#modules

1 messages · Page 218 of 1

fathom pendant
#

This server isn't about trolling people or spreading malware, it's about learning and practicing cybersecurity

split pelican
#

How Cookies can be Dangerous

terse latch
#

Guys I'm new and I'm doing some modules in HTB academy... I'm having problem with the File Inclusion module in the basic bypasses section. The final question of the section asks to find the file /flag.txt
I've tried everything but i'm not able to find it...can someone help me please?

dim wolf
#

you can just learn how to make a MsgBox in VBS, plenty of tutorials on youtube for that

upbeat oak
#

Yeah I don't know how to get this script to work

fathom pendant
upbeat oak
#

has anyone used another method than using their script

sly kelp
#

use guided mode it will help you

upbeat oak
#

forums had a script to get it to work, that took way longer than needed I feel

fathom pendant
upbeat oak
#

guess I didn't dig enough I only found it on the forums and geeksforgeeks

late galleon
#

are all the free boxes not good for OSCP?

#

someone told me the free ones don't prepare you whatsoever

#

bullshit or legit?

dire abyss
#

all the free ones isnt enough material, imo

rustic sage
#

Any hints or guidance on “find through spl searches against all data the two ip addresses of the c2 callback server” for intrusion detection with splunk

late galleon
#

dont want to waste my time with anything that's not useful

dire abyss
#

useless, i wouldnt say that. I think HTB has a ton to offer

#

im doing academy right now, plan to get my cpts and then oscp right after

#

but i paid for silver annual plan from the beginning, idk how limited the free version of academy is

dim wolf
next bronze
#

free boxes are just active boxes, new one gets added every week

next bronze
dire abyss
rustic sage
#

Found some funky Chinese stuff

dire abyss
#

i know im not ready, i just finished pivoting and port forwarding

next bronze
#

I mean there are 20 active boxes at any time so, if you can do those you're ready

#

whether you want to get vip sub to prep for oscp, that's up to you

late galleon
#

I guess that's just a load of shit though

#

thanks

dire abyss
#

cant say, i dont have the oscp. I went for CPTS because, imo its more challenging from what ive gathered. I believe if I can get CPTS then OSCP should be cake.

next bronze
late galleon
dire abyss
#

this is academy chat.. i was speaking on academy.

fathom pendant
rustic sage
#

My SPL is not finding it but I found 10.0.0.228:8080 doing something

fathom pendant
#

I.e. every n seconds they call back to the c2

rustic sage
#

Sorry .229

fathom pendant
#

You can likely search splunk resources for detecting a c2 server that uses average times and data like that to help narrow down

next bronze
sly grotto
#

no one solve this?

rustic sage
#

Agreed

fathom pendant
#

Try this video

upbeat oak
#

So I cracked the password hash with hashcat and got the cleartext answer however it's saying its wrong ipmi section currently running it through metasploit to see if I get different results a little lost

fathom pendant
#

I'd have to pull the page up to say truly

#

Ye it starts with t

upbeat oak
#

and metasploit crashed lol

fathom pendant
#

IIRC stands for if I recall correctly

#

Mobile autocapitalizes the first letter

#

Method: use Metasploit to pull the hash
Use hashcat and proper mode with the wordlist and get answer

rustic sage
upbeat oak
#

going to run it again looks like I got a different hash this time?

fathom pendant
#

What's your command syntax? You used mode 7300 yeah?

upbeat oak
#

Yeah mode -m 7300 -a 0

fathom pendant
#

Weird well, try with the new hash and see if that nets the right answer

upbeat oak
#

Yeah still gave me the wrong answer?

fathom pendant
#

Weird

#

Try restarting the box

#

I'd get up and sanity check, but the couch is comfy lmao

upbeat oak
#

okay and lol I don't blame you

fathom pendant
#

But looking at the answer I have for that section, at least, ik what it should be

#

And I doubt it's a weird collision error with the hash

ruby whale
#

Hey everyone, I have only one section left in the path Documetation and reporting proactice lab but not able to access the RDP, tried switching VPN, RDP connections keeps disconnecting any solution?

mystic light
upbeat oak
#

well fuck me sideways even that didn't work I'm going to try to run metasploit again maybe change my wordlist

ruby whale
fathom pendant
upbeat oak
fathom pendant
#

Weird

#

This is footprinting- ipmi yeah?

ruby whale
upbeat oak
fathom pendant
#

Have you tried with the provided Footprinting wordlist?

fringe urchin
#

But isnt the hash different since its salted?

#

I would need to pull out my notes to check tho.

fathom pendant
next bronze
#

if it cracks with a different password isn't the hash striaght up different

fathom pendant
#

^

next bronze
#

wrong module/section?

fathom pendant
#

I'd say restart the lab and try again

fringe urchin
#

But yea the pass came out with first letter t

limpid hemlock
#

Anyone knw how to mount the bitlocker file in password attacks hard lab

foggy siren
#

I'm stuck at the RDP and SOCKS Tunneling with SocksOver RDP with this error message: "The module SocksOverRDP-Plugin.dll was loaded but the call to DllRegisterServer failed with error code 0x80070005. What am I doing wrong?

runic smelt
#

Why can’t I talk in the general channel

fathom pendant
fathom pendant
upbeat oak
foggy siren
#

@fathom pendant That's a nice hint. Going to try that. Thank you!

fathom pendant
#

Just let it extract the hash

upbeat oak
#

initially I let it extract which got me the hash. I didn't change anything then I used hashcat. Was just thinking if I maybe run the whole thing through metasploit it will crack the hash that way

fringe urchin
upbeat oak
#

sudo hashcat -m 7300 -a 0 ipmi.txt /usr/share/wordlists/rockyou.txt

fathom pendant
#

Btw you don't need to use sudo for hashcat

#

(That won't change the output, just an fyi)

fringe urchin
upbeat oak
#

I just got in the habit of using it good to know

#

wow that was the issue was running it with sudo

fathom pendant
#

Lmao

upbeat oak
#

holy fuck

fringe urchin
#

Wat

#

Lol

upbeat oak
#

ran it without sudo added --show and boom..kek

fringe urchin
upbeat oak
#

It be the simplest things

fathom pendant
#

Gl

dim wolf
#

spring break would have been perfect to take the exam

fathom pendant
#

Isn't that coming up soon around Easter?

dim wolf
#

mine already started on monday

fathom pendant
#

Ahh

dim wolf
#

idk if i can knock out some of my assignments tomorrow i might have enough time

#

things will be figured out

rustic sage
#

Hello world

spiral pelican
#

Hi all . Any one had probleme with the skill assessment of the crakmapexec module? i tryied multiple time to connect to the internal network with chisel but it didnt work...

next bronze
bright mason
#

HTB Academy - Web Attacks / Bypassing Encoded References

While trying to complete this module, when I try to download a file and Intercept it in Burp Suite, I cant find it anywhere. Do you guys know what might be the issue?

