#modules

1 messages · Page 220 of 1

pine dune
#

Hi guys, I cant seem to get anything to work with the IP in this section in the nmap module

sonic ridge
#

ls /path/to/dir worked but what if I didn't know the path and wanted to move up a directory

dim wolf
#

ls ..

sonic ridge
#

oh i didnt know you could do that got ya

tranquil axle
#

You can use the pwd command to get the working directory

sonic ridge
#

is it possible to string together commands though

fathom pendant
dim wolf
#

yea just get the url-encoded value of |

#

or there may be somethjng else there in the module

fathom pendant
#

also do you have multiple vpn configs running? ip a and ps aux | grep openvpn to look for multiple instances

novel hinge
#

im guessing both of these are wrong?

fathom pendant
#

then sudo killall openvpn

#

you have multiple instances of openvpn running, causing the target to not know where to send it back to

pine dune
#

ahh

#

okay let me try reconnect

fringe urchin
fathom pendant
#

also running as root might cause issues

#

I see you're running as root user by the # in front of the command

novel hinge
#

@fringe urchin copy and pasted into file then added : admin

sonic ridge
#

@dim wolf so I could do %26command%7Ccommand%26 and that would string together the commands?

next bronze
#

how many lines in your file?

pine dune
fathom pendant
#

you don't add :admin at the end

fringe urchin
fathom pendant
#

hashcat expects a certain order to the hashes you present to it

dim wolf
#

the module i think explains it

fringe urchin
#

And like marcie said running iz as sudo can cause problems like it happend to someone else last time

dim wolf
#

if URL encoding doesn't work, there are other methods

sonic ridge
#

not the current one im on :/

novel hinge
#

okay let me try reg user and copy from msf without adding anything

fathom pendant
sonic ridge
#

is there anytime I would be stringing together commands anyways or would I normally just issue a command then go from there?

fringe urchin
fathom pendant
#

stopped using sudo and boom: right pw

fathom pendant
fringe urchin
#

Sudo go brrrr

fringe urchin
dim wolf
sonic ridge
#

so it is useful to know

dim wolf
#

of course

fringe urchin
#

Sometimes whitespace could get copies with or maybe a wrong character since you copied to much etc

dim wolf
#

i think most of the time URL encoding works

sonic ridge
#

ill give that a try and see if it works by url encoding |

fathom pendant
sonic ridge
#

i was trying to put another & sign into the url and that didnt seem to do anything

fathom pendant
#

wanna know the issue? CRLF encoding

#

so literally if you did a diff -y on it: they looked IDENTICAL but diff will say they're different

novel hinge
#

im so lost guys im so sorry

fathom pendant
fringe urchin
fathom pendant
#

i genuinely don't recall

fathom pendant
novel hinge
fathom pendant
#

bash doesn't like CRLF

pine dune
#

Hi guys, why isnt it showing me the OS of the IP?

fringe urchin
novel hinge
pine dune
#

following this

fathom pendant
pine dune
#

ahh

#

is there an alternative?

fathom pendant
#

-O

fringe urchin
pine dune
#

thanks @fathom pendant

fathom pendant
#

also smb-os discovery only works if SMB is running

next bronze
fathom pendant
#

it doesn't look like it is in your case

next bronze
#

running that script won't do anything

fathom pendant
#

and whatever guide you're following for whatever reason it was

fringe urchin
pine dune
#

ahh I see, but the guide I was following is for this specific room and module and this is what the person used, so im confused

fathom pendant
novel hinge
fathom pendant
fringe urchin
pine dune
#

thanks

next bronze
fathom pendant
#

Otherwise you end up in a situation like this: where you had all the answers but not necessarily understanding how it fully works

#

which in the long-run is a detriment

fringe urchin
novel hinge
fringe urchin
next bronze
#

-a 3?

novel hinge
fathom pendant
#

and just have ipmi.txt and the wordlist after

#

(also you'll have faster luck using the provided module wordlist)

novel hinge
#

let me change to footprinting wordlist but still giving error

fringe urchin
novel hinge
next bronze
next bronze
novel hinge
#

okay trying now w/ hash pasted and -a 0

pine dune
#

hey @fathom pendant I used the "-O" flag but this is the result it gave

fringe urchin
#

(yea even sudoJerryShockRight )

fathom pendant
#

and made an educated guess

pine dune
#

idk how u can tell the OS by viewing a web page tho

pine dune
#

ahh it says lol

#

thanks marcielee

fringe urchin
novel hinge
#

does this look right? and should it take awhile now?

fathom pendant
fringe urchin
fathom pendant
#

considering you have an i9 13900: a few minutes is a highball estimate

next bronze
#

no it wouldn't work, you're using stdin mode, it's expecting the wordlist to be fed via stdin

fathom pendant
#

i'm runningIntel(R) Core(TM) i5-7200U

#

oh wait it didn't read the input

#

i didn't peep that lol

next bronze
novel hinge
#

ohhhh

#

admin:013ebf2082000000efd8dc9e4ebeaf35089da6daffc1c044d97d8d1b551102506d7a60cd9e58426ba123456789abcdefa123456789abcdef140561646d696e:2775fff47dd69521ab1f9ce009bc306ae4207af0

fringe urchin
#

and was the password in that specific wordlist?
i personally didnt use it so i dont know

next bronze
#

yes it's in rockyou

fringe urchin
#

yea but he used footprinting one

#

i used rockyou

fathom pendant
#

cracked for me

next bronze
fathom pendant
#

i just downloaded and checked

fringe urchin
fathom pendant
#

but if my i5 can crack with rockyou in like half a second his i9 should be able to do it in a nanosecond

#

not i'm only using 2/4 cores in my vm for it

fringe urchin
fathom pendant
#

so it's not even in full turbo mode

fringe urchin
fathom pendant
fringe urchin
#

congratz now delete it since it containts the password

fathom pendant
#

ugh not all my files copied from my old parrot vm, good thing i didn't completely nuke it yet

novel hinge
#

my fault, thank you guys so much for your help today. i really do appreciate you guys helping here Pepodance

fathom pendant
#

had to reinstall due to some weird issue with ruby not recognizing i have openssl

#

but i'm fine it's all fine

fringe urchin
fathom pendant
#

also the fact that the http:// source for gems no longer works because it's a force upgrade to secure: it didn't like that

fringe urchin
fathom pendant
#

yep

fringe urchin
#

yea i fixed it last time. cleraing cookied and history helped aswell

fathom pendant
#

found that out by doing a debug and seeing that it's a 301

fathom pendant
fringe urchin
fathom pendant
#

it's literally a 301 redirect

fringe urchin
fathom pendant
#

i'm referring specifically to ruby/gems and how it sources them

fringe urchin
fathom pendant
#

error tells me to "use http/insecure source"

switches to 'insecure'
Still errors out telling me to switch to insecure
mfw: Sad_Squidward_Pepe

#

positive things i've received out of it: nxc instead of cme

fringe urchin
#

Pepereally just dont be insecure

fathom pendant
#

literally what it was telling me

#

it was a weird error with the openssl config in ruby

fringe urchin
#

joofa always a blast searching for a solution

gritty leaf
#

hey what codes do i need know to code a website like reddit

#

i mean there is react what i use

fathom pendant
fringe urchin
#

isnt reddit written in pylons framework?

fathom pendant
#

idk exactly what reddit uses on it's backend

gritty leaf
#

i was watching youtube people were clone it with next13.js

#

and the new one does not have the pages folder

fathom pendant
#

but also this is straying off topic from the channel

gritty leaf
#

any idea

fathom pendant
#

this is better suited to be asked in #web (read and follow #welcome to access more of the server)

gritty leaf
#

i dont have access

fathom pendant
#

if only i included a thing that tells you how to access more of the server

fringe urchin
fathom pendant
next bronze
#

even the new reddit?

