 entry]
+----+-----------+
| id | h}ntent   |
+----+-----------+
| 1  |           |
+----+-----------+
#

Thats when I decided to restart the host again in case risk 3 mucked it up

soft cedar
#

so usually what I do is to open the the req file copied from burp with a text editor and add * at the id parameter to indicate the injection mark.

soft cedar
weak beacon
#

I'll see what happens and thank you!

#

I went ahead and got the next question done and working on the last one. I'll circle back once I get case 7 finished up

soft cedar
soft cedar
weak beacon
#

Didnt have to restart

#

Ok I lied. I will because risk 3 butchered it lol

buoyant void
#

Command Injection module finally done, skill assessment was shockingly easy

shadow current
#

Attacking SQL Databases
im having a hard time connecting to the target should i rdp with the given credential? to perform the task

buoyant void
crimson moon
shadow current
buoyant void
# crimson moon So it’s CPTS path?

Yeah to take the CPTS you need to complete the Penetration Tester job role path. Every time you finish a module it'll give you an option to continue the penetration tester path and take you to the next module

crimson moon
buoyant void
#

@mrn0b0t I'm sure it's different for everyone but yeah command injection was far easier to figure out than file uploads. Barely took me 20 minutes. Best advice for it, take a few minutes to look at every request and then the actual command injection part is just everything taught in the module really simple

gilded fulcrum
#

so anyone willing to help me with a lab i'm stuck on?

#

essentially i found a private SSH key via IMAP. as far as i know, I can only copy paste the key. I made a id_rsa file and did chmod 600. only issue is when i use it to log i nto SSH it tells me "error in libcrypto and a permission denied public key.

soft cedar
gilded fulcrum
#

as far as the banners?

#

it has the -----BEGIN OPENSSH PRIVATE KEY----- and the ending banner

soft cedar
#

one thing is, you can send it over to ChatGPT to check it for ya.
remember to say please xd.

gilded fulcrum
#

can VIM show line breaks or whitespaces?

#

or do i need to use a text editor?

fathom pendant
#

I mean vim default shows $ at the end of a line

shadow current
fathom pendant
shadow current
#

thansk guyss

soft cedar
fathom pendant
gilded fulcrum
#

so i literally type in %s/ //g ?

fathom pendant
#

I believe you can do that in vim

#

You can also use sed to do it

#

You mean command mode

soft cedar
soft cedar
fathom pendant
#

Insert would Insert the chars

#

You don't have to use : to the front either

shadow current
#

still cant log in using mssqlsvc

#

idk what im doing wrong

#

im using the password that i got from cracking

soft cedar
shadow current
soft cedar
#

like @fathom pendant said, you can use mssqlclient.py
its quite a handy tool

fathom pendant
#

Spoilers as the pw is an answer to a question btw

soft cedar
shadow current
#

yeah deleted it

fathom pendant
#

What is the specific syntax used (omitting/obfuscating the pw)

#

I think mssqlclient needs the -windows-auth but I'm not 100% on that

fathom pendant
#

Unsure about sqsh since I couldn't get it installed at the time I did this module

soft cedar
shadow current
#

got it now

#

restarted the vm

gilded fulcrum
#

so i tried extracting the key directly from evolution so there was no formatting error. i am still getting the permission denied public key.

fathom pendant
gilded fulcrum
#

shit lol

#

srry for cursing

fathom pendant
fathom pendant
gilded fulcrum
#

yeah i did chmod and stil lsame thing

#

okay idk all the rules or not lol

#

im working on the hard lab the footprinting module

fathom pendant
#

Ah

soft cedar
fathom pendant
#

But yeah, either your key is wrong, or you're using the wrong username

#

Spelling and casing is important

#

Bob is different from bob

faint rampart
fathom pendant
#

Not really

gilded fulcrum
#

well i got the tom username and dudes password from braa

fathom pendant
#

Sounds like there's something wrong with the syntax

soft cedar
faint rampart
# gilded fulcrum shit lol

If you are so sure you have the correct perms and its the key itself
You can use curl to retrieve it. You dont need a GUI tool

soft cedar
#

I just asked chatGPT to format it for me kek

fathom pendant
#

Another thing you can try is pasting the key into another editor, I had a weird issue where it swapped characters around in one editor

faint rampart
#

You could easily download a mail with something like this

curl -k --url 'imaps://10.129.145.94/INBOX;UID=$MAIL_ID' --user $USERNAME:$PASSWORD > mail_file
fathom pendant
faint rampart
fathom pendant
#