#

Clicking on the file at the spawned Ip it performs the download, but Burp Suite doesn't catch it to see the POST request

spiral pelican
ruby whale
#

Finally completed the path. Thanks @fathom pendant @next bronze @soft cedar for all the support. Will be starting exam on 21st.

next bronze
#

nice 🎉 good luck!

next bronze
bright mason
#

Trusted Domain will solve this issue?

spiral pelican
opal dagger
#

hello there, im a bit stuck in linux priesc, more especifically the lab for logrotate, i found the log file the the student user has write access and i try executing the exploit logrotten on that acess.log but is stuck in Waiting for rotating, someone knows if im missing something?

glass quail
#

Can someone help me with configuring the etc/hosts file for advanced xss and csrf exploitation? It keeps going to https instead of http when trying to go the websites.

fathom pendant
#

You can try manually specifying http://<domain>

fathom pendant
#

Then Google "disable upgrade to https <insert browser name here>"

glass quail
fathom pendant
#

In the case where there's a non-standard port you'd still specify the port via
http://<domain>:port/

sly grotto
dreamy yew
#

Module: Password Attacks, Section: Pass the Hash, Last question on finding C:\julio\flag.txt, I got a reverse shell as inlanefreight\julio, however my hostname is MS01 instead of DC01. Could anyone point out any error in understanding?

fathom pendant
dreamy yew
glass quail
fathom pendant
dreamy yew
next bronze
#

please put your code in code blocks my guy

dreamy yew
#

how do i do it sry

cedar yew
#

hello guys, i need help

Module: Password Attacks
Section: Remote Password Attacks - Network Service (RDP)

myproblem-> i found the rdp credential but not the connect when i try the connect
show this message ( connectiong to sesman ip sendin login info to session manager please wait login daile for display)

https://academy.hackthebox.com/module/147/section/1327

next bronze
maiden field
#

Anyone did this question in the ids/idp Skills Assessment - Suricata module? There is a file named pipekatposhc2.pcap in the /home/htb-student/pcaps directory, which contains network traffic related to WMI execution. Add yet another content keyword right after the msg part of the rule with sid 2024233 within the local.rules file so that an alert is triggered and enter the specified payload as your answer. Answer format: C____e.

I'm kind of lost on how I'm supposed to know what to add

next bronze
dim wolf
#

```
here's your code block
```

dim wolf
dreamy yew
fathom pendant
#

I ain't reading all that

dreamy yew
#

I tried -Target DC01, but no connection was made at the attacker machine, hence no rev shell

#

In short, i just want to check if the -Target is correct

fathom pendant
#

Its been a minute since ive done this. I just remembered lightly following the examples and it just working

#

Btw, you're meant to have a reverse connection to the windows box, not your attack machine

next bronze
#

you can check if the target is the DC, do a nslookup or probe with cme

fathom pendant
#

As the windows box is the one with the connection to the dc

maiden field
dim wolf
#

sure

glass quail
dreamy yew
#

does it mean i am just connecting back to myself on the windows box haha

fathom pendant
dreamy yew
#

ok dang it

glass quail
fathom pendant
#

Sometimes the ps thing is buggy

#

And shows ms01, but you can connect to the dc01 share

dreamy yew
fathom pendant
cedar yew
#

Restarting the machine fixed it

#

I guess it happens sometimes

fathom pendant
#

Ye

#

Sometimes (especially with the windows labs) you gotta give em a little shake

crystal steeple
#

stuck on skills asssessment web proxy : Once you decode the cookie, you will notice that it is only 31 characters long, which appears to be an md5 hash missing its last character. So, try to fuzz the last character of the decoded md5 cookie with all alpha-numeric characters, while encoding each request with the encoding methods you identified above. (You may use the "alphanum-case.txt" wordlist from Seclist for the payload)

#

i set up the payload and add rules of ||encoding to BASE64+ASCII HEX ||

#

but i don't know what to really fuzz

#

whole cookie?

#

add character and fuzz it?

dreamy yew
fathom pendant
#

It's still a private ip, specifically the tun0 ip that's used to allow your device (via the vpn) to connect to it

fathom pendant
dreamy yew
#

ok but does the reason still stands by the fact that the ip address used should be in the same subnet of DC01?

fathom pendant
#

Correct

dreamy yew
#

is it because MS01 simply just cannot communicate to the tun0 as it is outside of its subnet

fathom pendant
#

MS01 is the initial windows box

#

DC01 however

#

Is on a separate subnet to the tun0

crystal steeple
#

tried to fuzz like this but didnt work

dreamy yew
unreal sinew
#

Alright I've been stuck on Q8 of AD Enumeration & Attacks - Skills Assessment Part II for two days and just cannot figure out what else I can pull from SQL01 box to get admin access to MS01. Can someone give a hint? I've secretsdumped, I've tried everything I can think of dumping in Mimikatz, and nothing is of value to move forward. I've tried passing the local admin hash extracted around the network and nothing is matching up. I've run Inveigh from SQL01 as admin, Inveigh from MS01 as low level user, nada. This CT user ID'd by bloodhound is a total ghost.

marsh echo
#

Hello for module 147 section 1320 I don’t know if I’m rigth Way, I enumerate service but that doesn’t work with user kira and the password provides

#

I try hydra smb://ip -l Kira -P password.list hé dosen’t work

#

I ve got a error does not support smbv1

crystal steeple
unreal sinew
crystal steeple
#

did you think about attacking SAM?

unreal sinew
#

I have the SAM dumped.

crystal steeple
#

you should have the admi hash then to log to ms01

unreal sinew
#

Can't crack any of the users or pass the NT

crystal steeple
#

well if pth didnt work for rdp try various remote access methods

#

how about evil-winrm , did you tried it?

unreal sinew
#

Let me try again...CME kept coming back saying no good but I've done this so many times I'm not sure

#

just to make sure I'm on same page, does MS01 and SQL01 share the same local admin account creds?

crystal steeple
#

you gonna find another hash if i remember well

crystal steeple
#

yes i guess they do share the same local admin creds

unreal sinew
#

yeah because passing the local admin hash of SQL01 to MS01 is failing.

crystal steeple
#

with evil-winrm?

#

dm me the hash

unreal sinew
#

ok.

marsh echo
fathom pendant
#

also it doesn't provide the password

#

it provides a password that can be mutated

#

(which this password is in the grander mut_passwords.list from the password mutation section)

brittle bay
#

I did CPTS module a while back, and I'm now trying to find a certain exercise, maybe someone could quickly remind me where to find it? It was basically about vulnerable web page form fields, and the vulnerable ones needed to be identified by setting up a web server on the attacker host, and different message to each of the victim host web page form fields, to identify which one calls the attacker host. What module was it again?...

marsh echo
#

aaah but don't said you need to mutated the password 😦

fathom pendant
#

it's meant to nudge you in the right direction and engage your brain in critical thinking

marsh echo
#

mhhhhhhhhhhhm yep You're right

brittle bay
analog dock
#

CT doesn’t come into play yet

#

That’s for later questions

loud torrent
#

Can someone help me with a code that it's seems to not working in the Introduction to bash scripting?

hollow ibex
#

anyone can help i am stuck on os command injection skill assessment i found vulnerable parameter in get request no what should i do ??? any hint

cursive oriole
#

I got struck in attacking common services - SQL section. How do i find mssqlsvc password.

I tried logging in using provided creds to SQL server found two tables fl*** and hma*** both are unable to access.
Tried crackmapexec using pws.list for "mssqlsvc" didnt work
tried logging in with provided creds on SMTP didnt work.

Please provide me hints on how to crack the first question pls! Sad_Squidward_Pepe

fathom pendant
#

SMTP has 0 to do with SQL

cursive oriole
next bronze
hollow ibex
#

@next bronze anyone can help i am stuck on os command injection skill assessment i found vulnerable parameter in get request and use ls and p'w'd but not showing output on screen

cloud urchin
#

how do you know you have the right injection parameter if you try injecting and it doesn't work

hollow ibex
#

by request denied

#

malious url denid

cloud urchin
#

alright, did you obfuscate it?

