#modules
1 messages Β· Page 228 of 1
it's incredible how much they HATE capitalism... to the point of doing that.
but it's beyond me how they do it, without any remorse
do i have to go to school to learn?
i mean to use your services?
i never went to stepped in a school again since elementary
and i will never do, those are just churches of statism. and its ok to not agree with me, but to ask my FULL name, in a hacking purpose community
is beyond me, why is that? explain
I have already warned you once today.
Please go back to the topic in this channel

seems i will never find real people in this city, not anymore
every day something new here lol
even the homeless i met are more into society than me
dude, like is the webpage serious?. full name is one of the worst info you could provide
and a hacker community should be against that
there is no hope into becoming a hacker nowadays
Join thousands of hackers.
Fullname is required
im still stuck there
and the worst part, is that all seems to beautiful and well done.
why the smartest people hate Crypto or hyper-capitalism?
why the smartest devs, are this WOKE
dude i made my account
yeah you're not woke, you're cringe
Final warning
Stop spamming this channel with content that does not belong in this channel
sorry
i just want to learn,
im trying to understand
Step 2: Copy your Account Identifier
Then sign up for the Academy and learn with the modules. Or you could sign up on the main platform and learn there, for example with the Starting Point
does this mean some sort of KYC ? cause i wouldn't be surprised
this: Step 2: Copy your Account Identifier
Login to your HTB Account
i made the account...
This is a Identifier that is available to you in the main platform. app.hackthebox.com
ok
been a wild night
I'm trying this with the simplest possible request (a single GET XMLHttpRequest to http://exfiltrate.htb/?didthiswork=yes )
I can't get the Delivery to work. Has anyone gotten this to work? A Discord search reveals confused people posting the exploit directly into the guestbook but I want to make sure this is actually possible.
Can someone please confirm it's possible?
Edit: I'm on the "Introduction to XSS Exploitation" section
Edit: Solved. For me the lab set up did contribute a bit to my confusion.
When you test it for yourself by visiting /exploit directly, it just shows you javascript code unless you wrap it in <script></scipt> tags.
But if you leave them in there, the delivery mechanism doesn't work.
Leaving this here so it hopefully helps someone else.
put right port into url
Seriously? Why the note saying not to do that? π€ (I'm referring to your message above).
Here's what I've done:
- XSS in guestbook - both with port and without port
- exploit script - with port and without port.
That said, there's always a chance I've missed something so I'll give it another go. Thanks for your help π
Oh I read it wrong, my bad. DONT use port. Some exercises you had to use but this one didn't work if you used if I remember right. But that note should be right
Ah no worries. What's weird is at one point it did work but I can no longer reproduce it. The whole setup feels a bit precarious so I'm not sure if it's something in my script, or if something is being cached behind the scenes somewhere.
I"d love to understand more about what's going on, but I don't have a lot of visibility into the "magic delivery" process.
I've been taking laborious notes throughout this whole process and even with a fresh machine, I can't make even a simple exploit work such that the admin hits the endpoint. I got through the CSRF stuff ok π€
I'm not sure how to launch an official request for help from the HTB team on this. I don't want to go around this by pasting the exploit directly into the guestbook, because I want to learn what's going on, but I don't have the visibility into it.
So I tried again with no port in the XSS (as instructed)
and with no port in the exploit. Still nothing. I'm not sure what to do now, I can't really make it simpler. π€·
I guess unless anyone has any better ideas, I'll do the direct workaround.
Very grateful for your help and engagement on this @snow ridge π
what are you trying to do
Module: Pivoting, Tunnelling, port forwarding. Section: Skills Assessment. Question: I am currently trying to do it using ligolo-ng, I was able to set up the agent (on the pivot host), and proxy (on attack machine). Afterwards, I added the subnet (for internal network) to my attack machine using ip route add.__ However, I am stuck on enumerating further internal hosts when i run nmap -sn <internal subnet> on my attack machine.__
need more info like the subnets and commands you used
also if you're using -sn you might as well just do a ping sweep
did you run ifconfig in ligolo to check what subnet you should be adding?
oh no i dint
well before you pivot, you must know what subnet you want access to
based on this, im assuming i am suppose to access to 172.16.0.0/16
if this is the case, i would have added to my attack machine via ip route add
you just need to add /24
Skills Assessment - File Upload Attacks
When sending the file, the form does so with the GET method instead of POST. Is this part of the exercise or is it an error in the form?
oh why is that so
/16 consists of 65536 addresses, you should start with the immediate subnets before moving to a range this big
ohh yes /24 has only 255 possible addr to scan
check group managed accounts
thks, but for all targets i get the result "are u sure it is running ldap?"
cme ldap FQDN user pas -gmsa
you need to target the dc of course
Feel free to DM me with your payload and I'll try to help out π
Thank you, DM'd
Hello guys
Is the cpts exam voucher has expiration date?
who tf pinged me 
sorry ||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||||β||_ _ _ _ _ _ _ @next bronze


I did on the command or not
cme ldap FQDN -u j... -p 0..... --kdchost
what? I said to use it against the dc, there's no need to use --kdchost
yes got, but all possible combination to dc, or IP of dc gives me this result: are u sure ldap running
what's the ip of dc?
172.16.15.3 : DC01
172.16.15.15: DEV01
172.16.15.20: SQL01
works for me
yes. same command, different output.
Chisel is working here, i can scan smb. so connection is not a problema
/etc/host: DC01 DEV01 SQL01.INLAINEFREIGHT.LOCAL and for all addresses
ββ$ proxychains4 -q crackmapexec ldap 172.16.15.3 -u j.... -p '0......'
SMB 172.16.15.3 445 DC01 [*] Windows 10.0 Build 17763 x64 (name:DC01) (domain:INLANEFREIGHT.LOCAL) (signing:True) (SMBv1:False)
LDAP 172.16.15.3 445 DC01 [-] INLANEFREIGHT.LOCAL\j......s:0........ Error connecting to the domain, are you sure LDAP service is running on the target ?
Happy Easter
yes for all of them
SQL01.INLANE...LOCAL
DEV01.INLANE...LOCAL
SQL01.INLANE...LOCAL
the whole line please
I tried to send it and i got an automatically message. dont send the same message again and again
just the entry for dc, not the other hosts
172.16.15.3 DC01 DC01.INLANEFREIGHT.LOCAL
ok i did it before. I just sent a message to suport. Ill wait for them. Thks for the help
terminate, wait, start && restart
yes yes yes
what does this doo
1 year after purchase
Thank you π€π»
You can find a typo in the text at https://academy.hackthebox.com/module/34/section/306. The Mental Subnetting subject's last paragraph ends with a sentence that needs correction. Instead of using '192.168.129-254,' it should read '192.168.1.129-254.'
Can anyone help me out with Password Attacks Module (Password Attacks Lab - Hard)? I've been trying to bruteforce the user with CME for over 3 hours and nothing yet...
What word list you using?
I'm using the customer wordlist generated using the resources provided for the module using this code here: hashcat --force password.list -r custom.rule --stdout | sort -u > mut_password.list
Check svc_workstations Sudo privs > pass the ticket > password attacks > cpts. I got the flag from the previous question, I have found an aes 256 for svc, I canβt use Sudo -l at all. I do not know where to go nor where to look. Hint is not useful. Can anyone help
What do you mean?
