#modules

1 messages · Page 224 of 1

tulip dragon
#

is NETEXEC tool part of cpts?

brazen saffron
#

Just to scan with ffuf the possible extensions in the website, there is something fastly than write -e .php,.phps,.html,.apsx etc?

tulip dragon
#

never saw that tool yet

gray merlin
cedar yew
#

hello guys ,i need help

Module - Password Attack
Section - Linux Local Passwrd Attack/ Credential Hunting in Linux

i'm starting brute force for kia but process very long time this normal? 1 hours

#

I customized the file using the password list and special rule list in the resources section and I attack with the special file.

minor stag
#

Did you try it without mut'ing the file?

cedar yew
#

yes

minor stag
minor stag
# cedar yew yes

If it's the one I'm thinking of, mine sat for several hours until it found the password. I'm sure there's an easier way, I just went to work and came back and it had cracked it.

cloud urchin
#

it is pretty much the same exact tool

cedar yew
#

my pass file my_passwd.list I think I'm using the right file

#

If it takes a long time, I can wait, but I don't want to wait in vain. 🙂

fathom pendant
tulip dragon
#

hmm gif not working

minor stag
#

From what I can tell the commands are essentially identical as well, but I went through several hoops to install CME just to properly follow along with the modules

fathom pendant
next bronze
#

there's no reason to use cme over nxc anymore

cloud urchin
#

didn't you say in the cme module 1 or 2 things didn't work with ncx and you had to revert to cme?

tulip dragon
#

what happen over last 2 month while i was gone, htb revoke my gif access? 😔

ocean night
tulip dragon
#

OoOOh

next bronze
gray merlin
#

Did you ever get an answer for your question?

marsh echo
fathom pendant
marsh echo
#

it's too weird i logged in with the user earlier it didn't work now it does...

rustic sage
#

hey, i really wanna get started with htb module, how should i begin?

fathom pendant
#

I'd argue introduction to academy would be better

cloud urchin
#

ah ok

#

oh yeah i was forced to do that one i think

rustic sage
marsh echo
#

not forgetting the fundamental modules intro linux intro AD ...

marsh echo
rustic sage
#

are there any options under 100$ or free?

fathom pendant
#

That's just for the voucher

#

The course price is different

#

If you're a uni student, you can use your student email to get a hefty discount of $8/month

tiny reef
#

The live engagament in shells & payloads is insaneeeeely slow and people have been complaining about this for months as it seems

#

When can we expect that it will be fixed?

fathom pendant
#

It's just on/off with latency issues

#

There's no permanent fix they can issue, just gotta suffer through it

tiny reef
#

Every single click takes 3 seconds it´s just paaaain

#

but thx for the fast response

cloud urchin
cloud urchin
rancid prairie
#

what is your question exacly

opal storm
rancid prairie
opal storm
#

specifically the event ids and dlls

rancid prairie
#

in the section about unmanaged code , they talk only about 1 event id that's the one you have to look at , and use the find button to look for a process loading a dll that it usually doesn't need

opal storm
#

idk what im missing here lol

rancid prairie
opal storm
#

well i just found it and the event id listed with the answer from what im looking at isnt referenced on that page

rancid prairie
#

"Additionally, by referring to both the related "Modules" tab of Process Hacker and Sysmon Event ID 7, we can examine the DLL load information to validate the presence of the aforementioned DLLs." from the same section

rancid prairie
opal storm
#

im interested to see how event id 7 would have gotten the answer but a different event id came up based on my filter

novel hinge
#

so i see that its running an old version of sudo. i found CVE-2021-3156 as a vulnerability. can someonee help walk me through what to do? i couldnt find this on GTFO-bins which im familar with

fathom pendant
#

gonna need to do some digging and figure out how to manipulate the cve to what you need

#

or just plug and play it

novel hinge
#

so my question is, i see these. and one that says shellcode. do i need to figure out how to use these while im shelled in? or is this something i need to do on my host vm

#

ahhh nvm i need to transfer it using scp

fathom pendant
#

meterpreter/msfconsole has an upload/download command iirc

novel hinge
#

ahhhhh

fathom pendant
#

as scp requires credentials to use

#

so if you don't have credentials for the user; or aren't running ssh on your machine:: SOL

novel hinge
#

figured out the upload for meterpreter, but even after running the eexploit.c and shellcode.c it doesnt work/grant me root. maybe im using the wrong vuln

#

so found it on msfconsole, but its saying session is wrong. it is my 3rd terminal that is open. thats what its asking right?

void kayak
gray merlin
fathom pendant
#

Sessions -l to list them

novel hinge
#

ahhh i got it

#

thank you! i should keep track of how many times you help me. i appreaciate your help ;c

hexed bluff
#

easy

coarse schooner
#

Is it just me, or is the RDP socks proxy module for CPTS super slow and flakey? I've gotten all the infra setup and when I go to launch the final rdp session through the socks proxy it refuses to load. I've tried setting the experience to 56Kbps per the module suggestion, but it still fails

rustic sage
#

Is anyone having issues with the labs not rdping?

#

Third times a charm I guess

runic depot
#

rdp was janky for me as well

bright shale
#

Hi everyone... I am struggling to answer a question in the Linux Fundamentals course and I have been fighting it for over a week. That is what I get for trying to learn something new with a concussion I guess. 😛 If anyone would like to lend a hand to this old man I would really appreciate it.

ocean night
# bright shale Hi everyone... I am struggling to answer a question in the Linux Fundamentals co...

If nobody comes to you, then as this is a Tier 0 module, what I'd recommend is looking for videos / writeups to help you to move past the point that you are stuck at. Ideally I'd say go back over the module content, take notes and try to get past it under your own steam, but if you need extra guidance then there is content out there (HTB allow writeups / walkthroughs to be published for Tier 0 modules)

#

..just, if you do go down that route, don't just watch, replicate and learn 🙂

#

Which specific question are you stuck on?

bright shale
#

It is in the Filter Contents section using curl.... I know I know, feel free to laugh at me. I am old and I can take it... HAHA

ocean night
#

So is that question 3?

bright shale
#

correct

ocean night
#

Ok.. DM me with what you're trying, the issue you're running in to or whatever, I've got a little more time before bed.. again.. 😅

bright shale
#

Ok will do think you

young spade
lyric raft
#

Hello, I am in module 231, I am stuck in the exercise of websocket analysis in burp, Apparently the application is vulnerable to xss, but I have not been able to read the flag, could someone please guide me a little bit.

robust fable
cloud urchin
robust fable
cloud urchin
#

I sent you a DM

marsh echo
#

Hello, I'm stuck on the user david I was able to find and crack the things to find on his directory share I have the password but I can not find the cred Admin to look what is in the B**** it's been an hour I brute force his account (I think it's useless but I try anyway)

lyric raft
#

is anyone in module 231? modern web exploitation techniques

cloud urchin
#

i am but i haven't completed it

acoustic owl
cloud urchin
#

i need a push on the skill assessment actually. i'm stuck on the 2nd question, not sure what to focus on. i'm assuming i'll need to gain the ability to change the name server so i can bypass the pdf filter, but i can't log into the webmin portal and haven't been able to do anything with the vault as i don't have any creds. i think the next step is to get into the webmin portal or get creds somehow, i messed around a bit more with the library but couldn't find anything more there beyond the 3rd username which didn't seem to do anything on the other sites.

sick mural
#

anybody who have completed Privlege escalation assessment Lab 1 ? Tried very hard for last 3 weeks no luck

brazen saffron
brazen saffron
half stag
#

hey guys, i need help with AD Enumeration & Attacks - Skills Assessment Part I
I have been stuck on it for days

#

could someone help?

analog dock
#

“And specify what you’re stuck on. No one even knows what you need help with”

soft cedar
#

and mount it there.

half stag
# analog dock What did I just tell you…

oh so on the active directory module assesment 1. I am stuck on the last question, i was able to get the clear text password for the user t****y. but i dont know what to acually do after it.

half stag
#

yeah

analog dock
#

So do that attack

half stag
#

thats the problem

#

i could not even connect to the user t****y, i tried psexec and enter pssession

analog dock
#

Why do you need that?