#

HTB Staff if you're watching please fix the CME VM so the commands you provide work on it

hollow ibex
#

yes , p'w'd like payloads i used but not getting respone on screen

cloud urchin
#

did you enumerate like the module says, going each character 1 by 1 to see what's stopping it?

hollow ibex
#

yes

cloud urchin
#

did you try obfuscating another way?

hollow ibex
#

i find it and when i use it its response directory not found or flag.txt persmission denied

cloud urchin
#

sounds like you're looking in the wrong spot then

#

if you get a response saying directory not found it sounds like it's executing the command successfully, but it can't find the dir

hollow ibex
#

can i paste the payload here so i can show you what i am doing???

cloud urchin
#

maybe DM it to me

hollow ibex
#

ok

#

i dm you

unreal sinew
plush solstice
#

Im struggling connecting to WS001 in the PKI-ESC1 section of Windows attacks and defenses. They dont give a IP address for WS001 only an IP for kali. I have tried connecting using WS001 as hostname and using the IP address given in the "Overview and Lab Environment section". If I try to start a target machine that is WS001 under a diff section my kali target machine disconnects. Any suggestions on what im doing wrong?

fathom pendant
#

WS001 is on a different internal network

#

you pivot to it/attack it from the Kali Machine

#

they are independent excersizes; therefore different environments

plush solstice
#

"Connect to the Kali host first, then RDP to WS001 as 'bob:Slavi123' and practice the techniques shown in this section. What is the flag value located at \dc1\c$\scripts?"

fathom pendant
#

yes; it's telling you the chain of events to do: Connect to Kali, from Kali RDP to WS001 with the given creds

plush solstice
#

Yea i get that they dont give an Ip address for WS001 and connecting by hostname isnt working. I tried the IP address from the module overview section. If I try to spawn a WS001 host from a diff section my kali instance disconnects

primal drift
#

What is max streak on htb academy for now?

plush solstice
#

I cant even ping WS001

grand zinc
#

Im trying to do the linux fundamentals, but i cant connect to inlanefright.com with curl in their pwnbox. Anyone else with this issue?

curl: (28) failed to connect to www.inlanefreight.com port 443 after 12936 ms: couldn't connect to server

next bronze
devout barn
#

It seems that https://academy.hackthebox.com/module/143/section/1422 ACTIVE DIRECTORY ENUMERATION & ATTACKS Internal Password Spraying - from Windows the RDP credentials are broken. I have tried <MACHINE_NAME>\htb-student, INLANE-FREIGHT.local\htb-student, and INLANE-FREIGHT.local\htb-student

I can't upload screenshots for some reason

next bronze
plush solstice
#

it works ty

next bronze
plush solstice
#

lol

devout barn
#

rdesktop

next bronze
#

read #welcome to get verified and you can send screenshots

devout barn
#

thanks I'll do that

next bronze
#

the creds work, just tested

devout barn
#

with or without a domain?

next bronze
#

I use xfreerdp, there's no need to specify a domain

devout barn
#

lol, seems it does not work using rdesktop

#

xfreerdp is fine thank you

cedar yew
#

hello guys, i need help

Module: Password Attacks
Section: Remote Password Attacks - Password Mutations

tried all the brute force with the customizations I learned but it doesn't work. I lost 2 hours in this module 😦

vestal crescent
#

this is referencing a password ive forgotten.. was it like LoveYou or something ?

#

nvm got lucky and found the mutated file i used to get it and recracked it

hollow ibex
#

@vestal crescent i am stuck at os command injection

#

Error while moving: mv: cannot stat '/var/www/html/files/605311066.txt': No such file or directory
mv: cannot stat 'cat': No such file or directory
mv: cannot stat '{/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin}home/flag.txt': No such file or directory

vestal crescent
#

do i look like i know what im doing brother

misty saddle
#

And I also think you had to submit it earlier in the module

winter hatch
#

i have a tiny question guys
so basically if i wanna do a port scanning why i'm gonna get back an ICMP request ??
i though ICMP request and responses are for host discovery (ping sweep) !

fathom pendant
winter hatch
#

@fathom pendant each time the host is up there will be an ICMP echo request/response ?

echo forge
#

you can DM me

mint lodge
#

got to say all of the modules on the cbbh are solid but the SESSION SECURITY one is hella confusing

echo forge
#

if you're still stuck, can dm me

fathom pendant
winter hatch
#

@fathom pendant thanks alot 🙂

solar grove
#

I'm stuck on the first question in the Log Injection topic in the HTTP ATTACKS module, can anyone give a clue?

lyric raft
#

In the module 231 modern web explotation techniques, in the second order attacks section, could someone write the script to filter the files with IDOR (whitebox)?

solar grove
#

@echo forge Hello, I solved that question, thank you. I passed the HTTP Attacks module. But I got stuck in the first question. Maybe I didn't understand it or I couldn't do it, can you help me, I need a hint.
Question: Try to use what you learned in this section to obtain RCE via log poisoning and submit the flag. You can access the log at /log.php

misty saddle
#

Anyone got a tip of what to do? I'm in the section: ICMP Tunneling with SOCKS. And I've followed the steps in the section and I just get this error when trying to execute ptunnel.

cloud urchin
#

looks like you don't have the required dependencies installed

misty saddle
#

Yeah, but it doesnt make any sense

#

It's literally the first step in the guide and it doesn't mention that I have to do anything on the target other than transfer the repo and then doing the mentioned command

runic remnant
#

Im doing WINDOWS PRIVILEGE ESCALATION - Windows Privilege Escalation Skills Assessment - Part I and I did the first question and got to mess with the website ping a lil, im just not sure where to go to get the ldapadmin password or anything else, if someone can push me in the right way that would be much appreciated

misty saddle
# cloud urchin looks like you don't have the required dependencies installed
#

Def not the only one with the issue. Mby its a box issue?

ember coral
#

Question with vim being +eip why can i do thinks like read a file like /etc/shadow with it, but any shells i spawn with it are always under the same lower privilage? I would think the shell would have the same privileges as the vim no?

next bronze
#

the shared library needed is missing

misty saddle
next bronze
#

yeah

misty saddle
#

I'll give it a shot.

next bronze
#

although libcrypto.so should be included in the standard ssl libraries thonk

cloud urchin
#

could be the path is wrong

next bronze
#

they're running an elf

solar grove
#

Has anyone solved the first question of the HTTP ATTACKS module?

maiden tulip
#

hey, slightly offtopic but I have the gold annual, where do i get my exam voucher? and the lab exercise guidance?

lyric raft
#

Has anyone finished module 231 modern web exploitation techniques?

tranquil axle
misty saddle
ember coral
cloud urchin
misty saddle
cloud urchin
#

what is making you use ubuntu i thought all the attack boxes were parrotos

misty saddle
#

I'm using Kali Linux

#

On my own VM

cloud urchin
#

so you're ssh'd into an ubuntu box?

fathom pendant
misty saddle
fathom pendant
#

like i've tried using Enter-PSSession, evil-winrm

#

i'm this close to a mental breakdown lmao

cloud urchin
#

does CME work? cme would be easiest probably, just use the -x command execution

cloud urchin
#

i know xre0us

tranquil axle
cloud urchin
#

i never said it was

next bronze
#

I don't think the box being outdated matters since ptunnel also hasn't been updated in a while

fathom pendant
cloud urchin
next bronze
#

yeah lemme test it

fathom pendant
cloud urchin
#

i think it's just the username

fathom pendant
#

i swear

cloud urchin
#

unless you're on a multi-domain environment? in which case domain1\user domain2\user

fringe urchin
fringe urchin
#

Waiting for him to flip out

fathom pendant
next bronze
#

you have admin hash?

cloud urchin
#

according to the module, he should have the cleartext password

fathom pendant
#

no? i was told by the question to use the password submitted for Q2

#

which I HAVE

next bronze
#

what's the error? use impacket with -debug

#

I'm guessing the domain is wrong

cloud urchin
#

you said you had the answer for #2. #3 says use the password you got from #2 to read the flag....