#

no wonder it runs like shit

fringe urchin
#

that was 2 years ago. no clue if that applies to current one

gritty leaf
#

what is with next13.js

fathom pendant
#

either way; straying far off topic

gritty leaf
#

it does not have anymore pages folder

fathom pendant
#

this channel is for assistance with academy modules

#

not random questions re: what a website's framework runs on

gritty leaf
#

why cant i write in general

restive grove
#

did anyone end up getting this question?
Im a bit confused about how zone information (which from my understanding is file origin, can show a rename)

I have the USN journal open and from my understanding of the logs show the file wasn't renamed? ||(rename old name was uninstall.exe, rename new name is uninstall.exe?)||

old vector
#

I’m on openvas scanning in vulnerability module. I use https://target:8080 get brought to greenbone login page. Use username htb-student pass HTB_@cademy_student! And it says login failed invalid username or password. Why is this I am copy pasting so I know it’s right

fathom pendant
#

is that the right creds it tells you?

old vector
fathom pendant
#

shitty ahhh mobile phone photo

old vector
#

Yes I e been stuck on this cuz I can’t login to green one

#

Greenbone

fathom pendant
#

reset the target; wait a minute; then try and log in

old vector
#

Ok

fathom pendant
#

sometimes it can take a few minutes to initialize

#

but you don't/shouldn't need to ssh in to config anything

old vector
#

Now I’m getting this message instead

fathom pendant
#

it just doesn't like you Sad_Squidward_Pepe

#

give it a few more minutes and try again maybe?

#

also as an fyi; there's pre-populated scans so you don't have to run one (they can take a LONG time)

old vector
#

Yes I’ll just use those because it’s saying time out and I just reset it I don’t have time

marsh echo
#

thanks I’m going to do the same

fathom pendant
marsh echo
#

Ahah I told you that it worked half for the rpc4 🙂 but thank you for sharing the solution

fathom pendant
#

but now you can have an updated openssl and ruby

#

:D

marsh echo
fathom pendant
#

and now you know: you didn't need to

#

kek such is the life of Cyber

marsh echo
#

Lool 🥳🥳 Excatly in all the it is important to find various ways to make a program work

mellow delta
crystal steeple
#

hello, im on sql injection fundamentals skill assessement, can anyone give me a hint on how to find which directory we have right to write in it?

cloud urchin
crystal steeple
#

i don't really even understand the hint given lol

cloud urchin
crystal steeple
#

the hint is : Try to read files you know to find a location you can write to.

cloud urchin
#

then why do you want to do it

crystal steeple
#

because i wanna get rce

cloud urchin
#

did you read all the files?

crystal steeple
#

and i can only write files in a specefic directory which is the one im looking for

crystal steeple
cloud urchin
#

the question seems to hint that the location is hidden in one of those files you can read

#

like, maybe off a txt file you read to find the location idk

crystal steeple
#

hmm i'll try some of the location i can read into it

cloud urchin
#

i didn't do that module but if you want to just find permissions for a database i'd use crackmapexec

cloud urchin
#

crackmapexec mssql <ip> -u <user> -p <password> --local-auth -q "your sql statements here"

crystal steeple
# soft cedar Take a look at the url

i tried to use that directory but i get error :
||Can't create/write to file '/dashboard/shells.php' (Errcode: 2 "No such file or directory")||

mellow delta
soft cedar
crystal steeple
#

you're right i forgot its was in web root dir

#

i'll try now

cloud urchin
# mellow delta can you explain a little further, I understand what you are saying about the hos...

yes, i explained this. nslookup reaches out to your DNS servers to resolve the hostname into an IP address. your computer is reaching out to your ISP to try and resolve inlanefreight.htb, which it can't , because it's not a public address it's a private address hosted within htb's virtual infrastructure. your computer will be unable to resolve that with the public resolvers, which is why you add the ip/hostname into /etc/hosts, doing that will tell your computer which ip to resolve the hostname (inlanefreight.htb) into. adding that entry to /etc/hosts makes it so you don't need to resolve the host via nslookup.

crystal steeple
cloud urchin
#

try it with a real address and it will work, like nslookup google.com

mellow delta
fast badger
#

help with the command and the answer input so i can learn please ...

cloud urchin
#

i'm sure the module went over how to find files, you should re-read that section

fast badger
#

i did

cloud urchin
#

i don't have that module unlocked but i can see in the syllabus there's a whole section about finding files and directories

#

also filter contents and regular expressions

crystal steeple
mellow delta
fast badger
#

Yes... but a number of commands and I try to input my answer but it seems wrong

next bronze
#

would be more useful to tell us what you have tried so that we can give better help

fast badger
#

i tried this command and few more

next bronze
#

did the section go through locate?

fast badger
#

nope ... and the input was 24 .. i guess i was wrong

next bronze
#

right, so use find

cloud urchin
#

Any other commands it taught you to find files on Linux?

next bronze
#

as it is in the section

fast badger
#

find gave me 0 and the input is wrong also

fast badger
next bronze
#

please provide more information instead of "not working"

fathom pendant
#

Also: big importance, are you connected to the target

mellow delta
#

I commented out the other entries in the /etc/resolv.conf file and added nameserver with the target machine IP. I am getting different output now but not what i need
simon@osboxes:~$ nslookup inlanefreight.htb
Server: 10.129.204.198
Address: 10.129.204.198#53

*** Can't find inlanefreight.htb: No answer

fast badger
next bronze
#

not the right syntax, read the section again

fathom pendant
#

nslookup domain ip/nameserver

mellow delta
fathom pendant
#

It's still trying to pull other records to resolve

fast badger
fathom pendant
#

It has 0 idea how to resolve inlanefreight.htb

#

Generally local name resolutions are done in /etc/hosts

worn holly
#

HTB learning process is so goddamn good

mellow delta
# fathom pendant Generally local name resolutions are done in /etc/hosts

this is what someone told me to do here
yes, i explained this. nslookup reaches out to your DNS servers to resolve the hostname into an IP address. your computer is reaching out to your ISP to try and resolve inlanefreight.htb, which it can't , because it's not a public address it's a private address hosted within htb's virtual infrastructure. your computer will be unable to resolve that with the public resolvers, which is why you add the ip/hostname into /etc/hosts, doing that will tell your computer which ip to resolve the hostname (inlanefreight.htb) into. adding that entry to /etc/hosts makes it so you don't need to resolve the host via nslookup.

fathom pendant
#

Again: not how it works

cloud urchin
#

sdlevy what's your goal here? why are you editing your resolv.conf file when you already have the ip/host added to /etc/hosts?