#

Just do the attack

half stag
#

how i f do the attack as a normal user it dosnt have the permission to do it

#

i even tried runas

analog dock
#

Go back to the dcsync section

soft cedar
#

^

analog dock
#

You literally answered question 7, saying that t**y can do that attack

#

So why would it not have permissions to do that..?

soft cedar
#

plus, you should utilize Bloodhound to find an attack pattern.

#

unless you guessed the answer

half stag
#

i did use bloodhound

analog dock
#

In that case you just lack understanding 🤷🏼‍♂️

half stag
analog dock
half stag
#

i am on it

analog dock
#

There’s a tool you can use

half stag
#

psexec?

analog dock
#

Bruh

#

Read the section

echo gulch
#

HELLO

#

What advice do you have for those new to the HACKER business?

compact patrolBOT
marsh echo
soft cedar
#

no, you can mount it in linux too

#

I used windows but there is a way with linux

echo gulch
#

A friend of mine sends people's credit cards through a discord channel and my friend buys items using this credit card.

marsh echo
#

thx 😉

soft cedar
echo gulch
#

How do I steal my friend's passwords?

soft cedar
#

you need admin privilege to mount the disk which is something you didn't have on the target cuz' you dont have the admin's password.

marsh echo
#

with David i can't connect me to rdp and winrm

soft cedar
#

thats why you send it over.

marsh echo
soft cedar
marsh echo
#

i understand

soft cedar
#

you can interact with that acc from the cli

#

using runas

half stag
# analog dock Bruh

i know i am stupid, but i am still stuck, itried mimikatz, secrets-dump, invoke-dsync

half stag
#

the secretsdump.exe

analog dock
#

No

#

……

marsh echo
#

yess thx a lot for you help, you light up my vision

soft cedar
#

its an internal network

half stag
#

cause i couldnt se the py one on windows

half stag
analog dock
#

Who says you need to do it from windows

soft cedar
half stag
#

so i could use chisel

analog dock
#

I prefer ligolo-ng

soft cedar
#

^

half stag
#

Thanks

echo gulch
analog dock
tulip bobcat
#

anyone done the wordpress skill assessment? i've solved all questions but this one which has no sense
. i got rce on the system 🙂 the only flag.txt files in the system are not working for this one

rustic sage
#

Soc > windows attack > print spoiler. It’s requiring I use impacket but I’m getting issues with NTLM relay.py any one can help?

#

NTLM relay config object has no attribute set add computer smb

#

I’ve been stuck for two days any thing could help with this install

#

Never mind, I figured it out if anyone is having trouble use the entire path along with Sudo

#

Sudo (full path of .py) then command

#

Fuck man

#

I tell you this Academy really likes to ambush you and booby trap. You with things that are not even mentioned.

echo forge
#

Any hint at the Skills Assessment blind sql injection? I was able to run sqlmap and identify databases, tables and columns, but I don't understand why sqlmap cannot dump the information from the columns

tulip bobcat
rustic sage
#

They leave so many things out like it’s cute. It’s not cute to sabotage people by skipping steps.

#

Normalize not ambushing students

next bronze
#

I've done the whole pentester path and I haven't found that to be the case as long as you read and understand the materials, if by ambush it means to apply some thinking outside of just copy and pasting commands, then I guess they do that

rustic sage
#

I’m using the SOC path

next bronze
#

same thing applies

cloud urchin
#

sometimes you just have to run as admin. in linux ports below 1024 require root.. so when you're dealing with listening ports you need to keep that in mind. nothing really to do with the module but instead basic linux

tulip bobcat
#

is the only one i could not answer in the skill assessment for wordpress module

cloud urchin
next bronze
#

^ it's excatly what the question asked

fringe urchin
tulip bobcat
cloud urchin
#

i don't know specifically what file, my first guess would be flag.txt

tulip bobcat
cloud urchin
#

if you have rce, you should be able to search for files too

#

looks to me like you found it

tulip bobcat
cloud urchin
#

it's right there in your screenshot??

tulip bobcat
#

really bad worded question with no context and can't be answered ..

next bronze
#

did the find the plugin?

tulip bobcat
#

yes, everything else is answered

cloud urchin
#

you should delete that image

tulip bobcat
#

all i need is to know what to look for... what file ? what should it contain ?

#

grep -r 'HTB' / did not find anything usefull either 🙂

fringe urchin
tulip bobcat
fringe urchin
next bronze
#

sounds like you didn't find the right plugin

tulip bobcat
#

and yes it's the correct plugin as the next question is what version number is that plugin which i answered correctly

next bronze
#

unauthenticated file download != LFI

fringe urchin
tulip bobcat
#

yes

fringe urchin
tulip bobcat
cloud urchin
#

"can you read" he tells me

tulip bobcat
cloud urchin
#

i re-read the question for you at the very start lol. read it next time.

tulip bobcat
#

he instead read and gave good feedback which helped a lot

next bronze
cloud urchin
next bronze
rustic sage
#

I’m having trouble with dementor not connecting to the relay can anyone help?

#

I have used Sudo

half stag
half stag
dull hamlet
#

can I dm someone for some SMTP questions?

cloud urchin
#

best to just post it here

dull hamlet
#

i tried, but the bot is removing my message as I'm spamming according to it

cloud urchin
#

go to #welcome and follow the steps so you can talk and stuff

marsh echo
#

alleluia 🤯

cloud urchin
marsh echo
#

It's a pleasure, thank you very much. Yes, I've had a lot of trouble.

normal latch
shut wraith
#

Hello can someone please help me use any dns enum command to find mail1.inlanefreight.com and a command for retreivign the TXT records from it? Thank you

frail sierra
#

can anyone help me with "Navigate to http://[Target IP]:5601, click on the side navigation toggle, and click on "Dashboard". Either create a new visualization or edit the "Failed logon attempts [Admin users only]" visualization, if it is available, so that it includes failed logon attempt data where the username field contains the keyword "admin" anywhere within it. What should you specify after user.name: in the KQL query?" please? Im struggling bad. I dont know what kind of answer is correct and i tried everything possible. Can anyone give me any hint?

cloud urchin
acoustic owl
#

dig ANY inlanefreight.con
dig TXT inlanefreight.con

normal latch
soft cedar
half stag
#

wdym

soft cedar
#

In order to run secretsdump from your attack box on that host, you’ll need to have access to the that network

#

Hence,pivot

half stag
#

i would try searching for it

#

btw thanks @soft cedar for helping

normal latch
dim wolf
#

you might just have really bad luck

dim wolf
gaunt rock
#

Hello, I have a question about port forwarding, in this command :

ssh -R 192.168.5.19:8080:0.0.0.0:8000 ubuntu@[IP] -vN

Who owns port 8080 ? 192.168.5.19 or ubuntu ?

shut quest
# frail sierra can anyone help me with "Navigate to http://[Target IP]:5601, click on the side...