#

so you say you compelted #2 but also don't have the password which was required to complete #2?

next bronze
#

no? marcie said they have the password

#

the target won't spawn 4Head

solar grove
#

Has anyone solved the first question of the HTTP attacks module?

cloud urchin
#

right.. they have the password for domain admin lol

#

so what's the problem, go get that flag

fringe urchin
vestal crescent
cloud urchin
#

crackmapexec smb 10.10.10.10 -u Administrator -p l33t -x 'type C:\flag.txt'

orchid gate
#

Hi, I didn't easily find this in pinned messages and just need some help: what is the "one-to-one lab exercise tutoring through Discord"? I have a gold annual subscription, and added Discord to my user profile--is there a channel that's suppoed to appear for specific labs?

next bronze
#

try with psexec

misty saddle
#

Works there

tranquil axle
#

My best guess is then that vim doesn’t execute the command in a way that keeps the capabilities. The gtfobin version for vim with capabilities relies on vom being compiled with python support, because running python through vim would drop the capabilities otherwise

next bronze
solar grove
#

Has anyone solved the first question of the HTTP attacks module? I am stuck on the Log Poisoning question

misty saddle
cloud urchin
#

yeah you said you were ssh'd into the ubuntu box and doing it there

misty saddle
#

Yup

cloud urchin
#

but you were running the program on the ubuntu box, not locally on your kali box

fathom pendant
#

oh my god i was overcomplicating it bc of the fucking dumbass bloodhound thing

fathom pendant
#

no

misty saddle
next bronze
# misty saddle Yup

ah yeah that's the problem, your vm probably has a later version of the C libraries than the target, if it's dynamically linked and the target doesn't have it it won't work

cloud urchin
#

that makes sense

next bronze
#

you'll run into this from time to time, either statically link it or have a few vms with older glibc for compiling

mint lodge
#

https://academy.hackthebox.com/module/153/section/1458
I'm in session Security Skill Assessment and i don't get how to find the second flag

  • 1 Go through the PCAP file residing in the admin's public profile and identify the flag. Answer format: FLAG{string}
    I've pressed the flag2 pcap file and catched it with wireshark but no flag

can i get a hit pretty please?

misty saddle
#

Aight, I'll make a couple of "older" ones just in case. Thanks for the support!

next bronze
#

you can just grab the older ubuntu servers

fathom pendant
next bronze
#

yeah just use the user and pass from q1 and 2

fathom pendant
#

fucking christ; the section leading up to it made it seem like i had to do all that

wise tartan
#

... Anyone know the origin of these attacks?

fathom pendant
#

no

wise tartan
#

-It's a history lesson.

fathom pendant
#

also what attacks kek

#

you've shown us nothing

wise tartan
#

BHG..

#

aka?

fathom pendant
fathom pendant
wise tartan
#

Oh come now

fathom pendant
#

We have very little data on what you're referring to my guy

wise tartan
#

Bloodhound was ex military, shared between the US and Russia. Their dissident brethren became PowerShell Empire.

fathom pendant
#

Still 0 idea what you're comin n here to yap about

wise tartan
fathom pendant
#

ok?

wise tartan
#

Oh- let me spell it out, it's NOT a history lesson. Because there is no official connection between American and Ukrainian spec-ops teams. It's a myth. A legend retold by script kiddies on Discord.

#

Easier that way. Right?

next bronze
#

I'll have some of what you're on

fathom pendant
#

still 0 fucking clue what made you yap

wise tartan
#

lolol

#

illiterate and proud.

fathom pendant
#

not really illiterate just fucking confused my dude

#

idk who said what or anything re: US and Ukrainian Spec Ops

wise tartan
#

That's not a CnC module? I haven't done the bloodhound one like 6 times> good, ok good.

fathom pendant
#

CnC?

#

like you're losing me here buddy

#

this channel is referring to htb academy modules

#

you mean C2?

wise tartan
#

: same shit

fathom pendant
#

never really seen C2 put as CnC

plush solstice
#

my computer in the 90s was faster than some of these machines. It just took over a minute to load notepad sheesh

fathom pendant
#

either way: no the module I'm working on isn't a C2 module

#

idt any academy modules really refer to using a C2

#

except potentially in passing

#

or in the case of the defensive modules: identifying one

wise tartan
#

Active Directory, god that is kindof sad

#

that is really sad, yes there use to be a 'C2' mr fancy pants

dim wolf
#

i don't understand.

wise tartan
#

bloodhound used to be a C2, but it was malware 'in the wild', now national security put a happy frilly powder blue dog collar on my shit. - used to lead you straight to PowerShell Empire. and right into the dirt.

fathom pendant
#

my brother in christ

#

i'm talking about htb academy learning modules

#

not whatever the hell you're yappin about

wise tartan
#

It's because Anony-moose doesn't want you hacking Russian banks without their trade-marked Guy Faux max.

#

I'm also- unfortunately for you: talking about HTB

fathom pendant
#

HOW? LMAO no idea how any of this is linked

wise tartan
#

Doesn't matter

dim wolf
#

because there's a bloodhound module in htb academy, duh....

fathom pendant
#

Like I'm trying to find the logic links

wise tartan
#

You're right I'm rambling

fathom pendant
#

but they're stretched so thin not even a spider could walk on them

wise tartan
#

Has anyone here seen practical application of FHE (Fully Homomorphic Encryption) : of course without Sec Clearance?

#

I'll wait.

wise tartan
#

Sick

fathom pendant
#

he can't type there

dim wolf
#

well that's the point really

fathom pendant
wise tartan
#

^not gonna do that

dim wolf
#

see?

fathom pendant
#

then get ignored or eventually have a mod/admin to tell you to stay on-topic

#

there's plenty of actually relevant channels to yap and ask questions in

#

but you need to follow some level of basic instructions first to be able to access them

wise tartan
#

'yap' the truth is the truth

next bronze
#

yeah I'll have some of what you're on cheesinpepe

wise tartan
#

🍓

dim wolf
#

there is no such thing as hacking. it's all memes

cloud urchin
#

wtf did i just come back to

fathom pendant
#

skill issues ig

thorn urchin
#

do you even know what a c2 is 😂

fringe urchin
#

Counter (strike) 2

#

ok thank you for coming to my ted talk

sterile epoch
#

I just completed the whitelist filter section of file uploads. I did it with the first method double extension but I am having trouble understanding the concept of character injection. In the section it said that these characters when stored they make the file from shell.php%0a.jpg to shell.php . so what I did was use the list of command injections provided in the section and appended to the shell.${working php ext}.jpg -> shell.${working php ext}${char injection list}.jpg and then used intruder on it. Then I tried to run commands with the url shell.${working php} all returned 404.

mellow delta
fringe urchin
#

So you either run it as that user or you login as that user with the password you found!