fathom pendant
#

Yes nslookup uses stuff from resolv.conf to try and find info: but inherently there's some flaws. For instance it doesn't understand that the domain you're trying to reach is also the same as what you're specifying as the nameserver

fathom pendant
mellow delta
fathom pendant
#

Why the module doesn't use dig is beyond me but eh, it is what it is

fathom pendant
mellow delta
#

yes

fathom pendant
#

It's important to not leave out important parts of the question

#

nslookup inlanefreight.htb ip

#

Do that and see if you get a different answer

fast badger
fathom pendant
mellow delta
fathom pendant
#

Now, remove the entry from your hosts file

mellow delta
#

same

cloud urchin
#

and revert any changes you made to resolv.conf

fathom pendant
#

That too

mellow delta
#

I have done both, deleted the nameserver ip from resolv.conf and removed the ip from /etc/hosts
same result

fathom pendant
#

Sec

#

Ah

#

Because you need to specify type

crystal steeple
#

||nslookup -type=NS inlanefreight.htb 10.129.109.136||

crystal steeple
fathom pendant
#

Nowhere in the section displays just using nslookup without a type query

mellow delta
#

let me try that

fathom pendant
crystal steeple
mellow delta
#

yep

fathom pendant
#

Given the copy/pasted terminal output:yes

mellow delta
#

thanks

fathom pendant
#

This is a heavy case of: read the material

#

It literally shows you multiple examples

#

None of which are missing -type

#

You only don't need -type if you specify -query

mellow delta
#

its really easy to say that. When people are learning and trying to understand content that is new to them they are going to miss things. It is unreasonable to hand someone that much information and have them fully understand everything without missing things or having questions

fathom pendant
#

I prefer dig for the cleaner output

fathom pendant
mellow delta
fathom pendant
#

I barely understood what it was when I first went through it

#

I am telling you as someone who's journey started with CPTS and minimal linux knowledge

mellow delta
#

sorry, I will get off my soap box now

fathom pendant
#

Well then read the content more and try and understand it better

mellow delta
#

not helpful

#

learning involves a network and a community

#

saying just learn better isn't helpfu

fathom pendant
#

I'd understand if it was an issue like with Footprinting/email where they give you the fetch <id> all command

#

Where the command just doesn't give the needed info

#

But it's pretty much shown how it works in the section

#

I'm not saying "learn better" I'm saying "read carefully"

crystal steeple
fathom pendant
#

Missing something happens, but I begin to doubt you re-read the material once you hit a wall

#

I re-read once I hit a wall. I try and make sure that before I ask the question it's not as simple as "oh I missed this argument" and if it is: then I accept that I was dumb and remember for next time. It's what makes me effective at helping people

#

I failed, messed up, and learned

#

Heck the only question I asked for the AD skill assessment was "is x on these machines," but I trusted that I had all the info given by the module

#

And/or from a module it expected me to already have gone through and understood

#

I value the struggle as a part of learning.

mellow delta
#

It irks me when people assume things about other people. I do re read, because this material is taught in a non interactive way with people who can explain why you are struggling with something. Being able to ask questions of others is extremely helpful. I fully accept and understand that i know nothing. sometimes I need people to explain things to me in a way that is different to the content

fathom pendant
#

And asking questions isn't inherently negative.

#

Why not work along with what's being taught

#

the examples used public websites ¯_(ツ)_/¯

mellow delta
#

I was a university professor for four years. I know a bit about the educational process

fathom pendant
#

And even in some other modules where it might be related to using a private ip, just spin up the ip and work alongside what's being taught

#

And before you know it you already have the answers for the questions

#

I'm making an observation based on past behavior, I say I begin to doubt because it doesn't feel that way to me. However i can concede that it could be a misunderstanding of material (which can happen)

mellow delta
#

I was just talking to someone today about how helpful this community is

fathom pendant
#

Sometimes even the process of asking the question actually gets you the answer

#

It's why I volunteer my time here. I just also dislike seeing certain patterns of behavior, some more egregious than others. I'm not accusing you of this behavior

rustic sage
#

Kerberoasting for windows attack second question must I RDP into this account ?

fathom pendant
#

Some people do just not fully read the provided material and expect someone to answer them

rustic sage
#

I’m having trouble RDP into it

rustic sage
#

Windows attack kerberoasting

mellow delta
#

I don't expect answers, just help understanding. Otherwise it's not learnign

fathom pendant
#

Also if the question says "authenticate" then rdp may not be the only way

#

Winrm is also a popular windows remote tool

fathom pendant
potent ermine
fathom pendant
#

Usually if rdp isn't enabled for a user there's a message that says it when it authenticates or something along those lines

fathom pendant
#

My favorite part of networked windows

mellow delta
fathom pendant
#

I apologize for offending you in any way

rustic sage
#

Or HTB misleads you

fathom pendant
#

Is English your first language?

fathom pendant
#

Fuckin still fresh in my mind about that shit in AD enum

rustic sage
#

65% my fault the rest is awful wording of questions

fathom pendant
mellow delta
rustic sage
#

Found it. They should of said connect via RDP via the original RDP connection to Bob

#

💩

#

It’s those kinds of things that get on my nerves

next bronze
#

is english your first language? I don't think the instructions are anything too confusing

rustic sage
#

Meh usually not but sometimes you can tell the person isn’t super fluent

#

It’s not that it’s wrong it’s just sometimes written awkwardly

potent ermine
#

I missed that too, I just couldn't wrap myself around RDPing within an RDP session

rustic sage
#

Glad it’s not me

#

Would have been nice to clarify within the host and not inside

#

Outside *

blazing topaz
#

Before I start this box do I have to buy minecraft?

#

I assume its a very popular exploit to do with logging and really don't want to purchase minecraft just for that...

thorn berry
#

Hi

granite thistle
#

Hello

fathom pendant
fathom pendant
next bronze
#

fair. having a bit of networking knowledge would helped I guess, the second target is in a different subnet

fathom pendant
#

oh @next bronze wanna know what else tripped me up on the first AD assessment: for like the first 10 minutes I couldn't ping DC01 kek so it confused me as to why, but more importantly how

next bronze
#

what was the problem kekw

rustic sage
# fathom pendant Module?

Any hint for the event viewer I am filtered in4769 looking for anything web mentioned or a new servicesid

#

Question two of windows attack, and defense kerbo roasting

#

👋

#

I am searching all 4769 I’m lost

potent ermine
rustic sage
#

I did that

#

I searched” webservice” on all 4769 nothing shows

dim wolf
# next bronze is english your first language? I don't think the instructions are anything too ...

the instructions involved in Windows Attacks & Defense are a bit misleading; the overview section makes it seem like you can RDP to both WS001 and kali from your VM when in reality it's just one or the other depending on the section. of course, you can always RDP from WS001 to kali and vice versa if you know the internal IP addresses of each, but i don't think that's inherent knowledge that you can have if you're simply doing the path in order

rustic sage
#

I am past that

#

Now I am in it and searching 4769 and now I’m lost I search web webservice

potent ermine
# rustic sage I am past that

Can you try bob? Honestly I don't remember if I searched something or just went one by one until I found it. I don't think I had to click that many before I found the webservice log

rustic sage
#

I’m suppose to be on HTB student for this portion

dim wolf
rustic sage
#

I backed out of that particular event now I’m searching wider

#

Second question windows attack and defense kerboroasting

#

I have RDP into the RDP from the RDP now looking at the event log

dim wolf
#

you can just filter for any instance of webservice

rustic sage
#

I did that just now

#

Looking

fathom pendant
#

and doing an fping revealed all the connected servers

#

i just couldn't for w/e reason ping it from the rdp session for a bit

#

which seriously confused me for a bit

next bronze
#

weird

#

tip: use netexec to sweep the subnet in an ad environment, it will almost always find all the windows machines

fathom pendant
#

i was like "i gotta get to DC01.... but where are you" (i was making the educated guess it was the first ip in the fping)

soft cedar
#

Hope that clarifies it.

rustic sage
#

Looked at this no one helped him lol it’s the same issue I’m having I’m searching 4769 I see nothing but junk

dim wolf
#

can you show a screencap of an event 4769

rustic sage
#

I’m on a work computer I can’t screen I RDP to the second questions host and searched event log > security > 4769 now I’m searching it all I tried to “find” web or webservice and got nothing

dim wolf
#

what's the command you're using

rustic sage
#

There’s no command its event viewer filtered on include 4769

dim wolf
#

oh man.. you're using that?