Take a look at the right side of the query with the word admin

Then take a read at this to help your understanding

https://support.microsoft.com/en-us/office/examples-of-wildcard-characters-939e153f-bd30-47e4-a763-61897c87b3f4

What can we do to the left side of the word admin?

fathom pendant
gaunt rock
fathom pendant
#

well the 0.0.0.0:8080 is on the ubuntu machine
the 192.168.5.19:8080 is the destination

#

meaning whenever it receives a connection on 8080 it tries to push it to the x destination on 8080

gaunt rock
fathom pendant
#

it helps to read the man pages

normal latch
silver moss
#

Idk where to go for this question but ive been looking for the correct student identifier so I can utilize this discord and I LITERALLY cant find this 60 character identifier and I SCOWERED my settings page

next bronze
#

if you're trying to verify in discord, click the link in #welcome

silver moss
#

I tried that but it keeps saying my password is wrong, AND I even created a global account to link to my HTB Academy acct

next bronze
#

the identifer is not in academy

silver moss
#

.....im a dingus....I think I know my issue (my dumb ass is using mobile since im at the laundry mat and of course that wont work lol) sorry for the silly question

tulip dragon
#

bruh i thought only rookie and beginner do academy

tulip dragon
astral beacon
#

can somebody help me find where did "windows fundamental" module mention about lusrmgr.msc(local user and groups)?

fathom pendant
normal latch
tulip dragon
fathom pendant
#

besides the ranks don't mean shit

tulip dragon
fathom pendant
#

it just means they've pwned a bunch of boxes on the main site

cloud urchin
#

sounds like something an unranked person would say

tulip dragon
#

well i tried retired machine , so i respect person with rank

cloud urchin
#

jk lol

fathom pendant
#

¯_(ツ)_/¯

tulip dragon
#

i am wrong or does this channel become more of general for academy members , coz before only they talk was only about modules content

fathom pendant
#

it's only for discussion of module content and assistance with modules

cloud urchin
#

this is the modules channel of the academy section of the htb discord

fathom pendant
#

the #general chat is the gen chat of the server

tulip dragon
fathom pendant
#

eh

#

rank doesn't mean shit; and it's mostly just talking shit

tulip dragon
#

if u say so , i belive u

blissful elm
#

i was on sterak for 50 days , still can't figure out what was special prize

fathom pendant
#

so far it's just been badges

blissful elm
#

ok

#

10 cube on 30days streak would be cool af

next bronze
#

don't they measure it in weeks

blissful elm
#

yes

vale blade
#

Who can help with BLIND SQL INJECTION Skills Assessment, user agent, login, password finds nothing. If you remove the user agent, we see an error, but I can not confirm the injection?

acoustic owl
#

For 1, 4 and 12 weeks

next bronze
#

oh now there's 26, 52 and 107 weeks

#

damn

rustic sage
#

Hello

fathom pendant
#

<@&861185840277487616>

#

@bronze holly we don't do carding here

bronze holly
#

Ho ok can u suggest me someone

fathom pendant
#

No

#

Read the #rules of a server you join

#

Carding is illegal. Full stop.

bright shale
#

waiting on the ban hammer...

bronze holly
#

K sry

dull hamlet
#

I think I found an unintended solution for Footprinting - Hard Lab. Anyone willing to talk about that in DM?

cloud urchin
#

sure

acoustic owl
#

@bronze holly pleas read the #rules

half stag
burnt owl
#

Hey I am doing the skills assesment for AD enum & attack Part 1. I am brain lagging on how I am suppose to do question 2 Kerberoast an account. I tried to use Inveigh over the webshell and a meterpreter shell but I don't get any response back from PS. could someone help me out?

rotund bobcat
#

Hello, what modules do you recommend to start hacking, I have knowledge of networks and Linux.

next bronze
next bronze
burnt owl
next sundial
#

Hey anyone wanna team up/ share knowledge on machines

finite mist
#

can anyone help me on ad enum & attacks skills assessment part 2 on q7? I'm not sure if SQLEXPRESS is supposed to be the user I login as and if it is, I keep getting untrusted domain errors from mssqlclient, cme, and sqsh isn't working for me

next bronze
#

that's a service account? check what prives the user has

magic forum
#

INTRODUCTION TO DIGITAL FORENSICS : Rapid Triage Examination & Analysis Tools:
stuck on this question, I see the zone ID but not sure how to see the rename.

"During our examination of the USN Journal within Timeline Explorer, we observed "uninstall.exe". The attacker subsequently renamed this file. Use Zone.Identifier information to determine its new name and enter it as your answer."

finite mist
rustic sage
finite mist
#

nvm i was trolling

acoustic owl
#

Perhaps you could just say what exactly you need help with. What have you tried? What is not working as you expect it to?

mystic loom
# acoustic owl Perhaps you could just say what exactly you need help with. What have you tried?...

Yea sure of course. Tough to mention a lot without spoiling though. Well, basically I was able to get access to the admin's account which later revealed a new endpoint that is asking for a pin. I did notice that the value of the ||host|| header was reflected in the response. The ||Forwarded|| header can also be used. But yeah, the problem is, I was expecting this to be chained with a web cache vuln but it seems like that specific page is not being cached. I see the ||Cache-Control: no-cache|| header which indicates that. And yeah, stuck here 😄

runic depot
#

@mystic loomi need help on something

#

Connect to DC1 as 'htb-student:HTB_@cademy_stdnt!' and look at the logs in Event Viewer. What is the TargetSid of the bonni user? . with this question, I tried to login with bonni and the bad password in order to create a log, I can see the log with 4625. 4625 has no targetSid. The event sid 4771 does have those yet the failed auth doesn't show in 4771

#

been at it since yesterday. this is the credentials in object properties section in windows attack and defense

silver moss
#

ok im lost, I cant seem to figure out how to get the number of .log files in the Linux Fundamentals module. Im on the 'File Descriptors and Redirections' section. Any help would be appreciated

mystic loom
runic depot
#

also searched for bonni within the last hour and got no luck. did see 2 events tho

silver moss
#

I keep trying to check /sys/ for files with *.log but keep getting access denied on what seems like everything. Not sure what im doing wrong. Like am I checking the right place? I feel like the anser is in front of me and that if I rout the positive hits to a text file maybe that will find my answer? this ones been frustrating me

potent ermine
# runic depot also searched for bonni within the last hour and got no luck. did see 2 events t...

Is this the Credentials in Object Properties? If so, I used the wmic utility, here's a link to a helpful article https://www.lifewire.com/how-to-find-a-users-security-identifier-sid-in-windows-2625149

Lifewire

Read these easy instructions to learn how to match a username to that account's security identifier, using either the registry or the command line.

runic depot
#

Yes it is

#

shit im looking at the link thats smart

dire abyss
next bronze
#

use the userlist you have gathererd previously

dire abyss
next bronze
#

no, it's the specific domain userlist

dire abyss
next bronze
#

kerbrute does not query the domain like cme does, it just brute force it

#

if you want an accurate list of all the users, you'll need to use cme or other tools

dire abyss
#

gotcha

#

is there an output flag for CME? -h doesnt state one unless the obv is "-o"? ||sudo crackmapexec smb 172.16.5.5 -u htb-student -p Academy_student_AD! --users|| doesnt write a file.

next bronze
#

--log, I usually use it with --log $(pwd)/users.out

dire abyss
next bronze
#

the command? print working directory

dire abyss
#

ahh okay makes so much more sense. i wish my brain didnt default that to password.

next bronze
#

also, should use netexec now, it's cme but better

dire abyss
#

ill try it out now! thanks

silver moss
#

anyone free to help with a Linux Fundamentals module??

dire abyss
#

what exactly do you need help with?

#

copy the URL of the section youre onto here

silver moss
#

oooooooooooooooooh thats how I should prrrooobably lead questions lol sorry im very new and new to this whole "asking for help" thing as well 😅 trying to get better at that last part especially hahaahha

dire abyss
#

alright thats the index, what specific question are you struggling with?

urban kindle
#

Idk if this is the right place to ask but if I get the 8$/month student subscription, will that cover all of CBBH/CPTS's material?

next bronze
#

yes

urban kindle
#

oh thank god

#

thank you

next bronze
#

you'll need to purchase the exam voucher separately

urban kindle
#

yeah that I understand

silver moss
# dire abyss alright thats the index, what specific question are you struggling with?

so basicly I keep doing the find function, specify the location which I believe would be /sys/ (i think) since the question asks how many files in the system have the .log ending , then i do, -name *.log, and I get a bunch of access denieds. I know that the section talks about stdout and stdin, so im wondering if I have all that sorted into text doc's that ill find my answer there

#

its a very confusing section, ive read it like 4 times already lol

dire abyss
#

are you using pwnbox or a personal vm?

silver moss
#

sorry for my very base level question 😅

#

pwnbox

dire abyss
#

hmm maybe you gotta run "sudo find *.log" ?