#

You gonna smash your ahead against a wall once you find the solution

mellow delta
#

youre absolutely right i am

#

i have been trying to get to smb with the important files user, it won't let me in

fringe urchin
#

I havent tried logging in via smb with that creds but i would see it being disabled for that user

mellow delta
#

hmm, I guess I am confused what service i should be trying to log in maybe rpc?

fringe urchin
#

There are two options. I personally went and saw what other users are reachable via the network tab from alex machine and tried my luck there or you ||run as somethinz || mssql

mellow delta
#

ok, I am going to go keep banging my head against the wall and see if anything else shakes loose

fringe urchin
#

Look

#

You found your credentials. Thr password is correct. But the username is not ||"sa"||

mellow delta
#

ah

#

ok

fringe urchin
crystal steeple
#

im lost in the the web proxies qst 3

#

skills assessement ,

#

idk how i should fuzz in burpsuite the cookie to get the last md5 char

#

tried to ||encode back to ASCII HEX and BASE64||

#

but i think im fuzzing something isnt supposed to fuzz

mint lodge
#

I'm in WEB SERVICE & API ATTACKS
SoapAction Spoofing question I'm curling the target and getting a Failed to connect error am i doing something wrong? or are the targets not working?

cloud urchin
#

make sure you're on the vpn, double check the IP/port

mint lodge
crystal steeple
mint lodge
#

am I still suppose to use the vpn? i never used it till now

cloud urchin
#

if you're using the pwn box, it will be connected to the network and you won't need the vpn

#

so double check the addresses

mint lodge
#

then wtf is going on I'm copying the address from the site

#

:/

cloud urchin
#

often the site tells you how, but you need to look at the actual results yourself based on the enumeration to see what the question is asking

#

so the site is just an example ip most likely, try it yourself in a real environment and find the answer

mint lodge
#

and find the wsdl page but the server is not responding

cloud urchin
#

ok, show the command you used and show the IP address of the VM

fathom pendant
mellow delta
#

I am hardcore riding the struggle bus on this one

mint lodge
#

as shown at the section
curl http://<TARGET IP>:3002/wsdl?wsdl

#

FUCK

cloud urchin
#

nope, show the IP of the VM you spawned for the questions

mint lodge
#

it was the port

fathom pendant
#

^

#

i was gonna say: looks like you didn't specify port

cloud urchin
#

and you still need to use the IP of the VM, not the one in the example in the module training

mint lodge
#

forgot the port

cloud urchin
#

alright cool

crystal steeple
mellow delta
fathom pendant
#

also for future reference: to avoid any issues with us reading your errors: make sure to wrap your command in backticks ` so it formats it like https://example.com so you don't get messed up with discord's formatting

mint lodge
#

to be fair the question does not spesify a port
Exploit the SOAPAction spoofing vulnerability and submit the architecture of the web server as your answer. Answer options (without quotation marks): "x86_64", "x86"

i had to assume that from the example

#

thats dumb

fathom pendant
crystal steeple
#

||sa refers to systemadministrator i think so basically you may try to run the mysql as administrator and provide the creds||

fringe urchin
mellow delta
cloud urchin
#

a web server can be ran on any port that it's configured for

#

so the question is still accurate

crystal steeple
fathom pendant
#

from the target host

mellow delta
fathom pendant
cloud urchin
#

this CME module is almost impossible to complete

mellow delta
#

ok, let me keep at it then. Thanks for the help

fathom pendant
mellow delta
#

administrator

fathom pendant
#

bingo

cloud urchin
#

do you mean nt authority\system?

#

more powerful than admin 😛

fathom pendant
#

he's already struggling hard enough with most of the answer already handed to him

next bronze
jade raptor
#

Just finished this...what a nightmare...misleading to say the least, but ok.

fathom pendant
#

?

jade raptor
fathom pendant
cloud urchin
#

It says to try all the methods, the methods provided are Command Injection, Command Substitution, Command Chaining, Environment Variables, and Shell Functions. Did you try each method?

mellow delta
#

OMG!!!! finally

#

Now for the hard one lol

fathom pendant
mellow delta
normal panther
#

on nmap module the time is increasing gradually I'm using the following command
nmap 10.129.238.171 -p- -sV -Pn -n --stats-every=5s -v --disable-arp-ping

gentle root
#

Anyone able to assist with predictable reset token Question 1?

gentle root
next bronze
#

yeah you'll need to convert to epoch time from the timestamp given by the website

normal panther
marsh echo
#

hello i don't understand how find the flag i'm connected with the hash David but i can't I can't reach the shared network //DC01

#

do i need to create a shared directory?

cloud urchin
#

maybe try c:\shares, find the directory it's being shared from

#

and if you don't have permissions to access the shared folder you'll need to get those

marsh echo
#

c\shares it doesn't exist :/

fathom pendant
marsh echo
#

i find a way i exploit this

fathom pendant
#

the prompt is telling you; that the shell that you have (through smbexec) can't CD

#

dir C:\shares should list it

crystal steeple
# marsh echo

You know where the flag is you dont necessarily need to cd to the its directory

marsh echo
#

that's how it should work, isn't it?

cloud urchin
# marsh echo i find a way i exploit this

The DC is going to be sharing from one folder. If you're on the DC on HTB, generally that folder is C:\Shares, which means the file you're looking for would be under C:\Shares\david. You'd only really use \dc01\shares\david\ if you weren't on the DC

marsh echo
#

i'm on the DC with credential david

cloud urchin
#

then find the folder it's being shared from

#

and if you look in your search bar in Explorer, why does it say MS01 if you're on DC01?

#

look in "This PC" not the network

marsh echo
#

oooooowhh okok sorry

cloud urchin
#

if you're on a computer as david, and david has access to the DC share, try typing \dc01\share\ in explorer and see if it goes there

#

\\dc01\shares

#

i guess discord deletes the first slash

marsh echo
#

my brain is overheating lol

cloud urchin
#

network shares and how to navigate to those shares is going to be very important

rustic sage
rustic sage
marsh echo
#

yepp but no acces because i'm on MS

cloud urchin
#

well that answers why you couldn't find it on c:\shares

rustic sage
#

the command from earlier is a pth attack

#

I dont remember how i did this.

cloud urchin
#

Review your notes, or if you're not taking notes I would suggest making some notes it helps commit things to memory. Plus there's just way too much stuff to know about to operate without notes imo.

rustic sage
#

I think theres a way

marsh echo
#

I'm trying to connect but nothing

rustic sage
#

kinda works like evilwinrm

rustic sage
#

but that wouldnt work; you're trying to reach the dc from ms01....

cloud urchin
#

depends on how the share is setup, generally shares are made to be accessed from other computers lol

rustic sage
#

lol good luck i tried to help only gets harder from here @marsh echo you'll make it out in one piece

#

technically i should know this im taking the same test too but my brain right now is stuck on file upload attacks

marsh echo
#

yesss persistence and be brave I've got it in me lol

fathom pendant
#

weren't you just auth as david? or you were misunderstanding who you were auth as

#

the issue wasn't that you couldn't access it bc you were on MS01; each of the shares in the scenario is designed to be accessed by their relative user

rustic sage
marsh echo
#

if i'm authenticated with david i just wanted to test if i could connect directly on the DC01 machine but i understood that it's a file share

fathom pendant
#

yes which is all you need

#

to get David's file

#

the fileshare, that shares the file that you're looking for

cloud urchin
#

in cmd or powershell type whoami to confirm

fathom pendant
#

i don't even think I used RDP for this

marsh echo
cloud urchin
#

looks like you don't have permissions

marsh echo
#

I agree with you

rustic sage
#

use something else with your smbexec command

cloud urchin
#

in your cmd, just for fun, what if you type "type \\dc01\shares\david\flag.txt" ?

marsh echo
#

but if i'm david and i don't have access to share it means there's a problem

fathom pendant
#

it wouldn't be under shares

cloud urchin
#

well wherever it is

fathom pendant
cloud urchin
#

yeah lol i noticed that..