Are you saying I should switch back to David?
Oops sorry, replied to the wrong person..
That doesnβt work, Sudo -l doesnβt work for David either
Taking a break if anyone wants to help im open I appreciate everyoneβs help
@low crescent Did you solve the CSRF Lab component of Advanced XSS in Academy?
pretty sure it's sudo privs
Iβm on Carlos
are you able to get svc_workstation?
I have to step away for an hour or so are you comfortable with me pming you later? If not thatβs cool
look for keytabs
Are you using CME or hashcat? Because you'll want to use different word lists for each
This is for the first step to log in as the johanna user. I'm using CME to brute force the RDP login but no success π¦
for that one try hydra
Hello, I have problem since yesterday with an IP address of the skill assessment of pivoting. I have enter the machine before with proxychains but then got freeze and stop working, and since then I havent been able to continue the lab. Im a silver plan and dont know why i dont get discord answer when i press the bottom for help.
The IP address that i will like to request help is with 172.16.5.35
In Academy: Advanced XSS it states: " Web browsers typically add the Origin header to cross-origin requests to indicate the target origin where the request originated from. An attacker cannot control this behavior." Is this true? I thought with proxys you could change the Origin header?
As Danitsu said, use hydra, it will be faster than CME, or use crowbar.
Im doing Pass the Ticket (PtT) from Linux and im trying the understand the part in where htb is exporting export KRB5CCNAME=/root/krb5cc_647401106_I8I133. Whose ccache file are we exporting? Im asking because trying to import julios ticket.
you can use klist
Finally, I changed from VPN and the machine from the vpn us 1 is not working, i dont know if this is under monitor, if not it should be and restart the machine, it has been stuck since yesterday..
It's better to tell the support
where?
Need some help? Learn how to reach the support team on Academy.
thanks, i send an email
Module: Pivoting, Tunnelling and Forwarding, Section: Skills Assessment, Question: I used LaZagne and got vfrank creds (in the form of nthash and shahash) but it did not seem to be crackable, any nudge?
If anyone would like to join my fortnite group please dm me and Iβll catch up to you later
Are you meant to crack it?
Wrong server bro
im looking at the lsa secrets password section, which turns out to be something outputted by Mimikatz
however it has no indication the output was for which user
It definitely does tell you, if you look closely lol
it just looks like hex dump and its decrypted contents haha, is it ok if i pm u
idw spoil
Nope
Also it won't be a hexdump
If it's a full hash then it'll be a large string but an ntlm hash consists partly of the lm:nt hash and some other data
umm i notice 2 accounts SC_DHCPServer and SC_SCardSvr having "Im w u_"
I don't recall it being that complicated
Also the examples won't always match, and will often omit things that would reveal an answer
examples as in?
ahh ok
Always carefully look at outputs
I had the same issue when I did that module. Chased cracking hashes and such. Reading is hard!
Hi friends, since yesterday I have been having problems with the IP TARGET, it never establishes a connection, does anyone have the same problem?
I ping and all the packets are lost.
Yes, change vpn server
Did you figure this out and can I dm you?
Yes
Hi guys... Anyone can help me with DNS part of Footprinting module for CPTS path? I don't understand why the response of a DNS query type=SOA for a domain is empty but when I do DNS Zone transfer for that domain, there is the DNS record type=SOA... Thanks so much
need help with Vuln-assessment- Nessus Skills Assessment... ive scannned the ip privded WITH nessus and i am not presented with any info that answers the asked questions. it tells to authenteicate a scan under a user(which i did over 5x) and it faills. its stupposed to be windows system but the scan says its linux. please help
(Look at the Kira from the older modules) Iβm so suprised they asked to pull a random password for the protected files lab like wtffff. So left field. Thank god I wrote it all in notion
It's not really
I mean I get it attention to detail but it took me aback
The whole module is all about grabbing and saving passwords
See if youβre skipping around I get the reason
You shouldn't be skipping around a module
Also remove this as its still a spoiler
How do I do that
Delete the message
The Linux labs and Windows labs are connected throughout the module
Which is why I tend to advise that once you get in, to check the C:/users or /home/ directory
They really keep us on our toes
So you can use creds from way early on in the ad enum module way later on
it's expected in the module Β―_(γ)_/Β―
Hello guys i need help
module - Password Attack
Section - pth attack
Question - Using Julio's hash, perform a Pass the Hash attack, launch a PowerShell console and import Invoke-TheHash to create a reverse shell to the machine you are connected via RDP (the target machine, DC01, can only connect to MS01). Use the tool nc.exe located in c:\tools to listen for the reverse shell. Once connected to the DC01, read the flag in C:\julio\flag.txt.
i use the command but not working
my hash powershell3 base64
my hash conf
yes i use the nc other window
im try 1.5 and 1.10 but not working
yup im waiting other window
PS C:\tools> .\nc.exe -lvnp 8001
listening on [any] 8001 ...
nope not working
Hey, for the Server-Side Attacks module in SSTI Exploitation Example 2 and SSTI Exploitation Example 3, is there a way to get a reverse shell in these scenarios? I've gone through each section twice using both the pwnbox, and my own VM with the same results. I've used the payload provided and attempted a base64 encoded command to make sure the special characters weren't causing trouble. The page hangs like it's attempting to connect, but then just sits for a minute before rendering again. I tried the payload with python and python3 as well. I'm just trying to figure out if I'm still doing something wrong, or if this is not possible on these exercises due to network restrictions. I can get command execution fine, but I can't catch the reverse shell at all.
where am i doing wrong
can i send dm bro
"If we addΒ .Β to the path by issuing the commandΒ PATH=.:$PATHΒ and thenΒ export PATH, we will be able to run binaries located in our current working directory by just typing the name of the file (i.e. just typingΒ lsΒ will call the malicious script namedΒ lsΒ in the current working directory instead of the binary located atΒ /bin/ls).
"
how would this benefit in linux PE? since we can just call the script directly in our directory?
i didnt understand this part of linux PE well, can someone elaborate , thanks in advance !
It's because PATH environmental variable will allow you to use those commands anywhere in the terminal, even outside of your current directory
so I will look some more
yes but in the section they say that when adding . we would be able to call binaries located in our current directories
what does that mean, isn't useless to do so if we can call binaries already from whatever directory we in just by adding them to PATH env var
"." just means "current directory". for example "mv /home/directory/file.txt ." will move the file.txt located in /home/directory to your current directory.
yes i do understand that, but let's say we can change the PATH env var and we added . to it so now, we can call any binaries in our current directory right?
no
so what does they mean by this phrase : "If we add . to the path by issuing the command PATH=.:$PATH and then export PATH, we will be able to run binaries located in our current working directory by just typing the name of the file (i.e. just typing ls will call the malicious script named ls in the current working directory instead of the binary located at /bin/ls)"
check what i told you
is 172.16.1.5 your IP?
yes
i don't think so
but i could be wrong
chatgpt says i'm right
now i'm questioning it lol
i guess test it out?
so when you type ipconfig /all it shows you that one of your interfaces is 172.16.1.5
i think i understand now what they mean , basically after doing that ,we can call whatever binaries located in our current directory from whatever directory we in
Generally yeah. If you have command execution you can create a rev shell.