rustic sage
#

Yes per the directions

dim wolf
#

it's a whole lot easier if you use Get-WinEvent

rustic sage
#

Hmm

dim wolf
#

can you just say what you think the ServiceSid is in a spoiler

fathom pendant
#

or at least the last 4

dim wolf
#

well no

rustic sage
#

Yeah hold on

fathom pendant
#

oh yeah you right

#

SIDs are weird man

rustic sage
#

|752445584–1001|

#

Included that s-1 shit too

fathom pendant
#

putting || before and after puts a spoiler message

#

||like this||

dim wolf
#

ok you're definitely on the right path then

#

try your hand at using Get-WinEvent

#

it makes it a lot easier to search and filter logs

rustic sage
#

Can I get a syntax for it it’s not working

#

And even the event log filtered on 4769 all the service sid are all the same

#

The lesson doesn’t even go through any of this

#

Nothing on forum about this nothing on chat about this . Nothing

fast badger
#

how do i know my target system , please help

dreamy yew
#

Module: Password Attacks, Section: Password Attacks Lab - Hard, Question: I have been figuring how to dump the LSASS files, have tried pd64.exe or using the Task Manager, but__ i have realised that I need administrator privileges, __so im stuck here and might need a nudge :/

dim wolf
rustic sage
#

Thanks, getting some sleep maybe my brain will work tomorrow

shut quest
dreamy yew
fathom pendant
sick shale
shut quest
fathom pendant
#

KeePass is definitely the right direction though

#

This lab is a bunch of back and forth

fathom pendant
shut quest
#

there's one section in ithat lab i didn't like

fathom pendant
#

The final part?

#

Or?

sick shale
shut quest
#

no, a couple of steps right before that bitlkOpen...

fathom pendant
shut quest
fathom pendant
#

But if you mean the whole "how do I even" bit was the only tedious thing

#

I think my first go around I just did it on my host then transferred to my vm

#

I very much did the lazier way my first go around in some modules

#

I.e. using an email client for the imap/pop3 stuff

shut quest
#

I hear what you're saying, but I couldn't do it that way 😂

fathom pendant
#

Not running that host? Or just running your setup baremetal? Or some other restrictions

shut quest
#

Former

fathom pendant
#

Gotcha

#

Either way a learned experience

dreamy yew
sick shale
dreamy yew
shut wraith
#

This command was placed in the section without any description or explanation. Can someone explain it to me please?

XP_SUBDIRS Hash Stealing with impacket

Attacking SQL Databases

sudo impacket-smbserver share ./ -smb2support

Impacket v0.9.22 - Copyright 2020 SecureAuth Corporation
[*] Config file parsed
[*] Callback added for UUID 4B324FC8-1670-01D3-1278-5A47BF6EE188 V:3.0
[*] Callback added for UUID 6BFFD098-A112-3610-9833-46C3F87E345A V:1.0 
[*] Config file parsed                                                 
[*] Config file parsed                                                 
[*] Config file parsed
[*] Incoming connection (10.129.203.7,49728)
[*] AUTHENTICATE_MESSAGE (WINSRV02\mssqlsvc,WINSRV02)
[*] User WINSRV02\mssqlsvc authenticated successfully                        
[*] demouser::WIN7BOX:5e3ab1c4380b94a1:A18830632D52768440B7E2425C4A7107:0101000000000000009BFFB9DE3DD801D5448EF4D0BA034D0000000002000800510053004700320001001E00570049004E002D003500440050005A0033005200530032004F005800320004003400570049004E002D003500440050005A0033005200530032004F00580013456F0051005300470013456F004C004F00430041004C000300140051005300470013456F004C004F00430041004C000500140051005300470013456F004C004F00430041004C0007000800009BFFB9DE3DD80106000400020000000800300030000000000000000100000000200000ADCA14A9054707D3939B6A5F98CE1F6E5981AC62CEC5BEAD4F6200A35E8AD9170A0010000000000000000000000000000000000009001C0063006900660073002F00740065007300740069006E006700730061000000000000000000
[*] Closing down connection (10.129.203.7,49728)                      
[*] Remaining connections []```
sick shale
#

It's for capturing hashes. This is the explanation from the hackthebox section: In the Attacking SMB section, we discussed that we could create a fake SMB server to steal a hash and abuse some default implementation within a Windows operating system. We can also steal the MSSQL service account hash using xp_subdirs or xp_dirtree undocumented stored procedures, which use the SMB protocol to retrieve a list of child directories under a specified parent directory from the file system. When we use one of these stored procedures and point it to our SMB server, the directory listening functionality will force the server to authenticate and send the NTLMv2 hash of the service account that is running the SQL Server.

cloud urchin
#

any guidance on this crackmapexec skill assessment? stuck trying to get into the ccache share. i have dev01 compromised, ||got the password from keepass|| but i can't see where to use it or how to get into that share.

loud dagger
#

does htb academy cover nessus at all? i’ve always wanted to learn it

#

oh it’s in vulnerability assessment

#

also do they teach about the individual tools you use or do they teach you the general idea and then you have to figure out how to use the tools?

sick shale
#

I think they have a complete section on Nessus

#

and a smaller one on OpenVAS as well

shut wraith
#

Hello can anyone help me enumerate mssql

soft cedar
dreamy yew
#

For pwnbox: a very smol question: how do i fix the error "There are no available instance." I have tried refreshing the page but to no success.

shut wraith
# soft cedar That’s vague, what do you want to do?

I am just trying to see the databases, tables, and their data.

This is my commands:
SELECT name FROM master.dbo.sysdatabases
SELECT * FROM master.dbo.sysdatabases
SELECT name FROM sys.databases;
SELECT *FROM sys.databases;
Nothing of these work. I tried a bunch of other commands, but likewise the response is just empty

shut wraith
leaden quail
#

is someone available to help me with Logrotate?

soft cedar
shut wraith
shut wraith
#

1

soft cedar
# shut wraith 1

The question is asking you for a password of a user:
What part of the section talks about stealing hashes?

#

You need to try one of the techniques shown there. No need to “enumerate” the DB

cloud urchin
#

"There are no available instances please try again later"

shut wraith
autumn pilot
#

It is in the section of the module

soft cedar
#

^ it should be easy to find xd

dreamy yew
cloud urchin
#

nah i think it's an issue with the platform

dreamy yew
#

dang it, i was so close to discovering more creds on the lab

cloud urchin
#

looks like it's back up

#

oh maybe not it just terminated again

misty saddle
#

Hi all, I'm currently doing the skills assessment in Pivot, tunneling and port forwarding. I got some issues with RDP to vfrank. I got his credentials but I don't seem to have the right IP to RDP to. I've tried to ping sweep 172.16.6.x and 172.16.5.x. I've attached a image of the IP's I've found. Can anyone nudge me in the right direction?

cloud urchin
#

i can't spawn the victim vm now

#

anyone else having issues on the platform?

misty saddle
#

Nope

rustic sage
#

plenty

#

having issues with my target machine at the moment.

autumn pilot
#

reach out to support

#

mentioning it in discord won't change anything

cloud urchin
#

i mean.. on the same hand i've seen other staff mention short downtimes etc, i was just asking

#

wasn't sure if it was me or the platform, since a while earlier the platform was actually down

rustic sage
#

asking the community was my inital idea before pinging support for help.