fathom pendant
#

\\like this

cloud urchin
#

annoying

fathom pendant
#

discord uses markdown

#

and \ is used to escape

#

so i can do `lol` and not have it do the markdown thing

rustic sage
#

The important thing is that the command got executed

#

i know it's probably overkill but what if he just uploads a remote shell.

fathom pendant
#

and conversely \lol\

cloud urchin
#

easiest way is going to be using crackmapexec tbh

#

but the module wants to reinforce what it taught

rustic sage
#

you know insert a powershell command that connects back to ms01

fathom pendant
#

that and re-reading how the section wants you to do things

#

¯_(ツ)_/¯

#

i recall the section being fairly detailed on things you can do

rustic sage
#

or use the uhh... big_think uh.... PS_remotesession thing

fathom pendant
rustic sage
#

because the type \dc01 thing got executed successfully

#

ah then that's def a no go

#

unless he did his enum right idk

#

ill stick to my original plan of theft just steal the file some how

marsh echo
#

acces denied lol

fathom pendant
#

imo reading the section will be more detailed

rustic sage
# marsh echo acces denied lol

(I think) your original approach of using pth with Invokethehash was correct not this, david does not have access to remote into the machine directly.

cloud urchin
#

i've never seen HTB setup their share folder structure like that, with the user just at the root of the share

rustic sage
#

i think the idea is to fool dc01 into thinking you're signing in with NTLM directly instead of rdp

alpine umbra
#

web info gathering module vhost section any ide?

rustic sage
#

I edited my statement

fathom pendant
#

that's really all I can say on it

alpine umbra
#

yes dear i did this

fathom pendant
#

the loop gets you a filter to use for ffuf

alpine umbra
#

but i have not any directions

#

yah ./vhosts

#

no such file

#

what should i do

fathom pendant
#

that is a great observation

alpine umbra
#

mm

fathom pendant
#

/etc/hosts is the file used

alpine umbra
#

i try fuff tool so many times got error in every timr

fathom pendant
#

but is not entirely required for this

alpine umbra
#

i try out that also

fathom pendant
#

it also provides another wordlist to use via SecLists

alpine umbra
fathom pendant
#

if you read the section, you'll see how they want you to do it

#

this is honestly a case of "read the instructions"

#

because it's fairly clear

alpine umbra
fathom pendant
#

took me like 2 seconds to find the relevant info on the page you're working on

brittle arch
#

For the module Documentation & Reporting, the optional question suggests we can submit our report to be evaluated. I have two questions: firstly, the question asks about the inlanefreight.local domain, should the report cover the scenario given in that module that our 'other tester' has started or should it cover the inlanefreight.local scenario from the Attacking Enterprise Networks module (presumably they aren't the same). Second question, what is the process for submitting such a report?

rustic sage
#

Am a noob hacker

alpine umbra
#

can you explain it

fathom pendant
alpine umbra
#

yah i locate it

#

but no path

fathom pendant
#

then you might need to download the SecLists wordlist

#

you can search for it and use git clone to copy the repository

alpine umbra
#

ok

alpine umbra
brittle arch
alpine umbra
narrow geyser
normal panther
#

firewall IDS/IPS evasion module they are using a different source IP for scan does that source IP have to be alive to scan at the first place or is it just a dummy IP?

alpine umbra
#

ffuf -w /usr/share/seclists/Discovery/DNS/namelist.txt -u http://10.129.251.107 -H “HOST: FUZZ.inlanefreight.htb” -fs 10918

alpine umbra
cloud urchin
#

use a different wordlist

#

or there are other tools to enumerate subdomains as well

alpine umbra
cloud urchin
#

well you're getting errors, we can't help with just 'it doesn't work' we need to see the command you're typing and the full error

#

you can see at the bottom it says "error", you should expand that and look there for your answer

#

even if its not cutoff you should show the command used to ffuf

#

also is the victim box on?

alpine umbra
#

pls send it last 2 ,essages

cloud urchin
alpine umbra
#

again same error

cloud urchin
#

what error though, all i see is 'error' try debug or more verbosity if you don't see it

#

also you still never showed the command

#

basic stuff here, getting an error, look at the error message. double check your command.

cloud urchin
#

nope

#

i want to see the command, never trust users lol

#

people always say that then they show something else

alpine umbra
#

what

#

this is not other one my own

#

from medium blog

cloud urchin
#

try looking at the command the module teaches

alpine umbra
#

mm

#

yah i use that also

cloud urchin
#

ok well if you can't provide the info i can't help

alpine umbra
#

yes i can

glass stone
#

I have a question about python library hijacking

alpine umbra
#

i want to know how i edit host

#

it is only problem

cloud urchin
#

nano /etc/hosts

alpine umbra
#

no i mean how i edit

#

host phase

#

it should replace with my vhost

cloud urchin
#

what does the module say?

alpine umbra
#

ffuf -w /opt/useful/SecLists/Discovery/DNS/namelist.txt -u http://10.129.249.109 -H "HOST: www.inlanefreight.htb" -fs 10918

#

same error any help?

alpine umbra
cloud urchin
#

As I said, I gave you the exact command to use, I linked you the github page that gives exact directions on what command to use, pointed you to the module you're on which will provide the answer, and I asked you to show a screenshot of the command you input as well as making your VM bigger to see the error it's telling you, or enable verbosity/debugging if you're able to see more details about the errors. I can't help you when you refuse to give me that information.

alpine umbra
#

found it i got reply from target

cloud urchin
#

good job

alpine umbra
#

some words respond with 200 status

cloud urchin
#

let me guess it was the wrong command

alpine umbra
#

no i miss the fuzz before vhost

cloud urchin
#

so.. wrong command

alpine umbra
#

why

cloud urchin
#

because you misinput the command

alpine umbra
#

what is your pov

#

am i did wrong or doing wrong

cloud urchin
#

no you're fine

#

glad you got it

alpine umbra
#

yeh bro thanks i try to find flags

alpine umbra
#

why all curl command give same output

#

do not care about vhosts words give same output

cloud urchin
#

idk, i never did that module, does it say to use curl in the module somewhere? i bet the command is on that page

alpine umbra
#

whatever vhost

#

find out and done that section thanks @fathom pendant @cloud urchin

silver ember
#

can someone help me with the last question of "Using Crackmapexec" module?

cloud urchin
#

i haven't complted the module but you should just post your question

dreamy solar
#

Hello how to transfert my cookies.sqlite on my linux machine? please?

#

scp not available

cloud urchin
#

smb share is my go-to

silver ember
heady fern
#

How should I follow the modules? If I'm a begineer. Should I take a path like Pentester or complete all tier 0 modules first and then take the path or something like that?

acoustic owl
#

Follow the paths. As a beginner, the Information Security Foundations path is probably the best place to start

proven crest
#

hum..

heady fern
#

@acoustic owl Are you referring to Basic Toolset?

acoustic owl
heady fern
#

@acoustic owl Ok! Will get back to you after finishing it.

junior oxide
#

hello, im working on the pivoting module Socksoverrdp section when i try to load the socksoverrdp.dll using the command "regsvr32.exe SocksOverRDP-Plugin.dll" i get the module socksoverrdp.dll faild to load

rare robin
#

can someone help im in FILE UPLOAD ATTACKS blacklist filters and when i uplaod a php4 webshell it shows the src of the script i tried using other extensions but it either shows the src or it wont let me upload at all

grim current
#

For AD Enumeration & Attacks - Skills Assessment Part I, am I expected to find webshell on the external facing site ? I found pdf file but there's no webshell at all on the uploads folder.