#

or locate *.log ?

silver moss
#

oh yeah cause theres 2 ways to locate things, I forgot about that

next bronze
#

ssh into the target

silver moss
crystal steeple
hollow ibex
#

@crystal steeple what time its take you to complete this module

burnt owl
#

Could someone help me with ad enum & att part 1 can't I don't know how to elevate privs on ms01.

crystal steeple
burnt owl
#

No 4th

hollow ibex
#

@crystal steeple is you practise it on tryhackme or any other platform if yes put it here

soft cedar
burnt owl
#

The sql creds?

grand sundial
#

I am working on module Password Attack on winrm service. When brute force attack with command: crackmapexec winrm TARGET-IP -u username.list -p password.list. I assume if I run it again with the same target, I should get the same result every time. However, I did not get the same result - sometimes it works other times it does not. Please advise, if you know. Thank you very much.

soft cedar
burnt owl
#

I only found 2 hosts one has the admin flag.txt and one is the DC.

next bronze
#

have you tried it with ms01?

burnt owl
#

Yeah I am logged in on RDP

#

DC just rejects SQL creds, I am stuck on elevating my priviledges so that I can read the flag

next bronze
#

why do you need to login to DC? the question is for ms01

soft cedar
burnt owl
#

I don't have a need yet to login to DC

burnt owl
old vector
#

Has anyone don’t the password module in academy? I’m stuck on the last user smb flag. I have successfully logged into the smb share but have no privileges to list directory so I see no way to get the flag

#

Done not don’t

#

Anyone?

crystal steeple
#

and i dived into htb academy

burnt owl
soft cedar
burnt owl
#

It hit on MS01 but I already knew that.

next bronze
#

huh? your task is to get admin on ms01

soft cedar
#

^

#

so just log in with the same creds on MS01?

burnt owl
#

That account doesn't have admin

next bronze
#

send a screenshot of your cme output

#

says Pwn3d! there

soft cedar
#

svc_sql is an administrative acc.

burnt owl
#

Than I don't understand why I can't open the flag

ocean night
#

T2 module 🤦‍♂️

#

Don't share info like that for modules above T0 in public, thank you.

burnt owl
#

Sorry my bad

next bronze
burnt owl
#

I am kicked out now, I will try later after I cleared my mind a bit.
But you mean as in like right clicking and run as admin?

next bronze
#

or you know, use a number of cli tools instead of rdp

latent frigate
#

Can someone give a help with the Module crackcapexec - Skill Assessment

I've got the first flag, using the --rid-brute 5000. I found actually only two users.

is there anything that I am missing here?

next bronze
latent frigate
#

7000 | 10000?

south folio
#

Hey MakingItJazzy, I have the same problem, have you resolved? Have some solution?

bright shale
#

ugh.... I hate when I dont understand the answer...

next bronze
#

check what you can access with those

naive shell
#

Just solved Linux Privilege Escalation - Skills Assessment... bit sad I took the easy route. 😓 Anyone else had this "problem"? Why don't they remove this way. (Don't get me wrong, I researched afterwards, where I took the "wrong" route... but yeah.)

naive shell
#

?

burnt owl
#

@next bronze You where right I just straight up opened the file.

visual fable
#

Can you give some help? I have already broken down all the SPL queries provided in the module, I have analyzed all the fields but I still haven't found the service name
"Detecting Golden Tickets/Silver Tickets"
For which "service" did the user named Barbi generate a silver ticket?

potent ermine
echo forge
#

I got the same problem with the flag..did you figured it out?

glad citrus
#

Password mutations… been working it for 2 hours… see I can hydra against FTP… set my password list with the instructions and I’m coming up dry

cedar yew
#

Can anyone find the ssh

echo forge
# quick magnet Yes

I solved it...if anyone need a hint at this exercise at the future, just DM me...

plucky void
#

a

reef rampart
#

Maybe stupid question but how are predictions on how many days a path can take calculated? Is it like 20 days 8/h work day?

fathom pendant
novel hinge
rancid prairie
fathom pendant
#

looks like one of the modules from the SOC analyst path

buoyant void
#

Man currently doing Exploiting Web Vulnerabilities in Thick-Client Applications and boy is this an information overload when you have no prior knowledge about decompiling JAR files and related tasks

bright shale
#

I feel you @buoyant void. I only recently started playing with Linux. I am still on the linux fundimentals course and it kicking my old ass. I spent 6-8 hours yesterday answering 1 question. I was able to find it but my method went from sorting to little to just a little to much. I am still unsure why my method was sorting more than intended

#

I guess I need to "get gud" or something... LOL

little bear
#

I'm another soldier into the pile of Reverse Engineering in Attacking Common Applications. Pro: Learning Reverse Engineering Vulnerability Research and Exploitation of Thick Clients among accepting the fact I am learning how to interpret java+syntax (and run analysis of exe/bat files in memory). Sickkk. Con: What. da fuk. ;-;

Anywho, I got jumped by a pair of .jars. Should I be worried if I'm still sane? Lmao

Anywho, Just figuring out how to leverage the injection among the information. I think I got it if I'm not lazy and actually muster up the intelligence to read the source code and not cut corners, but even better was learning I could simplify the compiling process of the modified file and save time, but you need to first understand what you're doing and what you are using. I'm basically stuck on the final mile. If the VM didn't suck, I would have an extra 3 hours to my life. Also, beware of architecture. Cryptic, but If you know you know.

I'm at the point in my CPTS and CBBH I've taken on teaching a friend. This is tremendously useful. There is a forum and helpful comments around (for the module mentioned). Once you've read those, reread the section and take your time. I'm on day three. It's good. Get Gud.

TL;DR: Reading this is optional. However, I'm ~82% through CPTS. A huge helper module should be The Learning Process. If you haven't done this one, you should. Good Luck.

fathom pendant
#

Congrats or I'm sorry - i'm not gonna read that

little bear
#

Lmao that's kind of the point~ Thanks Marcie 🙂

short hare
#

Stuck on Session Security - Skills Assessment

I found the cookie through the redirection and when i tried to paste the admin cookie in the http://minilab.htb.net/app/ i got no auth error [image 2]

Can anyone point how to go through this?

buoyant void
#

Exploiting Web Vulnerabilities in Thick-Client Applications is driving me nuts, trying to do all the compiling and going through source code is a nightmare with the RDP latency smh

little bear
#

I'm also on this exact section.

buoyant void
#

Yeah just saw your comment, you finding the latency holding you back at all? Personally I just need to understand the syntax better so I don't make any simple mistakes that derail everything I think

#

Maybe this is a stupid question but when you're editing something like Invoker.java what should I be editing it with? I was opening it up in notepad but something is telling me that's probably not ideal

little bear
buoyant void
fathom pendant
#

the general suggestion for the thick client application section has been to read the writeup for the retired Insane machine Fatty

#

that section has a long history of not being liked for a multitude of reasons

little bear
buoyant void
#

I think 0xdf has a writeup on that machine I'll go check it out now

fathom pendant
#

probably

#

0xdf, ippsec likely has one, plenty out there

#

but this section is basically ripped from that machine

little bear
buoyant void
#

Oh cool Ippsec has a video on it gonna make a coffee and watch it hopefully come back to the section with some fresh eyes

little bear
#

Knowing Fatty was a retired insane machine is pretty neat, though... insane lol

pastel lava
#

How can i access more of the server? Just says done reading and directs me here, cant type in general or anything

buoyant void
#

the section seems oddly out of place in the module, although I understand why its there it could've benefited from some introductory information about Java compilation at least I would've found it helpful lol

little bear
fathom pendant
fathom pendant
#

don't just click "done reading" - actually read and follow instructions

buoyant void
little bear
little bear
fathom pendant
#

focusing on all sorts of aspects

little bear
#

True^

#

I've just streamlined Acad for the time being. I'm overdue for a live ctf

#

box, similar things imo

little bear
fathom pendant
#

or did you participate in that

little bear
#

I did miss it ;-;

fathom pendant
#

the next one will be HackTheBoo (their halloween event)

little bear
#

Sweet, will want to participate in that one for sure.