#

but uh. ok?

dreamy yew
#

Password: Password Attacks, Section: Password Labs -Hard, Question: I have trouble transferring the .vhd file from target to attack machine, i think it was probably too big but i might need a nudge

autumn pilot
#

You are on the right path of considering the size of the file, knowing that you can approach SMB differently and the share, you can approach it like a NFS share

shadow current
dreamy yew
cloud urchin
#

i'm still stuck on CME skill assessment if anyone could push me in the right direction. i need to access the ccache share and don't have users who can. i have dev01 pwned and got the ||keepass password|| but it doesn't work anywhere that i can see

limber surge
#

Introduction to Digital Forensics > skill assessment

can someone hint me on this.

Using VAD analysis, pinpoint the suspicious process and enter its name as your answer. Answer format: _.exe

i tried to do a collection on Windows.KapeFiles.Targets under san triage, but no clue.

dreamy yew
#

Password: Password Attacks, Section: Password Labs -Hard, Question: I am still stuck on trying to download the Backup.vhd, it might relate to mounting the target share locally but i have no clue how to start on it

cloud urchin
#

Does it teach doing that in the module?

sick shale
dreamy yew
sick shale
#

you have to set it up on your attack machine

sick shale
#

and then on the target machine use powershell to upload the file

misty saddle
#

use smbclient from impacket

dreamy yew
# misty saddle

yea i did this, but the file was too big to transfer and it timedout

sick shale
#

yeah smb works too

dreamy yew
misty saddle
#

yes

dreamy yew
#

ohh ok i will try it out now

misty saddle
#

Mine didn't work with normal smbclient

#

but with impacket it worked

#

Had the same issue as you

#

Hi all, I'll try again to see if anyone here have the answers prayge
I'm on the second last question in PIVOTING, TUNNELING, AND PORT FORWARDING skill assessment.
I have the credentials for vfrank. I've found two IP's with ping sweep 172.16.6.45 and 172.16.6.35. But I can't RDP to either of them. Would appreciate any kind of help.

cloud urchin
#

are they both windows?

misty saddle
turbid kraken
#

[SOLVED]
DOCUMENTATION & REPORTING > Notetaking & Organization > Q1: What tool mentioned in this section can make logging a session easier?
Hey guys, So I'm stuck on the stupidest thing ever. See the question above; i read through the thing, knwo the answer (as it clearly stated in the question below) but can't find the exact formating used. Would someone be able to help me out? (I can put my answer as a spoiler if you want, it's nothing critical lol )

edit: disregard, Was being way too specific :/ it's the tool, not the plugin to the tool....

sick shale
#

i'm not at this module yet but is it possible RDP run on a hidden port?

dreamy yew
# misty saddle Had the same issue as you
Impacket v0.10.1.dev1+20230316.112532.f0ac44bd - Copyright 2022 Fortra

Type help for list of commands
# use david
# ls
drw-rw-rw-          0  Fri Feb 11 10:43:03 2022 .
drw-rw-rw-          0  Fri Feb 11 10:43:03 2022 ..
-rw-rw-rw-  136315392  Fri Feb 11 12:16:12 2022 Backup.vhd
# get Backup.vhd
[-] The NETBIOS connection with the remote host timed out.``` Did you encounter this before?
misty saddle
#

No, don't recognize that

zinc knoll
#

Hello,
I have a problem validating the first exercice of the "INTRODUCTION TO BASH SCRIPTING" module, could someone help me to understand what I did wrong ?

dreamy yew
sick shale
#

smbmap -H <IP> --download "notes\note.txt"

dreamy yew
sick shale
#

is the target machine still up?

dreamy yew
sick shale
dreamy yew
#
smbmap -H 10.129.202.222 -u david -p xxxxxx --download "david\Backups.vhd"
sick shale
dreamy yew
#

ok let me try it

dreamy yew
# sick shale and if you try with impacket maybe? I did a quick search and this is the syntax ...
└──╼ [★]$ /usr/share/doc/python3-impacket/examples/smbclient.py david:******@10.129.202.222
Impacket v0.10.1.dev1+20230316.112532.f0ac44bd - Copyright 2022 Fortra

Type help for list of commands
# ls
[-] No share selected
# use david
# ls
drw-rw-rw-          0  Fri Feb 11 10:43:03 2022 .
drw-rw-rw-          0  Fri Feb 11 10:43:03 2022 ..
-rw-rw-rw-  136315392  Fri Feb 11 12:16:12 2022 Backup.vhd
# get Backup.vhd
[-] The NETBIOS connection with the remote host timed out.

#

still doesn't work

sick shale
#

try with this syntax

#

impacket-smbclient -H 192.168.1.100 -U user%password -R Documents/important_document.txt -o important_document.txt

#

with the -U and the -R flag

sick shale
cyan gulch
#

@languid fjord Hello; I have a question, how come Academy is running so super insanely slow but HTB Labs is fine?

rustic sage
#

i cant even connect to a server

cyan gulch
#

It's so hard :L idk what's going on

#

Trying to ssh and it literally isnt working

worthy laurel
#

htb down

cyan gulch
#

Ohhh Labs is working academy isn't though i think, although i didn't try HTB Labs machines I just just logged in

dreamy yew
dreamy yew
sick shale
#

maybe it's related to the outage

#

try again when this is resolved

dreamy yew
#

the target ip for academy has been timing out on and off despite resetting it many times over 2 hours

cyan gulch
#

:L

dreamy yew
#

major headache now

cyan gulch
#

Yeah I'll wait it out like you guys, I may try HTB Labs, it seemed not to be slow at all

sick shale
#

yeah haha

gusty flicker
#

Hey guys! First time here nice to meet you all. If I found a problem or missing data on of the modules, where would I go to report it? 😉

dreamy yew
#

@sick shale thanks for the extensive help though

gusty flicker
#

Perfect, cheers!

sick shale
cyan gulch
#

Ima test HTB Labs to see if it's working or it's just Academy

#

Yeah must be system wide

#

Labs isn't working either :L

#

I guess I'll do Try Hack me or Over The Wire studies tonight hahaha

cedar yew
#

hello guys, i need help

Module-> Password Attacks
Task-> Remote password attacks - Password Mutations

my problem-> I created a word list and tried brute force, it took hours but I couldn't succeed.

my command-> hashcat --force password.list -r custom.rule --stdout | sort -u > mut_password.list
https://academy.hackthebox.com/module/147/section/1391

#

solved 🙂

fathom pendant
cedar yew
#

password list 😐

fathom pendant
#

Well if you used the provided one from the resources button, that wouldn't be the case

#

The end result should be 94044 words long

#

Either way: brute forcing ssh should be a last ditch effort if you were doing that

cedar yew
#

I used that list but it took too long

fathom pendant
#

Don't bruteforce ssh, and this module is an exercise in patience

#

With the right threads and protocol: it takes ~30 minutes

#

48 is the sweet spot for many

cedar yew
#

true

loud dagger
#

why do i get different numbers from locate *.log | wc -l and find / -name "*.log" 2>/dev/null | wc -l?

fathom pendant
#

The fastest bits of this module come from hash cracking

fathom pendant
#

Find searches the system

#

I.e. if you just uninstalled something, locate may still see it

loud dagger
#

ah ok gotcha

#

thanks

fathom pendant
#

Locate is basically a database search

drifting urchin
#

stupid question, in an AD environment the goal is to compromise the Domain Controller. I now have the admin credentials and logged into the system as NT Authority System. Does that means its compromised?

fathom pendant
#

That system, maybe

steady dust
#

You have local administrator. 🙂

next bronze
#

the goal depends on what is agreed upon at the start of an engagement. but if you have gotten DA, it's safe to say the domain is compromised

fathom pendant
#

But to pwn a domain, you need specifically "domain admin"

rustic sage
#

Windows attacks and defense - kerberoasting- second question. I have RDP into the HTB student account. I have visited event viewer and filtered all that is event 4769. I have tried to use xml to filter webservice user. It results with no findings. If I take the xml off for webservice. I get an ocean of 4769 logs with nothing webservice related . I tried to filter more for web and nothing. All the accounts from this point have often the same servicesid so this is very confusing and frustrating. If anyone has a tip from this point please let me know.