junior oxide
#

fixed it

fathom pendant
junior oxide
#

just turn off real time protection

fathom pendant
#

:D you figured it out as i was typing it LMAO

junior oxide
#

and add the folder to excpetion

shut quest
junior oxide
fathom pendant
nocturne reef
#

https://academy.hackthebox.com/module/144/section/1257.
regarding this section of the info gathering module. Do I need to provide my own word lists? Cause I used few from the internet and I managed to get 2 flags but the 3d one seems rough. Is this a standard wordlist that should be used?

fathom pendant
grim current
nocturne reef
fathom pendant
#

all the info for this section is provided in it

#

(you can then further drill down and do another curl loop to enumerate the correct hosts)

fathom pendant
#

you can also do it manually, but that's not fun

fathom pendant
#

it's a small list of hosts

rare robin
#

found it

shut quest
nocturne reef
#

with this list

fathom pendant
#

i don't recall having issues ¯_(ツ)_/¯

nocturne reef
#

When did you do the module?

fathom pendant
#

to be clear i'm referring to this wordlist /opt/useful/SecLists/Discovery/DNS/namelist.txt

#

not the ./vhosts list they have you make

nocturne reef
#

I am using my own machine that's why

junior oxide
#

im on the last step from the sockcsoverrdp section and for some reason rdp isn't working i've checked for the 1080 port and its open and i've set the performance to modem i've also added the username jason and it still doesn't connect

fathom pendant
nocturne reef
#

I love myself

fathom pendant
#

Let's spin it to be a learning experience

nocturne reef
#

It really was

fathom pendant
#

you learned that there is a repository with a bunch of wordlists

nocturne reef
#

At least I went from way to read more about vhosts

#

Exactly

#

thanks homie

fathom pendant
#

and you learned more about vHosts that you didn't otherwise think about

nocturne reef
#

Did you do the bug bounty certification?

fathom pendant
#

nope

#

halfway through CPTS

nocturne reef
#

that's what's app

cloud urchin
#

btw seclist is preinstalled on kali already you don't need to get it from github

junior oxide
crimson delta
#

Hey I need help
My college provided some CTF challenges for students and I am struggling with a few questions can someone help

fathom pendant
#

ask your colleagues and fellow students

nocturne reef
nocturne reef
crimson delta
#

Thanks mate, they gave us saleae logic Capture file and asked to decode it and no one knows how to do it I checked some tutorial but it doesn't work you have any clue how to do it

fathom pendant
#

looks like Saleae is a tool

#

at the very least; start there?

crimson delta
fathom pendant
#

it's still not the right channel my dude

crimson delta
fathom pendant
#

this channel is regarding htb academy content

crimson delta
fathom pendant
#

you can potentially ask in #1024429874246590575 or provide more details in a channel like #web or something: (you'll need to link your HTB Labs account following instructions in #welcome to gain access to more of the server

#

ah Saleae is a hardware analysis tool

crystal steeple
#

hello guys, i found the website page that says "you dont have access" im ffuff module skill assessement

#

but the answer doesnt seem to be correct

#

its says to submit full page url

#

nvm they wanted to put word PORT not the port number lol

next bronze
crystal steeple
#

yes

#

i found it when checked the hint

fathom pendant
#

he's saying

crystal steeple
#

forgot there was hint there sorry i should've checked before asking here

fathom pendant
#

literally use the word PORT

crystal steeple
rare robin
#

im stuck in file upload attacks Whitelist Filters after scanning with intruder i manualy checked all the files but i always got the file not found error

#

some plz help ive been stuck for 2 hours

timber hatch
#

should i be able to find with hydra the right password for the user i found?
module: attack common services, Attacking Email Services

fathom pendant
#

yes

timber hatch
#

any tip for the right password list...? my search goes way too long....
hydra -L usersfound.txt -P /opt/useful/SecLists/Passwords/xato-net-10-million-passwords-1000000.txt -f -t 4 smtp://10.129.203.12
Hydra v9.1 (c) 2020 by van Hauser/THC & David Maciejak - Please do not use in military or secret service organizations, or for illegal purposes (this is non-binding, these *** ignore laws and ethics anyway).

Hydra (https://github.com/vanhauser-thc/thc-hydra) starting at 2024-03-16 12:50:30
[INFO] several providers have implemented cracking protection, check with a small wordlist first - and stay legal!
[DATA] max 4 tasks per 1 server, overall 4 tasks, 1000000 login tries (l:1/p:1000000), ~250000 tries per task
[DATA] attacking smtp://10.129.203.12:25/
[STATUS] 522.00 tries/min, 522 tries in 00:01h, 999478 to do in 31:55h, 4 active
[STATUS] 526.00 tries/min, 1578 tries in 00:03h, 998422 to do in 31:39h, 4 active
[STATUS] 544.57 tries/min, 3812 tries in 00:07h, 996188 to do in 30:30h, 4 active
[STATUS] 537.40 tries/min, 8061 tries in 00:15h, 991939 to do in 30:46h, 4 active
[STATUS] 534.61 tries/min, 16573 tries in 00:31h, 983427 to do in 30:40h, 4 active
[STATUS] 540.26 tries/min, 25392 tries in 00:47h, 974608 to do in 30:04h, 4 active
[STATUS] 541.59 tries/min, 34120 tries in 01:03h, 965880 to do in 29:44h, 4 active

fathom pendant
timber hatch
#

aaah. thanks. haven't seen that

fathom pendant
#

also there should only be ONE found user

#

if you found more: your syntax was wrong

timber hatch
#

found only one...but with a seclist 😉

fathom pendant
#

well if it's the answer to the first question

#

then you're good :)

timber hatch
#

yes it matched

floral crow
# rare robin im stuck in file upload attacks Whitelist Filters after scanning with intruder i...

try adding some other extensions to that example script list, there is a clue at the end right before the exercise
Exercise: Try to add more PHP extensions to the above script to generate more filename permutations, then fuzz the upload functionality with the generated wordlist to see which of the generated file names can be uploaded, and which may execute PHP code after being uploaded.

timber hatch
fathom pendant
#

you might have to include the domain

#

username@domain

timber hatch
#

lol

#

of course. thanks 🙂

fathom pendant
#

sometimes it does: sometimes it doesn't afaik

#

i forget how you'd determine it

pseudo imp
#

Log in to the ACADEMY-EA-DC03.FREIGHTLOGISTICS.LOCAL Domain Controller using the Domain Admin account password submitted for question #2 and submit the contents of the flag.txt file on the Administrator desktop.

fathom pendant
#

literally overthought it because the damn bloodhound part of this section

mint lodge
quick laurel
#

hello peps

#

hope everyones doing great

#

I'm on session Hijacking lesson, XSS module of bbh course, have trouble getting callback to my php server (sudo php -S 0.0.0.0:80 or :8080)

#

if I try to call my server from browser I get response

#

if I try to ping from my cli to VMs IP its not possible

#

and I cant get a callback when I send request with browser

#

It seems php server never listens

#

but when I go searching videos and stuff people just do the request and BAM php server listens that door whatever it is (8080, 80, 4444 etc)

#

What am I doing wrong?