Correct
yes
thanks man for the clarification !
More specifically, you can call whateve rbinraries are located in the path you specified with the PATH env
and with the netcat exe you're specifying to use port 8001?
yes
Even more info: take your 'whoami' command. it's in /usr/bin. if /usr/bin was not in your PATH env, then you would have to type "/usr/bin/whoami" to call to the command. due to the '/usr/bin' folder being in your PATH env, you can call to that command anywhere in the terminal.
one more question, when issuing writing a script with the name ls, and issuing ls in our current directory, why is our script is the one getting executed and not the normal ls listing command
because it starts in current directory, then looks to path
ooh so that's why
yes, its saves us from writing absolute path to run it
similar to when you do a LoLBin with calc.exe by moving calc to a different location - the exe uses the cwd resources then looks to path
ok i think i'm wrong about this
chatgpt says this: When you type PATH=.:$PATH in the terminal while you're in the directory /home/dir, it will input PATH=.:$PATH into the environment, not PATH=/home/dir:$PATH.
yes that's it
but can chatgpt be trusted

its shown in section too
i think it's probably right
ahh yeah there you go
that's kinda dangerous though ngl
yep , still don't know how this can be used to PE, gotta follow next sections lol
convenience is always in balance with security
to see it in action
oh
It's likely using it to bypass any restrictions
i.e. it calls your current path at the front of the PATH variable instead of the end
that's what i thought when you said the script ls getting called first instead of the original one
Have you completed those sections and got a reverse shell? If you have, or know someone who has, then I definitely want to go back and try something else. I can "make" a shell like using a python script to automate sending the request with the template injection, but no matter the reverse shell I run, whether it be a python or bash I can't seem to get it to work. I've tried the "echo "base64_encoded_command_here" | base64 -d | /bin/bash" as well as attempting to run the reverse shell directly in the injection, but it'll hang for a while without me receiving a connection at all, so I'm leaning towards it is a network rule that's not allowing it to make the call out. Figured pwnbox would work because of it being apart of their network, but I get the same behavior there as well.
the pwnbox or your own vm generally doesn't make a difference
as they both use the same vpn connection
I have completed the module and gained remote code execution. With this particular module and computer, I have no idea what other protections there are. Generally when you have command execution on a computer, yes, you can create a reverse shell. There may be some additional things going on that HTB implemented to make it not possible, however.
i imagine you could catch a reverse bash shell with nc or something
I find it worth a shot to see if there are any difference. The Helpdesk in me just trying to cover everything before I start asking questions. π€·ββοΈ lol
Hello Guys, I hope all are doing well. can anyone help me with the following task please: CROSS-SITE SCRIPTING (XSS) Skills Assessment
Since you have then I'm going to go back and walk through it. Maybe I missed something. If I still get the same result I at least got the execution and it's hanging like the connection is attempting so maybe that should be good enough for now. lol I just try to experiment to see what I can do. Thank you. π π
if you can provide what problems you did encounter and what have you tried, ppl will be willing to offer you a hand
if you move on to the example 3, it shows you how to make a reverse shell
Sure, one sc
Yeah, I tried it and got the same hanging. I even did the base64 encoding after the first couple of shots didn't work. Then I looked at the python version and tried it with python3. I'm just hung up on it because I want that reverse shell and not just using cat to get the flag.
I set all requirements that were needed, I reached the comment page, and I started my port listener, but I can get anything
how did you found the vulnerable xss field
if you followed the steps in sesssion hijacking, you should be able to finish it, only thing that you need to find out is the vuln xss field
This is what I did, but I will try again, thank you mate
what is the vuln xss field you found?
this sounds like it'll push into spoiler territory
the field in the comment
lemme double check
i don't think it was in comment :3
Hi all, im stuck on the "using the stack section" of intro into assembly language. The task is telling me to debug the attached binary to find the flag being pushed to the stack. I have dowloaded the zip file like normal and tried to extract but where normally you would get a text file with instructions I cannot seem to open it. I don't know what I'm doing wrong:( Pluma (on parrot OS) says it can't detect the character encoding.
Thanks
it's a binary file, not a text file, so what tool should you be using?
long story short I finished a module that I'm still not certain I did the 'best' way. I was given one target IP and two vHosts for the questions. I was able to get the answer just by editing /etc/hosts and using the same IP but associated to 2 different vHosts/subdomains when the question called for it. However, that doesn't seem like the way this should be done. If i'm given one target IP and need to gather info/enumerate on 2 vHosts....was there a better way to go about this? I'm sure I'm missing something extremely simple here with what needs to be added to /etc/hosts
Hey, has anyone around here done the "Whitebox Attacks" by @upper haven .. Working on Prototype Pollution and I cannot get the "Exploitation of prototype pollution to execute code" through constructor.prototype property on the skill check. π€ Feel like my JSON request is a tad off somewhere but unsure.
Nope that's the intended way, adding the vhosts to /etc/hosts
Thanks @fathom pendant but is it as simple as just changing the subdomain in /etc/hosts with the same IP address being used?
An IP can host multiple subdomains
In this instance it's hosting both those subdomains
yeah that's why i was more/less thinking about having the IP associated to the top-level domain instead of editing to match specific subdomains
but thank you for answering!
That's not always how it works
Also it wouldn't be the tld you associate it with rather the domain
sudomain.domain.tld
oh, right. thanks again
www.google.com
www would be the subdomain
Google is the domain
Com is the tld
it should be gdb right?
yep
i've been tryuing to do that but when I type** gdb./stack** into the terminal i get :Reading symbols from ./stack...
(No debugging symbols found in ./stack)
you did unzip the folder? run file fileName, it should tell you it's an ELF executable
yes i did. i ran ./stack
bash: ./stack: cannot execute binary file: Exec format error
Did both of those
Iβm thinking I missed something in the instructions
But this file doesnβt seem to be behaving like the ones I have previously worked with in the module
Which is super frustrating
I was thinking if I try to do the same process on another distribution
run this, what does it say?
Iβll come back to it soon. My son is back home. Thank you for your help so far
I'm in the Pivoting module, Double Pivot section. I'm trying to do the exercise doing ligolo-ng. I'm running the agent on the first pivot host, established the connection. My understanding is that to access the 172.16.6.155 host, I have to start a listener and then run the agent on the 2nd host. I'm getting this error when I try to connect the agent from the DC01 host, even after adding the listener. I'm I missing a step?
you'll need to connect to the internal ip of the pivot host
You also need to set your routing table to use that second ip
Hop 1 -> hop 2 -> end
What do you mean by connect to the internal IP of the pivot host? When I run .\agent.exe -connect ... the IP should be the IP of the pivot host?