#

This question has me sweating like R Kelly in prison

#

I looked at the questions on the forum, zilch. The only questions were people not knowing to RDP into the HTB student rdp, and didn’t know they needed to do that from the first account. Nothing in regards to post event viewer searching for the proper SID. Looked at the chats looked at the forum, not a single tip

crystal steeple
#

hello, im in the sqlmap essentials module stuck on case6 , i used the hint and executed the command : ||sqlmap -r req.txt --dbms=mysql --prefix="')" --level=3 --risk=3 --batch --dump|| but still failed to get the flag, maybe something wrong with my command?

#

nvm got it

rustic sage
#

If anyone can help please let me know I’ve tried everything

dim wolf
late galleon
#

whats cheapest way to study for OSCP?

rustic sage
rustic sage
late galleon
rustic sage
#

Omg

late galleon
#

i have THM and HTB Free now

rustic sage
#

If you can’t do a basic Google search you are a goner

leaden quail
fathom pendant
rustic sage
#

I recommend you do the EJPT first before you touch this stuff you’re going to get crushed if you don’t

late galleon
fathom pendant
#

No

late galleon
#

I said FREE

next bronze
rustic sage
#

: Insert this is Sparta kick into the well:

fathom pendant
#

Well if you want free, just Google the course topics

next bronze
#

first thing to learn if you want to be a hacker: how to google

fathom pendant
#

And read articles upon articles of content

rustic sage
#

Use Google, bro don’t be an oxygen thief

fathom pendant
#

For the most part, the stuff on academy is well put together

#

And worth the cost for learning it

rustic sage
#

Sure is

#

My manager has his OSCP and he is still struggling with this CPTs exam

late galleon
late galleon
fathom pendant
#

Free boxes won't really prep you for OSCP

late galleon
fathom pendant
#

They help you develop methodology, sure

late galleon
#

I already have the course material from before

rustic sage
#

I figured it out. I was not refreshing the Academy page and it wasn’t registering the question.

fathom pendant
#

But there's a portion of oscp that's focused a bit on AD

#

Which boxes won't really prep you for

dim wolf
#

the fuck?

late galleon
#

yeah im just looking for a study routine with the proper material

#

dont wanna waste time with bs

fathom pendant
#

CPTS material goes over most, if not all, the material of OSCP and some more

late galleon
#

should I have my old course notes out?

fathom pendant
#

And for a fraction of the cost

#

Notes are useful

late galleon
#

mine are from when I last tried in 2020

fathom pendant
#

Well I think AD is relatively recent

#

Since CPTS dropped, OSCP updated their material

#

Buffer Overflow isn't on it anymore

eternal ridge
#

hey guys, in sqlmap chapter4, I got the flag of case1, but the web hit me: it's a mistake

#

what the correct type of case2 flag?

late galleon
crystal steeple
#

im in that module can u specify section

eternal ridge
#

my bad, sorry guys

late galleon
#

someone said do the labs on HTB

crystal steeple
late galleon
#

they're like 49/mo tho

fathom pendant
#

Cheapest you can get is like ~$400

#

For cpts course + voucher

dim wolf
#

if you want AD practice do the Offshore Pro Lab

fathom pendant
#

Just the course like $140

fringe urchin
fathom pendant
#

If that

fringe urchin
#

So like "free"pepefriends

dim wolf
#

it's basically free i'm riding that student subscription

fathom pendant
#

I'm riding my not rigged silver annual sub I got from the giveaway

next bronze
#

especially for oscp

crystal steeple
dim wolf
#

oh ur right

dim wolf
#

i forgot OSCP has like a 3 box AD set

fringe urchin
#

Well + the voucher

#

Ofc voucher needs to be pirchased seperatly

fathom pendant
#

Student sub doesn't include voucher

#

Still relatively cheap though

next bronze
#

you can technically get cpts for $218

dim wolf
#

who can do that though

fringe urchin
#

Can you just start every module as a student and then end sub?

late galleon
#

LMAO at thinking 200 bucks to study is "cheap"

dim wolf
#

210 bucks is the exam voucher

fathom pendant
#

Any module you don't complete when your sub ends, you lose access to

fringe urchin
dim wolf
#

8 dollars/month for all the modules

crystal steeple
fathom pendant
#

Honestly with how many people had "issues" with ad skill assessment 1, my only major issue was figuring out the right tool

next bronze
#

you can do the whole thing with with like 5 nxc commands 4Head

crystal steeple
fathom pendant
next bronze
#

probably the latter kekw

fathom pendant
fathom pendant
faint rampart
next bronze
fathom pendant
#

The hardest part for me was fixing evil-winrm

rustic sage
#

This is 400 bucks and it’s better harder stuff. What’s the issue?

#

Im getting my oSCP after cpts. I’m doing this way so I can prove to my team I wont fail it

#

That’s what my boss wants. Don’t waste corporate money on oSCP, do cpts and if you pass then you can have the fancy title.

#

And this is coming from a top company everyone sees daily but I can’t tell you due to privacy

#

Source me, a junior pentester

#

We should be lucky HTB offers all this shit for 400 it’s worth way way more. Sure the wording sucks sometimes but we are in an international community. Not everyone has the queens English. It’s a trade off that’s worth it in the end price and knowledge wise

dim wolf
#

compared to everything else, yeah of course 218-480 bucks isn't cheap, but HTB Academy is one of the cheapest options around in cybersecurity education

#

and for the quality you get, i'd say it's well worth it

rustic sage
#

Go do pnpt they are 200 300 but you have to download an ovpn and its a pain in the ass at least HTB has in house vms

fathom pendant
rustic sage
#

Yes but it’s an option pnpt isn’t

fathom pendant
#

Fair

late galleon
rustic sage
#

Pnpt has you doing ad and setting it all up which is awful if you have a slow computer

clever topaz
#

is there any way to solve Password Mutations? i ve been hydra-ing for 2 hours but only 4088 tries.... still got 8999 left to go AHHAHAHA

rustic sage
#

HTB its served right on a dinner plate. What’s there not to love?

rustic sage
late galleon
fathom pendant
#

Gotta know people to network

late galleon
rustic sage
#

It took me a year after I graduated to find a job how did I get it? I looked at pentesters at X Corp, and reached out!

fathom pendant
#

And we all know that leaving the house is game over for hackers

rustic sage
#

How can you be a pentester if you can’t Google or even do that like damn homie

late galleon
rustic sage
#

Yeah because that’s life

late galleon
#

your an idiot LOL

rustic sage
#

No one will give you shit you have to take it

#

You sound like a soft male that hates your own weakness

fathom pendant
late galleon
fathom pendant
#

Let's not get into personal attacks

next bronze
#

cringe kid

rustic sage
#

Why don’t you cowboy the fuck up and look for a job by ANY means necessary

#

Pentesters make due with shit they have if you can’t do that work tech support

fathom pendant
#

I dont wanna have to call in the eagle 500kg

rustic sage
#

If you can’t OSINT people on LinkedIn and tear down the barrier you can’t do it on an assessment

fathom pendant
#

^

late galleon
#

blocked

#

nice

fathom pendant
#

This field is all about research

rustic sage
#

So why don’t you just sit in your moms basement and cry your own problems you caused to someone else