#

or what do I have missconfiguired

quick laurel
#

Why can't I get a callback on CLI php server?

dense pollen
quick laurel
#

my payload is <script src="http://target_sistem_IP/username"></script>

#

I do this to all fields but a bit different in each I chamnge username to fullname etc so I can figure out where is vuln

old vector
#

I’m stuck on “vulnerabilities” module. I’ve connected to ssh target . How do I perform a Nessus scan from ssh?

quick laurel
#

and then I configure a file called index.php

#

then I start php server or ncat

#

but never get a callback but If I enable foxyproxy I get info that door opened and close

dense pollen
quick laurel
#

fine for me

dreamy yew
#

Just a question out of curiosity, does the windows machine feel laggy when you rdp into it from pwnbox

#

because i felt that its like that in most of the cases, where scrolling up and down in the powershell/cmd takes eternity

dreamy yew
#

but i am using the in-browser pwnbox, not the pwnbox set up using my vm

old vector
#

Will anyone help me with the Nessus scan in vulnerability module. I’ve re read all forward pages once again I’m not seeing anything on how to continue. I’ve ssh to target can see Nessus running now how to aces browser to do it?

next bronze
#

tcp won't help with latency, try to pick a server closest to you ig

#

but that's just how rdp is

dreamy yew
next bronze
#

not excatly, latency is more obvious wiht rdp since it has to stream the gui

#

it also takes a lot more data

old vector
#

With my setup if I use udp it is so unstable my terminal freezes. TCP allows me to do the most

#

Has nobody done Nessus over ssh? Nobody is answering

#

I have re read all beginning pages not understanding what to do once connected to target how do I open the browser over ssh. Terminal tells me it’s read only won’t let me access folders

shadow current
#

https://academy.hackthebox.com/module/143/section/1487
icant rdp here ive tried a lot of flags for xfreerdp still not working im using the command below
xfreerdp /v:10.129.121.194 /u:'htb-student' /p:'Academy_student_AD!' /dynamic-resolution /d:INLANEFREIGHT.LOCAL /cert-ignore

dense pollen
#

Can I ask someone about Predictable reset token, regarding question 2: Request a reset token for htbuser and find the encoding algorithm, then request a reset token for htbadmin to force a password change and forge a valid temp password to login. What is the flag?
I understand how the reset token for htbuser is encoded, so I can encode a password for htbadmin, but I don't understand how I should find the valid pw

fathom pendant
shadow current
#

xfreerdp /v:10.129.121.194 /u:'htb-student' /p:'Academy_student_AD!' /cert-ignore still the same with this command

analog dock
shadow current
#

xfreerdp /v:10.129.121.194 /u:'htb-student' /p:'Academy_student_AD!' /cert-ignore
[12:18:15:697] [419273:419274] [ERROR][com.freerdp.core.connection] - Timeout waiting for activation
[12:18:15:714] [419273:419273] [ERROR][com.freerdp.core] - freerdp_abort_connect:freerdp_set_last_error_ex ERRCONNECT_CONNECT_CANCELLED [0x0002000B]
its my first time encountering this a lot of rdp sessions are going through after i add /cert-ignore or /d: flags

next bronze
#

timeout

#

bad connection probably, try reconnecting the vpn or switch servers

shadow current
#

did a few times already

#

maybe a coffee break will help sadglas

old vector
#

Nobody is answering me all morning about Nessus over shh in vulnerability module. How to. I’ve reread all beginning chapters up to this point connected to target see Nessus running cannot access its browser to scan

sleek moss
#

The connection was reset

The connection to the server was reset while the page was loading.

The site could be temporarily unavailable or too busy. Try again in a few moments.
If you are unable to load any pages, check your computer’s network connection.
If your computer or network is protected by a firewall or proxy, make sure that Firefox is permitted to access the web. if i try anything else that doesnt work it loads but if its a proper file it just breaks
#

Local File Inclusion (LFI)

noble hazel
next bronze
#

read the Getting Started with Nessus section, it tells you how to connect

old vector
old vector
fathom pendant
#

i'll take my $20 consultancy fee now

fathom pendant
next bronze
#

yeah

old vector
#

Thank you

sleek moss
old vector
#

It worked

next bronze
#

it didn't tell you to use localhost

sleek moss
#

is it just me or is it server

next bronze
next bronze
#

enumerate excatly which template is vulnerable, and remember that there's 2 types of esc7

dreamy yew
#

Module: Password Attacks, Section: Pass the Ticket from Linux. Question: Check the /tmp directory and find Julio's Kerberos ticket (ccache file). Import the ticket and read the contents of julio.txt from the domain share folder \DC01\julio. For this question, I have managed to access the //dc01/C$ and cd into julio and found a flag.txt rather than a julio.txt

#

am i missing something

shut wraith
#

in a kerberos realm how do I find Which group can connect to a machine called LINUX01?

shadow current
#

Anyone did the AEN module blind? can you please tell me the section that is not covered by the previous modules so i can avoid thinking "this might be the one that isn't covered" everytime i will be stuck on a problem thanks!

#

cause some people say that there is one section specifically in AEN that is not covered by the previous modules

magic forum
#

WINDOWS ATTACKS & DEFENSE : PKI - ESC1
seems like i can not RDP to the ws001 host after connecting to the kali host. I have waited 15mins for everything to come up and also changed VPNs and terminated hosts and started them again.

next bronze
next bronze
magic forum
next bronze
#

it's in the lab overview section

magic forum
foggy siren
#

So I did the Skills Assessment for Pivoting, Tunneling, and Port Forwarding. Is the last question intended to be|| found via explorer without any pivoting? ||

hasty solar
#

Hi can I dm anyone who has completed advanced deserialization a quick question?

#

Thx

fathom pendant
dreamy yew
azure fog
#

Is there anyone who finished TE.TE section in the HTTP Attacks module?
I tried all the obfuscation methods but still no luck

dreamy yew
#

**Module: Password Attacks, Section: Pass the Ticket from Linux. Question: Use the LINUX01$ Kerberos ticket to read the flag found in \DC01\linux01. Submit the contents as your response (the flag starts with Us1nG_). **I have managed to get the ccache file for linux01: ccache_INLANEFREIGHT.HTB, and i converted to a kirbi file using Impacket-TicketConverter. Afterwards, I used Rubeus to import the converted ticket, however i ran into this error: [X] Error 1450 running LsaLookupAuthenticationPackage (ProtocalStatus): Insufficient system resources exist to complete the requested service. Can anyone explain to me this error or perhaps is there a problem with my way of approaching this question?

next bronze
dreamy yew
junior oxide
#

im doing the skill assessment in the pivoting module is it normal to get this message while doing nmap scan via proxychains "[proxychains] Strict chain ... 127.0.0.1:9050 ... 172.16.5.X:995 <--socket error or timeout!"

#

also whenever i scan an idependant port such as 3389 i always get the result as closed

clear swift
#

Tried and tried the "hbs" support thing

#

but screwed up the cookies somehow and I had to give up. You cant edit these in my developer tools

#

so you set it wrong once and you're fucked

marsh echo
next bronze
#

the user might not have wmi access, try another tool

echo forge
#

if you still need help DM me

#

if you still need help dm me

junior oxide
fathom pendant
#

nmap and proxychains don't generally go well together, at least for port scanning

hollow ibex
#

anyone can help i am stuck at os command injection skill assessment i find the right parameter but when i try to inject payload the error returns mv can not state : no such file or directory

frozen stone
#

Has anyone successfully completed the Hard skill assessment on ABUSING HTTP MISCONFIGURATIONS?

junior oxide
hollow ibex
#

can anyone help i am still here Error while moving: mv: cannot stat '/var/www/html/files/2561732172.txt': No such file or directory
mv: cannot stat 'cat': No such file or directory
mv: cannot stat 'flag.txt': No such file or directory on os command injection

quasi wave
#

for footprinting module's mysql section, the instructions for question 2 give away password and username to sha2 encrypted password that you get from nmap results in question 1. is that because I'm not expected to crack password?