Thanks, I did so also prior to trying to establish the agent connection from the DC01 host
run ifconfig on the first pivot host
This is from the first pivot host, the target spawned on the exercise 10.129.x.x.
yeah so, the second pivot will need to connect to that 172 ip
Thanks, I got the connection now! π
I am on the password attack module. I need some advise with crackmapexec command. When I run it on the parrot vm it working fine, but when I run it on my kali linux, it throws ton of exception errors.
install netexec instead, same thing but better
https://www.netexec.wiki/getting-started/installation/installation-on-unix
Thank you very much XreOus. I'll give it a try.
trying but cant find the answer some hint please MODULE:SHELLS & PAYLOADS --Infiltrating Windows, questions: Gain a shell on the vulnerable target, then submit the contents of the flag.txt file that can be found in C:\
I've tried many ways the eternal blue but it almost certainly isn't, unless I'm missing something.
it is eternal blue, make sure you're setting the lhost right
the local host is the eth0 right?
nope, it's your tun0 ip, it needs to be in the same subnet as the target
it's kind of funny how when you search for cme there's nothing that references nxc, that was kind of infuritating
there's some drama when the fork was created and it's still very new
Passwords are still the primary method of authentication in corporate networks. If strong password policies are not in place, users will often opt for weak, easy-to-remember passwords that can often be cracked offline and used to further our access. We will encounter passwords in many forms during our assessments. We must understand the various ...
I've been trying for like 6 hours straight and I feel like a fool right now haha, thanks brother for the hint, now I can go to sleep.
does anyone know how to convert a guid into the group name? the powerview module says to use get-gpo but that cmdlet doesn't seem to exist
:p
ran it and got bash: run: command not found
i did it without the run command and just typed in file stack and got the same output as you did.
apologies
yeah so run it through gdb
ran it through gdb and got this: Starting program: /home/fred/Desktop/stack
/bin/bash: line 1: /home/fred/Desktop/stack: cannot execute binary file: Exec format error
/bin/bash: line 1: /home/fred/Desktop/stack: Success
During startup program exited with code 126.
download it again and unzip it, check if the hash is the same
md5sum stack
90b443ce5fb71650b9b99f1277933642 stack
Will do thanks
Has anybody finished the NoSQL injection? Assessment 2. I have the injection, and have been progressing manually, but the data I am extracting is 60 characters long... can anybody help me script this?
hello, does anyone know if you can launch a skill assessment after your subscription has ended? I've been trying to launch one and it doesn't seem to launch
nvm, it just spawned
Hello everyone, quick question. Lately I've been having issues with running secretsdump.py
I get the same output every time
Impacket v0.11.0 - Copyright 2023 Fortra
[-] unpack requires a buffer of 4 bytes
[*] Cleaning up...
Could anyone please help with this ?
The method I used to exfiltrate the SAM,SECURITY,SYSTEM file was a nc method, but I double check and the files are transferred completely
I'm currently trying to exploit HiveNightmare.exe in the Windows Privesc Module
something is wrong with the files that you transferred out, make srue they're not corrupted or no data is lost
also run it with -debug
ooh the -debug is useful
thank you, okay I will try exfiltrate using a different method
As usual, @next bronze you are incredibly helpful. There was indeed something wrong with the way I did a nc transfer, Ill have to revisit that. Exfiltrating using powershell to an upload server proved to work better
the thing is, the victim host doenst always allow exfiltration through smbserver so I had to find another way
I like to use http servers, haven't failed me yet
or yknow, use this, whole thing is automated, just run the exe
https://github.com/Xre0uS/MultiDump
uuuuuuuuuuuuuuuuuuuuuh.... NOW we talking
yes so I just used that PSUpload
yep that's what I usually use, easy and always works
Damn, Im looking at Multidump and wow.. Well done you for writing that! very very very amazing. Let me play a bit with it, but if it works as well as I think it does, that is being added to the arsenal RIGHT AWAY
okay, I guess I can no longer avoid it. I never really saw how to build a binary like yours for example using visual studio. I dont know how Ive lasted til now without doing it but I always found a compiled binary somewhere. Now Im forced to do it.
it's a good thing to learn and very straightforward with VS
yep.. on it
aaaaaaaaaaaaaaaaaaaah I see
wow, a whole new world of projects (without binaries available) has just opened up
hahah
yeah literally just double click the sln file and build 
im going to crazy i use diffrent tool diffrent port why not working
i want to go dc01 from ms01
aaah is multidump only a "quickdump then automatically exfiltrate" kinda tool as opposed to just an exfiltration tool
it does both if you use remote mode
say I have this situation in windows
-a---- 4/1/2024 12:32 AM 65536 SAM-2021-08-07
-a---- 4/1/2024 12:32 AM 32768 SECURITY-2021-08-07
-a---- 4/1/2024 12:32 AM 12582912 SYSTEM-2021-08-07
How do I exfiltrate those using MultiDump?
the main purpose is to dump lsass without being detected, then I added functions to exfiltrate the data and also dumps the registry
I'm not familiar enough with SMBExec to know if it decodes that, but it looks to me like you're sending a system command encoded in base64 with 'powershell -e'. powershell -e isn't a native command, so that doesn't do anything (unless smbexec somehow gives it that capability). you'd probably need to run powershell -encodedcommand is my guess.
it doesn't do only exfiltration, so you can't give it an existing file. run it with --reg if you want to dump the reg hives
Your base64 strings looks odd.
aaaah thats what I meant. Yes because using the HiveNightmare attack doesnt necessarily require you to have admin privileges. Thats what I mean. But you need those to extract with your tool I take it
Feel free to DM me if you're still stuck π
im doing the last flag for the LINUX01 I have found it but its not working am I allowed to paste it here?
@upper haven can you give me a push on advanced xss & csrf skills assessment? i can read bits of the api but can't find a place for sqli, is that the right next step?
let me try pass the hash, get the creds, then play with your tool to get familiar with it
yeah, if you already have the saves then just transfer them out with any methods. the purpose of my tool is not just to transfer stuff
Powershell #3 (Base64)
can you send a screenshot of it from the revshell site.
that exercise is a bit weird from what I remember
the only thing i remember is the starting of the bs64 string.. and his doesnt look like that
Actually the command works but the shell does not give
fully get it. And it's great. Thank you for that again. I have a YT channel, next box I do where Ima have to dump SAM/etc, Ill 100% make sure to plug that tool for sure
im doing the last flag for the LINUX01 kerberos ticket I have found it but its not working am I allowed to paste it here to check if right or just box is glitched?
sweet! thanks 
module and section?
password attacks /Pass the Ticket (PtT) from Linux
It is already bs64 encoded, you are just encoding it again.
the question tells you what the flag starts with, does it match?
maybe read it again then
thats work
Sure thing π Have you identified an additional API endpoint? If so, identify potential injection points and keep in mind that web applications can catch SQL errors and the error may be invisible to you. If that does not help, feel free to DM π
ok, but in \DC01\linux01 there are no other flags. Where else to search?
yeah as in read it again to make sure it's printed correctly
hi guys, i have a question regarding the trickbot.pcap suricata rule question..i tried both JA3 hash but it seems that both works when checking the pcap file via suricata..i wonder why the other is the correct answer when it should be both
I want to make a tip for the future. I did find the key the only it needed to delete the space between the letters and add U letter from the hint.
huh? there's no space anywhere, also not in the hint
hi there π performance issues again for EU ?
doing Attacking Enterprise Network Question Steal an admin's session cookie and gain access to the support ticketing queue. Submit the flag value for the "John" user as your answer. I already got a cookie but it doesnt log me in even if i set the cookie
got ittt already
probably a bot
Guys you know when attacking thick client with x64dbg. I caught the 3000 rw thing but where do I right click to dump it executable?