A billion ways to crack an egg

faint rampart
soft cedar
#

^

fathom pendant
#

Sounds like you had bad syntax and are trying to blame the module

#

¯_(ツ)_/¯

#

There are definitely occasions where the section provides not-so-optimal commands

#

I.e. 1 fetch 1 all for imap when body[] actually retrieves the message

gilded fulcrum
#

not trying to blame module im trying to figure out what i'm doing wrong

#

ill try the body[] command

fathom pendant
mint echo
#

Hi Guyz, I was learning about SSH keys in the Getting Started module. I wanted to try it out for myself so,

  1. I opened up a VM Kali and created a Private SSH key on my host machine.
  2. I copied the key and pasted it in a text_file (id_rsa) in Kali then entered the following commands on my terminal:
  • chmod 600 id_rsa
  • ssh <target_system_username>@<target_ip> -i id_rsa

but after this it said connection refused, why is that?

#

can someone please help me out with this.

gilded fulcrum
#

also that curl command did not work for me it said log in denied

fathom pendant
#

On the target

soft cedar
fathom pendant
gilded fulcrum
#

ss my keys?

fathom pendant
#

Screenshot

soft cedar
fathom pendant
#

I'd have to spin the lab up and grab it

#

But screenshot works too

sterile epoch
#

I am in LFI module automated scanning section. when I try to scan for new LFI strings I do not get any hits even tho I use the same command and wordlist in the example
ffuf -w /opt/useful/wordlists/Security-Wordlist/LFI-WordList-Linux:FUZZ -u 'http://94.237.49.138:54324/index.php?language=../../../../FUZZ'

gilded fulcrum
#

Ive also tried without the ^M as well

fathom pendant
#

That's why it didn't retrieve

fathom pendant
#

Similar to $ as end of line

#

Looks like your program uses ^M instead of $

gilded fulcrum
#

no actually VIM did that automatically when i copy pasted it from evolution. it does'nt normally do that lol no idea why.

#

what do you mean no space?

#

you mean no added line from the brackets?

fathom pendant
#

yes

#

it's literally just 1 fetch 1 body[]

#

not body []

#

when you do md5sum <keyfile> what's the sum

#

here's what i got

#

also it works just fine for me

gilded fulcrum
#

so mine just worked after copy pasting it again from evolution lol

#

no idea why that worked this time

#

ill try that md5sum though because i've never done it

#

4496658cd8c13c64de541c4ce2b305ea id_rsa

faint rampart
# gilded fulcrum

youre using the imaps syntax for pop3 which is why it says "weird reply" lol

gilded fulcrum
#

i tried the same command for both imap and pop3 becausethe imap wasnot working either so i changed it to pop3 incase it worked on that

faint rampart
fathom pendant
#

it should work

#

ssh tom@ip -i key_file

#

if you don't add the key file as an argument it thinks you're connecting via passwd auth

gilded fulcrum
fathom pendant
#

which in this case: is disabled

gilded fulcrum
#

well i got it to work lol

sterile epoch
fathom pendant
next bronze
fathom pendant
soft cedar
next bronze
#

blocked and reported

gilded fulcrum
#

lol nano makes me suicidal

next bronze
#

that is @haughty stirrup behaviour

soft cedar
fathom pendant
#

anyway

#

i forgot how straightforward the hard lab was for this module

gilded fulcrum
#

it is a good lab for repetition would have completed this waaaaay faster if i had updated my copy paste skills

minor stag
#

I'm following along with the module here, but now I'm stuck. I can't get these commands to work to steal the hash and can't move on without it. Is there another term I'm supposed to replace "master" with that I'm missing?