#

Thank you, Marcie. Good to hear from you. I'm off for now though. l873s

fathom pendant
#

gl, hh

radiant oriole
#

Guys, sorry to just drop in like this. But I'm having issues with my Kali setup. When i run the firefox proxy though 8080 for zap, I'm getting errors at every page. - Your browser sent a request that this server could not understand.
or -The proxy server is refusing connections
An error occurred during a connection to www.google.com.

This one is new for me. It was working, until the other day. I have changed the cookies, any ideas what can cause this?

#

Or where is the best place to post for help? This is my first time on this Disc server!

fathom pendant
#

if not: read and follow #welcome and maybe in #web would be the best place

radiant oriole
#

Yes, sorry i should have stated this. Im on an introductory module, learning about Fuzzing using ZAP

#

Im wondering if i have done something, that has triggered this. The setup was workign fine before, and i can still fuzz the site using ffuf

crystal steeple
#

<@&861185840277487616> i think

fathom pendant
#

<@&861185840277487616> a bullshitter

fathom pendant
#

good thing discord tells you when you're clicking non-discord links

crystal steeple
#

I wanted the 50$ FeelsBadMan

radiant oriole
#

блять -

fathom pendant
#

it's a u.to link which is either: phishing OR credential harvesting

radiant oriole
#

On a srs note guys, and idead where ive fucked up here?

#

Im using pwnbox so i don't have to stop, but want to get back to my own Kali setup

#

Suggested course of action? Reinstall Zap and redo the proxy settings or?

fathom pendant
#

you can use whatever distro you're comfortable with

#

both Kali and Parrot are Debian based so most tools should be universal between the two

radiant oriole
#

Ah, sorry. This is about my issues with ZAP. I am learning to use it for Fuzzing, i have set up the proxy in the learning module. But for some reason, today, i cannot use Firefox at all when the proxy is on now.

#

it was working before... I've cleared the cache of cookies, but no luck

fathom pendant
#

ye just a bit of an info stuff

#

i haven't messed with zap/burp and setting proxies

radiant oriole
#

oops, my bad. I meant to say I'm using pwnbox 😅

#

sorry, bad context from me there!

fathom pendant
#

that's irrelevent tbh

#

also: if it's been a day/you've terminated and restarted the pwnbox you'll have to redo the settings

radiant oriole
#

Yeah. Key point is that my virtual machine has issues. Ok, if no other suggestions I'll reinstall all related applications, and then redo the security certs ect on the proxy

fathom pendant
#

so you need to re-set it up between sessions

fathom pendant
#

well you're giving mixed signals here

#

are you using the in-browser pwnbox or not

#

if you're not: then don't be running it

#

if the in-browser pwnbox is running and you're doing a module that requires the vpn: it will mess things up

radiant oriole
#

Im using pwnbox, presenty, because my setup has stopped running. I am wondering if anyone has an ideas.

fathom pendant
#

(networking reasons)

fathom pendant
#

you don't need to constantly bump your message

#

just be patient

#

someone that has more experience may come along and offer their help

radiant oriole
#

ok. My apologies. Ill wait for someone. Cheers 🙂

neat kelp
#

if i complete a path on htb academy while being on monthly sub can i access the course again after my sub ends ?

fathom pendant
#

any module 100% completed is yours forever under the annual subs and student sub

neat kelp
#

oh yes student

#

damn respect

short hare
torpid ermine
#

can someone please give me an hint on this corporate osint module cloud storage section

next bronze
torpid ermine
cedar yew
#

yes i use the mut-passwordlist.list

#

custom.role

novel socket
#

Hlo

narrow geyser
#

I finished this module with few searches from this discord channel. @fathom pendant I'm having difficulty finding definition of zone I thought it's the SOA record. why is the (number of) loopback = zone(s)? any reference? I haven't found anything on google (likely i'm searching wrong term here)

fathom pendant
narrow geyser
fathom pendant
#

The loopback is part of the SOA record

#

The loop back is on the same host relative to the query

#

I.e. when you see the loop back, it's on the same server you asked the information from

steady dust
#

On Windows Privilege Escalation - User Account Control do you have any idea why the shell is not comming?

rustic sage
#

Hello guys i have a question for the members that just finish this learn path the job rule path penatration tester

#

must i have some basic requirements or can i start with that ????????

#

Hi! Can someone help me with the Advanced XSS and CSRF Exploitation/ CORS Misconfiguration module? 🙂

knotty crag
#

Hello guys i actually had a problem, i am new to hack thebox so i dont know much but i am not able to use a virtual machine with hack the box using the openvpn which they provide

#

any suggestions and help pls

uneven lintel
knotty crag
#

yes sure see so i downloaded the vpns which hackthebox provides i connected to them using sudo openvpn /path/to/vpn_name.ovpn and then i succesfully connected to it but whenever i spawn a machine and try to ping it i am not able to ping it cuz i am in a different network then the target machine so how to fix this like what to do

#

like for example if i spwaned a starting point machine i wont be able to pwn it through a local vm

uneven lintel
#

try this

#

you must be mispelling it

knotty crag
#

yeah i did this the issue is that the target machine and the local machine are on different networks

#

becuz they have differenet ips

uneven lintel
#

they dont have to have same ip

#

mb they WONT have same ip

uneven lintel
knotty crag
#

oh so why am i not able to ping the machine then

uneven lintel
#

send terminal ss

knotty crag
#

yeah fine

#

of like what situation

uneven lintel
#

if u copying htb's ip and using ping idk why it aint working

#

just send ss for the ping <IP> awnser

knotty crag
#

yeah fine

next bronze
#

make sure you're connected to the vpn, don't kill the connection (ctrl c) after you run the command

knotty crag
#

yeah i am not doing that that was previously told and instructed in the walkthrough

#

btw how to s4end ss

#

i am not able to send

uneven lintel
#

bottom left + icon

knotty crag
#

yeah it is showing use apps

next bronze
#

you need to get verified, read and follow#welcome

knotty crag
#

it should show documents pictures and all those things right

knotty crag
#

yeah just a sec

#

yeah done

#

this is what it shows

#

the ip in the highlighted in yello is the target id

#

ip

uneven lintel
#

and keep with the exercise if u can reach it

knotty crag
#

i didnt get u what do u want me to do

uneven lintel
#

copy paste the ip in ur browser

#

if it gets you to a web page the IP is up

knotty crag
#

yeah

uneven lintel
#

there are no chances ip is down tho

#

as long as u know to start it

knotty crag
#

yeah i did that

#

but its not showing anything it shows an error but the target machine is up

uneven lintel
#

terminate connection reset vm and spawn another one

knotty crag
autumn pilot
rustic sage
#

`# Module name: PIVOTING, TUNNELING, AND PORT FORWARDING

Section name: RDP and SOCKS Tunneling with SocksOverRDP

Type of correction needed: Error fix

Description: whenever I run the command in the screenshot, it gives me this errors, I have run it in cmd and powershell, with normal user and as an admin, the binaries are 32 bit binaries but I have tried it with 64 bit as well`

knotty crag
#

yeah sure but it happens with every machine

next bronze
knotty crag
#

yeah

#

it is

#

in the walkthrough itself it told me to configure some setting and only tun0 should be visible

#

so i think thats fine

next bronze
#

are there other tunnel interfaces? also reboot your vm and download a new vpn file

#

contact support if it doesn't work

knotty crag
#

na

#

no other vpn interfaces one interface is there it my wifi

next bronze
rustic sage
#

I dont see how it would affect it tbh

rustic sage
#

windows refuses to open

#

might restart the machine this is annoying

knotty crag
next bronze
#

you just need to connect to the vpn

remote latch
#

hows wolfie

next bronze
#

what

wise vault
#

@dry halo hi

wise vault
primal vessel
#

Hy can anyone help me

#

I really want to start In cybersecurity but I don’t know how

#

If anyone knows something it’ll be appreciated

wise vault
#

from AD enum and attack module

rustic sage
primal vessel
rustic sage
#

and then you will see modules, I advise you start with Linux fundamentals

primal vessel
#

Can I talk to u in private?