It says right click the address but theres no dump option
you need to go back to the memory map tab
and then right click on the address.
yah, the section didn't mention that.
what is moving?
The memory map isn't paused. It says its paused and exited but its still dancing. I had to lay in wait to click the right one when it appeared

I don't think I'll have time for a right click but if this is what it takes

Okay so, if you click the column header to sort by type, they dance and you can't catch them to click.
If you leave it as it is when you load the file, they stay still. π€·ββοΈ
Thanks for the tip!
Weird section 
brace yourself for the next one
Is anyone having problems with the 'Active Directory Enumeration & Attacks'. The modules that requires RDP, they just don't work for me, from my own VM and from the attackbox
Oh no...
What do you mean by dont work? Do you get any error message? I had connection issues from my own vm, but attack box always worked?
Sometimes it connects but i get a blackscreen on xfreerdp, sometimes it does not connect at all with connection refused error message. For me it is almost luck based, as I'll have keep restarting the lab and try again until it works. But even when it eventually works it sometimes disconnect and doesn't let me connect again and I had to keep restarting and try again. I'm almost at the end of the module doing it this way but it is a very frustrating experience
Have you tried reaching out to support
If it connects and you get a black screen, hit enter, thats just a windows thing. My experience is, that the connection tends to be a little bit instable. Attackbox worked best for me. If thats not option to you, i recommend using a TCP VPN file.
If you get a black screen: just hit enter
Specifically thats a domain joined windows thing, it's the "you promise to use this computer as intended" type agreement
I see. I get the black screen alot, but didn't know you can hit enter to go pass that. Will definitely try that, because i get a lot of the blackscreens
Blackscreen = good it works
It's a very common issue
Sometimes the agreement screen doesn't show up
You can also resize the screen and it usually comes up
Thanks guys for the tips. This will definitely help me get through the last few modules
3 to go
whats HackThebread
Hey when i run evil-winrm through proxychains i'm getting this error
Error: An error of type OpenSSL::Digest::DigestError happened, message is Digest initialization failed: initialization error
I didnt find any work around, does someone know what's the problem here ?
Hello, I just completed the HTML section of Introduction to Web Applications, and your question asks for the tag for an image. The only correct answer allowed is <img> when technically <img /> isn't wrong either. I still got the cubes for it, but just a little thing,,, is there a way to make both answers correct for students?
That is why <img /> is not correct
so it can be broken by the src info... π€ I hadn't thought of that, to be honest... I know the order technically doesn't matter, but had always been taught src followed by alt, not alt followed by src... Now I see how it could be an issue. π€ π±
I have enough cubes for an additional module after finishing the cpts path, which one do you think would be more beneficial, powerview or adcs?
hey guys, i am stuck on the module "Password Attacks", the section "Attacking LSASS", the questions asks "Apply the concepts taught in this section to obtain the password to the Vendor user account on the target. Submit the clear-text password as the answer. (Format: Case sensitive)" i dumped the lsass.dmp file and moved it to my attack hosts but i am stuck on pypykatz saying "parsing file" it has been stuck for there for quite a while now.
update your pypykatz, don't use the verstion installed with apt, check their github repo
Thanks i will try
Hello guys,
Have you ever experienced RDP problems in this module?
https://academy.hackthebox.com/module/147/section/1639
Pass the Ticket from windows
password attack module
its still stuck
Module:NTLM Relay Attacks
Skills Assessment
i have problem with second question i have compromise BACKUP01 but when i try the same commands i cant get a shell can anyone help
pypykatz latest version?
the directory lists from Seclist is not bad
maybe you try /home/user/lsass.dmp im use this command
I can connect to the machine with Remmina, which I cannot connect to with xfreerdp. How is this possible?
Hi everyone.
I am just stuck on the medium lab of the footprinting module. I just mounted a share to my host and found some tickets*.txt files. what to do next?
i just used mimikatz
hi did you solved it?
Thank you π
Hi am just stuck.
Um read them?
Then look at the file sizes
there is def one of them thats different in size then others
ok
You can also cat * since the rest are empty afaik.
And scroll through until you find the right one.
found it
Bruhhhh. The next one is poo
RIP 
π’
Defn one of the worst section.
thank you i just found the right one got some creds. going for rdp
I'm at the stage where its time to edit the Invoker file to download fatty-server
It says to edit the one in fatty client new.jar.src
I was thinking it threw me a curve ball
Nevermind
from the file creds al* lol12* am using these to login MSSQL studio. is it right?
and were you successful?
so look somewhere else.
think smaller, check the C drive, folders and whatnots., just click stuffs.
ok
can someone give me a hint for the prototype pollution part of the whitebox attacks module? I have finished everything in the module except that one question.
I don't know how to formulate the answer in module Introduction to MSSQL/SQL Server
Is there anyone who solved it?
I got the answer but don't know how to formulate it
hello guys i have question i learning kerberos protocol and this output base64 keys equal .kirbi file?
@soft cedar Dude
I'm lucky to be a software engineer but that seems like it would slay anyone who wasn't
Onto the SQL part
is this code wrong or does this need sudo priv to work
coz i can't get the clipboard content
that's great
sa creds found but not working with MSSQL ?
is there anything am missing
what creds is that?
sa:???
it should work.
what should be the server name
when auth, choose windows authentication
why or how can we see that: "From the output above, we can see that only administrators have full access to the LSASS process, as expected."
because they have the FILE_ALL_ACCESS permission, which no other group has
FILE_ALL_ACCESS
Hi I got stucked at thsi question. I Used the premade board as well as my own. This is bullshit ..... the quetion is: Navigate to http://[Target IP]:5601, click on the side navigation toggle, and click on "Dashboard". Extend the visualization we created or the "User added or removed from a local group" visualization, if it is available, and enter the common date on which all returned events took place as your answer. Answer format: 20XX-0X-0X
I am using last 15 years with timestamp, event.created, event.ingested
what am i missing?
I don't know how to formulate the answer in module Introduction to MSSQL/SQL Server
Is there anyone who solved it?
I got the answer but don't know how to formulate it
?
guys , tf is with server logo , pleaseee i have ocd damnnn π
hi guys, Iβm new here. what are the best modules to start ?? i have no knowledge of linux etc..
thank you.
sry if my English isnt perfecrt im from italy.
best place to start is the Information Security Foundations skill path
ty
if you're looking for more blue-team oriented content, check out the SOC Analyst Prerequisites skill path
rn im doing the learning process module
hello i'm pretty much beginner. Is there any fellow-noob here interested in doing pwnboxes together? I'm currently at startingpoint. Also i'm downloading the parrot iso and setting it up with qemu so I don't have enough time to complete any boxes today. But perhaps for the near future if anyone is interested send me a message, i think it is more fun together.
You don't do pwnboxes
Pwnbox refers to the in-browser vm
Password attack lab - easy. Used the custom rule for a mut password, running it on ftp since itβs faster against the given user name list. I have a feeling itβs one of those wait and see ones. Thoughts? I donβt want to waste my time
Hydra l username list mutated list ftp ip on t4
Always analyze and examine to make sure you're attacking it properly. Make sure no ports are allowing "anonymous" login
Don't lower threads my dude
-T 48 is the most stable and fastest threadcount
I meant 48 sorry typo, we spoke about this a few weeks ago
Also -t is a different thing than -T
Iβm on my phone
Just making sure for clarity
Sorry for the short hand
Iβm assuming use the given user name list and mutate on ftp basically
Perhaps
well how do i call it then? i'm at Tier 0
I'll have to double check my notes on it
Hello
Ok Iβll just wait itβs only been 5 minutes
You mean starting-point?