faint rampart
minor stag
#

And that's what I was missing. I had the correct amount of dots for one of them and that's the one that I didn't need lol

fathom pendant
#

lol

minor stag
#

Thanks

fathom pendant
#

np

faint rampart
#

Nope

faint rampart
# faint rampart Nope

Ligolo does portforwarding like a portbind, all you gotta do is bind a port to a local one and access from there.

#

Youre welcome!

next bronze
#

172.17.6.20 is in a difference subnet than 172.17.8.0/24

soft cedar
#

^

next bronze
#

use -windows-auth, also blur out passwords please

minor stag
#

Deleted. WIll remember that

#

Why didn't I need to use -windows-auth for the original login?

fathom pendant
#

because it's telling the program that you're authenticating with a local user instead of a domain user (i think)

#

i could be wrong on that

#

it's at least triggering an auth for windows systems

#

i.e. a ntlm auth mechanism

minor stag
#

I don't think the module explicitly mentions needing to use -windows-auth so I could've been stuck at that for awhile lol

#

It also seems to prefer sqlcmd and sqsh, neither of which I can get working

fathom pendant
#

well sqlcmd is a windows binary

#

and sqsh is just dumb afaik

minor stag
#

It's weird. I managed to get sqlcmd to work on a single terminal instance, but when I switched terminal instances it didn't recognize the 'sqlcmd' command anymore

faint rampart
fathom pendant
faint rampart
fathom pendant
#

¯_(ツ)_/¯

#

i haven't tried

soft cedar
faint rampart
fathom pendant
#

TIL

fathom pendant
#

worst case is "no"

faint rampart
soft cedar
sterile epoch
faint rampart
sterile epoch
#

why is this happening?

faint rampart
misty mirage
#

I try solve first exercise of linux module and I copy then type the passowrd

ssh htb_student@10.10.11.253
htb_student@10.10.11.253's password: 
Permission denied, please try again.
htb_student@10.10.11.253's password: 
Permission denied, please try again.
htb_student@10.10.11.253's password: 
htb_student@10.10.11.253: Permission denied (publickey,password).
faint rampart
# sterile epoch yes

Dont copy-paste the module examples everytime with the intent that its the same environment in the assessment.

minor stag
#

It's a pain in the ass doing DNS enumeration on the htb spawned servers lol. They seem to be very finicky

sterile epoch
#

94.237.48.205:49425
here is the ip you can try visiting it. I tried to look at the source it wasn't much sense

fathom pendant
#

the target IPs follow 2 formats: either private IP 10.129.x.x or public IP:port

faint rampart
sterile epoch
#

oh alright I will look elsewhere then thanks

misty mirage
fathom pendant
#

linux fundamentals?

misty mirage
misty mirage
fathom pendant
#

what section?

sterile epoch
#

I guess I get whats wrong now

misty mirage
faint rampart
fathom pendant
#

spawn instance =/= spawning target

#

spawning instance spawns the in-browser pwnbox

misty mirage
fathom pendant
#

??

misty mirage
fathom pendant
#

if you're using your own vm/vpn the tun0 ip is YOUR ip that the labs will communicate with

fathom pendant
#

and perform the tasks

#

again not "Spawn instance"

misty mirage
fathom pendant
#

it will give you a 10.129.x.x address to ssh to

misty mirage
fathom pendant
#

also as stated previously it's htb-student not htb_student

#

the ip you were attempting to ssh to is either yours or another user that's been assigned that ip

#

even if the user doesn't exist: ssh will still prompt for a password

rustic sage
#

Password module
Credential hunting
Third question
Tells me to use lazange but the victim doesn't have outside connection, had to smb server it over. Lazange.py can't run on the environment. Lazange has a folder for windows but apparently needs Python to work. Tried to run it all sorts of ways but no luck