primal vessel
rustic sage
cedar yew
#

Actually, that's what I did, but I can't find it.

rustic sage
#

Hey guys, I've a question regarding the Introduction to Splunk & SPL, I am really struggling with the last question (it's about finding the account with the most login attempts within a span of 10 minutes), I have tried to use timechart , bucket _time span=10m and nothing works, I have seen the hint but i found no resources about the range() function and how to use it.

shut quest
rustic sage
cedar yew
#

i use this command - > hashcat --force password.list -r custom.rule --stdout | sort -u > mut_password.list

uneven lintel
#

What is going on if ms6 does not create session but does for other people doing the module?

fathom pendant
fathom pendant
uneven lintel
#

i tried everything already

fathom pendant
#

Your lhost looks wrong

faint gulch
#

I am stuck on the assessment of the Using CME module, in the 3rd question (trying capturing DEV01's flag). I got ||james|| credentials via ||ntlm relay|| but does not appear to unlock any futher access. Any nudge would be highly appreciated!

uneven lintel
fathom pendant
#

I've not seen an academy ip that was 10.0.x.x

uneven lintel
fathom pendant
#

Your screenshot shows your lhost variable as the eth0 interface, not the tun0 one

faint gulch
#

@rustic sage I have sent you a DM

uneven lintel
#

it had never happened to me

fathom pendant
#

Maybe you accidentally hit ctrl-c?

uneven lintel
#

idk this was strange

#

ty tho

fathom pendant
#

Well generally, unless there's major connection issues, the vpn doesn't just shut itself off

uneven lintel
#

idk it was not ctrl c as it was still on load

fathom pendant
#

¯_(ツ)_/¯

tranquil copper
heavy edge
#

DM me for hard lab tips if need be

shut quest
versed oriole
#

Hi all,

I'm trying to complete RDP and SOCKS Tunneling with SocksOverRDP of the Pivoting, Tunneling, and Port Forwarding module but I don't seem to get it working and I'm starting to wonder if the machine might be broken.
What I have tried so far:

  • Follow the SocksOverRDP approach
  • Port forwarding like a few sections before
  • Using RDP from within the RPD host. (So rdp into the 'target' and inside rdp to 172.16.6.155 using the UI program)
  • Resetting the target numorous time (including waiting +15 min)

Am I correct asuming that all these approaches should work or is this a special network setup that will only work using the SocksOverRDP approach? aka, do I search for a mistake in my SocksOverRDP experiment or should I indeed asume a broken enviroment.

#

And offcourse after asking the question everything works...
I have no idea what went wrong but it works now. Sorry for the noise 🙂

finite mist
#

In ad enum & attacks skills assessment part 2, I'm not sure why but every type of import or install of PowerView/ActiveDirectory or RSAT-AD-PowerShell doesn't work? commands like Set-DomainUserPassword or Get-DomainUser are not being recognized as cmdlets, etc. after. Not too sure why this occurs as the PowerView I import from C:\Tools in the other sections of the module lets the cmdlets work fine.

cloud urchin
finite mist
#

yeah i tried that with powershell -nop -exec bypass but commands like Set-DomainUserPassword still don't exist for some reason

#

maybe i'll just try to use mimikatz setntlm

cloud urchin
#

what is the command you used to import the module

finite mist
#

I tried Import-Module .\PowerView.ps1 or .\PowerView.ps1 or Import-Module ActiveDirectory

cloud urchin
#

ok, it should be the first command. try that again and see if one of the cmdlets work, if not show a screenshot of the import command

#

and make sure powerview is in the same directory you're executing the import-module command with

fathom pendant
#

^

#

That or specify full path

shut wraith
#

ACTIVE DIRECTORY ENUMERATION & ATTACKS

LLMNR/NBT-NS Poisoning - from Windows

I cannot get this command to work:
(Get-Command Invoke-Inveigh).Parameters
I am trying to use Inveigh. I have already imported:
Import-Module .\Inveigh.ps1

Can anyone please help?

fathom pendant
#

Iirc inveigh.exe is 1000x better than the inveigh.ps1 script

soft cedar
#

yah, the powershell version is no longer maintained.

minor stag
#

Pretty sure I gave up on getting the .ps1 to work so I just used the .exe

fathom pendant
#

I mean the ps1 worked fine for me

#

And using both- the exe is far more functional and nicer

#

And it allows you to do far more while it's running

cloud urchin
glossy flame
#

Hello, on the Practical Digital Forensics Scenario section I am getting a error while trying to convert it to csv as they do in the example:

C:\Users\johndoe>python C:\Users\johndoe\Desktop\files\USN-Journal-Parser-master\usnparser\usn.py -f C:\Users\johndoe\Desktop\kapefiles\ntfs\%5C%5C.%5CC%3A\$Extend\$UsnJrnl%3A$J -o C:\Users\johndoe\Desktop\usn_output.csv -c

Traceback (most recent call last): File "C:\Users\johndoe\Desktop\files\USN-Journal-Parser-master\usnparser\usn.py", line 263, in <module> main() File "C:\Users\johndoe\Desktop\files\USN-Journal-Parser-master\usnparser\usn.py", line 180, in main journalSize = os.path.getsize(args.file) ^^^^^^^^^^^^^^^^^^^^^^^^^^ File "<frozen genericpath>", line 50, in getsize FileNotFoundError: [WinError 2] The system cannot find the file specified: 'C:\\Users\\johndoe\\Desktop\\kapefiles\\ntfs\\%5C%5C.%5CC%3A\\\\%3A'

Any ideas?

cloud urchin
glossy flame
#

yeah, but the file do exist

cloud urchin
#

apparently not

glossy flame
dim wolf
#

sorry not the filename the filepath

glossy flame
#

Thanks, I did tried with double quotes, single quotes actually works sadglas Can we have it with the quotes in the text of the module? 👀

hearty nymph
#

whats the difference between the system owns and user owns?

dim wolf
strange forge
#

in the Attacking common services module- Easy assessment. I found the user, when iam trying bruteforcing with mysql. iam getting hit with "Host '10.10.15.30' is blocked because of many connection errors; unblock with 'mysqladmin flush-hosts'
". tried resetting target too.

cedar yew
#

hm

#

i use the custom.rule file for passwd file

#

yes

#

other service but im read the a htb forms

#

he says use the custom.role and brute force kira ssh service

#

What I don't understand is that this is not in the module anyway, we know this technique, but why couldn't I find the password?

#

can i dm you pls

heavy edge
#

yeah they kinda hint at uppercase, i had to figure this out for a while. the wording tbh is very very bad

heavy edge
#

nmap the network and try the other services. remember that this is after the 'password reuse" section i believe

cedar yew
#

solved thx

#

There was a small part I missed but I figured it out.

stiff flax
#

Can anyone give me a hint in the first question introduction to Linux privilege escalation? I tried everything to find credentials for lab_adm but there is nothing

heavy edge
#

PTH module is fun

valid spear
#

Working through the ESC1 module and I can't figure out which step I'm missing here. Error output is pretty generic and I can't figure out from the -debug what's going wrong either. Tried different versions of WMIexec as well with no luck

next bronze
#

did you update your /etc/hosts?

valid spear
#

Yeah, I have LAB-DC.lab.local in /etc/hosts and I can ping lab-dc.lab.local as well so I believe it's properly configured on that front

next bronze
#

just LAB-DC.lab.local? you need to add the domain and hostname too

valid spear
#

I'm not sure I follow. Isn't LAB-DC the hostname and lab.local is the domain name?

next bronze
#

yes, add those in

valid spear
#

Huh, interesting. I've never run into having to format my /etc/hosts like that before

#

@next bronze Thanks for the assist!

next bronze
#

np, when you're dealing with kerberos, always add 3 things to /etc/hosts for dc's ip: hostname, domain name and fqdn

valid spear
#

Will do, thanks! I've never had to use more than just the FQDN so that's illuminating.

heavy edge
#

you always wanna add ip and hostname to hosts incase there is internal targets that only auth from the target IP

#

if you add the /etc/hosts, i believe it routes traffic through no?

fathom pendant
#

Kerberos checks a handful of things in its query back and forth for auth

runic depot
#

After performing the ESC1 attack, connect to PKI (172.16.18.15) as 'htb-student:HTB_@cademy_stdnt!' and look at the logs. On what date was the very first certificate requested and issued?