That's part of the main site read and follow #welcome ti access more of the server like #starting-point
mmm ok
like I said always make sure you can't anonymously log in first before attacking it Β―_(γ)_/Β―
There may be a somewhat faster answer in there
I genuinely forget this lab though
can I dm anyone at ADVANCED DESERIALIZATION ATTACKS Skill Assesment? Thx in advance
i have a stupid problem in the mass idor enumeration in web attacks module
i found the uid and a .txt file for the flag
but when i go for it i get a webpage opened with no interesting content in it
These labs got me sweating like Justin beiber at puff daddyβs house sometimes I swear
Just gotta exercise patience
Amen
I'm doing Sherlock: Recollection. I unzipped the file and there's a file called recollection.bin that i have no idea what to do with. Anyone?
I've been stuck on this question from the SOC path for a couple hours
Navigate to http://[Target IP]:8000, open the "Search & Reporting" application, and find through SPL searches against all data the port that one of the two C2 callback server IPs used to connect to one of the compromised machines. Enter it as your answer.
I've been looking for the SourcePorts with the DestIp of the two in previous answers to no avail
hey quick question abt powreshell
Get-ObjectAcl "DC=inlanefreight,DC=local" -ResolveGUIDs | ? { ($_.ObjectAceType -match 'Replication-Get')} | ?{$_.SecurityIdentifier -match $sid}```
after the first pipe we used () inside the { } but not the second time, why? π
The use of parentheses around script blocks in PowerShell is optional and a matter of personal preference or code style. It does not affect the functionality of the code
Thank claude. Maybe you should ask ai for questions like that next time. Can someone help me with my question that ai can't help me with
lol
just try the sourceip
lolll
Do you know the name of the site that teaches bash hacking skills through those "leetcode"-like exercises?
I had it bookmarked but lost it; I thought it could be useful.
I can't believe that between me, htb forums and claude opus could not figure out to simply use sourceip. Wow. Thank you
if it's a C2, it's most likely sending commands from the C2 IP to the target IP
Makes sense. Completely overlooked that
anyone else feels like the Introduction to Networking module (at least the first section) talks about, and mentions way too many concepts that people that are new to networking will not be able to understand or learn as a first introduction to it?
WINDOWS PRIVILEGE ESCALATION , great modul so far, but the windows host is lagging very much...
rdp conenction goes down a lot...
try changing vpn i personally had similar issue i had to type half a command then disconnect and then type the other half then disconnect and connect and keep going in a circle
it's worth a shot..but i've already chossen the best one...
Yep, I have
using tcp for the connection?
any idea why these creds arent working? AD attacks, DCSync section
udp
try tcp
i swear im banging my head against the wall, wtf is going on π
it is way better! thanks
Username:password, they worked fine for me
u mean?
ssh htb-student:HTB_@cademy_stdnt!@172.16.5.225 ?
yes
didnt work
don't specify the password, it will ask for it later
'wrong password'
why is not work i dont understand
i think you should wrap the tickt file name with " "
works π thanks
wlc :).
Are u using that command in the MS01 powershell console or your linux vm
Can I delete the download for kali Linux
the MS01 console
what do you mean?
what π
Can u delete the download for kali idk
i'm not sure what that's supposed to mean.. do you mean the kali vm on your computer?
I confused the ticket name with the file name. π
i just wanna finish this section man π
can you help me with the rce pollution part?
Do you mean deleting whatβs you already downloaded in kali?
check for trailing whitespaces kekw
trust me i did
the creds work, probably a layer 8 issue
are you following the instructions correctly
@shell ore feel free to dm me the issue that you are having
8? You mean h00man?
yeah, its litterally just ssh π
try resetting the lab and resetting the VPN
sometimes works, dunno why or how it "just" works
could I DM you about something related to Pentest Path?
tried
it worked, @autumn pilot, appreciate it 
what was it?
you can ask in the #cpts channel
No the download to get the application
I would really prefer DMing sb
And you seem pretty active hence me asking
what?
the ππ» = okay to DM you or "ok good luck"? Just wanna make sure π
litteraly no idea
Kali-Linux-2024.1-VMware-amd64
Tech Experience : p
the goat just fixed it π
you want to remove a download... from the Kali website
yeah go ahead
can anyone help me on USING WEB PROXIES, on ZAP Fuzzer??
yeah.. this isn't the place to ask.
not to mention that it's most likely illegal
Guys, I have a small question regarding an exercise on the CPTS path, can someone help me?
ask your question, no need to ask to ask
In Linux Privilege Escalation specifically in Shared Object Hijacking. I have a doubt regarding the answer I have to give because I have already done the process that htb tells us and I am as root.
The question in question is:
Follow the examples in this section to escalate privileges, recreate all examples (don't just run the payroll binary). Practice using ldd and readelf. Submit the version of glibc (i.e. 2.30) in use to move on to the next section.
When validating with ldd and readelf I do not find this information.
is glibc a binary?
does the mysql section take a while for the db to connect on attacking commons svcs
solved but thanks
it's a library, GNU C lib
is there a problem with the vpn servers or is it just me? I have terrible connection issues
oh wait you're asking someone else 
so i found some msql hashes but what do i use to crack it with? john and hashcat do not crack it
common svcs lab btw
skills assessment?
is should be crackable. attacking sql db right?
yes sir
make sure you copy the whole hash.
wot
copy everything. starting from ms**

henlo,
can someone help me with Attacking
Common Services module. I am stuck on second question of attacking ftp. how do I find the username?
https://academy.hackthebox.com/module/116/section/1165
did you nmap the ip? also did you take the previous module labeled password attacks?
yes I nmapd the ip got the port
I am stuck on some part of the previous module so thats on hold for a while? Is it necessary to finish it first?
I am using hydra rn tho, I have used hydra and crackmapexec before
i woul ddo the entire password module as this brings some of it with you
also make sure you run -sC
youll see some info
Ive run this.
after that I ran nmap -sC -sV -p2121 <ip> as well
I see.
one second
@heavy edge I ran the hydra command and it says 1 password found. ran with userlist and passwordlist
there were 26000 of these, how do I find the valid one π
sorry for this newbie question
im scanning the IP rn one sec
oh okay
okay so
i just scanned the IP with the -sC flag.
and you should read the first half of the section
wait Ima respawn my service, it said host down
id read the first half of the ftp section, and from there youll find what you need
there is always something you try before you do anything else post ftp nmap scan
okay wait its scanning
read the first half of the article
should I paste the scan result here?