Maybe I need to import the entire git

Maybe I should of used cmd

Idk I'm stuck if you're bored but I spent about 2 hours on it.

strange pivot
rustic sage
#

Agggggghhhg

#

Ok done. Thanks

#

HTB always gets me on some crazy technicality

strange pivot
#

Its all trial and error my friend, it happens to me all the time, don't worry about it

rustic sage
#

Ok I was thinking I was a dunce, did you pass anything yet

strange pivot
#

I did that module I'm on the attacking common services one now

rustic sage
#

This module is an ass whooping

#

Good luck

strange pivot
#

Thanks, you too

rigid holly
#

Attacking Thick Client Applications

timid steeple
#

thanks for your reply, can you tell where is the probelm is from? feeling stupid here.

dense pollen
#

In the Blind SSRF Exploitation Example module, does anyone know if it is possible to perform a portscan via the html we can upload? I have tried it but I cant seem to get it to work

quasi summit
#

Hi all , in the AD Administration: Guided Lab Part II i have been trying to connect to the Windows machine so I can do the 2nd part of the assessment for the last two weeks and I can't seem to get the Windows VM to function for longer than a minute. Any ideas?

#

It's driving me crazy

#

i just want to finish the module

#

not yet

#

ill give that a go

#

thank you

deep needle
#

why freerdp is super slow and laggy? any solution for that?

next bronze
#

why not

dense narwhal
#

HTB{FLAG} : FLAG like this ?

opaque hatch
deep needle
opaque hatch
mint lodge
#

wtf is the bread enthusiast role?

dim wolf
#

exactly as it sounds

dim wolf
mint lodge
#

WHAT

#

explain yourself

#

enlighten me

#

O_O

#

well damn nice

dim wolf
#

.\SharpHound.exe?

#

why are there three sharphounds

#

oof

#

i wonder what the issue is..

#

maybe try running it with -v 0 and see what it outputs

mint lodge
#

off topic question where can i find my account identifier so i can be verified

next bronze
#

try with an older version of sharphound, download it from github

limber river
dim wolf
#

did it work?

opaque hatch
#

guys, i kept getting network error when i login to HTB account. My internet is fine. Any idea ?\

placid needle
#

me too ^

#

sounds like their end so we wait -v-

dim wolf
#

so it looks like you need the hex value in rax at the instruction at <_start+16> right

#

oh you're not blackwolf

mint lodge
#

i cant spawn a target

#

htb servers are dying

next bronze
limber river
next bronze
#

you can dm, but I think you got the wrong thing

limber river
distant adder
#

I am very sorry guys but i can only join from tomorrow, but till then gl 🫡

limpid hemlock
#

Hlo

#

In The password attacks protected archives lab
How did you get into the target to get the zip file to Crack?

deep bay
#

why would a target spent more then 10 minutes to spawn?

#

🙃

limpid hemlock
#

Refresh the page

deep bay
#

done the page refresh multiple times

#

🙃

limpid hemlock
#

Usualy I refresh and click again on target spawn

#

It works

soft cedar
#

You’ll need to download a new vpn (if you’re on a Vm)

deep bay
#

A_A, it just spawn, after the 4th page refresh

mint prawn
#

i need help

#

i get Network error and cannot use labs

#

sorry im using this channel i just cant verify

#

@sterile hawk

#

@haughty stirrup

deep needle
haughty stirrup
next bronze
mint prawn
#

i cant

mint prawn
deep needle
#

While doing pass the ticket (windows) section I got a couple of questions

Q. What is the difference between pass the key/OverPass the Hash and Pass the ticket?
Q. What exactly do we get with pass the ticket and Pass The Ticket with PowerShell Remoting?