#

on that one ive got the runas and powershell up and then ran the Get-WINEvent -FilterHashtable @{Logname='Security'; ID='4886'} and 4887 and the earliest one should be 12/19/2022 but its not it. am i missing anything

#

someone asked this a while ago as well

rustic sage
fathom pendant
#

It's just hard to condense down tbh

#

Kerberos just asks for a few things and it's a pain of you don't have them all

next bronze
#

the kerberos module explains it pretty well

royal sigil
#

hello do you know how i can import external librarie in vscodium
its for the question in introduction to c# Libraries

fickle cargo
#

Hi, why when I paste a 100% correct flag it says it is incorrect?

heavy edge
#

the rdp boxes for academy suck ass

#

im even on tcp

fathom pendant
strange forge
#

in the Attacking common services module- Easy assessment. I found the user, when iam trying bruteforcing with mysql. iam getting hit with "Host '10.10.15.30' is blocked because of many connection errors; unblock with 'mysqladmin flush-hosts'
". tried resetting target too.

fathom pendant
#

Yeah that happens, try the command shown

#

mysqladmin flush-hosts

strange forge
fathom pendant
#

You don't need to be logged in to run that

#

It's not a server side command

#

Alternatively restart your vm and try again

heavy edge
#

annnnd tcp D/C on rdp again jfc

fathom pendant
#

Try changing vpn regions

#

If it's a consistent issue no matter which vpn you use: message support

heavy edge
#

do we know whwere the regions are?

#

because all it says is us 1 2 and 3

fathom pendant
#

Try EU

next bronze
#

you can measure the ping yourself

fathom pendant
#

I dont think they've publicly stated where the servers are hosted

#

But it can generally be understood as West/Central/East

#

For the US regions

#

But changing region doesn't just mean from within the same geographic area

#

I've had times where switching to EU worked when US was being dumb for me

#

And then vice versa

heavy edge
#

could this play a hand in the issue?

fathom pendant
#

No

heavy edge
#

100k ms for pwnbox hosts on the west?

#

i LIVE on the west coast

cloud urchin
#

have you considered upgrading from dialup

fathom pendant
#

Those timings are solely for pwnbox spawn locations and have 0 bearing on the vpn stability

heavy edge
cloud urchin
#

just teasing

fathom pendant
#

I've also seen, firsthand, where I've changed machines and the pwnbox delay is different

#

Like my own physical machines

heavy edge
#

wtf

fathom pendant
#

90% of the time when I'm doing sanity checks I'm doing it from pwnbox because I don't feel like spinning up my own vm

#

And the concept is the same anyway

#

So it could be some weird connection thing

sage relic
#

does anyone know curl ?

fathom pendant
#

But again, the best way to actually get an issue resolved/looked at is to message support

#

Support doesn't regularly check the discord

onyx vapor
fathom pendant
#

Have you tried doing the thing

#

But in all seriousness: it helps if you provide info on what you've tried and what errors you may be facing

onyx vapor
#

Yea

fathom pendant
#

Just saying "I need help" with no additional info doesn't help anyone help you

#

We can't read your mind

onyx vapor
#

I found the administrator's id, tried to change his password, but I can't log in with his name and new password

#

changing the administrator's password doesn't help, I can't log in with his password

fathom pendant
#

It looks like you need to re-encode the data into a token

#

¯_(ツ)_/¯

#

Also careful posting images as they may contain spoilers, if it's not something given to you by the question: then it's a spoiler

heavy edge
#

us1 is slow

#

us2 a bit better

fathom pendant
#

At least 2 isn't showing jitters

raven lagoon
#

Hello, im doing Server-Side Attacks

Replicate the steps shown in this section to connect to the above server's "hidden" Tomcat page through the AJP proxy, then write the Tomcat version as your answer. Remember that the port you will see next to "Target:" will be the AJP proxy port. Answer format: X.X.XX

Why do i receive that error? I should have configured the ajp module properly

#

i forgot to comment a }

candid night
#

Heya, I arrive with a bizzare question.
Could someone tell me, how is that possible that I can access the Administrator folder from ps, but can't from cmd shell? For both shells I used the same account.
Could it be that ps has some higher privilages? Or It might it be a bug, since I still coudln't view the contents of the folder even after accessing it

novel hinge
#

anyone run into this problem w/ hydra cracking SMB?

heavy edge
#

i wonder if msf could help ^

thorn urchin
thorn urchin
#

cmd just isnt letting you because it doesnt see the point

candid night
thorn urchin
#

it isnt

#

just a quirk of the developers

#

cmd knows you dont have any perms to the folder so it doesnt let you cd into it at all. PS basics goes hey maybe you have some weirdo permission on a sub folder and lets you.

#

CD just changes the process current working directory

#

the cwd is just a setting, it has literally nothing to do with permissions

#

you can have a cwd to folders that dont even exist. just typically shell applications dont let you do this cause itd confuse users and have little benefit

upbeat oak
#

If I can't find a specific plugin id on my nessus scan do I have to do it over again? I was able to answer every question except that one

astral inlet
#

finally 🙂

fathom pendant
cloud urchin
#

well except the thick client

astral inlet
#

the performance of rdp is below zero

upbeat oak
next bronze
#

so it's the same

fathom pendant
#

The module tells you all you need to know to find info

upbeat oak
cloud urchin
#

The whole module is a tutorial for it

latent frigate
#

Thks for the answer, but i am stuck i some activities despite having tried a lot of options.

fathom pendant
#

As its a tier 3 module, there won't be any official or even sanctioned writeups for it

cloud urchin
#

just ask here what you're struggling with

latent frigate
#

ok, I will think how i can ask it properly and then come back

fathom pendant
#

Guides and walk-throughs for modules above tier 0 are expressly disallowed by HTB

latent frigate
#

ok i didnt know. thks anyway

upbeat oak
#

didn't know that either

#

So are youtube videos on the module eventually taken down or is it like if they see your username they will ban you or something like that?

cloud urchin
#

yeah i think they dmca them etc

fathom pendant
#

They issue takedown notices and issue bans on accounts if necessary

upbeat oak
heavy edge
#

iwent complete stupid on pth lol

fathom pendant
#

I mean it's part of the website ToS and content creation guidelines

heavy edge
#

there are so many guides for htb

#

theres also a site that sells exam andmodule flags

candid night
#

Got it, thanks for the explanation @thorn urchin and @next bronze

fathom pendant
#

Also exam flags (afaik) are dynamic

magic forum
#

**INTRODUCTION TO DIGITAL FORENSICS : Skills Assessment **
what hunt options should i pick in Velociraptor to get back the data needed? Seems like all the ones that i think makes the most sense are not pulling back what's needed.

heavy edge
fathom pendant
#

Then report it

#

You can either dm a mod/admin directly or use /spoiler

heavy edge
#

which channel?

dim wolf
#

based on the information you want to find you're gonna have to choose certain options. the search option will help a lot

fathom pendant
heavy edge
#

nope

#

there we go

#

damn this site is yuge

little bear
#

Turned out that was WAY simpler after iterations of getting setup. Thank you for the support!

novel hinge
#

trying to find shares to connect to, maybe this isnt the right user:pass ?