I have in the footprinting module
just anon login

see when I try
ftp <IP> 2121
instead of prompting for username it goes straight into root
ftp ip -p 2121
what am I missing? if I remember correctly it should ask for a username right?
uh i dont think -p flag is needed
if you are using a nonstandard port for ftp it is
iirc if FTP runs on a non-standard port, it's required
kek
ftp 10.129.40.164 -p 2121
usage: ftp host-name [port]
ftp> username: anonymous
?Invalid command
not working for me
cant even post Screenshot here but
ββ[eu-academy-1]β[10.10.14.243]β[htb-ac-883403@htb-plsvlrjuxd]β[~]
ββββΌ [β
]$ ftp 10.129.40.164 -p 2121
usage: ftp host-name [port]
ftp>
dont just mash enter
wait till the username comes up
then go. the box takes a bit to load
uh wdym?
when it loads theres a bit of waiting time. you can type anonymous and then enter when its a blank screen
nah its instant for me
it will bring up a pw box
i wonder what ftp is running on the pwnbox..
i was thinkng the same thing
guys thanks for the help but I'll do this tomorrow, its 3 am already.
I gotta sleep
thanks again for trying, if I cannot figure it out, Ill again be here tomorrow. GN frens
head to #welcome to verify your account
You don't specify port with -p for ftp
You literally just add the port after
Thats what I did man
You don't need to*
But also wait for it to load
Wait for it to ask you to put in a name
Okay
I'll retry tomorrow. Almost 3:30 am
Hi Guys! anyone could give a hint on the 3 question of the "Credentials in Object Properties" I have been stuck in here for a while :C
does someone know any cmd commands that can make me admin on my computer i got locked out π¦
ask in the baking channel
are there even account lockout bypasses?
im in the passwords module on https://academy.hackthebox.com/module/147/section/1315 . i followed along with target and pwnbox. i reset the machine. serveral times i am posting picture of me trying to dum lsa hashes from target it says absolutely nothing and is same command as lesson does
linux ignores characters like '@' in the console. try wrapping the password in single quotes 'like this'
genius
i forgot all about that there was some other charachters that has done that to me before to
I'm working through Shells & Payloads: The Live Engagement, and I think the version of msf that is on the foothold machine is incomplete. I can't find the necessary exploit to throw, and I can't run an update to try to get it onto the foothold box because it doesn't appear to be connected to the actual internet. Any suggestions?
This is for Host-02
You cab still use it
use (exploit name)
i already did the module, all exploits are there, you just cant find the correct way, i personally had to look for walkthrough because the rdp was so fucking slow and unbearable and couldn't do shit
Can someone help me understand how to find the zones in active subdomain enumeration
I did the nslookup any and axfr zone transfer test and it returned some subdomains but im not sure how to identify a zone. Or am I going in the wrong direction
Did anyone found the TE.CL section lab from HTTP Attacks module a bit contradictory? First TE smuggle is shown, then you force WAF to fall back to CL, not sure how the second GET request to admin is not blocked by WAF since CL stops body block after 27\r\n (from the example)
You're thinking in the wrong direction
The number of zones is small
You have exactly what you can transfer to as the zones
@fathom pendant i know the answer already but im not sure how to get there as I dont understand how to identify the actual zones. Am I at least using the right command to identify the zones?
The zone is what's holding the records you see, and the other zone you could transfer to has 127.0.0.1 indicating its on the same server
Ok so then the dns server is holding the records correct?
Sort of, but yes
So that would be considered one zone
Would the other zone be root.inlanefreight.htb?
That's the administrator email
It's literally the other zone you transfer to
The i*.inlanefreight.htb and the inlanefreight.htb domains
i cannot for the life of me crack the administrator hash for the hard password attack lab
dumped the sam backup and got the hashes but john and hashcat aren't working
And you used both .Save files in there yea?
@fathom pendant now im really confused. So why is it those two?
From the perspective of the server you query, one has 127.0.0.1 (localhost) relative to the server
What wordlist are you using? Have you tried multiple wordlists?
Also hashes can have multiple uses
You don't always need to crack it
@fathom pendant wouldn't inlanefreight.htb have that local host
sigh
i mounted the share to linux and got this
Tried mutated, and rock you. Hashcat said cracked but didn't show a password and now I keep getting "All hashes found as potfile and/or empty entries! Use --show to display them." Even with the --potfile-disable flag
Multiple subdomains can exist on a server
Go into the potfile and delete the entry
@fathom pendant ok that one i understand
When I say relative, I mean - you are asking for records regarding inlanefreight.htb using the ip as the nameserver to resolve. You see that another entry has 127.0.0.1
Already deleted it. I'm just going to restart the VM
So relative to the inlanefreight.htb server, the other subdomain is on the same host
@fathom pendant and that would be i*.inlanefreight.htb?
Yes
This lab makes me want to pull my hair out, every step is like 45 minutes of troubleshooting
@fathom pendant and I can tell that they are on the same host by using nslookup correct?
Hey I'm stuck in RFI of File Inclusion module. Targets IP is not working
Or by just using your eyeballs
@fathom pendant how is that though?
Literally the entry for i*.inlanefreight.htb when you query inlanefreight.htb has the 127.0.0.1
127.0.0.1 is a reserved ip to refer to localhost
@fathom pendant well i know that
(Similar to ::1 for ipv6)
@fathom pendant thats the loopback address
So if the other entry is on the localhost...
Loopback/localhost
Point still stands
The entry shows that, according to the records you see: the other zone you transfer to is on the same host
@fathom pendant so then how would I identify zones using a website like facebook as an example
It's hard to determine because you don't quite know what their infra is like
And you generally never need to dig into them
@fathom pendant so then how is identifying zones useful?
Because you might find subdomains that you otherwise couldn't see
But again: that goes beyond the scope, and you'd need to refer to whatever company you're trying to sniff at's bug bounty program
Sometimes those extra domains are outside the scope of the bounty program, and can lead you to legal trouble
@fathom pendant but if i were to identify the zones on facebook then can I expect them to be on the same host?
Maybe
It depends how Facebook has it structured
Zones are an administrative dns tool
I linked a cloudflare article earlier
The point of the question is "don't overthink"
@fathom pendant yeah im going to read it. I dont think I fully grasp it to be honest with you but im trying.
And you're focusing too hard on it
Should I just move onto the next set of problems then?
Zones can be useful or useless, it all just depends on scope. As shown in the section, text records might reveal things they shouldn't
I.e. what if the flag was actually credentials
Yes
Ok will do. Thank u again ur always so helpful
this is so scuffed
Managed to get the user, crack it's password, used it on ftp to get the file, Now I don't know what to do next.
https://academy.hackthebox.com/module/116/section/1466
Take a step back and take a break
Probably a good idea
The file seems interesting regarding how the server may be set up
Tried to upload a file but don't have the relevant permissions
I will tell you, everything you need to know has been taught to you up to this point
Check if those creds work on other services
MySQL works and RDP doesn't.
Tried shell upload via MySQL also but relevant permissions don't exist
Or you're looking in the wrong places to upload it
sorry, but i cant message in the general channel, i havent messaged in this server ever so i dont have a ban. can someone help me out here
Read and follow #welcome
I reloaded the page, the VPN and it keeps loading my IP, does anyone know how to get out of this?
anyone else having issues spawning instances for modules
Target: Target is spawning... forever 
rip
bro this is sooo annoying
i cant authenticate to any host even after responding

Server Side Attacks: SSRF Exploitation Example
-I'm like right there but can't find this damn flag. I have shell and can see whats in root (internal.py, internal_local.py, start.sh) and have cat'd all of the but I see nothing. Any help would be awesome!
test in the virtual instance outside your own virtual machine
im in the Pwnbox now
Hey I accessed flag.txt in exercise directory but dont know how to view contents of flag.txt.