next bronze
mint prawn
#

aight

#

thanks

next bronze
deep needle
next bronze
#

enumerate the network, maybe nslookup or something

deep needle
next bronze
#

yeah, it's just now you auth with the AD network, kerberos or NTLM

deep needle
#

just one last thing, my freeRDP runs very slow and laggy with this, is this any kind of problem at my end or its like that only?

next bronze
#

try using a vpn server closest to you

deep needle
deep needle
next bronze
#

contact support

limber river
deep needle
next bronze
#

not sure what you mean. it will be the rights/access of whatever user you ptt with

deep needle
#

this might be silly but I couldn't get it and trying to clear my concept with PTT

next bronze
#

what are you using to ptt? through smb?

deep needle
#

mimikatz

kerberos::ptt "C:\Users\plaintext\Desktop\Mimikatz[0;6c680]-2-0-40e10000-plaintext@krbtgt-inlanefreight.htb.kirbi"

next bronze
#

and wdym "able to get till dir \DC01.inlanefreight.htb\john ", what happens next

deep needle
next bronze
#

the machine you ran mimikatz on probably isn't the DC so obviously C:\john doesn't exist, when you psremote you're opening a shell on DC if that's the ip you set

deep needle
#

😄

graceful mortar
minor stag
#

I'm on the attacking common services lab - easy. I found that I'm able to write files to the mysql server, but I don't know what to do with this information. I'm kind of stuck.

rustic sage
#

Does anyone have any issues with whatweb?

#

I was running the commands fine and now it won't work

#

Using the example given it gives this

minor stag
#

There's only one question

graceful mortar
#

DM ME

graceful mortar
minor stag
#

Yes. I think I'm trying to get a webshell but I don't know how/can't get it to work

graceful mortar
#

try connect to connect via ftp

minor stag
#

Already have and downloaded all the files

#

I have the file path I need to put stuff at, I just don't understand how to do a webshell

royal tundra
#

we are top 33

graceful mortar
minor stag
#

Empty value

#

So I can place stuff in the file path, and I can load_file it, I just can't get the webshell

graceful mortar
#

so you can upload a shell via mysql

minor stag
#

That's what I'm trying to do, I just don't know how. I followed the module and put "SELECT "<?php echo shell_exec($_GET['c']);?>"" into a file. I can load it and see it, I can curl it but it tells me it can't "execute a blank command"

fathom pendant
#

oh wait

#

did you put a command in the parameter?

minor stag
#

That's what I'm trying to figure out

fathom pendant
#

i.e. ?c=<insert command here>

minor stag
#

The module doesn't detail that syntax

#

So is it SELECT "<?php echo shell_exec($_GET['c=id']);?>"

fathom pendant
#

no

#

i mean when you curl the file

minor stag
#

OH, at the end of the url

fathom pendant
#

yes

#

i think you need to revisit how webshells work

minor stag
#

I haven't done a lesson on webshells

#

Not yet at least

fathom pendant
#

well if you're following the cpts path it comes before attacking common services

minor stag
#

Wait, nevermind, I learned about laudunum

graceful mortar
#

your webshell need works like shell.php?c=id

fathom pendant
#

you learned about a lot of different shells

#

not just 1 particular type

minor stag
#

I just looked back over the webshell section and it never details curl/url based webshells. They're all browser based

#

Probably the same concept, but going from uploading onto a website GUI to putting it into a mysql database isn't intuitive for me

fathom pendant
#

ah yeah i just rechecked too

#

it's still a basic concept

minor stag
#

Yeah, something I'll need to work on

fathom pendant
#

it's how the $_GET['variable'] function works in php

minor stag
#

I guess I just need to learn php

minor stag
#

Thanks. Hopefully this'll get me through the basics, like how to deal with spaces in a webshell cause I feel like an idiot

fathom pendant
#

i mean you can urlencode them

#

or use quotes

minor stag
#

I tried c=cd%20..

fathom pendant
#

you can't cd with a webshell

#

gonna need to use other commands

graceful mortar
#

but you can list

minor stag
#

Oh, so my options are exclusively in the folder the shell is spawned in?

fathom pendant