fathom pendant
cloud urchin
#

try adding this: --smb-timeout 5

fathom pendant
#

It's also likely the user/pass is incorrect

cloud urchin
#

no, it's timing out

#

you can see the error right there

fathom pendant
#

Oh I can't read

novel hinge
#

setting timeout worked

#

thank you !

cloud urchin
#

yup i'd add that to pretty much every command with cme when dealing with htb windows smb

dire abyss
heavy edge
#

can i not rdp into this>?

fathom pendant
heavy edge
#

or do i need to set the reg key

dire abyss
#

how does 0x457 = 1111

fathom pendant
dire abyss
#

yeah im trying to understand that so i can find the user with a certain decimal value

heavy edge
#

wrong sys my b

fathom pendant
#

Convert the decimal number they give you to hex and search that RID

dire abyss
#

i found a converter online.. rapidtables. do pros really do this or just use an online converter?

cloud urchin
heavy edge
#

i knot but im using the given IP username and Password

cloud urchin
#

try wrapping the password in single quotes

#

the screen shot you showed has the error right there, it says login failed, so that's likely bad username/pass

heavy edge
fathom pendant
#

$$ is a variable call

#

Specifically calling the PID of your shell

heavy edge
#

sigh

fathom pendant
#

Single quotes will solve your issue as @cloud urchin said

heavy edge
#

yeah it did thanks. thats annoying

fathom pendant
#

Single quotes tells bash to interpret the text as literal

#

As a general tip, whenever you have a password that has special characters-- always use Single quotes

fathom pendant
#

Wait until you get to the "just hit enter" blackscreen that's been the bane of many kek

magic forum
dire abyss
#

just out of curiosity is there every going to a module or section that dives into bloodhound?

#

i keep seeing mentions of it but no questions built around it

cloud urchin
#

there's a whole bloodhound module

fathom pendant
#

^

#

But also bloodhound is a relatively small portion of what's taught

dire abyss
#

is it in the CPTS path?

fathom pendant
#

A good portion of stuff I've done in the AD enum module didn't require BH

fathom pendant
#

But it's also not really a core requirement, just a nice extra tool

dire abyss
#

dang i wanted to learn it, looks fun. maybe ill spend some cubes to unlock it just dont wanna take too much time away from the CPTS path

fathom pendant
#

I mean if you want to, that's up to you - latest bh CE is docker only afaik

cloud urchin
#

bloodhound is a cheat code for AD attacks

fathom pendant
#

If anything BH for me would just be used for me to mark network/user pwns

cloud urchin
#

idk, in real engagements you're going to encounter giant companies

#

bh makes it manageable

#

there are things bh won't show you though

dire abyss
#

the main reason i wanted to learn is because my NGAV has something similar that maps out attacks and communication between end points. im pretty sure its inspired by BH or built off it.

fathom pendant
#

maybe

shut quest
fathom pendant
#

yeah

#

and other tools tend to do better digging

heavy edge
#

definitely one of the more fun modules

#

BH i dont think would be a cheat tbh. idk aboout you, but i dont wanna write down every bit of info about every account on the domain

#

and then search for attack vectors

fathom pendant
#

<@&861185840277487616>

fathom pendant
#

and it's like "really? i missed that user I have as a domain admin?"

heavy edge
#

i think its good to map out the AD and such and see where possible vectors lie. but its NOT good to consistanly rely on

fathom pendant
#

like any tool -- it's as useful as you make it

heavy edge
#

as it can give wrong/old information

fathom pendant
#

ntm i think BH lights up most AV/EDR? though i could be wrong about that one

heavy edge
#

VT flags it on like 60 of 64 scans

#

so yeah its heavily monitored for

cloud urchin
next bronze
#

that's just sharphound, plenty of collector can do it remotely

#

it's just LDAP queries

heavy edge
#

yeah sharhound will light it up, but what would you reccomend as a replacement

fathom pendant
#

i knew i was braining something and missing it as I just mash the collector and the viewer into one

next bronze
#

bloodhound python or rusthound

heavy edge
#

i mean you could export the entire domain into csv

next bronze
#

or use a PE loader or write the queries yourself

#

there's nothing inherently malicious with sharphound

heavy edge
#

if i load sharphound into my windows laptop rn sentinelone will go off liek xmas carols

next bronze
#

yes because it's well known and sigged, but again it's just LDAP queries

fathom pendant
#

¯_(ツ)_/¯

#

everything done is being done via ldap queries and just exporting that data to a csv/json file

dire abyss
#

is the AD enum & attacks the longest?! i finish one section only for more to appear.. or at least it feels that way lol

fathom pendant
#

it's pretty girthy

dim wolf
#

no need to get surprised over another section appearing, just check the right hand side of the page

fathom pendant
#

but lots of good info in it

#

i think there's like 20 sections or so total?

heavy edge
#

i think AD will be the most needed tbh

#

everything is AD now

fathom pendant
#

some of them shorter than others

dim wolf
#

AD enum is super long, and then there are extra AD modules you can do

dire abyss
#

it is long though, are other modules just as long or does this one take the cake?

dim wolf
#

can't think of anything longer

keen compass
#

Hello, anybody available in DM to talk about : "WINDOWS EVENT LOGS & FINDING EVIL Mini-Module skill assessment > By examining the logs located in the "C:\Logs\PowershellExec" directory, determine the process that injected into the process that executed unmanaged PowerShell code. Enter the process name as your answer. Answer format: _.exe" please ?

dire abyss
#

why the need to DM? just ask in here

heavy edge
#

^

dire abyss
#

i dont think anyone will flat out give you answers but we can do our best to guide you.

dim wolf
keen compass
#

well, i found the ||Calculator.exe|| by searching for ||clr.dll|| with eventid ||7||

keen compass
# dim wolf there's a Sysmon Event ID that you can filter for

i read about parent child relationship so looked for the pid parend even if I don't really know how does the parent could inject the clr.dll without raising an eventid 10. The parent child relationship reveals that ||svchost.exe|| is the parent of ||Calculator.exe|| which indeed looks like an abnormal behaviour.
I don't don't see Inter Process access to ||Calculator.exe|| (ID 10). I don't see any uncommon dll appart from clr.dll (ID 7)
I found powershell.exe running in memory and perhaps the right answer but I don't understand how I can get a like with ||Calculator.exe||

dim wolf
#

there is an Event ID you can filter for that will get you the answer

keen compass
#

yep sorry I found the answer at least I guess I am on the right track

#

||id 8|| looks promising

#

(but I don't understand why multiple answers were talking about parent child relationship in chat history)

shut quest
#

in a strange parent-child relationship

worn parcel
#

Is the academy subscription different then the subscription for the boxes?

cloud urchin
#

yes

dim wolf
worn parcel
#

So subscription to academy don’t get access to machines?

dim wolf
#

no access. the two are separate from each other

desert cypress
#

Well, I don't know what to do anymore, the module boxes are still unusable, I can't move forward in my modules. I've contacted support and no viable answer has been given (I'm still waiting to hear back from the person I spoke to). I really need help, I've still got 1 module left (not counting the one about reporting and attacking network enterprise). It's completely ruining my hack the box academy experience ...

#

and I must point out that it's not coming from my house. I have no problems with classic HTB. I have the same internet speed as when I started the modules.

fathom pendant
#

I take it you've changed vpn regions and everything?

cloud urchin
#

speed doesn't equal stability

desert cypress
#

I've always had the same ISP and no problems with stability at home, for anything other than htb academy

cloud urchin
#

yeah i don't doubt it's htb's side, but just because your internet has been stable for 100 years doesn't mean it'll be stable tomorrow, things change etc

desert cypress
#

I understand what you're saying, but I only have a problem with HTB.

#

and while searching i noticed on reddit and htb forum (recently) that i was not the only one to have this problem

next bronze
#

there was some downtime a earlier in the year but it has been resolved, no one else is having this problem, or this channel would be flooded

desert cypress
#

it's precisely since the maintenance about 1 month ago that I've been having problems.

next bronze
#

and it has been since resolved