Here's the url
http://<target ip>/index.php?language=http://<my ip>:<port>/shell.php&cmd=ls /exercise
This is #starting-point but short answer: ask support on the website
Ok thanks
You can ls, can you cat?
I reached the flag I used cat /exercise/flag.txt
π
In meow I'm having a error to execute the Open-VPN any advise?
Read and follow #welcome
Then use #starting-point
I really need advice for getting the right hash for the password attack hard lab
samdump on the vhd gives null hashes and every technique the module goes through for windows machine requires elevated privileges
Can't find anything online
Shouldn't be null, maybe recheck that nothing got corrupted in file transfer
You used both sam/secret that was in the vhd yeah?
I just did this one as you were having the exchange with @fathom pendant , finally got it. LMK if you still want to bounce some ideas when you get back to it.
Active Directory Skills Assessment I
||Has anyone else encountered this issue? I'm unable to RDP to MS01. I've restarted the lab, tried with both Remmina and xfreerdp. The credentials are correct and I do have connectivity - I'm able to run nmap scans on it. I've also tried adding the /ignore-cert flag and still no luck. Any help would be appreciated.||
I'd delete the image/redact the username and pw as those are still answers
I didn't have issues myself with it though
Did you try INLANEFREIGHT/<username> ?
I did.
Try putting your path for the drive mount in single quotes
Also try doing it without mounting the drive and see if it goes through
Still nothing, I haven't had this issue on any other lab.
Try resetting the lab and trying again or try using a different pivot?
I've done all those things, tried bother ligolo and chisel
Yea, which is weird becuase those are the correct credentials
Hey.
It's not
Check your answer to q1
And check your screenshot
Then check again
I had to check my answers bc I was like "something feels off"
I didn't do assessment 2 yet
Guys! I'm a little stuck in this question as I can't generate the right event.
I need a hint to solve this please, I've been working on this with no solution π¦
Do I need to change the settings of the user on the server? someone a hint please
This is from the "Credentials in objects properties" module
Does silver/monthly subscription allow you to access silver/gold modules/path or only annual?
hi
@soft cedar sa:???
these creds are not working by selecting windows auth and also the server auth.
can you send a screenshot ?
ok
or you can log in as admin via rdp with those creds and open mssql, that also works.
let me try
nothing happened
that is sql injection, not windows. click on the drop down arrown
windows dont have administrator account as sa....
also did by selecting wind auth but it automatically selects alex and trying to connect
yes that's because you are not admin.
in the ticket file i just got normal user creds
do you mean i have to use that pass as a admin
sa in windows is Administrator
I mean when logging in you will have to modify the creds a bit.π
loggged in
Does silver/monthly subscription allow you to access silver/gold modules/path or only annual?
okay so now you can enum the db, if you have problem with the interface, you can always use the linux impacket / sqlcmd.
ok am just exploring the folders
guys
monthly subs give you cubes, which can be used to unlock modules
so it doesn't give you access to the pen testing then?
Learn about the different Academy subscriptions.
it does, you can use cubes to buy modules
can this be a command
/academy-subscriptions
i subs student 8/month
got full access to CPTS path
upto Tier 2
i got to pay Β£53+ to get same access u do
also you can
gay af
you need student email id
dont start uni for 6 months
without student email you cant subs
Use the help page that I sent you to find such information
There is conflicting information
On your site it says that I can use a student email, but somewhere else it says it's only the listed educational organisations
which is it
what's the "somewhere else"
Carefully read what it says there
...If the student plan remains unavailable after changing the email on your account to be your academic email, or if you do not have an academic email, please contact support.
dm'd u the image
"If the student plan remains unavailable after changing the email on your account to be your academic email, or if you do not have an academic email, please contact support." This suggests it can be any educational email
The other piece of information suggests it's limited to whitelisted educational emails
Reach out to support please, they will be able to assit you
π€¦π»ββοΈ
Hi all, Iβm struggling with hard lab from attacking common services module. It seems that even though I may have impersonated john, heβs not in sysadmins group so I canβt enable xp_cmdshell nor do any other operation to access the flag. I followed instructions from academy on impersonation. Did it both from cmd windows (after rdping) and mssqlclient.py. I even found one metasploit module and it said that neither john nor simon are sysadmins. Any clue what Iβve been missing here? Many thanks
if you cant really do anything with that user, look somewhere else..
have you check for linked servers?
Yes. I found 2 servers, one seems to be linked.
Im just a bit confused because one of the questions suggests I should be impersonating john
and you have done that but you can exec commands or do anything.
has anyone hacked hackthebox before
so perhaps try this.
Could you please be more specific? Try what exactly?
your end goal is to escalate your privileges.
you might be able to move laterally if you gained access to a linked server.
Any specific way you could recommend to move laterally here?
it is shown in the sql section, the last sub topic I think.
kindly refer to the module.
I will try again, thanks. Itβs just I canβt seem to be able to use any of the mentioned commands, such as bulk , openrowset etc. due to lack of privileges
Like a vicious circle π
where from all these commands? lol
Im executing them from john impersonated account (allegedly). Should I execute them from linked server or at least make it look like that?
if you have linked the server then execute the commands on the linked server.
Ok. Thank for very useful tip. Iβll be fighting with this case the upcoming evening.
for the What is the flag value located at \\dc1\c$\scripts? question on WINDOWS ATTACKS & DEFENSE: PKI - ESC1, im trying to run the openssl command after importing the cert.pem file to the kali machine from the Windows one. i've been trying every combination i can think of and keep getting this error:
003448604A7F0000:error:1E08010C:DECODER routines:OSSL_DECODER_from_bio:unsupported:../crypto/encode_decode/decoder_lib.c:101:No supported data to decode. Input type: PEM
any clues as to what im doing wrong?
my cert.pem file might not have the right formatting... these are the (shortened) file contents
-----BEGIN PRIVATE KEY-----
MIIEpAIBAAKCAQEA5j33yZbsQEuxABp6jot1MKfjSRLOkTaDehbYbDjSRY2zUX3h
0WWHez3KOb5ql/tlGe4PZ9KTQLlyL9ksTKG2hcZ4Qe8CeZITEsZfqDFFYnIhZCMu
...
wEllkmxW7uR1JAIfLG7WMS/O3zGLW4D1WmEUMP7IzeuKKn28+M+vuel9G7w7kt8o
0gV1JdIDQDYnGcYUQO2HdAIZVaYeH3C7CMokFXxpYI3nInxwEq/9yw==
-----END PRIVATE KEY-----
-----BEGIN CERTIFICATE-----
MIIGLzCCBRegAwIBAgITFgAAADqZoTLtUlWdCAAAAAAAOjANBgkqhkiG9w0BAQsF
ADBFMRUwEwYKCZImiZPyLGQBGRYFbG9jYWwxFTATBgoJkiaJk/IsZAEZFgVlYWds
...
htMH/mWNKf7JvA5Oi+jQQ/3PnVmBwCgKfhz/kjYL/ZYDQ/MCrF/uonR1qYYbMJCy
PuKQ
-----END CERTIFICATE-----
it was moving so fast