#

Beta male behaviors

fathom pendant
#

If you can't do bare minimum research, then the field isn't for you

fringe urchin
rustic sage
#

Go be tech support and make 15 an hour

fathom pendant
clever topaz
fathom pendant
clever topaz
fathom pendant
#

This has 0 to do with modules, and the reason for not being able to post in #general is quite literally skill issue

shut quest
# late galleon your an idiot LOL

Coming in and attacking everyone that is articulating counter points by name calling is a poor reflection upon yourself. This channel is about htb academy modules. Might want to take your attitude to a different channel before the mods come in.

fathom pendant
#

Need to be hacker rank+ to post images in general chat

dry halo
fathom pendant
#

Also I don't think anyone monitors the hackthebox discord account

clever topaz
fathom pendant
#

If you look at the hydra output you will see that it drops to like 4 threads

clever topaz
#

thanks for the knowledge

#

which protocol is the fastest to bruteforce? rdp, ftp, smb

next bronze
#

ftp/smb

fathom pendant
clever topaz
#

yes ive put it as -t 64 ahahahaha

fathom pendant
clever topaz
#

im doing it on ftp but still 668 tries per sec

next bronze
#

if you can access ldap or kerberos those are even faster

fathom pendant
#

A good amount of people have luck with 48

clever topaz
fathom pendant
#

It should take ~20 minutes

#

So go do something else while it searches

upbeat oak
#

Hmm can you use braa without the oid? Found the community string and I think a user with snmpwalk using the community string. Trying to use braa to doublecheck but I get a invalid syntax when I use the community string braa <community string>@ipaddress

fathom pendant
#

Do I look British to you?

fathom pendant
#

The .1.*

upbeat oak
fathom pendant
#

Then realize I made a minor spelling mistake

fathom pendant
#

Inlanefreight.htb instead of inlanefreight.local

#

I'll probably tackle the second ad enum lab later

late galleon
#

its a giant joke ive tried everything. i will probably be able to get into this field as a hobby but the pipeline is totally broken. the best I can get is a data entry job. had a IT Helpdesk job but got fired because I was "to slow". that was 3 years ago. couldn't get a new job since. now im not taking it seriously at all but still pursuing it because I love it. I tried LinkedIn, cold emailing, cold calling, applying, applying to different countries. nothing

#

its a giant joke

upbeat oak
#

Not really the right place to ask this but in reference to what you guys were talking about earlier @fathom pendant are you working as a pentester now and if so could you maybe dm the steps you took?

fathom pendant
#

If you got fired from IT helpdesk for being too slow, then you really must have been slow af

#

Part of your training generally includes SLA for handling incidents

late galleon
fathom pendant
#

Bare minimum standards to follow

#

Truly. I could spend an hour on a call (actively doing troubleshooting/fixes) and not be considered slow

#

I had great CSATs

#

Only one dickweed every now and then that doesn't understand "we can't do that"

#

Proper training/actively following training keeps you out of trouble

#

Shit part of training before full prod they had us making sure we had a good workflow

#

Mind you, OEM support but still

#

~5 cph if the issues were simple

#

usually was ¯_(ツ)_/¯

#

Occasionally it was slightly out of scope questions that didn't take more than a few searches within the KB to fix

#

Not really

#

People get frustrated with AI telling them to do things

dim wolf
#

would love to see an AI do a pentest

fringe urchin
rustic sage
next bronze
dim wolf
#

best to leave some important things to humans... like pentests

next bronze
#

I agree the job market sucks right now, but there are other things you can do

shut quest
fringe urchin
next bronze
#

yeah well said

#

many things to learn, keep going

drifting urchin
#

anyone here to have taken successfully the PJPT exam?

rustic sage
#

I was an accountant for 7 years. Got a masters in IT. No one wanted to hire me. Networked and found a person plus I fluffed up my resume. Got an It audit job, did that 9 months, got another job making 12k more doing third party risk assessments, did that 4 months, switched took a 10K pay cut as a junior pen. Been doing that for a year now I’m going to be getting hopefully 25K raise here soon

#

Also I worked at Pizza Hut up until a year ago so I could meet ends meat.

#

All while I had a divorce/custody battle that emptied my 401K

upbeat oak
#

working on the footprinting lab hard and I've gained ssh access but am unsure of what I'm looking for now in reference to HTB or if I did something wrong with my ssh?

#

nevermind

fringe urchin
upbeat oak
fringe urchin
upbeat oak
fringe urchin
upbeat oak
#

Tracking tracking, I'm getting a can't connect to server error now wondering if its just the target machine needs to be refreshed however I can still ping it

fringe urchin
upbeat oak
#

restarted the target machine and can't connect to the server still?

#

if I just try mysql -u usernmae -p then enter the password I get access denied

fringe urchin
upbeat oak
fringe urchin
#

In hard lab, im pretty sure

upbeat oak
#

Now to easy modules and back to medium

fringe urchin
#

You havent done those two?

upbeat oak
fringe urchin
#

I though you going back to easy footprint lab and then medium

upbeat oak
vital zephyr
#

Hello everyone, I hope you are well.
I'm in the 'Web Server Pivoting with Rpivot' module
following all the steps expressed in the form, that is:

from my attack host: python2.7 server.py --proxy-port 9050 --server-port 9999 --server-ip 0.0.0.0

then from the ubuntu server: python2.7 client.py --server-ip -here I entered my ip- --server-port 9999

finally I give the command: proxychains firefox-esr 172.16.5.135:80

but the apache page comes up, could you give me some suggestions?

#

In what sense?

cursive oriole
#

Attacking Common Services - DNS:

I don't know what I am doing wrong i added it to /etc/hosts.

cat /etc/hosts
<SNIP>
10.129.235.249 inlanefreight.com ns1.inlanefreight.com


Tried domain transfer for all domains found:


dig axfr @inlanefreight.com cu<SNIP>.inlanefreight.com

; <<>> DiG 9.18.16-1~deb12u1~bpo11+1-Debian <<>> axfr @inlanefreight.com cu<SNIP>.inlanefreight.com
; (1 server found)
;; global options: +cmd
; Transfer failed.

Tried it on all found sub-domains but no results

fringe urchin
#

Ofc some subdomains arent for zones!

cursive oriole
#

Tried all SUB domains but transfer failed yaar! sadCat

┌─[eu-academy-2]─[10.10.14.75]─[htb-ac-189143@htb-je3dfbeyrg]─[~/subbrute]
└──╼ [★]$ dig axfr <SUB>.inlanefreight.com @10.129.235.249

; <<>> DiG 9.18.16-1~deb12u1~bpo11+1-Debian <<>> axfr <SUB>.inlanefreight.com @10.129.235.249
;; global options: +cmd
; Transfer failed.

fathom pendant
#

i can tell you by your snipped output

#

let subbrute work for a few minutes

cursive oriole
#

I already did its been 10 mins and its still running also ran fierce and these are the ones i found
||
inlanefreight.com
w<SNIP>.inlanefreight.com
b<SNIP>.inlanefreight.com
m<SNIP>.inlanefreight.com
s<SNIP>.inlanefreight.com
n<SNIP>.inlanefreight.com
c<SNIP>.inlanefreight.com
ns3.inlanefreight.com
ns2.inlanefreight.com
||

fathom pendant
#

none of those look correct let me double check

cursive oriole
#

Okay!

fathom pendant
#

you should be using the provided list that comes with subbrute

cursive oriole
#

Oh okay

fathom pendant
#

i believe unless i'm thinking a different tool

#

but it comes with a resolvers file yeah?

#

if not then the issue is that you didn't find all the right subdomains in your initial enumeration

#

nope it's the one i'm thinking

cursive oriole
#

I think im using the name.txt that comes with it only changed resolver

||./subbrute.py inlanefreight.com -s names.txt -r resolvers.txt
Warning: Fewer than 16 resolvers per process, consider adding more nameservers to resolvers.txt.
Warning: No nameservers found, trying fallback list.
inlanefreight.com
w<SNIP>.inlanefreight.com
b<SNIP>.inlanefreight.com
m<SNIP>.inlanefreight.com
s<SNIP>.inlanefreight.com
n<SNIP>.inlanefreight.com
c<SNIP>.inlanefreight.com
ns2.inlanefreight.com
ns3.inlanefreight.com

||

fathom pendant
#

you're attacking the wrong thing

#

you're meant to attack inlanefreight.htb

#

👍 Inlanefreight.com is a functioning (fake) website used by HTB for several modules

#

took me a second of looking back over your output to realize this

#

question: "Find all available DNS records for the "inlanefreight.htb" domain on the target name server and submit the flag found as a DNS record as the answer."

cursive oriole
#

Oh Okay sorry ! 🥹

fathom pendant
#

always read the question

opal estuary
#

I noticed the debate about oscp earlier on, can someone explain what the deal is with oscp or what it is

fathom pendant
#

it's an industry standard pentesting cert

#

you can easily google and find details regarding it

#

It's OffSec's PEN-200 course and is notorious for being heavily restricted in tools and fairly difficult (due to a mostly lack of prep from the purchased course)

covert schooner
#

Hello does htb academy silver sub (monthly) give access to tier 3 modules?

misty saddle
#

But you can earn cubes from the tier 2 modules and then use them to unlock tier 3

#

a bit of a lenghty progress but it's possible

fathom pendant
#

he said monthly

misty saddle
#

Oh my bad

fathom pendant
#

and his question was answered in #general

covert schooner
#

thanks

zenith mango
hexed oyster
#

I'm seeing something kind of strange and I wanted to get some feed back to see if I'm just missing something. I just finished up with the 'Introduction to Web Applications' module. All of the sections within the Module have a green ✅ next to them, however the 'Progress Bar isn't filled suggesting I'm missing something. Is that correct?

#

what I'm seeing on my end.

fathom pendant
hexed oyster
hexed oyster
fathom pendant
#

Repeat for all sections to be sure

next bronze
#

you definitely missed something

#

send a screenshot of the section list in the module

wild girder
#

Hey guys can anyone point me in the direction of where I might find out how to make /etc/hosts editable to add vhosts

hexed oyster
wild girder
#

Currently doing Information Gathering - Web edition on Active Infrastructure Identification

next bronze
#

edit using a text editor with sudo

wild girder
#

I have tried sudo nano /etc/hosts and i still get the unwrittable error when trying to use ctrl + X then Y to save

rustic sage
#

Job recruiters will do everything, but give you the expected salary expectation range

wild girder
#

you were right lol thank you

#

I misspelt sudo in my attempt lol

mystic loom
#

Actually is there any way to proceed without using that tool

novel hinge
#

so im on footprinting lab hard, trying to get community string. but snmpwalk and onesixtyone arent yielding any results. is there another tool to try?

analog dock
#

I used seclists/discovery/snmp/snmp.txt

novel hinge
#

so i couldnt get onesixtyone to work, but i got snmp brute to work!

#

i think when i was using onesixtyone i wasnt using right wordlists but i yielded now, probably going to get stuck again soon but happy i got that one

novel hinge
analog dock
#

There’s more ports open

novel hinge
#

okay let me try some things thank you!

rare robin
#

is there a way to see when my sub is ending??

mystic loom
#

For those struggling, it works on the pwnbox system htb provides

analog dock
#

Not sure about that module though, haven’t done it

mystic loom
#

Sounds like a good suggestion. Thank you!

analog dock
cloud urchin
#

Can anyone provide a push in the right direction? CrackMapExec skill assessment - Read the flag from the shared folder Ccache, I've obtained system access on DEV01 but cannot find any user who has access to this share. I also grabbed the ||master keepass password|| but I don't see anywhere to use it as it doesn't work to open the vault nor is it re-used on any account that I have.

novel hinge
# analog dock Yes

hey, was able to ssh. could you push me in the right direction on what i should be looking for? should i be trying to priv escalate?

analog dock
novel hinge
#

ohhhhhh

upbeat wind
#

Hey guys I’m new here.
Currently stuck on the “Redeemer” very easy starting point CTF.

I’m trying to find the open ports - Sudo nmap -p -sV ‘IP’

#

And it’s just… going…

#

I peeked at the solution and that’s what it says to do too. Using a pwnbox… tried using the performance options

next bronze
novel hinge
#

i also got the flag btw, thank you for help. just curious on how that works

analog dock
upbeat wind
#

Don’t thanks

novel hinge
#

Cool! thank you again for your help 😄

inland mesa
#

On LLMNR/NBT-NS Poisoning - from Windows did anyone have trouble loading up the rdp? It just comes up with a black screen for me for a few mins. Not sure if i should keep waiting or if it is not working for me

cloud urchin
# next bronze check the output of the || keepass module || carefully

I'll look again. When I did ||the keepass module in the training section, it showed several different passwords. I assume because the user mistyped the first password because it was very close to the 2nd password, which worked. However, in the skill assessment I only see the 1 password.|| should there be more than 1 or do I just need to look at the whole file ||without looking specifically for the protectinmemory line||?

next bronze
#

you'll see whatever is in the db

cloud urchin
#

i got it, thanks Xre0us you're a legend.

strange forge
#

Can someone help in attacking smb module? I tried null session it doesn’t allow me to download the file. Enumerated and got 2 username (without password). Its a local machine . Now have no idea what to do. According to some hints, there is password file somewhere in resource and iam unable to find it

#

Got it.

fathom pendant
#

👍

strange forge
#

Htb put the file in resources section 😭

fathom pendant
#

Yeah

#

That's generally how these modules work

#

Always check if there's a resources tab

cloud urchin
#

wow

#

lol

#

something new every day in here

fathom pendant
#

<@&861185840277487616>

rose temple
#

I need help with Using CrackMapExec Skill Assessment, I'm stuck at the third question, the one about DEV01. Send private message if you could give me a hand real quick. 🙂

fathom pendant
#

Don't be a dick

#

No, I'll get a disease

viral glacier
#

hello, can i get help with SSH login on the Linux Fundamentals module. I'm not sure what commands to use to find the target maching hardware name

fathom pendant
#

Again with personal attacks kid

viral glacier
fathom pendant
#

The command being uname

next bronze
#

cringe kid's back holy

haughty stirrup
viral glacier
#

I'm not following the order of the commands and where I should be... i only receive my name.. thanks tho

viral glacier
#

thanks tho

fathom pendant
#

It will give you details on what the command does

#

I'm purposely not giving you the flag so that you can do the final bits of the legwork and get the answer yourself

viral glacier
#

we're done

fathom pendant
#

This field is all about taking base info and learning all you need from it

viral glacier
#

wow... ididn't know that

#

thanks tho

fathom pendant
#

man <command> and <command> --help go very far in understanding tools

#

After that it's just applying what you're reading to the question being presented